At Rolling Repairs, protecting your personal information isn't an afterthought โ it's built into every layer of how our platform works. This page explains exactly what data we collect, how it's protected, and the technical security measures we've put in place to keep your account and information safe.
Security at a Glance
๐
Multi-Factor Authentication
Admin accounts are protected with Time-based One-Time Password (TOTP) MFA โ a six-digit rotating code required at every login.
๐
256-Bit Encryption in Transit
All data transmitted between your device and our servers is encrypted using TLS โ the same standard used by banks and major e-commerce platforms.
๐ก๏ธ
Database Access Rules
Server-side database rules enforce that each customer can only access their own appointments. No customer can view, modify, or delete another customer's data.
๐ต
Card Data Never Stored
We never store your card number, CVV, or expiry on our servers. Payment processing will be handled exclusively through Stripe's PCI-compliant infrastructure.
๐งฑ
Content Security Policy
Our web server enforces strict Content Security Policy headers that block unauthorized scripts and prevent cross-site scripting (XSS) attacks.
โก
Rate Limiting
Booking submissions are rate-limited to five per 24-hour period per account, protecting against automated abuse and spam.
1. Information We Collect
When you create a Rolling Repairs account or book a service, we collect the following:
- Identity information: First name, last name, and email address.
- Contact information: Phone number (required at signup, used for appointment coordination and day-of communication).
- Service address: The address where you want the repair performed. This is used only to confirm we serve your area and to schedule travel time for the technician.
- Appointment history: The services you've booked, their dates, times, and status.
- Device notes: Any notes you provide about your device at the time of booking (e.g., "cracked screen, won't charge").
We do not collect your Social Security number, government ID, or financial account information. Payment card details are processed by Stripe and are never transmitted to or stored on Rolling Repairs servers.
2. How Your Account Is Protected
Your Rolling Repairs account is secured through an industry-standard cloud authentication platform used by thousands of production applications. Here's how it protects you:
- Password security: Passwords are never stored in plain text. Industry-standard hashing algorithms are used so that even Rolling Repairs staff cannot see your password.
- Email verification: New accounts require email verification before full access is granted, preventing account creation with addresses you don't own.
- Secure password reset: Password reset links are sent only to the verified email address on the account and expire after a short time window.
- Session management: Authentication tokens are short-lived and automatically rotated, reducing the risk of stolen session attacks.
- Admin MFA: The Rolling Repairs administrative account is protected with Time-based One-Time Password (TOTP) multi-factor authentication. Every admin login requires a live, rotating 6-digit code from an authenticator app in addition to a password โ so even a stolen password cannot grant access.
3. Database Security
All customer data is stored in a fully managed cloud database with automatic encryption at rest, operated by Google. Access is governed by server-side security rules that we have written and deployed โ these rules are enforced at the infrastructure level and cannot be bypassed by client-side code.
Specifically, our rules enforce the following:
- Customer isolation: Each customer can only read and write their own appointment records. Accessing another user's data โ even with a valid login โ is blocked at the database level.
- Admin-only appointment records: Full appointment details (name, phone, address, service notes) are stored in a collection that only the verified admin email address can access. Customers cannot list or read the appointments of other customers.
- Availability collection: To allow the booking calendar to check for time-slot conflicts, a separate availability collection is maintained. This collection contains only dates, times, and durations โ no names, addresses, or personal information of any kind.
- Write validation: All database writes are validated server-side. Customers can only submit fields we explicitly permit (date, time, service type, address, notes). Attempts to inject unexpected fields are rejected.
4. Website & Infrastructure Security
The Rolling Repairs website and customer portal are built with security hardening at the server and application level:
- HTTPS everywhere: All pages are served exclusively over HTTPS. Unencrypted HTTP requests are automatically redirected to the secure version.
- Content Security Policy (CSP): Our web server sends strict CSP headers with every page response. These headers instruct your browser to only execute scripts and load resources from a pre-approved whitelist of trusted domains. Any attempt by an injected script to load from an unauthorized source is blocked by your browser before it can run.
- Input sanitization: All user-supplied text (names, addresses, notes) is sanitized before being rendered in the browser, preventing cross-site scripting (XSS) attacks.
- Service area validation: Booking requests are validated against our 50-mile service radius using the Google Maps Distance Matrix API. This happens server-side and cannot be bypassed by modifying form values in the browser.
- Rate limiting: Each account is limited to 5 booking submissions per 24-hour period. This protects against automated scripts flooding our calendar with fake appointments.
5. Payment Security
Rolling Repairs takes payment security extremely seriously. Our payment architecture is designed with one core principle: your card data never touches our servers.
- Payment processing is handled through Stripe, a PCI DSS Level 1 certified payment processor โ the highest level of payment security certification available.
- Card numbers, CVV codes, and expiry dates are submitted directly to Stripe's servers over an encrypted connection. Rolling Repairs never receives, processes, or stores this information.
- Our database stores only the outcome of a payment (e.g., booking fee paid, payment pending) โ never any card details.
- The $25 refundable booking fee is the only charge collected at the time of booking. The remaining service balance is not collected until the repair is completed.
6. How We Use Your Information
We use the information we collect exclusively to:
- Create and manage your customer account.
- Schedule, confirm, and track your repair appointments.
- Coordinate travel and verify that your location is within our service area.
- Send appointment confirmations, status updates, and service-related notifications to your email or phone.
- Improve the reliability and performance of our booking system.
We do not sell, rent, or trade your personal information to any third party for marketing or advertising purposes. We do not use your data to train AI models. We do not share your information with any outside party except as required to deliver the service (e.g., payment processing via Stripe) or as required by law.
7. Data Retention
We retain your account and appointment records for up to 3 years following your last appointment. This is necessary for warranty tracking, legal compliance, and service history. You may request deletion of your account and associated data at any time by contacting us at rollingrepairsco@gmail.com. Deletion requests are processed within 30 days, subject to any legal hold requirements.
8. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Update or correct inaccurate information in your account at any time via the Account Info section of the Customer Portal.
- Deletion: Request that we delete your account and personal data.
- Opt-out: Unsubscribe from any promotional or non-essential communications at any time by contacting us directly.
9. Changes to This Policy
We may update this Privacy & Security Policy as our platform evolves. When we make material changes, we will update the effective date at the top of this page. We encourage you to review this page periodically. Continued use of our platform after any update constitutes your acceptance of the revised policy.
10. Contact Us
If you have questions, concerns, or requests regarding your privacy or the security of your data, please contact us directly: