Subprocessors
This page is maintained by MechanicX and lists the third-party services we rely on to deliver the app. It is editable project content and is not an independent certification or audit report. For a Data Processing Agreement, email hello@mechanicx.co.uk.
| Subprocessor | Purpose | Data | Region |
|---|---|---|---|
| Cloudflare | Application hosting, edge runtime, CDN, WAF, DDoS protection | All request/response traffic; no persistent customer data at rest | Global edge; UK/EU points of presence |
| Supabase | Managed PostgreSQL database, authentication, file storage | Garage workspace data, user accounts, uploaded photos and documents | EU (Ireland) |
| Stripe | Card payment processing for subscriptions and hardware shop | Billing contact, payment method tokens (no full card numbers stored by MechanicX) | EU / UK / US (Stripe-controlled) |
| Square | Optional card payment processing for garage-to-customer invoices | Only used when a garage enables Square; provider-side identifiers only | Provider-controlled |
| Google (Gemini API) | Number-plate OCR when a technician scans a plate to open a job card | The captured image of the plate at scan time; not retained by MechanicX after processing | Google-controlled |
| Email delivery provider | Transactional email (invoices, reminders, auth emails) | Recipient email address, message content generated by the app | EU / UK |
| SMS delivery provider | Booking reminders, MOT reminders, custom SMS | Recipient phone number, message content generated by the garage | UK |
| Vehicle data providers (DVLA / third-party VRM lookup) | Populating vehicle details from a registration number | VRM only, sent at the moment of lookup | UK |
Optional integrations (e.g. Square, Xero, supplier catalogues, HaynesPro, Autodata) are only active if the garage explicitly enables them in their workspace. When disabled, no data is shared with those providers.
Last updated 5 August 2026.