Privacy Policy
Tintify Holdings, Inc.
Last updated: August 19, 2026
1. Introduction
Tintify Holdings, Inc. ("Tintify," "we," "us," or "our") provides a software-as-a-service platform designed for automotive services businesses, including window tinting, paint protection film, ceramic coatings, detailing, and vinyl wrap operations. This Privacy Policy describes how we collect, use, disclose, and protect information in connection with our platform and services (collectively, the "Services").
Our Services are offered exclusively to business entities and their authorized representatives ("Customers"). This Policy governs our handling of data relating to Customer accounts, business contacts, and end users whose data Customers may input into the platform.
By accessing or using Tintify, you agree to the practices described in this Privacy Policy.
1.1 Roles and Responsibilities
Tintify provides software services to automotive restyling businesses ("Customer Shops"). When a Customer Shop uploads or manages data about its end-customers through the Services (such as vehicle owners, appointment information, or communications history), the Customer Shop acts as the data controller for that end-customer data, and Tintify acts as a data processor. The Customer Shop is responsible for: (a) obtaining all required consents from its end-customers; (b) responding to data-subject rights requests from its end-customers; (c) providing notices required by applicable privacy law to its end-customers; and (d) ensuring its use of the Services complies with applicable law.
2. Information We Collect
2.1 Account and Business Information
When you register for or use Tintify, we collect:
- Business name, address, and contact information
- Name, email address, phone number, and job title of account holders and authorized users
- Billing information (processed via third-party payment processors; we do not store full card numbers)
- Subscription plan and account preferences
2.2 Platform Data
As part of normal platform operation, we collect data you input or generate through use of the Services, including:
- Customer records, appointment and scheduling data, and job notes
- Invoice, estimate, and payment records
- Inventory and materials data
- Employee and technician records
- Communications sent through the platform (SMS, email)
- Sales pipeline and commission data
- Photographs and other media uploaded to document vehicles, job progress, and completed work
2.3 Usage and Technical Data
We automatically collect certain technical information when you use the Services:
- IP addresses, browser type, and device information
- Pages visited, features used, and time spent within the platform
- Error logs and performance data
- Cookie and session identifiers (see Section 8 and our Cookie Policy)
2.4 Data You Import
You may import data from third-party tools or systems (e.g., CRMs, scheduling platforms). You are responsible for ensuring you have the right to share any such data with us.
2.5 Location Data
When an employee clocks in or out using the built in time clock, we capture the device's GPS coordinates at that moment, provided the device supports it and the user has granted location permission. Those coordinates are stored with the corresponding time entry and are used to verify attendance. We do not track location continuously, and we do not collect location in the background or at any other point in the app. If permission is denied or the device cannot provide a position, the time entry is recorded without coordinates.
3. How We Use Your Information
We use the information we collect to:
- Provide and operate the Services. Process transactions, manage accounts, and deliver platform functionality. Legal basis: performance of a contract.
- Communicate with you. Send account notifications, billing updates, support responses, and, where you have opted in, product announcements and marketing. Legal basis: performance of a contract for service messages; consent for marketing messages.
- Improve the Services. Analyze usage patterns, fix bugs, and develop new features. Legal basis: legitimate interests in maintaining and improving our product.
- Ensure security. Detect fraud, unauthorized access, and abuse. Legal basis: legitimate interests in protecting the Services and our Customers.
- Comply with legal obligations. Respond to lawful requests, court orders, and regulatory requirements. Legal basis: compliance with a legal obligation.
- Billing and payments. Process subscriptions, invoices, and refunds. Legal basis: performance of a contract and compliance with a legal obligation (tax and accounting records).
- Non-essential cookies and similar technologies. Functional, analytics, and marketing technologies on our website. Legal basis: consent, collected through our cookie banner and withdrawable at any time.
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to that processing as described in Section 7.
We do not sell your personal information or use it for targeted advertising.
No automated decision-making. We do not use automated decision-making, including profiling, that produces legal or similarly significant effects on Customers or their end-users. Service operations are performed by scheduled processes (such as appointment reminders or invoice generation), but these processes execute deterministic logic configured by the Customer Shop and do not make discretionary decisions affecting individuals.
SMS Communications. Tintify enables Customers (the shops using our platform) to send transactional and promotional SMS messages to their own end users, including appointment confirmations, reminders, invoices, proposals, and vehicle status updates. End users provide their phone number and SMS consent directly to the Customer shop they are doing business with, at the shop, through the shop's own branded lead forms, or through other direct interactions with the shop. The Customer shop is the sender and brand of record for all such messages. Tintify acts solely as the technology service provider that transmits messages on the Customer's instruction and is not a party to the underlying messaging relationship.
No sharing of opt-in data. Tintify does not share, transfer, sell, or otherwise make available SMS opt-in data, including phone numbers, consent records, and opt-out status, between Customer shops, with affiliates, with Tintify business lines, or with any third party for their own messaging, marketing, or other independent use. Opt-in data collected by or on behalf of one Customer is used solely to deliver the messages that originating Customer instructs and is logically isolated from other Customers on the platform. End users may opt out of SMS communications at any time by replying STOP, or reply HELP for assistance. Message frequency varies. Message and data rates may apply.
4. How We Share Your Information
We do not sell or rent your data. We may share information in the following limited circumstances:
4.1 Service Providers
We share Customer Data with the following categories of service providers, each acting under contractual obligations to protect the data:
- Cloud hosting and database: Supabase (US-East regions)
- Payment processing and subscription billing: Stripe, Inc. (Stripe collects and stores payment card details directly; Tintify does not receive or store full card numbers); Square, Inc. (for shop point-of-sale integrations)
- Transactional email: Resend
- SMS messaging: Telnyx LLC
- Voice calls: Dialpad, Inc. (for shop voice integrations)
- OAuth-based integrations: Google LLC (for Google Business Profile and Gmail SMTP if connected by Customer)
The categories above reflect our current subprocessors. A complete and current list is also available on request by emailing privacy@tintify.io. Customers may subscribe to subprocessor change notifications at the same address. Tintify will provide reasonable advance notice of the addition or replacement of a subprocessor, and Customers may object on reasonable data-protection grounds as set out in our Data Processing Agreement (Section 13).
Subprocessors that handle SMS traffic may only transmit messages on the originating Customer shop's behalf and are contractually prohibited from using SMS opt-in data, phone numbers, or consent records for any other purpose, including their own marketing or sharing across Customers.
4.2 Tintify Personnel Access
Authorized Tintify personnel may access Customer Data on a need-to-know basis to: provide technical support; investigate security incidents or suspected abuse; comply with legal obligations; or maintain the integrity of the Services. Such access is logged and reviewable. Tintify personnel do not access Customer Data for marketing, sales, or competitive purposes.
4.3 Business Transfers
If Tintify is involved in a merger, acquisition, asset sale, or similar transaction, your information may be transferred as part of that transaction. We will notify affected Customers as required by law.
4.4 Legal Requirements
We may disclose information when required to do so by law, regulation, subpoena, or court order, or when we believe disclosure is necessary to protect the rights, property, or safety of Tintify, our Customers, or others.
4.5 With Your Consent
We may share information in other ways with your explicit consent.
5. Data Retention
We keep personal data only for as long as necessary for the purpose it was collected for, plus any period required by law. Our standard periods are:
- Customer Data in an active account. For the life of the account.
- Customer Data after termination. Retained 30 days in a suspended state so the Customer can request recovery, then permanently deleted via automated cascade processes.
- Billing, invoicing, and tax records. Up to 7 years, as required by applicable tax and accounting law.
- Security and administrative audit logs. Up to 24 months, for forensic, compliance, and fraud-prevention purposes.
- SMS and email consent and opt-out records. Retained for the life of the account and up to 4 years afterwards, as evidence of consent and to honour opt-outs.
- Trial and contact-form submissions that do not become accounts. Up to 24 months, then deleted.
- Website cookie-consent records. Stored in your browser for up to 12 months, or until you clear them or change your preferences.
- Support correspondence. Up to 3 years from the last interaction.
Beyond these periods we retain only data that is anonymized (and therefore no longer personal data) or that we are required to keep to establish, exercise, or defend legal claims.
6. Data Security
We implement commercially reasonable administrative, technical, and organizational measures to protect Customer Data, including:
- Encryption in transit using TLS for all client connections
- Encryption at rest for sensitive credentials and integration tokens (including OAuth tokens, webhook secrets, and integration credentials) using authenticated symmetric encryption
- Tenant data isolation enforced through database row-level security policies, ensuring each Customer's data is logically isolated from other Customers
- Role-based access controls, audit logging of administrative actions, and least-privilege access principles for Tintify personnel
- Regular security reviews of infrastructure, dependencies, and access patterns
Audit logs of administrative and security-relevant actions are retained for forensic, compliance, and fraud-prevention purposes beyond the standard Customer Data retention period defined in Section 5.
No system is perfectly secure. Despite our efforts, we cannot guarantee absolute security of Customer Data. Customers are responsible for safeguarding their account credentials and notifying us promptly of any suspected unauthorized access.
6.1 Breach Notification
In the event of a confirmed security incident affecting Customer Data, Tintify will notify affected Customers without undue delay, and within 72 hours where required by applicable law. Notifications will be sent to the primary account email on file and will describe, to the extent known: the nature of the incident, the categories of data potentially affected, the measures Tintify has taken or proposes to take, and recommended actions for the Customer.
7. Your Rights and Choices
Depending on your jurisdiction, you may have rights with respect to your personal data, including the right to:
- Be informed about how your personal data is processed (this Policy)
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your data (subject to legal and contractual obligations)
- Object to processing carried out on the basis of legitimate interests, including direct marketing
- Request restriction of certain processing activities
- Export your data in a structured, commonly used, machine-readable format (data portability)
- Withdraw consent at any time, where processing is based on consent, including SMS and email marketing opt-ins and non-essential cookies. Withdrawal does not affect the lawfulness of processing carried out before withdrawal
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see Section 3)
To exercise any of these rights, contact us at privacy@tintify.io. We will respond within 30 days, and within one month where the GDPR or UK GDPR applies (extendable by two further months for complex requests, with notice to you). We do not charge a fee for exercising these rights unless a request is manifestly unfounded or excessive. We may ask for information reasonably necessary to verify your identity before acting on a request.
You can withdraw SMS consent at any time by replying STOP, withdraw email marketing consent using the unsubscribe link in any marketing email, and change cookie consent via the "Cookie settings" link in our website footer.
7.1 Right to Lodge a Complaint
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to lodge a complaint with your local data-protection supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk); in the EEA, a list of authorities is published by the European Data Protection Board (edpb.europa.eu). We would appreciate the chance to address your concerns directly first.
7.2 Requests About Shop End-Customer Data
If you are an end-customer of a shop that uses Tintify, that shop is the controller of your data (see Section 1.1). Direct your request to the shop. If you contact Tintify instead, we will refer you to the relevant Customer Shop and assist that shop in responding, as required by our Data Processing Agreement.
8. Cookies
We use cookies and similar technologies to operate and improve the Services. Strictly necessary cookies are used on the basis of our legitimate interest in delivering a functioning service. Functional, analytics, and marketing technologies are used only with your consent, collected through the cookie banner on our website as required by the ePrivacy Directive and Article 6(1)(a) GDPR. You can change or withdraw that consent at any time via the "Cookie settings" link in our website footer, with no effect on the lawfulness of processing carried out before withdrawal. For full details, including the categories we use, see our Cookie Policy.
9. Children's Privacy
The Services are business tools and are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. Separately, under the GDPR the age at which a child can consent to information-society services ranges from 13 to 16 depending on the EU Member State; because we do not offer the Services to children at all, we do not rely on children's consent for any processing. If you believe we have inadvertently collected such information, please contact us immediately.
10. International Data Transfers
Tintify is headquartered in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your jurisdiction.
Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States, Tintify relies on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), together with the UK International Data Transfer Addendum issued by the Information Commissioner's Office for UK transfers, and the Swiss adaptations for transfers from Switzerland. These clauses form part of Tintify's Data Processing Agreement (Section 13).
Tintify carries out transfer impact assessments covering the destination country's legal framework, the categories of data transferred, and the supplementary technical and organizational measures applied (including encryption in transit and at rest, access controls, and a policy of challenging unlawful government access requests). A summary of the current assessment is available on request from privacy@tintify.io. Our subprocessors are bound by equivalent transfer safeguards.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify Customers via email or a prominent notice within the platform at least 14 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
12. EEA and UK Representative
Tintify is established in the United States and directs its Services to automotive services businesses in the United States. Where Tintify's processing falls within the territorial scope of the EU or UK GDPR and an Article 27 representative is required, Tintify will appoint one and publish its contact details in this Section. Until then, all data-protection enquiries from individuals in the EEA, the UK, or Switzerland should be sent to privacy@tintify.io, and will be handled under the rights and timelines described in Section 7.
13. Data Processing Agreement
Where Tintify processes personal data on behalf of a Customer Shop, Tintify acts as a processor (or service provider) and the Customer Shop acts as the controller (or business). Tintify's Data Processing Agreement, which incorporates the Article 28 processing terms, the confidentiality, security, sub-processing, assistance, and deletion obligations described in this Policy, and the EU Standard Contractual Clauses and UK Addendum where applicable, governs that processing.
A copy of the current Data Processing Agreement is available on request from privacy@tintify.io. Customer Shops subject to the GDPR or UK GDPR should execute the DPA before entering personal data of EEA or UK individuals into the Services.
14. Contact Us
Questions about this Privacy Policy, requests to exercise privacy rights, or concerns about how we handle Customer Data may be directed to:
Tintify Holdings, Inc.
Attn: Privacy
1883 West Royal Hunte Drive, Suite 200A
Cedar City, UT 84720
Email: privacy@tintify.io
We will acknowledge receipt of privacy-related requests within a reasonable time and respond within 30 days, or sooner where required by applicable law.