Privacy Policy

Last updated: June 15, 2026 · Effective: June 15, 2026

The short version

BaySpark is a B2B service for auto repair shops. We do not have a customer database — your customers' names, phone numbers, and license plates stay inside the shop management system (Shop-Ware) you already use. We do operate a small cloud backend that handles shop owner sign-in, draft telemetry (which advisor created which draft, what it totaled, which recommendations they promoted), and operational metrics. We also send vehicle VINs to industry data providers under the permitted-use provisions of the federal Driver Privacy Protection Act.

We do not sell, rent, share for advertising, or otherwise monetize any data. We do not use customer or shop data to train AI models. If you are a California resident, you have specific rights under CCPA / CPRA — see Section 9.

1. Who we are and how to contact us

Bayspark LLC ("BaySpark," "we," "us," "our") is a Georgia corporation that makes software for automotive service advisors. Our product helps shops draft repair-order estimates faster inside the shop management software they already use. We operate the website at bayspark.ai, the dashboard at app.bayspark.ai, and the telemetry API at api.bayspark.ai.

For privacy questions, data-deletion requests, or to exercise any of the rights described below, email zeek@bayspark.ai. We respond within 10 business days.

2. What personal data we handle

"Personal data" here means information that could identify a specific person. The categories below match the structure California and similar US privacy laws use.

Category What's in it Where it lives
Account information Owner email address, owner display name, role (owner / regional manager / shop manager / viewer), shop name, shop tenant identifier Cloudflare D1 database operated by BaySpark; encrypted at rest by Cloudflare. Backed up by Cloudflare's standard procedures.
Authentication data Hashed magic-link tokens, hashed login-code values, the IP address from which a magic-link request was made, login timestamps Same Cloudflare D1 database. Raw tokens never stored.
Operational telemetry For each draft an advisor previews or creates: the advisor's full name (as it appears in your shop management system), vehicle year/make/model, anonymized concern hash, anonymized VIN hash, list of operation tags, dollar totals, recommendation tags surfaced and which were promoted, draft creation timestamp, the repair order ID inside your shop management system Same Cloudflare D1 database. Customer name, phone, plate, and full unencrypted VIN are NOT included.
Error and debugging data Adapter exception stack traces, harness selector-failure snapshots (DOM + screenshot of the page where BaySpark could not find an expected element), vehicle year/make/model, anonymized concern hash Same Cloudflare D1 database. Screenshots may incidentally capture customer-identifying information visible on the shop management screen at the moment of failure; we delete error captures on the schedule below and never use them for any purpose other than diagnosing the failure.
Shop credentials Shop-Ware username/password, Mitchell1 / WorldPac / Vehicle Databases API keys, NHTSA tokens On your shop's own computer only, in the BaySpark configuration file. Never transmitted to BaySpark's servers.
Customer and vehicle data inside your draft flow The customer name, phone, plate, full VIN, and free-text concern entered by your advisor when creating a draft Read briefly by BaySpark from your shop management system during draft creation; transmitted to BaySpark's industry data sub-processors as needed (see Section 5); not retained on BaySpark's servers after the draft is complete. Anonymized hashes of VIN and concern are retained in operational telemetry.
Website analytics Aggregate visit counts and country to bayspark.ai via Cloudflare's built-in analytics. No tracking cookies, no third-party advertising pixels. Cloudflare analytics service.

3. Why we handle it

We process the personal data above for the following business purposes (these align with the categories in California Civil Code § 1798.140(e)):

We do not use personal data for behavioral advertising, content recommendations on other platforms, profiling unrelated to the service, or sale of any kind.

4. Where data comes from

5. Sub-processors

We use the following third-party services to provide BaySpark. We have agreements in place requiring each to handle data on terms equivalent to this policy. We do not authorize them to use your data for any purpose other than delivering their service to us.

Sub-processor Service Data sent to them
Cloudflare, Inc. Compute (Workers), database (D1), static hosting (Pages), key-value storage (KV), DNS, edge caching, DDoS protection Everything we store server-side (account info, authentication data, operational telemetry, error data). Hosted in US data centers.
Resend, Inc. Transactional email (magic-link sign-in) Owner email address, owner display name, magic-link sign-in URL
Anthropic, PBC Large language model inference (Claude Haiku) for concern interpretation and fluid-capacity look-ups Free-text concern entered by the advisor; vehicle year, make, model, engine; anonymized VIN hash used as a cache key. Anthropic retains prompts for up to 30 days for abuse monitoring per their published policy. We do not opt into model training.
Shop-Ware Source / destination of the customer's repair orders We read your shop's RO data and write drafts back via Shop-Ware's API or browser interface, using the credentials you provided.
Mitchell1 (Snap-on Inc.) Labor times (when configured) VIN, operation tags. No customer-identifying data.
Vehicle Databases VIN decode and repair catalog lookups VIN, operation tags. No customer-identifying data.
WorldPac SpeedDIAL Parts pricing (when configured) VIN, part numbers, operation tags. No customer-identifying data.
NHTSA vPIC Public VIN decoding service VIN only. NHTSA is a US federal agency; no credentials required.
Open Labor Project Labor-time cross-reference (when configured) Operation tags. No VIN, no customer-identifying data.

We will update this list before adding any new sub-processor that materially changes data flows, and we will notify customers in advance for paid-account changes.

6. How long we keep it

Category Retention
Account information (owners, roles, location mappings) Active for the life of your account. Deleted within 30 days of account closure unless we need to retain specific items for tax or legal reasons.
Authentication data (login tokens, IPs) Magic-link tokens are deleted from active use 15 minutes after creation. Audit records of login events: 90 days.
Operational telemetry (draft events) 90 days. Configurable shorter on request.
Error and debugging data 30 days. Selector-failure captures (which may contain incidental screenshots) deleted on the same schedule.
Heartbeats (5-minute liveness pings) 7 days.
Customer and vehicle data inside the draft flow Not retained on BaySpark servers. Lives in your shop management system per its retention policies.
Shop credentials On your shop's own computer until you remove or replace them. Never stored on BaySpark servers.

7. How we protect it

8. Vehicle Identification Numbers (DPPA)

The federal Driver Privacy Protection Act (18 U.S.C. § 2721 et seq.) treats vehicle identification numbers tied to motor vehicle records as protected personal information. BaySpark uses VINs solely for the permitted purposes of (a) the normal operations of a business in providing or extending an authorized service related to motor vehicles, and (b) use by the registered owner or operator of the vehicle, or with their consent, in connection with their authorization of repair work.

Our industry data sub-processors (Mitchell1, Vehicle Databases, WorldPac, NHTSA) maintain their own DPPA permitted-use justifications and operate under the same purpose limitations.

9. Your California rights

If you are a California resident, the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act, gives you the following rights regarding personal data BaySpark holds about you:

To exercise any of these rights, email zeek@bayspark.ai with "California rights request" in the subject line. We will verify your identity (typically by confirming control of an email address associated with your account), respond within 45 days as required by CPRA, and complete the request within 90 days where possible.

You may designate an authorized agent to make a request on your behalf. We require written proof of authorization from the consumer.

BaySpark does not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.

10. Use of AI and large language models

BaySpark uses Anthropic's Claude Haiku model to interpret advisor free-text concerns and to look up vehicle-specific fluid capacities. The model receives the concern text, vehicle year/make/model/engine, and a VIN hash used as a cache key. The model does not receive customer names, phone numbers, plates, or any personal data outside what the advisor types into the concern field.

We do not opt our use of Claude Haiku into Anthropic's model training. Anthropic retains prompts for up to 30 days for abuse monitoring per their published privacy policy.

BaySpark does not use customer or shop data to train any AI model, ours or anyone else's.

11. Children's privacy

BaySpark is a business-to-business tool for auto repair shops. It is not directed to children under 13 and we do not knowingly collect data from any consumer under 13. If we learn that we have inadvertently collected such data, we will delete it.

12. Changes to this policy

If we make material changes — including adding a new sub-processor that handles a new category of personal data, or changing what we use data for — we will update the "Last updated" date at the top of this page and email all account owners 30 days before the change takes effect. For non-material changes (fixing a typo, restructuring sections), we update the date without notice.

13. Contact and complaints

Email zeek@bayspark.ai. We respond within 10 business days.

If you believe we have not adequately responded to a privacy concern, California residents may also contact the California Attorney General's office at oag.ca.gov/privacy.