TorqBox / LegalPrivacy PolicyTerms of ServiceData Processing Addendum
TorqBox

Privacy Policy

Effective Date: September 22, 2026

TorqTech AI Inc.

This Privacy Policy (this “Policy”) explains how TorqTech AI Inc. (“TorqTech,” “we,” “us,” or “our”) collects, uses, discloses, and protects Personal Information in connection with TorqBox Garage, TorqBox Office, TorqBox DIY, our websites, including torqtech.ai and tbox.tools, our mobile applications (each, an “App”), and related features, content, and services (collectively, the “Services”). “Personal Information” includes information treated as personal information or personal data under applicable law.

The Services include professional vehicle reference assistance, business document and insurance related administrative assistance, and limited consumer assistance for owner tasks, including the Conditional Tasks described in the DIY Addendum. This Policy applies to account holders and other people whose information is processed through the Services, including authorized users and customers of participating shops. It does not govern an independent third party service that you choose to use outside TorqBox.

This Policy forms part of our Terms of Service (the “Terms”). Capitalized terms not defined here have the meanings given in the Terms. This Policy controls over conflicting general Terms concerning our handling of Personal Information. Mandatory law and any controlling data processing agreement may provide additional protections. A shop’s acceptance of the Terms does not replace notices, legal bases, or consents that the shop must provide or obtain from its customers.

Our data practices at a glance. We use information to provide and secure the Services and carry out authorized tasks. We do not disclose Inputs, Uploads, conversations, Output, or other information collected through the Services to underlying foundation model providers for inference, training, or otherwise. We do not sell Personal Information or raw private Inputs, Uploads, conversations, or customer records, and we do not share Personal Information for cross context behavioral advertising. We may create de-identified or aggregated information and use it to train and improve our own models, conduct research and analytics, develop commercial data products, and disclose or license qualifying data, reports, analytics, or insights to third parties as described in Section 3. Organization administrators and recipients you authorize may receive information as explained below.

1. Information We Collect

1.1 Information you or an organization provides. Depending on the features used, we collect the following:

  • Account and contact information: name, email address, phone number, shop or organization name, business contact information, role, account identifiers, and authentication information. Phone based verification may be used to establish or secure an account.
  • Billing and transaction information: subscription, payment status, billing contact, receipts, and limited payment details received from a payment processor or app store. Payment processors or app stores process full payment card details; we do not store full payment card numbers.
  • Inputs, Uploads, and vehicle information: questions, prompts, symptom descriptions, diagnostic trouble codes, year, make, model, VIN, vehicle configuration, repair history, measurements, manuals, records, documents, images, photographs, and other information submitted or imported.
  • Office and customer records: estimates, invoices, repair orders, inspection records, loss descriptions, property damage photographs, policy and claim identifiers, relevant insurance documents, correspondence, customer or recipient contact details, and information needed for an authorized administrative task. Users must minimize personal details and exclude unrelated sensitive material.
  • Voice and other media: audio recorded or uploaded through an enabled feature and resulting transcripts, together with images and files. Device permissions control access to microphones, cameras, and photo libraries. Do not record or upload another person without required authority and consent.
  • Conversations, Output, and workflow records: prompts, generated responses, source references, edits, selected attachments, approval records, recipient instructions, transmission status, and related history, to the extent supported by the features used. These records may be associated with an organization, vehicle, customer, or job.
  • Communications and permissions: support requests, correspondence, feedback, research or survey responses, records of Terms acceptance, and customer consent or other authorization records provided to us.

1.2 Information collected automatically. We collect device and app details, browser and operating system information, language and settings, device or installation identifiers, IP address, authentication and security logs, feature usage, queries, interaction timestamps, performance and crash information, and similar technical information. We may infer approximate location from IP address. We collect precise geolocation only through an enabled feature with the required device permission and legal basis. Cookies, local storage, and similar technologies are described in Section 5.

1.3 Information from other sources. We may receive information from your organization or administrator, authorized collaborators, app stores, authentication or messaging providers, payment processors, infrastructure and analytics providers acting on our behalf, and external services you authorize us to connect. Authorized Office workflows may include information received from a designated insurer or other recipient. We also obtain reference materials from licensed or otherwise lawful sources; these generally are not account holder information but may be used to support responses.

1.4 Information not appropriate for the Services. Do not submit government identification numbers, full payment card or financial account information, passwords or access secrets, medical records, bodily injury claim records, biometric templates, or unrelated information about health, race, religion, sexual life, or other sensitive matters. Office is not intended to process medical or bodily injury claims. Information incidentally included in an upload remains subject to this Policy and applicable law; the prohibition does not make it unprotected. We may restrict, remove, or seek deletion of inappropriate information. Submit only the portions of a document reasonably necessary for a permitted task and redact unnecessary personal details.

2. How We Use Information

We use Personal Information as reasonably necessary to provide, operate, maintain, and secure the Services; authenticate users and manage organization access; process Inputs and Uploads and generate Output; save permitted history and preferences; carry out approved administrative workflows; and process subscriptions and billing.

We also use information to provide support, investigate errors, troubleshoot performance, evaluate a specific incident or suspected misuse, prevent fraud and security threats, enforce lawful Terms, comply with legal obligations, preserve relevant records, and protect rights and safety. Authorized personnel may review relevant content for these operational purposes. This operational review is not permission to train general purpose models on identifiable private content.

We may send service, verification, security, and transactional communications. Where permitted, we send updates and marketing communications, which recipients can opt out of. Consent to a customer repair workflow is not consent to unrelated marketing. Text message and data rates may apply.

For our own model training, general research, dataset and data product development, commercial analytics, benchmarking, and licensing of qualifying data, reports, analytics, or insights, we use De-identified or Aggregated Data as described in Section 3. A new use of Personal Information outside the disclosed purposes requires any additional notice, legal basis, consent, or choice required by applicable law.

3. AI Processing; Our Own Training; De-identified and Aggregated Data

(a) No disclosure to underlying model providers. We do not disclose or make available Inputs, Uploads, conversation history, Output, Personal Information, Usage Data, or data derived from them to providers of third party foundation models underlying the Services for inference, training, fine tuning, evaluation, safety review, or otherwise. This includes content submitted through feedback and user derived de-identified information. Using licensed models does not authorize sending information to their providers.

Ordinary cloud infrastructure, hosting, security, and other authorized service providers may process information solely on our behalf under appropriate restrictions. They may not use it to train or improve their own or another party’s AI models. A vendor’s separate AI business does not give that business permission to receive or use our service data. Section 4 describes permitted service provider processing; it is not an exception allowing underlying model provider processing.

(b) What qualifies. “De-identified or Aggregated Data” has the meaning given in Section 7(f) of the Terms. It is information derived from content, usage information, or Feedback that has been processed so that it does not identify, and cannot reasonably be linked to, a natural person or household, or otherwise qualifies as de-identified, anonymized, or aggregated information under applicable law. It may include record level or transaction level information where permitted by applicable law; it need not be reduced to statistical summaries solely because it is used commercially. We determine the methods and level of detail used to create such information, subject to applicable law and any controlling signed agreement.

(c) Uses and commercialization. Where we have the necessary rights and authority, we may create, retain, reproduce, modify, combine, analyze, use, disclose, distribute, publish, license, commercialize, and otherwise exploit De-identified or Aggregated Data for any lawful purpose. These purposes include operating and improving the Services; training, fine tuning, evaluating, and developing TorqTech models and other artificial intelligence and machine learning systems; research; benchmarking; analytics; industry insights; dataset and data product development; and licensing or providing qualifying data, reports, analytics, or insights to third parties. We need not obtain additional approval or pay compensation, attribution, or revenue sharing except where required by law or a controlling signed agreement. We do not sell Personal Information or raw private Inputs, Uploads, conversations, or customer records.

De-identified or Aggregated Data may preserve commercially useful attributes such as vehicle characteristics, diagnostic codes, repair categories, labor information, pricing ranges, repair outcomes, geographic or market information, and other operational or industry data, provided the resulting information is handled consistently with applicable law and the rights we and users have in the underlying information. De-identification does not itself create copyright, database, contractual, or other rights in third party manuals, policy forms, photographs, databases, or other protected source materials.

(d) Safeguards. We maintain De-identified or Aggregated Data in a form intended not to identify or reasonably permit identification of a natural person or household and comply with any additional safeguards required by applicable law, including applicable restrictions on reidentification and recipient obligations. We do not undertake a higher aggregation or anonymization standard than applicable law requires unless a controlling signed agreement expressly provides otherwise.

(e) Access, confidentiality, and Feedback. Authorized personnel and service providers subject to appropriate restrictions may access information for permitted operational, support, security, or legal purposes and to create qualifying data as authorized. We do not sell or make raw private Uploads or conversations available to unrelated third parties. This does not restrict uses or disclosures of De-identified or Aggregated Data permitted by this Section, authorized disclosures, or other disclosures described in Section 4. Feedback is handled as described in the Terms.

(f) Organization instructions and previously collected information. Where we process information on an organization’s behalf, we follow the applicable agreement and lawful instructions. Mandatory restrictions and a controlling data processing agreement govern. Expanded commercial permissions in the updated Terms apply prospectively to information provided under those Terms, unless existing rights and applicable law independently authorize the use or required additional permission is obtained.

(g) AI limitations. Output may be inaccurate, incomplete, or fabricated. It is not an authoritative record, an OEM instruction, or a verified insurance claim. Review original sources and human approved records. Privacy protections do not change the verification and safety requirements in the Terms and Service Addenda.

4. How We Disclose Information

(a) Service providers. We use providers for hosting and infrastructure, authentication and messaging, payment processing, permitted analytics, customer support, security, and other operational services. They may process information only for authorized purposes on our behalf under appropriate confidentiality and data protection obligations, subject to applicable law. Underlying foundation model providers are not recipients of service data. Contact us for information about relevant subprocessors; any additional notice and objection rights depend on applicable law or the governing data processing agreement.

(b) Organizations and collaborators. If your account is provided or managed by an organization, its authorized administrators may access or manage account details, usage, content, and workflow records. Authorized users or collaborators receive information according to configured permissions and instructions. An organization is responsible for its own privacy notices and management of access. A customer of a shop may need to direct a request to the shop when the shop controls the relevant records.

(c) Approved recipients and integrations. At an authorized user’s direction, information may be provided to a designated customer, insurer, claims administrator, repair platform, or other recipient through an enabled workflow. The required final human approval under the Office Addendum applies to submissions made through Office. Users must verify the recipient and have permission to make the disclosure. A recipient acting independently handles information under its own obligations and policies. An integration does not authorize disclosure to an underlying model provider contrary to Section 3(a).

(d) Legal, security, and safety purposes. We may disclose information where reasonably necessary to comply with law, valid legal process, or a governmental request; protect rights, property, or safety; investigate or respond to fraud or security incidents; enforce lawful agreements; or establish, exercise, or defend legal claims. We assess requests as appropriate and give notice where required and legally permitted. This provision does not authorize routine model provider processing.

(e) Business transactions. Information may be disclosed under appropriate protections in connection with a proposed or actual financing, merger, acquisition, reorganization, bankruptcy, or transfer of business assets. A completed transfer remains subject to applicable law and legally binding commitments concerning the information. A transaction does not by itself authorize an incompatible new purpose or eliminate a required consent.

(f) De-identified or Aggregated Data. We may disclose, license, or otherwise commercialize qualifying information as described in Section 3, subject to applicable law, third party rights, controlling signed agreements, and the prohibition on disclosure to underlying model providers.

(g) Other directed disclosures. We may disclose information with a person’s valid consent or at their authorized direction for a disclosed purpose, subject to the specific restrictions in this Policy. A general consent does not silently amend those restrictions.

5. Cookies and Similar Technologies

We and providers acting on our behalf use cookies, local storage, and similar technologies for authentication, preferences, security, functionality, analytics, and performance. We do not use them to sell Personal Information or for cross context behavioral or targeted advertising. A new advertising use would require an updated notice and any legally required choice or consent before implementation.

Manage available choices through browser or device settings and any consent controls provided in the Services. We obtain consent for nonessential technologies where required, and honor legally applicable opt out preference signals, including Global Privacy Control. Disabling a necessary technology may affect functionality. Browser settings do not necessarily delete information already submitted to an account or organization.

6. Data Retention

We retain information only as long as reasonably needed for the purposes described in this Policy and as permitted or required by law. The relevant period depends on the type of information, account and organization instructions, subscription and support needs, security risks, applicable retention duties, and the establishment or defense of legal claims.

Account and operational content generally remain while needed to provide requested services and manage the relationship. Billing, consent, approval, and transaction records may require longer retention for accounting, compliance, or dispute purposes. Security and support records are retained according to the need to investigate, prevent recurrence, and meet legal obligations. Relevant records may be preserved when an incident, claim, or investigation is reasonably anticipated.

On a valid deletion request or account deletion, we delete or appropriately de-identify associated Personal Information within the applicable legal period, subject to lawful exceptions. Residual backups are protected and removed through applicable backup cycles; if restored, applicable deletion instructions are reapplied. We may need to retain limited information to document a request, honor an opt out, prevent fraud, or comply with law. Deleting your individual account does not automatically erase a separate organization’s records or copies already lawfully delivered to an independent recipient.

We may retain and use lawfully created De-identified or Aggregated Data after termination, account closure, or deletion of source content for as long as permitted by law, without further approval or compensation except as required by law or a controlling signed agreement. This does not apply to information that remains Personal Information or must legally be deleted. Deleting a conversation does not necessarily require removal of qualifying nonpersonal data from our datasets, models, analytics, reports, or insights.

7. Data Security

We use reasonable technical, administrative, and physical safeguards designed to protect information, including appropriate access controls and protections for information in transit. No system or transmission method is completely secure. We do not guarantee absolute security. Organizations and users must safeguard credentials, configure access appropriately, and promptly report suspected compromise to support@torqtech.ai. These user responsibilities do not eliminate our own security obligations. Where required, we provide notices of a qualifying security incident in accordance with applicable law and agreements.

8. Your Privacy Choices

You may review or update account information, manage available conversation or upload controls, and request access, correction, export, or deletion through available account settings or by contacting support@torqtech.ai. We may need information reasonably necessary to verify identity or authority. Some organization controlled records must be handled through the organization; we will assist as required by law and the governing agreement.

You can opt out of marketing emails through the unsubscribe mechanism or by contacting us. Service, security, and transactional notices may still be sent. Where applicable, reply STOP to nonessential texts to opt out; do not rely on an SMS opt out to cancel a paid subscription. Device settings control microphone, camera, photo, notification, and location permissions. Cookie choices are described in Section 5.

Vehicle customers may ask the shop about AI use and withdraw a prospective authorization through the shop, subject to legal requirements and prior lawful processing. The shop must not continue customer specific Garage use after required consent is withdrawn. Contact us concerning information we control; we may coordinate with the shop to address records processed on its behalf. Withdrawal does not authorize destruction of evidence or other records that must lawfully be preserved.

9. U.S. State Privacy Disclosures and Rights

9.1 Scope and categories. This Section applies where a U.S. state privacy law covers the relevant processing. The categories of Personal Information that we collect and may disclose for operational purposes, including during the preceding twelve months to the extent the relevant features were used, are identifiers and customer contact records; account and limited billing details; commercial and transaction information; internet, device, and network activity; approximate location and any precise location separately enabled; audio, electronic, and visual content; professional or employment information provided by a user; submitted vehicle, repair, and administrative records; and limited inferences or generated responses associated with that information. Examples, sources, purposes, and recipient categories are described in Sections 1 through 4. Not every category is collected from every person.

Account access credentials and any enabled precise location may be sensitive Personal Information under applicable law. Sensitive material may also be incidentally included in an upload despite our restrictions. We use or disclose sensitive Personal Information only for permitted operational and other legally authorized purposes, not to infer sensitive characteristics for an unrelated purpose. We provide any additional notice, consent, or limitation mechanism required for a proposed use.

9.2 No sale of Personal Information or targeted advertising. We do not sell Personal Information or share it for cross context behavioral advertising, and we do not use Personal Information for targeted advertising as defined by applicable state privacy law. We do not knowingly sell or share Personal Information of minors. We may use, disclose, license, or otherwise commercialize De-identified or Aggregated Data as described in Section 3; information that does not meet the applicable standard is treated as Personal Information rather than as de-identified merely because identifiers were removed.

9.3 Rights. Depending on applicable law, you may have rights to confirm processing; access and receive a portable copy; correct inaccurate information; delete information; opt out of a sale, targeted advertising, or certain profiling; limit a covered use of sensitive information; withdraw consent where processing relies on it; and appeal a denied request. We do not use the Services to make solely automated decisions about individuals that produce legal or similarly significant effects as contemplated by applicable privacy law. A user must not use AI Output to make an otherwise prohibited decision. No person will receive unlawful discriminatory treatment for exercising a privacy right.

9.4 Requests and appeals. Send requests to support@torqtech.ai or use available account controls. We will respond within legally required periods, subject to lawful extensions and exceptions. We use proportionate verification and do not request unnecessary sensitive information. An authorized agent may act with appropriate proof of authority and any legally required verification. If we deny a request, you may appeal by replying to our response or contacting the same email address with “Privacy Appeal” in the subject line. We explain the outcome and, where applicable, how to contact the relevant attorney general or regulator. We may route a request to the organization responsible for the records and assist it in responding.

9.5 California direct marketing disclosures. We do not disclose Personal Information to third parties for their own direct marketing. California residents may contact us concerning rights under California’s Shine the Light law.

10. Children’s Privacy

The Services are intended for adults at least 18 years old, or the higher applicable age of majority, and are not directed to children. We do not knowingly collect Personal Information directly from children for their use of the Services. Users should not include unnecessary information about minors in repair or administrative records. If we learn of information collected in violation of applicable children’s privacy law or our age restrictions, we take appropriate steps, including deletion where required. Contact support@torqtech.ai with a concern.

11. International Users and Transfers

TorqTech is based in the United States. We and our authorized service providers may process information in the United States and other countries in which our permitted infrastructure operates. Access to a website does not mean every service is offered in every jurisdiction. Where applicable law requires a transfer mechanism, legal basis, additional notice, representative, or data processing agreement, we must implement the applicable requirement before relying on the processing or transfer. Acceptance of the Terms or this Policy is not a substitute for a legally required transfer safeguard or a freely given consent. Contact us for information about relevant processing locations and applicable safeguards.

An insurer, shop, payment service, app store, manufacturer website, or other independent service may apply its own privacy notice to information it collects directly or receives lawfully at your direction. Review those notices and disclose information only when authorized. Providers acting on our behalf remain subject to our obligations and applicable processor restrictions; a reference to their own policies does not release us from those obligations. Underlying model providers do not receive service data as described in Section 3(a).

13. Changes to This Policy

We may update this Policy to reflect lawful changes in practices or requirements. We will post the updated Policy and effective date and give additional notice for material changes as required by law. Where a change requires consent or another legal basis, we obtain it before implementing the affected processing. Changes do not retroactively authorize incompatible use of previously collected information. Continued use is not, by itself, consent to a use that requires a separate affirmative choice. Until a lawful change takes effect, the existing applicable commitments continue to govern.

14. Contact Us

TorqTech AI Inc.

Email: support@torqtech.ai

TorqBox is a service of TorqTech AI Inc. Copyright 2026 TorqTech AI Inc. All rights reserved.