Subprocessors

This page is maintained by MechanicX and lists the third-party services we rely on to deliver the app. It is editable project content and is not an independent certification or audit report. For a Data Processing Agreement, email hello@mechanicx.co.uk.

SubprocessorPurposeDataRegion
CloudflareApplication hosting, edge runtime, CDN, WAF, DDoS protectionAll request/response traffic; no persistent customer data at restGlobal edge; UK/EU points of presence
SupabaseManaged PostgreSQL database, authentication, file storageGarage workspace data, user accounts, uploaded photos and documentsEU (Ireland)
StripeCard payment processing for subscriptions and hardware shopBilling contact, payment method tokens (no full card numbers stored by MechanicX)EU / UK / US (Stripe-controlled)
SquareOptional card payment processing for garage-to-customer invoicesOnly used when a garage enables Square; provider-side identifiers onlyProvider-controlled
Google (Gemini API)Number-plate OCR when a technician scans a plate to open a job cardThe captured image of the plate at scan time; not retained by MechanicX after processingGoogle-controlled
Email delivery providerTransactional email (invoices, reminders, auth emails)Recipient email address, message content generated by the appEU / UK
SMS delivery providerBooking reminders, MOT reminders, custom SMSRecipient phone number, message content generated by the garageUK
Vehicle data providers (DVLA / third-party VRM lookup)Populating vehicle details from a registration numberVRM only, sent at the moment of lookupUK

Optional integrations (e.g. Square, Xero, supplier catalogues, HaynesPro, Autodata) are only active if the garage explicitly enables them in their workspace. When disabled, no data is shared with those providers.

Last updated 5 August 2026.

v2026.08.05.1008