Data Security & Privacy Commitment
Last Updated: November 12, 2024 | Effective Date: Immediate
Automotive DIY maintains a zero-compromise approach to data security. This document outlines the technical, administrative, and physical controls we implement to protect your personal information, payment data, and community contributions.
1. Security Overview (Our Commitment)
As a platform bridging e-commerce, educational content, and interactive community forums, Automotive DIY handles multiple data types with distinct risk profiles. Our security architecture is built on defense-in-depth principles, continuous monitoring, and transparent accountability.
🛡️ Core Principle
We treat every byte of user data as critical infrastructure. Security is not an afterthought; it is embedded into our development lifecycle, infrastructure design, and operational workflows.
2. Data Collection & Scope
We only collect data necessary to provide, secure, and improve our services. Data categories include:
- Account Data: Name, email, secure hashed passwords, 2FA credentials, and preferred vehicle profiles.
- Transaction Data: Billing addresses, order history, and PCI-compliant tokenized payment references.
- Usage & Diagnostic Data: Tool usage metrics, guide engagement, OBD2 diagnostic sync logs (anonymized by default).
- Community Contributions: Forum posts, uploaded repair photos, project logs, and peer reviews.
All data is classified by sensitivity level and stored in isolated environments with appropriate access controls.
3. Technical Safeguards
Our infrastructure employs enterprise-grade protections across every layer:
🔐 Encryption
AES-256 at rest, TLS 1.3 in transit. Zero-knowledge architecture for sensitive user preferences.
🌐 Network Security
Web Application Firewall (WAF), DDoS mitigation, VPC isolation, and strict egress filtering.
👥 Access Control
Role-Based Access Control (RBAC), mandatory MFA for internal systems, just-in-time provisioning.
📊 Monitoring
24/7 SIEM logging, anomaly detection, automated threat hunting, and quarterly penetration testing.
4. User Account Protection
Your account is protected by industry-leading authentication standards:
- Passwords are hashed using bcrypt with adaptive cost factors and salted per user.
- Two-Factor Authentication (2FA) is strongly recommended and supported via TOTP, hardware keys, and secure SMS fallback.
- Session management uses secure, HTTP-only, SameSite cookies with automatic timeout and device fingerprinting.
- Unauthorized access attempts trigger immediate account lockout and user notification.
5. Payment Security
Automotive DIY does not store raw credit card numbers. All payment processing is handled through PCI-DSS Level 1 certified partners. We utilize:
- Tokenization for all recurring billing and order history references
- 3D Secure 2.0 verification for high-risk transactions
- Real-time fraud scoring and velocity checks
⚠️ Important Notice
We will never request your full card number, CVV, or password via email, phone, or in-app chat. Always verify support communications through official channels.
6. Community & Forum Data
Our DIY community thrives on shared knowledge. We protect contributor data through:
- Automated PII scanning to prevent accidental exposure of license plates, VINs, or personal addresses in posts
- Granular privacy controls for project logs and repair uploads
- Content moderation pipelines that balance safety with open knowledge sharing
- GDPR-compliant data export and permanent deletion tools for all forum accounts
7. Compliance & Standards
Automotive DIY adheres to globally recognized data protection frameworks:
- GDPR (EU): Lawful basis mapping, DPO oversight, cross-border transfer safeguards
- CCPA/CPRA (California): Opt-out mechanisms, sale/sharing disclosures, verified deletion rights
- PCI-DSS v4.0: Validated annually for all payment-handling subsystems
- ISO 27001: Certification roadmap in progress, targeting Q3 2025
8. Breach Response Protocol
In the event of a security incident, we follow a strict response timeline:
- 0-4 Hours: Containment, forensic isolation, initial impact assessment
- 4-24 Hours: User notification preparation, regulatory consultation, remediation deployment
- 24-72 Hours: Full transparency report published, affected users contacted via verified channels
- Ongoing: Post-incident review, architecture hardening, independent audit scheduling
We prioritize transparency over reputation management. You will always be informed if your data is compromised.
9. User Rights & Requests
You maintain full ownership of your data. Available rights include:
- Access, export, or correct your personal information
- Request permanent deletion (subject to legal retention obligations)
- Opt out of non-essential data processing and marketing
- Appeal automated decisions affecting your account or content
Submit requests via your account dashboard or contact our privacy team. We respond within 30 days as required by applicable law.
10. Security & Privacy Contact
For security vulnerabilities, policy questions, or data requests:
- Email: security@automotivediy.com
- PGP Key: Available at security.automotivediy.com/pgp
- Bug Bounty: Report via our HackerOne program for eligible findings
- DPO: Data Protection Officer available for regulatory inquiries
We welcome responsible disclosure and commit to acknowledging all valid submissions within 48 hours.
This document is governed by the laws of Michigan, USA. Automated DIY reserves the right to update this policy with 30 days notice.