Storm Rider Solutions LLC
Privacy policy
Effective 15 September 2026 · Version 1.0
Who we are and what this covers
Easy Shop is management software for collision and paintless dent repair shops, operated by Storm Rider Solutions LLC (stormrsolutions.com), Texas, United States. Contact us at privacy@stormrsolutions.com or 401-203-5823.
This policy covers two different relationships, and the difference matters because your rights differ.
What we hold
About shop staff, as our own users
Name, email address, the shop you belong to, your role and trade, and your password stored only as an Argon2id hash — we never hold the password itself and cannot recover it. To keep accounts secure we record sign-in times, IP address and browser for each session. Where a shop uses Easy Shop for pay, we hold the pay rates, hours, commission and pay sheets the shop enters.
About vehicle owners, on the shop's behalf
Name, phone numbers, email address and postal address; the vehicle's VIN, plate, make, model and colour; insurance claim and policy numbers, deductible, date of loss and adjuster contact details; photographs of the vehicle and its damage; estimates, supplements, invoices and correspondence; and notes shop staff write about the repair. Most of this arrives by importing an estimate file the shop received from their estimating system.
Automatically
Server logs holding IP address, timestamp, page requested and error details, kept for security and troubleshooting. An audit trail of changes made inside a shop's account — who changed what, when, and what it was before — which exists so a shop can answer that question about its own records.
Cookies
Nothing is set on these pages unless you say yes. We use Google Analytics, through Google Tag Manager, to see which pages people find useful. It sets cookies, so it does not load at all until you allow it. Decline and no analytics script is requested, no cookie is written, and the site behaves identically. There is no "reject" that quietly means "some".
Your answer is remembered in your browser's local storage under es_consent, not in a cookie — setting a cookie on somebody who just declined cookies would be a poor start. Change it at any time from Cookie choices in the footer of every page. Turning it back off clears the analytics cookies and reloads the page, so nothing carries on in memory.
If your browser sends a Global Privacy Control signal we treat that as a no and never ask. You do not have to click anything and you will not see a banner.
What Analytics records is the ordinary set: pages viewed, roughly where in the world the request came from, the kind of device and browser, and how you arrived. We do not use it to identify you, and no advertising or remarketing tags are configured. Google processes that data under its own terms.
Inside the application, Easy Shop sets one cookie, es_sid. It holds a signed session identifier, is not readable by scripts in your browser, and exists solely to keep you signed in. It expires after 14 days, sooner if the session goes unused. It is strictly necessary for the service to work and so does not require consent; if you block it you cannot sign in.
We set no advertising cookies and run no remarketing, on the public pages or in the application.
This measurement covers these public pages only. It is not in Easy Shop. Inside the application there is exactly one cookie, es_sid, and no analytics of any kind: no tag manager, no Analytics, no pixels, no session recording. A shop's own screens are not measured, and no repair order, customer record, photograph or claim detail is ever sent to Google or to anyone else for measurement. The two are separate systems that happen to share a domain.
One third-party resource loads whatever you answer, because it sets no cookie: the Inter typeface from Google Fonts. Google receives the request for the font files, including your IP address, as it would for any image loaded from another site. Google Tag Manager and Analytics are requested only after you allow them.
Why we hold it, and what we never do
To provide the service, to keep accounts and records secure, to support shops when something goes wrong, to bill for the service, and to meet our legal obligations.
We do not sell personal information. We do not share it for targeted advertising. We do not use one shop's data to serve another shop, and we do not use vehicle owners' information for our own purposes at all. Each shop's records are held in a separate database with its own credentials.
Who else sees it
People at your own shop, according to the permissions the shop sets. Our hosting provider, DigitalOcean, which stores the data in its New York City, United States region. Google, only if your shop connects Google Calendar, and then only the appointment details needed to create the calendar entry — nothing about the customer's insurance or money. Resend, which delivers our email, and Twilio, which will deliver text messages once that is live — each receives only what is needed to deliver the message. We may disclose information if the law requires it, and we will tell the affected shop unless we are forbidden to.
Our staff can access a shop's account only to provide support or fix a fault. That access is logged.
How long we keep it
Repair records, including customer details and photographs, are kept while the shop's account is active. A closed file moves to archival storage a year after closing, and personal details are held no longer than ten years; the accounting record of the repair — its number, dates, amounts and labor — is kept as the shop’s business record. A shop may instruct us to delete sooner. Sessions expire and are removed within a fortnight. Server logs are kept one year. Audit records are kept ten years because their purpose is to reconstruct what happened.
If a shop closes its account we delete or return their data within 30 days, except where we must keep something to meet a legal obligation.
Security
Traffic is encrypted in transit. Passwords are stored as Argon2id hashes. Each shop's records sit in a separate database with its own credentials. Access inside a shop is limited by role, and changes to records are recorded in an audit trail. Repeated failed sign-ins lock an account, and sessions end after a period of inactivity.
No system is perfectly secure. If a breach affects your information we will notify you and the relevant authorities as the law requires.
Your rights
Depending on where you live you may have the right to know what we hold about you, to get a copy, to correct it, to have it deleted, and to appeal if we refuse. You may also ask us not to sell or share your information — we do neither, so there is nothing to opt out of. We will not treat you differently for exercising any of these rights.
Write to privacy@stormrsolutions.com. We will respond within 45 days and will tell you if we need longer. We may need to verify who you are first. If we deny your request you may appeal to appeals@stormrsolutions.com, and we will answer an appeal within 60 days.
If you are a vehicle owner, your rights run against the shop repairing your vehicle. Contact them and they can act at once; contact us and we will pass your request to them and help them fulfil it.
Children
Easy Shop is a tool for businesses and is not directed at children. We do not knowingly collect information from anyone under 13.
Accessibility
We are working towards WCAG 2.1 Level AA. If any part of Easy Shop is difficult for you to use, tell us at accessibility@stormrsolutions.com and we will help you get what you need and fix the cause.
Changes
We will post any change here with a new effective date, and will tell shops in advance of a change that materially affects them.