RampBookPro

Privacy Policy

Last updated: 25 July 2026

1. Overview — two kinds of data, two roles

RampBook Pro (“RampBook”, “we”) is workshop management software used by vehicle garages in the UK. Two different relationships apply under UK data protection law (UK GDPR and the Data Protection Act 2018):

  • Garage account data — the details of the people who sign up and run a garage account (name, email, login). For this, we are the controller.
  • Garage customer records — the customers, vehicles, bookings, checks and invoices a garage enters into RampBook. For this, the garage is the controller and we are its processor: we store and process that data only to provide the service, on the garage’s instructions.

If you are a garage’s customer (for example, you received an invoice or an MOT reminder through RampBook), the garage that holds your details is responsible for them — please contact the garage first. We will assist them with any request about your data.

2. What we collect

  • Account data: name, email address, password (stored as a secure hash by our authentication provider), garage business details (name, address, phone, VAT details, logo).
  • Garage customer records (as entered by the garage): customer names, phone numbers, email addresses, postal addresses; vehicle registrations and details; booking, inspection-check, service-history and invoice records.
  • Vehicle data from public sources: where a garage uses vehicle lookup, registration-linked details and MOT history are retrieved from DVLA/DVSA records.
  • Technical logs: standard server logs (IP address, timestamps, requests) kept for security and troubleshooting.

We do not run advertising or cross-site tracking, and we do not sell personal data.

3. Why we process data (lawful bases)

  • To provide the service — performance of our contract with the garage.
  • To secure and improve the service (fraud prevention, debugging, capacity) — our legitimate interests.
  • To meet legal obligations, such as accounting records.
  • As processor for garage customer records — on the garage’s documented instructions. The garage is responsible for its own lawful basis (typically its contract with, or the legitimate interests of serving, its customers).

4. Emails sent through RampBook

Garages can send transactional emails to their customers through RampBook: invoices, booking confirmations, vehicle check reports and MOT reminders. These are sent on the garage’s behalf, from our sending domain, showing the garage’s name. Where a garage has given us its own contact address, we set it as the reply-to address so your reply goes directly to the garage and not to us. MOT reminder emails always include a one-click unsubscribe link; unsubscribed customers are excluded from future reminders automatically.

5. Where data lives, and who helps us process it

RampBook runs in the United Kingdom and Europe: the database and file storage are hosted in London, and the application runs in London. We use a small number of specialist providers (subprocessors) to deliver the service:

  • Supabase (database, authentication, file storage — hosted on AWS, London, UK)
  • Vercel (application hosting — functions run in London, UK; global content delivery for static assets)
  • Resend (transactional email delivery — EU region)
  • Anthropic (optional: only if a garage uses the document-scanning import feature, the scanned image is processed transiently to extract text; USA, under standard contractual safeguards)

Where any transfer outside the UK occurs, it is protected by recognised safeguards such as adequacy regulations or standard contractual clauses.

6. Security

  • Data is encrypted in transit (TLS) and at rest.
  • Every garage’s data is isolated by database-enforced row-level security — one garage cannot access another’s records.
  • Access to production systems is restricted and credential-protected.
  • Invoice documents are stored privately and shared only via short-lived signed links.

7. How long we keep data

  • While a garage account is active, its data is retained so the service works (service history is the product).
  • After an account closes: data is available for export on request for 30 days, then deleted from live systems. Provider backups expire on a rolling basis after that.
  • Technical logs are kept for short periods appropriate to security and debugging.

8. Your rights

Under UK GDPR you can ask for access to, correction of, deletion of, or a copy of your personal data, ask us to restrict or object to processing, and withdraw consent where consent is the basis. To exercise rights over garage customer records, contact the garage (the controller); we support them in responding. To exercise rights over account data, contact us directly. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).

9. Cookies

RampBook uses only essential cookies: the secure session cookies that keep you logged in. There are no advertising or third-party tracking cookies, so no cookie consent banner is required.

10. Changes and contact

If we make material changes to this policy we will give notice in the app or by email. Questions or requests: support@rampbook.co.uk. See also our Terms of Service.