Privacy Policy
Effective date: May 1, 2026 · Last updated: May 14, 2026
Arron Brewster, doing business as Indy Exotic Detailing ("we," "us," or "our"), operates the website at indyexoticdetailing.com. This Privacy Policy explains what personal information we collect, why we collect it, how we protect it, and your rights. By using our site or services, you consent to the practices described here.
1. Information We Collect
We collect information you provide directly when you submit an inquiry or use our dealer portal:
- Contact details — name, email address, and phone number
- Vehicle information — year, make, model, and type of vehicle(s)
- Business details — dealership name, city, and state (fleet inquiries only)
- Service details — selected services, notes, and preferred appointment dates
- Referral source — how you found us, if provided (e.g., Google, referral, social media)
- Promotional code usage — if a promo code is submitted with an inquiry, we record the code used and any discount applied
- Account credentials — email address used to authenticate via Supabase magic link (dealer portal only)
- Electronic signature data — name, IP address, browser/device information, and timestamp recorded when you execute account agreements (dealer portal only); required by the E-SIGN Act and used solely to verify agreement execution
- Condition report photographs — photographs of vehicles taken during pre-service inspection or in the course of service; stored in private cloud storage and used for condition documentation, dispute resolution, and — subject to your opt-out rights described in Section 9 — marketing purposes
We do not collect or store payment card information. Dealer invoices may be issued via Square; card payment data is handled entirely by Square and is not accessible to us. See Section 4.
Agreement records: Dealer account agreements (Master Service Agreement, Fleet Service Contract, and related documents) are retained for the duration of the account relationship plus 7 years to satisfy legal and dispute-resolution obligations. Execution of these agreements is required before services are rendered; see our Terms of Service for details.
2. Legal Basis for Processing
We process your personal information on the following legal grounds:
- Contract necessity — to fulfill service requests you submit, schedule appointments, and manage your account
- Legitimate business interest — to communicate about your service, improve our operations, and protect against fraud
- Legal compliance — to retain records as required by applicable law, including tax and dispute resolution obligations
3. How We Use Your Information
We use collected information to respond to inquiries, schedule and complete services, send transactional emails, manage dealer accounts, and comply with legal obligations.
Automated analysis: Condition report data — including damage flags, service notes, and vehicle details — may be processed by automated analysis tools to help our team identify service patterns and prepare service recommendations for internal review. No automated output is communicated to clients without human review by our team first.
Post-service communications: Approximately 48-72 hours after a service is marked complete, we may send a follow-up email requesting a Google review. These are sent once per completed service and are not a marketing subscription. You may opt out by replying to any such email.
Marketing: We do not send marketing emails without your explicit consent. We do not sell or rent your personal information to third parties — ever.
4. Third-Party Service Providers
We use the following third-party services to operate our business. Each processes data on our behalf and is bound by its own data protection obligations:
- Supabase — database, file storage, and authentication. Data stored in the United States. Privacy policy
- Netlify — website hosting and serverless functions. Privacy policy
- Resend — transactional email delivery. Privacy policy
- Square — dealer invoice generation and payment processing. We provide Square with dealer contact and service information to create invoices; payment card data is handled entirely by Square and is not accessible to us. Privacy policy
- Sentry — backend error monitoring. Sentry receives anonymized request metadata (function name, error type, stack trace) when errors occur in our serverless functions. No form submissions or personal identifiers are intentionally forwarded to Sentry. Privacy policy
- Automated analysis tools — condition report data (damage flags, service notes, vehicle details, and service history) may be processed by automated software to assist our team with internal pattern identification and service recommendations. This processing is strictly internal; data is not shared with third parties for advertising, profiling, or resale.
- Google Analytics 4 — website usage analytics; see Section 8.
We do not authorize these providers to use your data for any purpose other than providing services to us.
5. Data Security
We take reasonable technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption in transit (HTTPS/TLS) for all data transmitted to and from our site
- Encrypted storage via Supabase's managed database infrastructure
- Access controls — database access is restricted by row-level security policies; service credentials are stored in server-side environment variables, not in client-facing code
- Authentication via Supabase magic links — no passwords are stored
No method of transmission or storage is 100% secure. While we implement industry-standard safeguards, we cannot guarantee absolute security.
6. Data Breach Notification
In the event of a qualifying data breach, we will provide notice to affected individuals without unreasonable delay and within the timeframe required by applicable law. For Indiana residents, notice will be provided consistent with Indiana's data breach notification requirements under Indiana Code 24-4.9. Notification will be made via email (where an address is on file) or by a prominent notice on our website. The notification will describe the nature of the breach, the data involved, and steps we are taking to address it.
7. Data Retention
We retain personal information for the following periods:
- Service inquiries — 2 years from submission, unless converted to an active client relationship
- Service and transaction records — 7 years from the date of service, for tax, accounting, and dispute resolution purposes
- Dealer account data — duration of the active account relationship, plus 2 years following termination
- Condition report photographs — retained for the duration of the service relationship plus 2 years for condition documentation and dispute resolution; may be retained longer in anonymized form for marketing use unless an opt-out request has been submitted
- Authentication logs — retained per Supabase's infrastructure policies
You may request deletion of your data at any time. Requests will be honored within 30 days, subject to legal retention requirements that may prevent immediate deletion of certain records (e.g., signed agreements, transaction records).
8. Cookies and Tracking
We use Google Analytics 4 (GA4) to understand how visitors interact with our site. GA4 collects anonymized usage data — including pages visited, time on site, general geographic region, device type, and how you arrived at our site — and sends it to Google servers. This data is used solely to improve our website and services. Google Analytics does not collect your name, email, or any information you submit through our forms.
You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on, or by enabling a global privacy control in your browser.
Supabase may set strictly necessary session cookies for dealer portal authentication — these do not track you across other sites and are required for the portal to function.
We do not use advertising pixels, cross-site behavioral tracking, or sell your data to third parties for advertising purposes.
Do Not Track: Our site does not respond to browser Do Not Track (DNT) signals. Google Analytics data collection can be controlled via the opt-out method described above.
9. Your Rights
You have the right to request access to, correction of, or deletion of your personal information. You may also opt out of non-essential communications or marketing use of photographs of your vehicle at any time. To exercise these rights, contact us at privacy@indyexoticdetailing.com and we will respond within 30 days.
Photo opt-out: To opt out of marketing use of photographs of your vehicle, submit a written request to privacy@indyexoticdetailing.com. Requests are effective going forward within 30 days of receipt. We are not obligated to remove previously published materials where your vehicle is not personally identifiable.
State-specific rights: Depending on your state of residence, you may have additional rights under applicable privacy laws. We will honor verifiable requests consistent with applicable law even if you reside outside Indiana.
10. Business Transfers
If Indy Exotic Detailing is involved in a merger, acquisition, asset sale, or transfer of all or a portion of its business, your personal information may be transferred as part of that transaction. We will notify you via email or a prominent website notice before your information becomes subject to a different privacy policy.
11. Children's Privacy
Our services are not directed to children under 13. We do not knowingly collect their personal information. If you believe we have inadvertently done so, contact us immediately and we will delete it.
12. Changes to This Policy
We may update this policy at any time by revising the "Last updated" date above. Continued use of our services after changes constitutes acceptance of the updated policy.
13. Governing Law
This Privacy Policy is governed by the laws of the State of Indiana, without regard to conflict of law provisions.
14. Contact Us
For privacy-related requests — data access, correction, deletion, or photo opt-out — use the dedicated privacy contact below. For general business inquiries, use our main business contact.
- Privacy and Data Requests: privacy@indyexoticdetailing.com
- General Business: indyexoticdetailing@gmail.com
- Phone: 317.420.4962
- Location: Fishers, IN