Privacy
How DCA handles personal data
Last updated 5 September 2026
This policy explains what personal data the Dealership Companion App (DCA) collects, why, and what rights you have. DCA is business software used by equipment dealerships and their field engineers. Your employer (the “organisation”) is the data controller for the operational records it keeps in DCA; we process that data on its behalf and act as controller for account, security and product-analytics data described below.
1. Data we collect
Account data. Name, work email address, role, profile photo (optional), and the organisation(s) you belong to.
Operational records. Jobs, quotes, parts, customer and machine details, evidence photos, notes, signatures and reports entered by you or your organisation. These describe work on equipment and may include customer contact details supplied by your organisation.
Location. The engineer app records a GPS position when you confirm arrival at a job, and can convert it to an address. Location is captured only for that action, never tracked in the background.
Device and push data. A push-notification token so the office can notify you about assigned jobs, queried reports and rejected evidence; app version and platform.
Biometric sign-in. If you enable Face ID, Touch ID or Android biometrics, your sign-in credentials are stored in the device’s secure keychain, protected by the operating system. Biometric data itself never leaves your device and is never sent to us.
Usage analytics. Screens viewed, actions taken (for example “job submitted”), app version, device type, and on the web portal, session recordings of your interactions with our own pages. Analytics events reference record identifiers, not customer names or free text.
Support and contact. Messages you send through the contact form or by email.
2. How we use it
- To run the service: assigning and completing jobs, quoting, parts fulfilment, scheduling, invoicing and reporting.
- To keep the app working offline and synchronise your changes when you reconnect.
- To send push notifications and emails you would expect as part of your work (assignments, review outcomes, password resets, invitations).
- To secure accounts: sessions, sign-in, organisation membership and audit trails of changes.
- To understand how the product is used and fix problems, using aggregated and pseudonymous analytics.
- To deliver app updates.
We do not sell personal data and we do not use it for advertising.
3. Legal bases (UK and EU GDPR)
Performance of a contract and legitimate interests of your organisation in running its field-service operations; our legitimate interest in securing and improving the service; consent where you enable optional features such as biometric sign-in or location capture; and legal obligations such as tax records held by your organisation.
4. Who we share it with
We use a small number of processors to run the service. Each only receives what its function needs:
- Cloud hosting and database for the API and web portal.
- File storage (S3-compatible object storage) for photos, signatures and generated PDF documents, accessed through short-lived signed links.
- Push notifications via the Expo push service to deliver notifications to your device.
- Transactional email for invitations, password resets and contact-form messages.
- Geocoding services to turn a captured position or postcode into an address and to estimate travel.
- Product analytics (Mixpanel, EU data residency) for usage analytics and web session recordings.
- App update delivery for over-the-air updates to the engineer app; the update service receives only the app version and platform.
- Accounting integration. If your organisation connects Xero, invoice and customer data it chooses to sync is sent to Xero under that organisation’s Xero account.
Your organisation’s office staff can see the operational records you create. We may disclose data where required by law.
5. International transfers
Data is hosted in the UK/EU where possible. Where a processor operates outside the UK/EEA, we rely on adequacy decisions or standard contractual clauses.
6. Retention
Operational records are kept for as long as your organisation uses the service and for the period it needs for its own legal and accounting obligations, then deleted or anonymised. Account data is deleted when your organisation removes you or closes its account. Analytics data is retained in aggregated form; identifiable analytics profiles are removed on request. Push tokens are removed when you sign out or uninstall.
7. Security
Data is encrypted in transit. Sessions are protected with signed cookies; integration credentials such as Xero tokens are stored encrypted. Every record is scoped to an organisation so one organisation cannot read another’s data. The engineer app stores an offline queue of your unsent changes on the device until they synchronise, and clears it when you sign out.
8. Your rights
You can access, correct, export or ask for deletion of your personal data, object to or restrict certain processing, and withdraw consent for optional features at any time from the app’s Settings (biometric sign-in, notifications, theme). Requests about operational records are usually handled with your organisation, which controls them. Contact us at [email protected]. You also have the right to complain to the Information Commissioner’s Office (ICO) in the UK or your local supervisory authority.
9. Children
DCA is a workplace tool and is not intended for anyone under 16.
10. Changes
We will update this page when the policy changes and show the date above. Material changes will be announced in the app or by email to organisation administrators.
11. Contact
Questions about privacy: [email protected].
