Privacy Policy
How WashOps collects, uses, and protects your data — yours and your team’s.
Effective: July 22, 2026
1. Who we are
WashOps (“WashOps,” “we,” “us”) is the staff-operations app for car wash and detail teams, operated by Suds Software LLC, in the United States (Alabama). WashOps is available at getwashops.com and as an iOS app. Reach us at support@thewashcrm.com.
2. Who this applies to
- Operators — car wash businesses that subscribe to WashOps to run their operations.
- Team members — an operator’s owners, managers, and staff who use WashOps (the schedule, time clock, tasks, performance, financials, etc.), including through the WashOps mobile app. We process this data on the operator’s behalf.
- Applicants — people who apply for jobs with an operator through WashOps hiring tools.
- Visitors — anyone browsing the public getwashops.com marketing site.
3. What we collect
- Account & business info: business name, locations, contact name, email, phone.
- Team member info: names, contact details, roles and permissions, schedules, time entries, pay/HR fields the operator enters, performance and training records.
- Mobile app — photos: with your permission, the WashOps iOS app uses your device camera to capture photos for damage claims and incident reports. Those photos are uploaded to our file-storage provider and attached to the relevant claim or incident record.
- Location — time clock: if your operator enables geofenced time tracking, the app captures your device location at the moment you clock in or out to confirm you are at your assigned work site. This is a single reading at each punch; we do not track your location continuously or in the background. Operators are responsible for notifying their staff that location is recorded at clock-in/out, as required by applicable law.
- Messaging: in-app messages and transactional notifications, and — if you enable them — push notifications (iOS) and SMS text messages.
- New-hire onboarding: when an operator adds a team member, limited payroll onboarding details (including a Social Security Number) are collected through a separate emailed link — see Section 5.
- Hiring / applicant info — application answers, resumes, and interview notes — see Section 6.
- Accounting data from QuickBooks Online, if the operator connects it — see Section 8.
- Subscription billing: handled by our PCI-compliant payment processor; we store a customer reference, the processor stores card details.
- Usage & diagnostics: feature usage, sign-in events, and error diagnostics, used to operate and improve the Service.
4. How we use it
- Provide the Service — run the operator’s workspace, features, and integrations.
- Support — respond to questions you send us.
- Improve the product — aggregated, de-identified analytics. We do not sell personal data or your team’s data, ever.
- Security & legal — prevent abuse, and comply with lawful requests.
5. Payroll onboarding & Netchex
When an operator adds a new hire, the employee receives an emailed link to a secure onboarding page they open in their own browser (this is not part of the WashOps app). There they may enter the details a payroll processor requires, including a Social Security Number.
- The SSN is encrypted on the employee’s device before it leaves it, transmitted to our payroll provider Netchex, and is not stored, retained, or logged by WashOps.
- Bank-account, direct-deposit, and W-4 tax details are collected by Netchex directly through its Employee Self-Service and never pass through WashOps.
- We do store ordinary employment-record fields (job title, hire date, date of birth, home address, emergency contact) to run operations.
6. Hiring & AI features
For hiring, we process application answers, resumes, and interview notes to help operators evaluate candidates. Where an operator enables them, WashOps uses AI providers — Anthropic and OpenAI — for features such as AI phone screens, candidate summaries, suggested interview questions, and resume parsing.
AI output assists human decision-makers; operators remain responsible for hiring decisions. We limit the personal information sent to AI providers, and those providers are contractually restricted from using your data to train their public models except as our agreements permit. We never use this data for advertising and we never sell it.
7. Who we share with (sub-processors)
We share data only as needed to operate the Service, with reputable third-party providers under contract. Each is bound to use the data only to provide its service to us, and we select providers that meet industry-standard security certifications (SOC 2 / ISO 27001 or equivalent):
- Stripe — subscription billing
- Netchex — payroll / new-hire processing (Section 5)
- Anthropic and OpenAI — AI hiring features (Section 6)
- Telnyx — SMS / voice messaging
- Intuit (QuickBooks Online) — accounting (Section 8)
- Resend — transactional email delivery
- Sentry — error diagnostics
- Vercel — application hosting (United States)
- Neon — encrypted PostgreSQL database (United States)
- Vercel Blob — file and photo storage (claim and incident photos)
- Apple Push Notification service — delivery of iOS push notifications
We may also share data when legally required, or in connection with a merger, acquisition, or asset sale (with advance notice).
8. QuickBooks Online & accounting data
Operators can optionally connect their business’s QuickBooks Online company to WashOps (Settings → QuickBooks) to review and correct their financials inside WashOps. If you connect it, here is exactly what we access, how we use it, and how we protect it:
- What we access: using the QuickBooks Accounting scope, we read your Profit & Loss and Profit & Loss Detail reports, and the account, class, and transaction data needed to display and review them. When you approve a coding correction, we update the account or class on the specific transaction you approved.
- How we use it: solely to provide the WashOps financial-review features you connected — displaying your reports, letting your team flag miscoded transactions, and applying the corrections you explicitly approve back to QuickBooks. We do not use your QuickBooks data for advertising, and we never sell it.
- Your control: WashOps only writes changes to QuickBooks that an authorized manager explicitly approves, after a confirmation that states the exact change. You can disconnect QuickBooks at any time from Settings → QuickBooks.
- How we protect it: your QuickBooks access and refresh tokens are encrypted at rest (AES-256-GCM) and are never exposed to your browser or to other tenants. Pulled reports are stored in your own tenant’s encrypted database records.
- Retention & deletion: when you disconnect QuickBooks — or delete your WashOps account — we delete the stored QuickBooks tokens. Pulled report data is removed on account deletion under our standard retention (Section 9).
Our use of information received from the QuickBooks/Intuit APIs adheres to Intuit’s developer terms and applicable API data policies. Intuit is an independent service; its handling of your data is governed by Intuit’s Privacy Policy.
9. Data location, retention & security
Data is stored on servers in the United States. We retain Customer Data for the duration of your subscription; on termination it is preserved for 90 days and then deleted. Server logs are retained ~30 days; database backups may persist longer per our provider’s point-in-time recovery policy.
We use industry-standard security: TLS in transit, encryption-at-rest, hashed passwords, per-tenant access controls, and audit logging. No system is perfectly secure, but if we discover a breach affecting your data we will notify you within 72 hours of confirmed discovery.
10. Your rights
You can access, correct, export, or delete your data — through your WashOps workspace or by emailing support@thewashcrm.com. California and other state residents have additional rights (know/delete/opt-out of sale); we don’t sell personal data, and we honor verified requests.
11. Children
WashOps is for businesses; you must be at least 18 to sign up. We don’t knowingly collect data from children under 13.
12. Cookies
We use cookies for authentication and basic functionality (session handling, CSRF protection). We don’t use third-party advertising cookies or cross-site tracking.
13. Changes
We may update this policy. Material changes will be sent to your account’s contact email at least 30 days before taking effect, and the effective date above will be updated.
14. Contact
Privacy questions? Email support@thewashcrm.com with the subject “Privacy.”