FIXD Automotive, Inc. Privacy Notice

We believe that transparency is the key to any healthy relationship. At FIXD, we’re all about helping you keep your vehicle healthy. We appreciate that you are trusting us with information that is important to you, and we want to be transparent about how we use it.

  1. About This Notice

FIXD Automotive, Inc. (“FIXD”) and (“we”, “us” and “our”) are committed to ensuring that we process your personal data in compliance with applicable data protection laws, including but not limited to the General Data Protection Regulation, the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (the “Data Protection Laws“).

For the purpose of the Data Protection Laws, FIXD Automotive, Inc (999 Peachtree St NE, Suite 840, Atlanta, GA, USA)) is the controller with respect to your personal data. 

In this privacy notice (this “Notice”), we explain how we use the personal data of users of our FIXD service (the “Service”), including the associated mobile application (the “App“). The Notice describes what data we collect, the purposes for which we use it, for how long we may keep it, and the third parties to whom we may disclose it. It also explains what rights you have in relation to your personal data. Please take the time to read and understand this Notice.

This Notice supplements any other fair processing or privacy notice that may be provided to you from time to time. 

Note that the Notice does not apply to providers of third party services, including those which may connect or interact with the Service or which are linked to within the Service, and we recommend that you read their privacy policy to understand how they might use your personal data. We are not responsible for the use of your personal data by such third parties.

This Notice explains how we use, store and share the information we collect about you, how you can exercise your rights in respect of that information and the procedures that we have in place to safeguard your privacy. Please contact us by email at privacy@fixdapp.com if you have any questions, comments or concerns about this Notice or how we handle your personal information, or if such information changes at any time.

  1. Changes to this Notice

We may update our privacy policy from time to time. If we make material changes to how we treat our users’ personal information, we will post the new privacy policy on within the Services and an in-App alert the first time you use the FIXD App and the FIXD Website after we make the change. You are responsible for ensuring we have an up-to-date active and deliverable email address and/or phone number for you and for periodically visiting this privacy policy to check for any changes.

  1. Definitions

In this Notice, where we refer to:

(a)          your “personal data”, this means any data which relates to you and from which you can be identified. It may include contact details, information about how you use the Service and your location. We describe the personal data which we collect in connection with the Service in Section 4 of this Notice;

(b)          our “affiliates”, this means our subsidiaries, our parent companies, and any subsidiaries of our parent companies; and

(c)           “processing”, this means any use of your personal data such as collecting, storing, using, transferring or deleting it.

  1. What personal data we use and how we collect it

This section describes the personal data which we use and collect in connection with the Service.

You provide us with some of this data directly, for example, when you subscribe for the Service, register in the App or when you communicate with us. This will only include your email address and the content of your communications, such as any feedback or complaints. 

The data we collect and process is described in the table below:

Type of data

Description

Source

User Information

Some information is required to create an account on our Services, such as your name, email address, password, and in some cases your mobile telephone number. You may also choose to provide other types of information, such as where you identify on the DIFM (‘Do It For Me’) and DIY (‘Do It Yourself’) spectrum.

From you when registering for an account. 

Vehicle Information

You may choose to provide us with additional information particular to your vehicle, such as Vehicle Identification Numbers (VINs), manufacturer, model, engine type, and mileage.

We also anonymize and aggregate this data to power predictive algorithms. This will never contain any of your personally data. 

From you through our App.

Sensor Information

Examples of the type of information we collect from the vehicle’s onboard computer and sensors include diagnostic trouble codes, which help explain why the vehicle’s check engine light came on; and data from the mass air flow sensor, which helps us to calculate fuel efficiency.

We collect information about the vehicle into which you plug the FIXD Sensor.

Device Information

When you install the FIXD App, we collect information about the device the application is running on. Examples include the platform, operating system version, manufacturer, and model number. 

From the App.

Language Information

We collect information related to your locale, such as your country, preferred language, and currency.

From the App.

Location Information

The Services include features that use location data, including GPS signals, Wi-Fi access points, and cell tower IDs.

You opt-in to this functionality by enabling location permissions within the App. You can revoke these permissions at any time by going to the application settings menu of your device.

Through your use of the Services and App.

Usage Information

This includes information about your interaction with the Services, for example, when you view or search content, create or log into your account, pair your device to your account, or interact with your FIXD sensor. 

Through your use of the Services and App.

Cookies Information

When you access the FIXD website, we collect anonymized information about your browsing, such as the pages you visit, the browser you are using, and the way you arrived on the site. We do not store your IP address.

Through your use of our website. 

Survey, Contest and Promotion Contact Information

If you contact us or participate in a survey, contest, or promotion, we collect the information you submit such as your name, contact information, and message.

From you through the applicable survey, contest or promotion entry method.

Payment and Card Information

If you purchase FIXD products or services on our website, you provide your payment information, including your name, credit or debit card number, card expiration date, CVV code, and billing address.

From you through our website.

Information from Third Parties

If you choose to connect your account on our Services to your account on another service, we may receive information from the other service. For example, if you connect to Facebook, we may receive information like your name, age range, language, and email address.

From a third party when you link your account to another service. 

  1. Why we use your personal data

The following table sets out the purposes for which we use your personal data in connection with the Service. We only use your personal data to the extent that this is necessary to fulfil the relevant purposes.

Under the Data Protection Laws, we are also required to have a “lawful basis” to process your personal data. This is summarised in the table below. 

Why we use your personal data

The personal data we use

Lawful basis

To provide you with the Service and tailor this to your needs.

Using the information we collect, we are able to deliver the Services to you and honor our Terms of Service contract with you. For example, we need to use your information to provide you with your FIXD vehicle health report within the FIXD App and to give you customer support.

  • User Information
  • Sensor Information
  • Vehicle Information
  • Device Information
  • Usage Information 
  • Location Information

To take steps at your request to enter a contract with you, and for the ongoing performance, management and facilitation of such contract.

To improve the Service, including the quality of the Service, the App, our website and the user experience. This involves carrying out analytics to understand how the Service is used.

  • User Information
  • Sensor Information
  • Vehicle Information
  • Device Information
  • Usage Information
  • Cookies Information

We process your data on the basis that is necessary for our legitimate interest to improve the quality of the Service, App and website to provide you with the best possible experience. 

To communicate with you in relation to the Service. This includes sending you service communications, dealing with questions, messages or requests you may have, and managing complaints.

  • User Information
  • Content of communications between us

In some cases, the processing is for necessary for the ongoing performance, management and facilitation of our contract with you.

Where the processing is not necessary for the contract, we process your data on the basis that it is necessary for our legitimate interest to provide you with a good customer experience.

We use the information we collect to promote the safety and security of the Services, our users, and other parties.

For example, we may use the information to authenticate users, facilitate secure payments, protect against fraud and abuse, respond to a legal request or claim, conduct audits, and enforce our terms and policies.

  • User Information
  • Vehicle Information
  • Device Information
  • Usage Information 
  • Location Information
  • Payment and Card Information

We process your data on the basis that is necessary for our legitimate interest to ensure the safety and security of our Services. 

In some cases, the processing is necessary to comply with our legal obligations or for the ongoing performance management and facilitation of our contract with you.

To deliver relevant website content and advertisements, (including to measure their effectiveness).

  • User Information
  • Device Information
  • Usage Information
  • Survey, Contest and Promotion Contact Information
  • Cookies Information

Legitimate interests (to understand how customers use our services and improve our products, services).

Consent where cookie rules require we obtain consent (via our cookie consent tool which can be found at the bottom of our website) which you are free to refuse.

To market our services to you e.g. providing recommendations and suggestions for services that may interest you.

  • User Information
  • Device Information
  • Usage Information
  • Survey, Contest and Promotion Contact Information
  • Cookies Information

With regard to direct marketing communications, we will, where legally required, only engage in such communications where you have consented to receive such communications. You will have the opportunity to withdraw your consent at any time if you no longer wish to receive direct marketing communications from us.

 In addition, we may process the personal data described in this Notice:

  • To comply with laws and regulations applicable to us (on the basis that this processing would be necessary to comply with legal obligations)
  • To protect our business and the Service, including by enforcing our terms and conditions, obtaining legal advice and progressing legal claims (on the basis that this processing is necessary for our legitimate interest to protect our business)
  • To offer for sale or obtain funding for, our business including our assets and services (on the basis that this processing would be necessary for our legitimate interest to conduct our business in a profitable manner)

We have determined, acting reasonably and considering the circumstances, that we are able to rely on legitimate interests as the lawful basis on which to process your personal information in certain circumstances (we have stated this above and set out our legitimate interests). We have reached this decision by carrying out a balancing exercise to make sure our legitimate interest does not override your privacy rights as an individual. If you require further information regarding this balancing test, please contact us.

  1. Sharing your personal data

We will only share your personal data as described in this section.

For the purposes set out in the previous section, we will only share your personal data: 

  • With our corporate affiliates, service providers, and other partners who process it for us, based on our instructions, and in compliance with this policy and any other appropriate confidentiality and security measures. These partners provide us with services globally, including for customer support, information technology, payments, sales, marketing, data analysis, research, and surveys.
  • More specifically, your personal data will be shared with our:
  • App and platform provider namely, Apple App Store and Google Play Store
  • Analytics services providers namely, Mixpanel
  • Customer support service provider currently, Zendesk
  • Cloud hosting provider namely, Amazon Web Services
  • Diagnostics services providers
  • PCI Level 1 service providers, such as Paypal, Stripe, Shopify, and Amazon
  • Providers of our central IT systems, such as our customer management platform
  • Our professional advisors (including without limitation tax, legal or other corporate advisors who provide professional services to us)
  • Insolvency practitioners
  • Prospective buyers or funders of our business or assets
  • Competent authorities and regulators, including law enforcement or fraud prevention agencies and the courts, for the purposes of investigating any actual or suspected criminal activity or other regulatory or legal matters
  • We may also disclose your personal data to third parties as may be required in the following situations:
  • in the event that we consider selling any business or assets, in which case we will disclose your personal data to any prospective buyers of such business or assets;
  • if we, or substantially all of our assets, are acquired by a third party, in which case personal information held by us about our customers will be one of the transferred assets; 
  • in the event we are the subject of any insolvency situation (e.g. the administration or liquidation);
  • in order to enforce or apply our terms and conditions, policies or any contract we have with you or have facilitated between you and a third party; and 
  • to protect our rights, property, or safety, or that of our people, or others. This includes exchanging information with other companies and organisations (including without limitation the local police or other local law enforcement agencies) for the purposes of safety, crime prevention and fraud protection; 

We may share your personal data if we are under a duty to disclose or share your personal information in order to comply with any legal obligation or regulatory requirements, or otherwise for the prevention or detection of fraud or crime. We attempt to notify users about legal demands for their data when appropriate in our judgment, unless prohibited by law or court order or when the request is an emergency. We may dispute such demands when we believe, in our discretion, that the requests are overbroad, vague, or lack proper authority, but we do not commit to challenge every demand.

We do not share mobile contact information with third parties or affiliates for marketing or promotional purposes. Information may be shared with subcontractors in support services, such as customer service. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

We may share non-personal information that is aggregated or de-identified so that it cannot reasonably be used to identify an individual. We may disclose such information publicly and to third parties, for example, in public reports about vehicle age and problems, to partners under agreement with us, or as part of the community benchmarking information we provide to users of our services.

  1.     Third party services

This Notice does not cover third party websites, apps or portals that we may link to from our Services and does not cover any services of other providers. We are not responsible for the privacy policies and practices (including use of cookies) of such third parties even if you accessed the third party website, app, portal or service using links from our Services.

We recommend that you check the policy of each provider and contact such third party if you have concerns or questions. Any provider of other services such as providers of social media platforms, mobile networks, Wi-Fi hotspot services, music or messaging services are separate controllers of your data and are responsible for their own processing.

  1. International transfers of personal data

Your personal data will be transferred to the EEA, the UK and the US.

Where your personal data is transferred to any third party outside of the UK/Switzerland/EEA, we will ensure an agreement is in place with the third party, on terms which adequately protect your personal data. We will always ensure additional safeguards and supplementary measures are put in place, before sharing your personal data. For example, we would implement an appropriate transfer solution, such as standard contractual clauses approved by the EU Commission, UK government or Swiss government (as applicable). In some exceptional cases, we may also transfer your data abroad without such safeguards, where permitted under applicable law, e.g. with your consent, where the disclosure is necessary for the performance of the contract, for the establishment, exercise or enforcement of legal claims, or for overriding public interests.

  1. Cookies, Analytics and Marketing

We work with partners who provide us with analytics and advertising services. This includes helping us understand how users interact with the Services, serving ads on our behalf across the internet, and measuring the performance of those ads. These companies may use cookies and similar technologies to collect information about your interactions with the Services and other websites and applications.

Google AdWords

When you use the Services or their content, certain third parties may use automatic information collection technologies to collect information about you or your device. In particular, we use Google AdWords remarketing to advertise FIXD and our products and services across the Internet and on third party websites (including Google) to users of the Services. AdWords remarketing will display ads to you based on what parts of the Services you have used by placing a cookie on your mobile device or computing device. It could be in the form of an advertisement on the Google search results page, or a site in the Google Display Network. This cookie does not in any way identify you or give us access to your mobile device. The cookie is only used to indicate to websites and other applications that you have used a particular feature of the Services, so that they may show you ads relating to those features. If you do not wish to participate in Google AdWords Remarketing, then you can opt-out by visiting Google’s Ads Preferences Manager at https://adssettings.google.com

Mediavine Programmatic Advertising 

The website works with Mediavine to manage third-party interest-based advertising appearing on the website. Mediavine serves content and advertisements when you visit the website, which may use first and third-party cookies. A cookie is a small text file which is sent to your computer or mobile device (referred to in this policy as a “device”) by the web server so that a website can remember some information about your browsing activity on the website.

First party cookies are created by the website that you are visiting. A third-party cookie is frequently used in behavioural advertising and analytics and is created by a domain other than the website you are visiting. Third-party cookies, tags, pixels, beacons and other similar technologies (collectively, “Tags”) may be placed on the website to monitor interaction with advertising content and to target and optimize advertising. Each internet browser has functionality so that you can block both first and third-party cookies and clear your browser’s cache. The “help” feature of the menu bar on most browsers will tell you how to stop accepting new cookies, how to receive notification of new cookies, how to disable existing cookies and how to clear your browser’s cache. For more information about cookies and how to disable them, you can consult the information at All About Cookies.

Without cookies you may not be able to take full advantage of the website content and features. Please note that rejecting cookies does not mean that you will no longer see ads when you visit our Site. In the event you opt-out, you will still see non-personalized advertisements on the website.

The Website collects the following data using a cookie when serving personalized ads:

  • IP Address
  • Operating System Type
  • Operating System Version
  • Device Type
  • Language of the website
  • Web browser type
  • Email (in hashed form)

Mediavine Partners (companies listed below with whom Mediavine shares data) may also use this data to link to other end user information the partner has independently collected to deliver targeted advertisements. Mediavine Partners may also separately collect data about end users from other sources, such as advertising IDs or pixels, and link that data to data collected from Mediavine publishers in order to provide interest-based advertising across your online experience, including devices, browsers and apps. This data includes usage data, cookie information, device information, information about interactions between users and advertisements and websites, geolocation data, traffic data, and information about a visitor’s referral source to a particular website. Mediavine Partners may also create unique IDs to create audience segments, which are used to provide targeted advertising.

For specific information about Mediavine Partners, the data each collects and their data collection and privacy policies, please visit Mediavine Partners.

  1. Information Security

We work hard to keep your data safe. We use a combination of technical, administrative, and physical controls to maintain the security of your data. This includes using Transport Layer Security (“TLS”) to encrypt all of our Services. The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of the FIXD App, you are responsible for keeping this password confidential. We ask you not to share your password with anyone. No method of transmitting or storing data is completely secure. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures we provide. If you have a security-related concern, please contact Customer Support.

  1. Retention of your personal data

We keep your account information, like your name, email address, and password, for as long as your account is in existence because we need it to operate your account. In some cases, when you give us information for a feature of the Services, we delete the data after it is no longer needed for the feature. Unless otherwise specified, we keep other information, like your vehicle diagnostic information, until you request that we delete the data or your account because we use this data to provide you with your vehicle information and other aspects of the Services. We also keep information about you and your use of the Services for as long as necessary for our legitimate business interests, for legal reasons, including as described in the ‘Why we use your information’ and ‘Sharing your information’ sections.

For more detailed information about these retention periods, please email privacy@fixdapp.com 

  1. Your rights

As a data subject, you have a number of legal rights in relation to the personal data that we process about you. 

Right

Description

(1) To be informed

A right to be informed about the personal information we hold about you. This Notice sets out how we collect, hold and store your information, what we do with it and why. If you have any questions, please contact us so we can provide you with the further information you require. 

(2) Of access

A right to access the personal information we hold about you.

(3) To rectification

A right to require us to rectify any inaccurate or incomplete personal information we hold about you.

(4) To erasure

A right to ask us to delete the personal information we hold about you. This right will only apply where (for example): 

  • we no longer need to use the personal information to achieve the purpose we collected it for;
  • where you withdraw your consent if we are using your personal information based on your consent; or 
  • where you object to the way we process your data (in line with Right 7 below). 

Note that you may trigger the deletion of your profile information and the anonymization of all vehicle data by deleting your account.

You may also trigger the anonymization of all vehicle data by de-enrolling your vehicle (although this does not result in the deletion of information in the app).

(5) To restrict processing

In certain circumstances, a right to restrict our processing of the personal information we hold about you. This right will only apply where (for example): 

  • you dispute the accuracy of the personal information held by us; 
  • where you would have the right to ask us to delete the personal information but would prefer that our processing is restricted instead; or 
  • where we no longer need to use the personal information to achieve the purpose we collected it for, but you need the data for the purposes of establishing, exercising or defending legal claims.

(6) To data portability

In certain circumstances, a right to receive the personal information you have given us, in a structured, commonly used and machine readable format. You also have the right to require us to transfer this personal information to another organisation, at your request.

(7) To object

A right to object to our processing of the personal information we hold about you where our lawful basis is for the purpose of our legitimate interests, unless we are able to demonstrate, on balance, legitimate grounds for continuing to process the personal information which override your rights or which are for the establishment, exercise or defence of legal claims.

(8) In relation to automated decision making and profiling

A right for you not to be subject to a decision based solely on an automated process, including profiling, which produces legal effects concerning you or similarly significantly affect you.

Note that the Service does not involve automated decision-making.

(9) To withdraw

A right to withdraw your consent, where we are relying on it to use your personal data (for example, to provide you with marketing material). Please note that the withdrawal shall only be effective for the future. Processing that occurred before the withdrawal shall not be affected.

By using the FIXD App, you can access, and in some cases export, much of your personal information, including information on your account and vehicles. Your account settings let you change and delete much of your personal information. For instance, you can edit the email address we have on file. 

You can also exercise your rights by contacting privacy@fixdapp.com or our customer support team.

Note that while we will make every effort to respond to these requests as soon as possible, it may take up to 3 weeks to complete your request. 

  1. EU-U.S. and UK Data Privacy Framework

FIXD complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, set forth by the U.S. Department of Commerce. FIXD has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, FIXD commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF.

FIXD is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC)

FIXD is obligated to arbitrate claims and follow the terms as set forth in Annex I of the DPF Principles, provided that an individual has invoked binding arbitration by delivering notice to FIXD and following the procedures and subject to conditions set forth in Annex I of Principles.

FIXD remains liable under the DPF Principles if a third-party agent processes personal data we transfer to them in a manner inconsistent with the DPF Principles, unless we can prove that we are not responsible for the event giving rise to the damage.

  1. Our Policies for Children

The Services are not intended for children under 18 years of age, and we do not knowingly collect personal data from children under 18. If we learn we have collected or received personal data from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 18, please contact us at privacy@fixdapp.com.

  1. Contact information

If you have questions, suggestions, or concerns about this policy, or about our use of your information, please contact us at privacy@fixdapp.com.

If you have questions that aren’t related to this policy or data usage, such as order information or product support, contact our support team at support@fixdapp.com.

If you live in the European Economic Area, United Kingdom, or Switzerland, and are seeking to exercise any of your statutory rights, please contact our Data Protection Officer at data-protection-office@fixdapp.com.

If you reside elsewhere, then FIXD Automotive, Inc., a US company, is the data controller that provides you with the Services. You may contact us at:

Address: Data Protection Office, FIXD Automotive, Inc. 999 Peachtree St NE, Suite 840, Atlanta, GA, USA)

We encourage you to contact us first if you have any queries, comments or concerns about the way we handle your personal information. However, if you are not satisfied with our handling of any request by you in relation to your rights or concerns, you also have the right to make a complaint to the applicable supervisory authority. For further information on how to contact the supervisory authority please email privacy@fixdapp.com 

If you would like this notice in another format (for example audio, large print, braille) please contact us using the details above.

Last updated: February 2025