Privacy policy
Version 1.0
1. Who we are
In these documents "TuneGrid", "we", "us" and "our" mean Tune Grid Pty Ltd, an Australian company (company registration in progress; the registered details, ABN and registered address will be added to this document on registration and shown in your portal settings). The platform runs on remapsolutions.com and its subdomains.
This policy explains how personal information is handled on the TuneGrid platform: the workshop portals on remapsolutions.com subdomains, the onboarding wizards, and the operator console. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles and, for customers in the EU and UK, the GDPR and UK GDPR.
2. The two roles we play
Each workshop portal is run by an independent business (the workshop). For the personal information of a workshop's customers, the workshop is the controller (the business responsible for it) and TuneGrid processes it on the workshop's behalf to run the platform. For the account information of workshop owners and staff, for platform billing, and for platform security and analytics, TuneGrid is the controller. Requests about your data as a workshop customer can be made to your workshop or directly to us; we pass requests to the right party and assist either way.
3. What we collect
Account and identity: email address, verified mobile number (required for workshop operators, optional for customers), display name, and for workshops their legal and trading name, country, business identifiers (such as ABN or VAT numbers) and GST status. Sign-in is passwordless: we store no passwords, and verification codes are stored hashed and expire within minutes.
Files and vehicle data: the ECU files you upload, files derived from them, delivered tuned files, identification fingerprints and match labels, and optional vehicle details you provide (such as registration plate, state, make and model).
Money and records: orders, projects, payments and refunds (processed by Stripe; full card numbers never touch our systems), store credit ledgers, invoices, subscription records, tax calculation records and tax ID validation results, which we must keep accurate and retain for legal periods.
Agreement records: when you accept our legal documents we record which document and version, the time, and your IP address, as evidence of the agreement.
Support and assistant: support threads and their attachments, and conversations with the AI help assistant.
Technical: server logs, error reports, session cookies, and the referral, affiliate or invite context that brought you to the platform.
4. Why we use it
We use personal information to: provide the service you asked for (contract); keep the platform secure, prevent fraud and enforce our terms (legitimate interests); meet legal duties such as tax record keeping (legal obligation); and send marketing only with your consent, which you can withdraw at any time. Verification codes and service messages (such as "your file is ready") are part of the service, not marketing, and carry no marketing content.
5. Who can see what
Your workshop: a workshop sees the data of its own customers, staff see it per their access permissions, and no workshop can see another workshop's customer data. Customer accounts are workshop-scoped.
Cross-workshop marketplace flows: identification results may be enriched from the TuneGrid base library for every workshop, and from a partner workshop's library where both workshops have approved a partner link; results carry their source, and file content is not exposed by matching. When a workshop resells another provider's tune, a business record of that purchase (including the relevant files for that job) exists on both sides so the supplying provider can support and deliver the work. Provider access to a customer file for support is time-boxed and every such access is logged.
Service providers (sub-processors): Google Cloud Platform (hosting and storage, region australia-southeast1, Sydney), Stripe (payments and payout identity checks), Twilio (SMS codes), Resend (transactional email), Anthropic (the AI help assistant), Sentry (error monitoring), and, when a workshop orders tool file decoding, Magic Motorsport and Alientech (using the workshop's own vendor credentials). We also query the Australian Business Register and the EU VIES service to validate business identifiers. We do not sell personal information.
Authorities: we disclose information where the law requires it, and we tell you unless the law prevents that.
6. Overseas disclosures
Data is stored in Australia (Google Cloud, Sydney region). Some providers above process data in the United States and other countries (Stripe, Twilio, Resend, Anthropic, Sentry). For EU and UK customers these transfers are covered by Standard Contractual Clauses, and our processing for workshops is governed by the data processing terms in the workshop service agreement.
7. Security
We protect information with tenant isolation enforced in the database (row level security per workshop), private storage buckets with signed, expiring links, encryption in transit and at rest, hashed verification codes, no stored passwords, audited access to files, and least-privilege access for our own operators. No system is perfectly secure; we operate a data breach response process under Australia's Notifiable Data Breaches scheme and will notify affected people, workshops and the OAIC where the law requires, and notify affected workshops without undue delay of breaches affecting their customers' data.
8. Retention
Abandoned signup drafts are deleted after 30 days of inactivity. Deleted files are recoverable for up to 30 days, then purged. Invoices, tax records and agreement acceptances are kept for as long as tax and corporate law require (generally at least 5 to 7 years). Support threads and project records are kept while the account exists. When an account or workshop closes we delete or de-identify personal information after the export window and the legally required retention periods.
9. Your rights
You can ask us or your workshop to: access a copy of your information, correct it, export it in a portable format, or delete it (deletion is subject to records we must keep by law, which we then quarantine from other use). Contact us through the Support page in your portal, or by email to admin@remapsolutions.com. We respond within a reasonable time, normally within 30 days. If you are unhappy with our handling, you can complain to us first, then to the Office of the Australian Information Commissioner (oaic.gov.au). EU and UK customers additionally have the GDPR rights of access, rectification, erasure, restriction, portability and objection, and may complain to their local supervisory authority. New Zealand and Singapore customers have the corresponding rights under their local privacy laws.
10. Automated processing and the AI assistant
File identification and pricing suggestions are automated, but decisions that significantly affect you (such as refusing a refund, suspending an account or blocking a payment) are not made solely by automation: a human at your workshop or at TuneGrid is responsible for them, and you can ask for a human review of any automated outcome. The help assistant is an AI system: it is labelled as such, its conversations are processed by Anthropic, it answers only from our documentation and your own account context, and it can be wrong; binding information comes from your workshop or our official documents, not the assistant.
11. Cookies
We use only functional cookies: your session, your signup draft, and small preferences (such as the last project you opened). We do not run third party advertising or tracking cookies.
12. Changes and contact
We will post changes here and, for significant changes, notify you in the portal or by email. Every version is archived with its date. Questions and requests: the Support page in your portal, or admin@remapsolutions.com.