Legal
Privacy Policy
Last Updated: 27 November 2025
This Privacy Policy explains how PanelDesk ("we", "us", "our") collects, uses, stores, and protects your information when you use our website and workshop management system.
PanelDesk is currently operated by Sam Fourie, based in South Africa. By using PanelDesk, you agree to the practices described in this Privacy Policy.
1. Information We Collect
We collect the following types of information when you use PanelDesk:
1.1 Account Information
- Workshop name
- Contact person name
- Email address
- Password (stored securely by Firebase Authentication)
We do not store or process your password directly.
1.2 Workshop Data
This includes all information you enter into the system, such as:
- Quotes
- Job cards
- Final costing
- Invoices
- Customer names and contact details
- Workshop logo
- Labour, parts, paint and outwork information
- Any other operational data added by you
This data belongs entirely to your workshop. PanelDesk acts as a data processor.
1.3 Quote & Invoice Tracking
When you send a quote or invoice and a customer opens it, we collect:
- Date and time opened
- IP address
- Device or browser information
This is used to provide "quote viewed" tracking inside your dashboard.
1.4 Usage & Analytics Data
We use Vercel Analytics to collect basic, anonymous usage statistics such as:
- Page views
- Device type
- Browser type
- Country (approximate)
This helps improve system performance and stability.
1.5 Payment Information
We use Paystack to process payments.
- We do not receive or store credit card numbers.
- All card data is handled securely by Paystack under PCI-DSS compliance.
2. How We Use Your Information
We use your information to:
- Provide and improve PanelDesk
- Authenticate users and secure accounts
- Generate quotes, job cards, invoices and logs
- Deliver transactional emails (via Resend)
- Provide customer support
- Maintain backups and system stability
- Comply with South African legal requirements (POPIA)
We do not sell, rent or market your data to third parties.
3. Legal Basis for Processing (POPIA & GDPR-Aligned)
We process your data on the following legal bases:
- Contract — to provide the PanelDesk service
- Legitimate interest — to improve security, analytics and functionality
- Consent — for cookies and optional features
- Legal obligation — for tax, security and compliance requirements
4. How Your Data Is Stored
Your data is stored securely in:
- MongoDB Atlas (primary database)
- Firebase Authentication (login & identity)
- AWS S3 (logos and uploaded workshop assets)
- Vercel (hosting infrastructure)
All providers use industry-grade security, encrypted connections and global cloud compliance.
5. How Long We Keep Your Data
We retain your workshop data for as long as your PanelDesk account is active.
After cancellation, we retain data for up to 90 days, unless you request a faster deletion. Backups may persist for an additional short period.
6. Sharing of Information
We do not share your data for marketing or commercial purposes.
We only share information with trusted service providers who support PanelDesk:
- Firebase (Google) — authentication
- MongoDB Atlas — database
- Vercel — hosting
- AWS S3 — storage
- Paystack — payment processing
- Resend — transactional emails
These partners process data strictly on our behalf.
7. Your Rights
Under POPIA and similar privacy laws, you have the right to:
- Access your data
- Correct inaccurate information
- Request deletion of your data
- Withdraw consent for optional features
- Request export of your workshop data
To exercise these rights, email sam@paneldesk.co.za.
8. Cookies
PanelDesk uses cookies for:
- Authentication
- Maintaining sessions
- Basic analytics
- Security and fraud prevention
You may disable cookies in your browser, but some features may stop working.
9. Data Security
We implement multiple layers of security, including:
- Encrypted HTTP (HTTPS)
- Secure cloud infrastructure
- Passwords stored via Firebase hashing
- Database access restrictions
- Regular backups
- Firewalls and access monitoring
While no system is 100% secure, we take all reasonable measures to protect your data.
10. Children's Privacy
PanelDesk is not intended for children under 18. We do not knowingly collect information from minors.
11. Changes to This Policy
We may update this Privacy Policy as the platform grows. When changes are made, we will update the "Last Updated" date above.
12. Contact Us
If you have any questions, contact:
📩 sam@paneldesk.co.za
Founder & Operator of PanelDesk