Privacy policy
What BayStacker holds, and who else touches it.
Written from what the product actually does: the database every record lives in, the processors that handle a piece of it, and what the diagnosis assistant is and is not sent.
How to read this
What is promised, in the order it applies.
The sections below are the policy in full. Every provider named is accurate as at the effective date at the foot of this page, and section 5 lists each one with what it handles and where.
1. Who this policy is for, and what it covers
BayStacker is software for repair shops, sold to businesses. It is operated by Bellu Productos, of Mariano Monterde 309, 31000 Chihuahua, Chihuahua, Mexico ("we", "us"), which is responsible for the information described here. The account holder is a shop, not a consumer, and this policy describes what we do with the information that flows through the product.
There are two kinds of information in BayStacker and they are treated differently. Your shop’s own information — the accounts, the records, the billing relationship — we handle as the business you are transacting with. Your customers’ information — the vehicle owner, their contact details, their repair — we handle on your instructions, because it is your shop that has the relationship with them.
If you are a vehicle owner whose shop uses BayStacker and you want your details corrected or removed, ask the shop: they hold that record and they decide what happens to it. We will help them do it, and section 8 says how.
2. What we collect
- Account and shop details: the name, email address and role of each person with an account, the shop’s name, address, phone numbers, tax and invoice settings, and the locations it operates.
- The shop’s records: everything the shop enters about its work — vehicles, customers and their contact details, work orders, diagnosis cases and their findings, estimates, invoices, payments, parts, appointments and messages sent from the product.
- Billing information: the subscription, its edition, its status, its period dates and which invoices were paid. Card numbers are entered on Stripe’s own pages and never reach us.
- Usage and device information: which routes were opened, when, and by which account; the browser and operating system; the IP address the request came from. This is what the audit trail, the rate limits and the security of the service are built from.
- Support communications: what you write to us, and what we answered.
We do not collect advertising identifiers, we do not run third-party analytics or advertising scripts, and there is no tracking pixel anywhere in the product.
3. What we do with it
- To provide the service: showing each shop its own records, running the diagnosis assistant, sending the mail and messages the shop asks us to send, and taking the subscription.
- To secure it: scoping every row to the shop and role it belongs to, detecting abuse, and keeping the records a security investigation needs.
- To support you: answering your questions, with access to your shop’s records only as far as the question requires.
- To improve the product: aggregate, de-identified repair outcomes may be used to rank future diagnoses, as described in section 4 of this policy and section 4 of the Terms of Service.
- To meet our obligations: tax, accounting, and responding to lawful requests.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. That has always been true here, and it is stated so it stays true.
4. The diagnosis assistant, and what it is sent
When a shop runs an analysis, the product sends the facts needed to rank the possible causes: the complaint as recorded, the vehicle’s year, make, model and transmission, the mileage, the fault codes, and the findings already documented on the case. It also sends de-identified summaries of comparable completed repairs from elsewhere on the platform, which carry no VIN, no repair-order number, no customer name and no free-text note.
It does not send the customer’s name, contact details, address, VIN or plate. Each analysis is recorded on the case together with which provider answered it and what it cost, so a shop can see where any answer came from.
Two providers answer these calls: TypeSafe, which adjudicates the candidate causes, and OpenRouter, which routes to a DeepSeek model for the calls TypeSafe does not take. Both are used under their business terms. We do not claim on their behalf what they do with a request after it arrives — their own policies govern that, and they are linked below so you can read them.
5. Who else handles it
We use a small number of service providers to run BayStacker. Each one is bound by a written agreement that limits it to what we have asked it to do, and each is named here with what it handles.
| Provider | What it handles | Where |
|---|---|---|
| Contabo | The server the database runs on | EU (France) |
| Supabase | The database software every record lives in, the accounts and sessions that sign people in, and the row-level rules that scope each record to its shop — self-hosted on that server | EU (France) |
| Netlify | Serving the web application and its API | United States |
| Stripe | Subscription billing: the card on file, the charges, the invoices for the subscription, and the customer portal; and, where a shop has set up card payments for a location, its customers’ card payments | United States |
| Resend | Transactional email: invoices, estimates, receipts, reminders, and account mail such as password resets | United States |
| Twilio | Text messages, where a shop has switched SMS on for its customers | United States |
| Sentry | Error reports from the application, with personal data switched off at the client | United States |
| TypeSafe | Adjudicating the candidate causes of a diagnosis, from the repair facts listed in section 4 | United States |
| OpenRouter (DeepSeek) | The model calls that TypeSafe does not take, from the same repair facts | United States |
We also disclose information where the law requires it, where it is necessary to protect someone’s safety, or to a buyer if the business is sold — in which case this policy continues to apply until it is replaced, and we will tell you.
7. How long we keep it, and how you get it back
- Your shop’s records: kept while your account is active. After the subscription ends you have 30 days to export them, and then we delete them.
- Subscription and tax records: kept for as long as tax and accounting law requires, separately from the operational records.
- Error reports: kept according to the error monitor’s retention window, with personal data switched off at the client.
- Support email: kept while it is useful to answer you and to keep a history of the account, and reviewed each year.
You can export your records at any time from the settings page: a zip of CSV files covering work orders, customers, vehicles, invoices, payments and estimates, with a manifest of row counts. You do not have to ask us for it, and it does not depend on your subscription being active within the 30-day window.
8. Your rights, and how to use them
For the information we hold about you as an account holder, you can ask us to show you what we hold, correct it, delete it, object to a use of it, or give you a copy in a portable form. Write to the support address below and we will answer within 30 days. We will not charge you for the first request in a year.
For a vehicle owner whose details sit in a shop’s records, the shop is the one to ask, because the record is theirs. If you come to us instead, we will pass the request to the shop and help them answer it, and we will confirm to you that we did.
If you are in California, the categories of personal information we collect are those listed in section 2, we do not sell or share them as those terms are used by the CCPA, and you will not be treated differently for exercising any of these rights. You may use an authorised agent; we may ask for proof that they act for you.
Because Bellu Productos is established in Mexico, Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties applies to how we handle personal information, alongside the law where your shop operates. The requests in the first paragraph are the access, rectification, cancellation and opposition rights that law provides, and they are made the same way.
9. How it is protected
- Every record is scoped to the shop and the role it belongs to by rules in the database itself, not by the screen that asks for it. A signed-in reader sees the same rows the shop’s own system would show that person.
- No privileged database credential is shipped to the browser. Every change goes through a server route that checks who is asking first.
- Traffic is encrypted in transit, and passwords are never stored by us in a form we can read.
- Access to production is limited to the people who operate the service, and is recorded.
If a breach affects your shop’s records, we will tell you without undue delay and tell you what was affected, what we have done, and what you should do. We will not wait for a legal deadline to pass before saying something useful.
10. Where it is processed
BayStacker’s database runs on a server hosted by Contabo in the EU (France). Every other provider in section 5 processes in the United States. Bellu Productos, which operates the service, is in Mexico, and the people who operate and support it may reach records from there, under the access rules in section 9.
A shop that needs a data processing addendum, or a specific transfer mechanism, can have one: write to the support address and we will put it in place before the shop goes live.
11. Children
BayStacker is business software and is not directed at children. We do not knowingly collect information from anyone under 18, and an account may only be created by someone old enough to bind their business to our terms.
12. Changes to this policy
If this policy changes in a way that materially affects what we do with your information, we will tell you before the change takes effect. The effective date at the foot of this page always names the version you are reading.
Anything here you want in writing — a data processing addendum, the sub-processor list as a document, or an answer about a specific record — write to support@baystacker.com or open the support page. The Terms of Service are at /terms.
BayStacker is operated by
Bellu Productos
Mariano Monterde 309, 31000 Chihuahua, Chihuahua, Mexico
Effective Sep 27, 2026. Governed by the laws of Mexico; disputes are heard by the courts of Chihuahua, Chihuahua, Mexico.