Effective date: March 1, 2026 ยท Last updated: March 1, 2026
This Privacy Policy describes how The Wash Report ("we," "us," or "our") collects, uses, stores, and shares information when you use our service at thewashreport.com. By using the Service, you agree to the collection and use of information as described in this policy.
When you register for an account, we collect:
During the account activation process, you may provide:
When you upload CSV files from your access-control system, we store the data contained in those files, which typically includes vehicle wash event records: entry numbers, event/department identifiers, dates, times, and access types. This data belongs to your organization and is scoped to your account.
If you submit a support ticket through your dashboard, we collect the content of your message and any responses exchanged.
We do not use tracking cookies, advertising pixels, or third-party analytics services. We do not collect browser fingerprints, IP addresses for tracking, or behavioral data beyond what is inherent to operating the service (e.g., server logs maintained by our hosting provider, Netlify).
We use browser localStorage (not cookies) to store your authentication token for session persistence. This data stays on your device and is not transmitted to third parties.
We use the information we collect solely to:
We do not use your data for advertising, sell it to third parties, or share it with any party not described in this policy.
We do not sell or rent your personal information. We share information only with the following service providers necessary to operate the Service:
These providers act as data processors on our behalf and are contractually bound to process data only as instructed. We may disclose information if required by law, court order, or government authority, or to protect the rights, property, or safety of our users or the public.
Your data is stored in a PostgreSQL database hosted by Neon on AWS infrastructure. All data is transmitted over HTTPS (TLS encryption). Passwords are hashed using bcrypt and are never stored in plain text. Authentication uses JSON Web Tokens (JWT) with a 7-day expiration.
While we implement industry-standard security measures, no system is completely secure. We cannot guarantee absolute security of your data and encourage you to use a strong, unique password for your account.
We retain your account information and wash data for as long as your account is active. If your account is terminated or cancelled, we may retain your data for up to 30 days before permanent deletion to allow for recovery if needed. Support communications may be retained for up to 2 years for quality and compliance purposes.
You may request deletion of your account and associated data at any time by contacting us (see Section 9).
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:
To exercise any of these rights, contact us at the address in Section 9. We will respond to verifiable requests within 45 days as required by law.
Regardless of your location, you may:
The Service is not directed to individuals under the age of 13, and we do not knowingly collect personal information from children under 13. The Service is intended solely for business use by authorized dealership personnel. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information promptly.
We may send you transactional emails related to your account (e.g., account activation confirmation, support ticket responses). We do not send unsolicited marketing email. All service emails comply with the federal CAN-SPAM Act. You may contact us to request removal from any non-essential communications.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice in your dashboard at least 14 days before the changes take effect. The effective date at the top of this page will always reflect the most recent version. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy, wish to exercise your rights, or want to report a privacy concern, contact us at: