Privacy policy

Last updated: 2 July 2026

This policy explains how Simplysim Solutions Ltd(“we”, “us”, “our”), trading as MechManager, collects, uses and protects personal data when you visit our website, create an account, or use the MechManagersoftware (the “Service”). We are committed to handling your data in line with the UK GDPR and the Data Protection Act 2018.

Who we are

MechManager is operated by Simplysim Solutions Ltd, a company registered in England & Wales under company number 16302568, with its registered office at 4 Gallowsfield Walk, Market Drayton, England, TF9 3FP. We are registered with the UK Information Commissioner’s Office (ICO) under reference ZB960469.

For any privacy question, or to exercise your rights, contact us at hello@simplysim.co.uk.

Controller and processor roles

MechManager is business software used by garages to run their operations. Depending on the data, we act in one of two roles:

  • As a controller— for the personal data of the garage’s account holders and staff logins (names, email addresses, contact details, login and billing information), and for visitors to our marketing website.
  • As a processor — for the personal data a garage enters into the Service about its own customers and vehicles (for example customer names, contact details, vehicle registrations and job history). The garage is the controller of that data; we process it only to provide the Service on their instructions. If you are a customer of a garage, please contact that garage about your data.

Information we collect

  • Account & profile data — your name, business name, email address, phone number and password (stored only as a secure hash).
  • Business data you enter — customers, vehicles, bookings, jobs, invoices, quotes, staff and rota records you create in the Service.
  • Billing data — subscription plan, and payment details processed by our payment provider (we do not store full card numbers).
  • Usage & technical data — IP address, browser/user-agent, and activity needed to keep your account secure and the Service working.
  • Vehicle lookups — when a registration is looked up, we query the DVSA MOT History service and cache the public vehicle/MOT result.
  • Communications — messages you send us and emails the Service sends on a garage’s behalf (e.g. booking confirmations, invoices).

How and why we use it (lawful bases)

  • To provide the Service under our contract with you (UK GDPR Art. 6(1)(b)) — creating your account, running bookings/jobs/invoices, sending transactional emails.
  • Billing and fraud prevention under our legitimate interests and to perform our contract.
  • Security, support and improving the Service under our legitimate interests, balanced against your rights.
  • Legal and accounting obligations (e.g. keeping invoice records) under legal obligation.
  • Marketing emails only where you have opted in or under the soft opt-in for existing customers; you can unsubscribe at any time.

Sharing and sub-processors

We do not sell your personal data. We share it only with service providers who help us run MechManager, under contract and only as needed:

  • Stripe — payment processing for subscriptions and, where a garage enables it, taking card payments from their customers.
  • Email delivery provider — to send transactional and account emails.
  • DVSA — the government MOT History service, for vehicle registration lookups.
  • Hosting & database providers — to store and serve the Service securely.
  • Authorities or advisors where we are required to by law, or to establish or defend legal claims.

International transfers

Where a provider processes data outside the UK, we rely on an approved safeguard such as UK adequacy regulations or the International Data Transfer Agreement / addendum to the EU Standard Contractual Clauses.

How long we keep it

We keep account and business data for as long as your account is active and for a reasonable period afterwards to meet legal, accounting and tax obligations (invoice records are typically retained for six years). Data we process on behalf of a garage is retained per that garage’s instructions, and deleted or returned on request when our contract ends. Cached vehicle-lookup data expires automatically.

Security

Passwords are stored as salted hashes, sessions use secure httpOnly cookies, and access to data is restricted. We take appropriate technical and organisational measures to protect personal data; however, no system can be guaranteed completely secure.

Your rights

Under UK data protection law you have the right to access, correct, delete or restrict your personal data, to object to certain processing, and to data portability. To exercise any right, email hello@simplysim.co.uk. If you are a garage’s customer, please contact that garage (the controller) in the first instance.

You also have the right to complain to the ICO at ico.org.uk, though we’d appreciate the chance to help first.

Cookies

We use a small number of essential and preference cookies. See our Cookie policy for details.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “last updated” date above and, where appropriate, notified to you.

Contact us

Simplysim Solutions Ltd, 4 Gallowsfield Walk, Market Drayton, England, TF9 3FP. Email: hello@simplysim.co.uk.