Autovena
Features Pricing Integrations Contact Start Free
Legal

Privacy Policy

Last updated: 29 July 2026

In short

Autovena is workshop management software. We process the data you and your team enter to run the service. We do not use advertising or analytics trackers, and we never sell your data.

[email protected]
Contents
  1. Who we are
  2. Scope of this policy
  3. Our role: controller and processor
  4. Information we collect
  5. How and why we use information
  6. Camera, photos and scanning
  7. VIN and vehicle lookups
  8. Authentication and device security
  9. Push notifications
  10. Cookies and similar technologies
  11. Analytics and advertising
  12. Service providers
  13. International data transfers
  14. Data retention
  15. Security
  16. Your rights
  17. Deleting your account and data
  18. Children's privacy
  19. Changes to this policy
  20. Contact us

This policy explains what personal data Autovena processes, why we process it, who we share it with and what rights you have. It is written to meet the transparency requirements of the EU/UK General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK).

1. Who we are

Autovena ("Autovena", "we", "us") provides automotive workshop management software consisting of a web application at app.autovena.com that runs in any modern browser, mobile applications for phones and tablets, a backend API at api.autovena.com, and this website.

For questions about this policy or about your personal data, contact us at [email protected]. We respond to privacy requests at this address.

2. Scope of this policy

This policy applies to personal data processed through:

  • the Autovena website, including the trial and demo request forms;
  • the Autovena web application used by workshops and their staff;
  • the Autovena mobile applications, on phones and tablets;
  • the Autovena backend API and supporting infrastructure;
  • support and email communication with us.

It does not apply to third-party websites or services you reach through links from Autovena. Those have their own privacy policies.

3. Our role: controller and processor

Autovena is business software. Two different relationships exist, and our legal role differs in each:

We are the data controller

for the account and usage data of the workshops that subscribe to Autovena and of the individual users they create — for example your name, email address, role and login records. We decide how this data is used to deliver, secure and support the service.

We are a data processor

for the operational records a workshop enters into Autovena about its own business — its customers, their vehicles, work orders, invoices and inventory. The workshop is the controller of that data and decides what to enter and how long to keep it. We process it only to provide the service, following the workshop's instructions.

If you are a customer of a workshop that uses Autovena and you want to access or delete your data, please contact that workshop directly. We will support them in responding to you.

4. Information we collect

4.1 Account and profile data

  • Full name, email address, phone number and username
  • Password, stored only as a salted bcrypt hash — we never store or can read your password
  • Profile photo, if you upload one
  • Role and permissions (for example Owner, Admin, Manager, Technician), account status and language preference
  • Workshop/company name, country, currency, time zone and tax details used on documents

4.2 Operational records entered by workshop users

Data workshops enter to run their business, for which they act as controller:

  • Customer records: name, phone number, email address, address and tax details
  • Vehicle records: licence plate, VIN, make, model, model year and mileage
  • Work orders, visits, service notes, assigned technician and job status
  • Appointments and service reminders
  • Invoices, payments and current account balances
  • Inventory: parts, stock movements, warehouse locations, suppliers, purchase orders and goods receipts
  • Customer approval records created when a workshop asks a vehicle owner to approve work

4.3 Images and scans

  • Photographs of vehicle registration documents that you capture with the camera or select from your photo library
  • QR codes and barcodes you scan, for example on stock labels

See section 6 for exactly what happens to these images.

4.4 Technical and security data

  • IP address, device type, operating system and browser user agent
  • Session records, including web sessions, mobile sessions and device identifiers
  • Audit logs recording which user performed which action and when
  • Error and diagnostic logs generated when something fails

4.5 Support and communication data

  • Support tickets, their messages and attachments
  • Messages you send us by email or through website forms, including trial and demo requests

5. How and why we use information

We only process personal data where we have a legal basis to do so. Under the GDPR our bases are listed below; the corresponding KVKK bases are Article 5/2(c) for contract, 5/2(ç) for legal obligation, 5/2(f) for legitimate interests, and explicit consent where stated.

Purpose Legal basis
Creating and managing your account, and providing the workshop management features you subscribe to Performance of a contract
Authenticating users, maintaining sessions and protecting accounts from unauthorised access Performance of a contract; legitimate interests in securing the service
Reading vehicle registration documents and looking up vehicle details from a VIN Performance of a contract, at your request
Sending service emails such as account setup, password reset and notifications Performance of a contract
Providing support and responding to your requests Performance of a contract; legitimate interests in assisting users
Keeping audit and error logs, preventing abuse and investigating incidents Legitimate interests in a secure and reliable service; legal obligations
Diagnosing faults and improving reliability and performance Legitimate interests in maintaining and improving the service
Meeting accounting, tax and other statutory record-keeping duties Legal obligation
Sending product announcements or marketing messages Consent, which you can withdraw at any time

Where we rely on legitimate interests, we have considered the impact on your privacy and limit the processing accordingly. You can object to this processing — see section 16.

6. Camera, photos and scanning

The Autovena mobile app asks for camera access, and optionally photo library access, only for the scanning features described here. The camera is never accessed in the background, and we do not use images for advertising, profiling or model training.

6.1 QR codes and barcodes

When you scan a QR code or a barcode — for example on a stock label — the recognition runs entirely on your device using Google ML Kit. The camera image is not uploaded to our servers and is not sent to any third party. Only the decoded value, such as a stock code, is used by the app.

6.2 Vehicle registration document scanning

If you photograph a vehicle registration document, or choose an existing photo from your library, to fill in vehicle details automatically:

  • the image is uploaded to the Autovena API over an encrypted connection;
  • it is sent to OpenAI, our text-extraction provider, which returns the fields it reads — such as licence plate, VIN, make, model and, where the document shows it, the registered owner's name;
  • the uploaded image is deleted from our servers immediately after the extraction finishes, whether it succeeded or failed. We do not keep a copy of the photograph;
  • the extracted text fields are shown to you for review and are saved only if you choose to save the vehicle record.

Because a registration document can contain the vehicle owner's personal details, only scan documents you are entitled to process.

6.3 Photo library

If you grant photo library access, we receive only the specific images you select. We cannot browse your library.

7. VIN and vehicle lookups

When you look up a vehicle by its VIN, we send that VIN — and no other personal data about you or your customer — to external vehicle databases to retrieve technical specifications such as make, model, engine and body type:

  • the vPIC database operated by the United States National Highway Traffic Safety Administration (NHTSA), a public government service;
  • API Ninjas, a commercial VIN lookup service.

Results are cached so that repeated lookups of the same VIN do not need to be sent again.

8. Authentication and device security

You sign in with an email address and password. Passwords are stored only as bcrypt hashes.

  • Web sessions use a strictly necessary, encrypted, HttpOnly session cookie. Sessions expire after 8 hours of inactivity and after 7 days in total, or 30 days if you choose to stay signed in.
  • Mobile sessions use tokens held in the device's secure storage — the iOS Keychain or the Android Keystore.
  • Biometric unlock (Face ID, Touch ID or Android biometrics) is optional. The check is performed by your device's operating system; Autovena receives only a success or failure result. We never receive, see or store your fingerprint or face data.

9. Push notifications

Push notifications are not enabled in the current release of the Autovena app. We do not register device notification tokens, and no notification data is sent to us or to any third-party messaging service.

If we introduce push notifications in a future version, they will be optional and will require your permission on the device. We will update this policy and our app store data declarations before that happens.

10. Cookies and similar technologies

We use only strictly necessary cookies. There are no advertising, tracking or profiling cookies on our website or in our application.

  • A session cookie that keeps you signed in to the web application. It is HttpOnly, Secure and SameSite=Lax, so it cannot be read by scripts and is not sent from other websites.

The language of these legal pages is chosen automatically from your browser's language settings. This happens on our server as the page is requested, and nothing is stored on your device.

Details are in our Cookie Policy.

11. Analytics and advertising

We do not track you.

Autovena contains no analytics SDK, no advertising SDK and no third-party tracking pixels. Analytics collection is disabled in our mobile application builds. We do not build advertising profiles, we do not track you across other apps or websites, and we never sell or rent personal data.

12. Service providers

We share personal data only with the providers we need to operate the service, and only to the extent required. They act on our instructions under written data protection terms.

Provider What it is used for Where
Hetzner Online GmbH Server and database hosting European Union
Cloudflare, Inc. Website delivery, DNS and network security Global network
OpenAI Extracting text fields from vehicle registration images you scan United States
NHTSA vPIC Public vehicle specification lookup from a VIN United States
API Ninjas Vehicle specification lookup from a VIN United States
Brevo Sending service emails European Union
Amazon Web Services (SES) Sending service emails United States / European Union

We may also disclose personal data to professional advisers, or to public authorities and courts where we are legally required to do so.

13. International data transfers

Your data is hosted in the European Union. Some of the providers listed above are located in the United States, so using the related features involves transferring data outside the EU/EEA and outside Türkiye.

For these transfers we rely on the European Commission's Standard Contractual Clauses or another valid transfer mechanism, together with technical measures such as encryption in transit. For transfers from Türkiye, we rely on the mechanisms permitted under Article 9 of the KVKK.

14. Data retention

  • Account data is kept while your account is active and for a reasonable period afterwards to handle disputes and legal claims.
  • Workshop operational records are kept for as long as the workshop keeps them in the system. The workshop decides what to delete and when.
  • Uploaded registration images are deleted immediately after text extraction completes.
  • Session records expire automatically, at the latest after the periods described in section 8.
  • Audit and error logs are kept for a limited period for security and troubleshooting, then deleted.
  • Invoicing and accounting records are kept for the periods required by tax and commercial law.

When a retention period ends, data is deleted or irreversibly anonymised.

15. Security

  • All traffic between your device and our servers is encrypted with TLS.
  • Passwords are stored only as bcrypt hashes.
  • Mobile credentials are held in the device's secure storage (iOS Keychain, Android Keystore).
  • Each workshop's data is isolated from other workshops, and access within a workshop is limited by user role.
  • Administrative actions are recorded in audit logs.
  • Databases are backed up regularly.

No system can be completely secure, but we work to protect your data using appropriate technical and organisational measures. If a personal data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, you.

16. Your rights

Depending on where you live, you have the following rights over your personal data:

  • Access — find out whether we process your data and obtain a copy
  • Rectification — have inaccurate or incomplete data corrected
  • Erasure — ask us to delete your data where the law allows
  • Restriction — ask us to limit how we use your data
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time
  • Portability — receive your data in a structured, machine-readable format
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting past processing
  • Automated decisions — object to a decision based solely on automated processing that significantly affects you. Autovena does not make such decisions
  • Compensation — under the KVKK, claim damages if you suffer loss from unlawful processing

To exercise any of these rights, email [email protected]. We reply within 30 days. We may ask for information to verify your identity before acting, so that we do not disclose data to the wrong person.

If you are not satisfied with our response, you can complain to your local data protection authority. In Türkiye this is the Personal Data Protection Authority (KVKK Kurumu); in the EU it is the supervisory authority of the country where you live or work.

17. Deleting your account and data

You can request deletion of your Autovena account and its associated data at any time. Full instructions, what gets deleted and how long it takes are on our Account Deletion page.

18. Children's privacy

Autovena is business software intended for workshop owners and their staff. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

19. Changes to this policy

We may update this policy when our product, our providers or the law changes. The "last updated" date at the top always reflects the current version. If a change materially affects how we use your personal data, we will tell you in the application or by email before it takes effect.

20. Contact us

For any privacy question or request, write to [email protected]. You can also read our Terms of Service, Cookie Policy and Account Deletion instructions.

autovena Digitalise your workshop operations with Autovena.
Home Pricing Terms of Service Privacy Policy Cookie Policy Account Deletion
© 2026 Autovena. All rights reserved.