Trust & Security

This page is maintained by MechanicX to answer common security and privacy questions about the MechanicX application. It is editable project content and is not an independent certification or audit report.

Shared responsibility

MechanicX is delivered as a hosted web application. Security is a shared responsibility: the underlying hosting platform provides infrastructure controls, MechanicX (the app owner) is responsible for application-level controls described on this page, and each garage (customer) is responsible for how it uses the app — including who they invite, the passwords they choose, and the customer data they enter.

Authentication & access

Access to MechanicX requires an account. Sign-in is available via email and password and via Google. Each user belongs to a single garage workspace and can only see data inside that workspace. Within a workspace, an admin controls who can change settings such as company information, integrations, and billing-related preferences.

Data isolation

Each garage's customers, vehicles, bookings, invoices, and worksheets are scoped to that workspace at the database level. Internal platform configuration is restricted to MechanicX operators and is not readable by garage users.

Data we hold

MechanicX stores the data garages enter to run their workshop: their own company details, their customers' contact details, vehicle records, job history, invoices and payments, and any photos attached to job sheets. Garages choose what to enter. We do not sell this data.

Payments & sensitive credentials

Card payments are processed by trusted third-party payment providers (Stripe and Square). MechanicX does not store full card numbers or card security codes. Provider-side identifiers and webhook signatures are verified server-side and are not exposed to the browser.

Integrations & subprocessors

MechanicX uses third-party services for hosting, email delivery, SMS delivery, payment processing, and vehicle data lookups. Garages can choose which optional integrations to enable. See our subprocessors page for the current list, or contact us at the address below for a Data Processing Agreement.

Retention & deletion

Workshop data is retained for the lifetime of the garage's subscription so it remains available in the app. If a garage closes its account and asks us to delete its data, we will action that request. Specific retention periods for backups and operational logs are available on request.

Reporting a security issue

If you believe you have found a security issue in MechanicX, please email admin@mechanicx.co.uk with details and steps to reproduce. We will acknowledge the report and keep you updated as we investigate. Please give us a reasonable window to respond before any public disclosure.

ISMS & standards alignment

MechanicX operates a lightweight Information Security Management System (ISMS) aligned with the principles of ISO/IEC 27001:2022. We are not yet formally certified, but we maintain the core management-system elements: scope, risk register, asset register, statement of applicability, and a regular review schedule. We are also preparing a Cyber Essentials 2026 self-assessment.

Contact

For privacy requests, data export, deletion, or questions about this page, email admin@mechanicx.co.uk.

Last updated 5 August 2026.

v2026.08.05.1008