My Workshop
  • Features
  • Pricing
  • Download free

Last updated: 22 July 2026

Privacy Policy

Operator: Atlantic IT Services (ABN 29 892 371 842) — a sole trader based in Victoria, Australia, and the provider of the My Workshop app.

Contact: support@atlanticit.com.au

This policy explains how we handle personal information in connection with the My Workshop application and service (the “App”). We handle personal information in line with the Australian Privacy Principles (APPs) in Schedule 1 of the Privacy Act 1988 (Cth).

About the two roles in this App — please read first

My Workshop is a multi-tenant platform. Each subscribing workshop (a “Workshop”) uses the App to run its own business and to hold information about its own customers.

  • The Workshop decides what customer information to collect and why. It is the business that has the direct relationship with the customer.
  • The Operator provides and hosts the platform on the Workshop’s behalf. We store and secure that customer information and make it available back to the Workshop; we do not use it for our own purposes.

Describing these roles as “the Workshop’s information” and “we host it on their behalf” is a plain-English explanation, not a way for us to sidestep our own duties: where we independently hold personal information, we are responsible for it under the Privacy Act regardless of these labels.

This single policy covers both how the Operator handles information and how information flows through the platform, because most Workshops are small businesses that rely on us for this. If you are a customer of a Workshop and have a question about your information, contact that Workshop first — it has the direct relationship with you. If you cannot resolve it with them, you can contact us using the details above and we will help.

Each Workshop is responsible for having a lawful basis to collect its customers’ information, for telling its customers how that information is handled, and for its own compliance with privacy and spam law. The Operator provides and secures the platform, but is not responsible for a Workshop’s own decisions about, or handling of, its customers’ information — including any information a Workshop exports from the App or uses outside it.

1. What personal information we collect

1a. Information the Operator collects directly (about Workshop staff & billing contacts)

InformationWhy we collect it
Name and roleTo create your sign-in, attribute job cards and labour entries to the person who made them, and provide support.
Email addressYour sign-in identifier, password resets, and service notifications.
Mobile number and device push tokenTo deliver push notifications about job updates. Optional — you can turn notifications off in App Settings.
Access and activity records (which jobs you opened, edited, or completed, and when)To keep an audit trail for security and accountability, as APP 11 requires.
Pseudonymous usage analytics — which screens you view and features you use, plus non-identifying segmentation such as your role and your Workshop’s subscription planTo understand how the App is used and improve it. Collected through Google Analytics for Firebase, which may involve a device / app-instance identifier, and is switched on only after you accept this policy. No customer personal information is sent to analytics.
Billing and subscription contact detailsTo manage your Workshop’s subscription and issue our invoices to you.
Anything you send us in a support requestTo diagnose and resolve the issue.

1b. Information the Operator processes on a Workshop’s behalf (about the Workshop’s customers)

When a Workshop creates a job card it may enter:

InformationPurpose (decided by the Workshop)
Customer full nameTo match jobs to customers and to appear on invoices.
Mobile numberTo contact the customer about their vehicle.
Email address (optional)To send invoices and job-ready notifications.
Vehicle registration, make, model, year, colour, engine, transmissionTo identify the correct vehicle and produce service-history records.
Odometer readingService history; some manufacturers require it for warranty validation.
Photos of the vehicleTo document work performed and pre-existing condition.
Business ABN (optional)Where the customer is a business — needed on a tax invoice of $1,000 or more.

The App is not designed to collect government identifiers (driver’s licence, Medicare, passport, tax file number), health information, payment card numbers, or the “sensitive information” categories defined in s 6 of the Privacy Act 1988. Please do not enter that kind of information into free-text fields, and take care that vehicle photos do not unnecessarily capture people or other identifying detail.

How the information is collected

  • Workshop staff enter customer details into the App, usually at the point of booking.
  • The App shows a short collection notice at the point of entry (APP 5). Where a booking is taken over the phone and the customer is not present, the Workshop is responsible for making the customer aware of this policy — for example by linking to it from the Workshop’s own website or mentioning it when booking.
  • Photos are captured by Workshop staff on Workshop-controlled devices.

2. Why we collect, hold and use it

The Operator uses the information in section 1a to run the platform: to create and secure accounts, deliver the service and notifications, provide support, manage subscriptions and billing, keep the security audit trail, and improve the App. Workshops use the information in section 1b to run their own businesses — principally to:

  1. Manage the day-to-day job workflow.
  2. Produce tax invoices that comply with the A New Tax System (Goods and Services Tax) Act 1999 (Cth).
  3. Maintain service-history records for their customers’ vehicles.
  4. Communicate with a customer about that customer’s own vehicle and job.
  5. Meet business record-keeping obligations — Australian tax law generally requires records to be kept for at least five years (see section 6).

We do not use personal information for marketing, we do not profile individuals or make automated decisions about them, and we do not sell or rent personal information to anyone.

3. Direct marketing and SMS/email messages (Spam Act 2003)

Some Workshops enable the optional ShopSMS add-on, which can text a customer a booking reminder or a “your vehicle is ready” notice, and lets the Workshop reply within the App.

  • These messages are service messages about a specific job the customer has with the Workshop — they are factual and are not advertising. Under the Spam Act 2003 (Cth) a message of this kind may be sent without separate marketing consent, and every message identifies the sending Workshop.
  • A customer can opt out of reminder texts for a booking at any time, and replying STOP adds their number to the Workshop’s do-not-contact list.
  • Neither the Operator nor a Workshop may use the App to send marketing or promotional messages unless the recipient has consented and every message carries a working unsubscribe facility, as the Spam Act requires. The App is not built for marketing campaigns and must not be used for them.

4. Who we share it with

We disclose personal information only as follows:

RecipientWhatWhy
Google LLC (Firebase & Google Analytics for Firebase)App data — names, contact details, vehicle information, photos, audit logs — and the pseudonymous usage analytics described in section 1a.Cloud hosting, authentication, file storage, push notifications, and usage analytics. Data is stored and processed overseas — see section 5.
The OperatorStaff-account and billing details (section 1a); the contents of any support request you send us; aggregated and pseudonymous usage statistics (section 1a).To run the platform, support you, and improve the App.
Maropost / Neto (only if a Workshop connects this integration)Parts SKU and catalogue lookups. No customer personal information is sent to Maropost.Live parts catalogue and pricing.
A regulator, court, or law-enforcement bodyOnly the specific records lawfully required.Where we are compelled by law (for example a subpoena, warrant, or a lawful request from the ATO or a regulator).

We do not sell or rent personal information, use it for advertising, or disclose it to data brokers, insurers, or social-media platforms.

5. Overseas disclosure (APP 8)

The App runs on Google Firebase. Personal information — including customer details, job records, photos, audit logs, and the usage analytics in section 1a — is stored and processed on Google infrastructure located in the United States, and may transit other countries in which Google operates.

We do not ask each person to “consent” to this overseas storage, because a genuine, informed consent is not something we can reliably obtain from everyone — particularly a Workshop’s customers, who do not use the App themselves. Instead, as APP 8.1 permits, we take reasonable steps to ensure the overseas recipient handles the information consistently with the Australian Privacy Principles: Google processes the data as our service provider under Google’s Cloud Data Processing terms, which restrict Google from using it for its own purposes. We remain accountable for that information under APP 8.1.

Because the information is held on servers outside Australia, overseas recipients are subject to the laws of the countries in which they operate, which may differ from the Australian Privacy Act. Workshops should make their own customers aware, at the point of collection, that their information is stored with an overseas cloud provider.

6. How we secure it (APP 11)

  • Data in transit is encrypted (TLS).
  • Data at rest is encrypted on Google’s infrastructure.
  • Access is restricted by role (mechanic / front desk / admin) and enforced at the database layer by server-side security rules, so a user only reaches data their role permits.
  • Sensitive server actions require a valid, verified sign-in token and a check of the user’s role, workshop, and account status before they run.
  • On mobile builds, app-attestation (Firebase App Check) is active as an additional integrity signal. (Note: attestation is not currently enforced as a hard block on every server call, because the Windows desktop build cannot provide an attestation token — do not describe it in stronger terms than this.)
  • Access to customer records is written to an internal audit log.
  • Workshop admins can deactivate or fully off-board a staff member at any time, which revokes their access.

No method of electronic storage or transmission is ever completely secure, so — while we take the steps above and keep them under review — we cannot guarantee absolute security, and you and each Workshop use the App on that basis.

The Privacy and Other Legislation Amendment Act 2024 clarified that “reasonable steps” to protect information include both technical and organisational measures; we aim to meet that standard and to keep these measures under review.

Data breaches

If a data breach that we are responsible for is likely to result in serious harm, we will notify the affected individuals (or, where the breach concerns a Workshop’s customers, that Workshop so it can notify them) as soon as practicable after we assess it, and — where the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act applies — the Office of the Australian Information Commissioner (OAIC). We commit to telling affected people about a serious breach even if a technical exemption from that scheme would otherwise apply.

7. How long we keep it (retention)

Record typeRetentionReason
Invoiced jobs (full record, including photos and the related audit log)Kept for 5 years from the invoice date, then destroyed or de-identifiedAustralian tax record-keeping, then APP 11.2.
Active / completed (not yet invoiced) jobsUntil invoiced or cancelledOperational data.
Inactive customer contact detailsDe-identified or destroyed once no longer needed and the record-keeping period has passedAPP 11.2.
Workshop staff accountsDeactivated on off-boarding; the identity is retained only where needed to keep the audit trail meaningfulAPP 11.2, balanced against the accountability duty.

To keep the daily views tidy, the App archives older invoiced jobs (roughly 12 months after invoicing) — this moves them out of the main lists but is not deletion; the record is still kept and secured until the retention period above ends, when it is destroyed or de-identified. Non-identifying figures (for example invoice totals with no personal information) may be kept longer for business-history continuity.

8. Your rights (APP 12 and APP 13)

You may ask to:

  • Access the personal information we hold about you.
  • Correct information that is wrong, out of date, incomplete, or misleading.
  • Ask us to delete your personal information — subject to any legal duty to keep tax and business records (see section 6).
  • Withdraw consent to optional features (such as notifications) at any time.
  • Make a complaint about how your information has been handled.

If you are a Workshop’s customer, direct access and correction requests to that Workshop, since it has the direct relationship with you. For anything the Operator holds directly, contact us using the details at the top. We may need to verify your identity before giving access, and in the limited cases the law allows we may decline a request — if so, we will explain why in writing.

How we handle a complaint: email us with the details. We will acknowledge it promptly, look into it, and give you a written response within a reasonable time (and, where the Privacy Act applies, within 30 days). If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at https://www.oaic.gov.au or 1300 363 992.

9. Children

The App is a workplace tool for motor-vehicle workshops and is not directed at children. We do not knowingly collect a child’s personal information except where it forms part of a vehicle booking made by a parent or guardian. (A Children’s Online Privacy Code is being introduced under the 2024 reforms and is due to be registered by December 2026; we will review this section when it applies.)

10. Changes to this policy

We may update this policy as the App or the law changes. The “Last updated” date above shows the latest revision. Where the change is material, we will notify you in the App and — where required — ask you to re-acknowledge it before continuing.

11. How to contact us

  • Email: support@atlanticit.com.au
  • Privacy Officer: The owner, Atlantic IT Services

My Workshop is provided by Atlantic IT Services (ABN 29 892 371 842). Each Workshop has the direct relationship with its own customers; the Operator provides and hosts the platform on the Workshop’s behalf and remains responsible, under the Privacy Act, for the information it holds.

My Workshop

Job card management for Australian auto repair workshops.

Product

  • Features
  • Pricing
  • Download

Legal

  • Privacy Policy
  • Terms of Service

Support

  • support@atlanticit.com.au

2026 My Workshop. Distributed by Atlantic IT.

Privacy Terms