🔒 Policy Document v2.4

Data Security & Privacy Commitment

Last Updated: November 12, 2024 | Effective Date: Immediate

Automotive DIY maintains a zero-compromise approach to data security. This document outlines the technical, administrative, and physical controls we implement to protect your personal information, payment data, and community contributions.

1. Security Overview (Our Commitment)

As a platform bridging e-commerce, educational content, and interactive community forums, Automotive DIY handles multiple data types with distinct risk profiles. Our security architecture is built on defense-in-depth principles, continuous monitoring, and transparent accountability.

🛡️ Core Principle

We treat every byte of user data as critical infrastructure. Security is not an afterthought; it is embedded into our development lifecycle, infrastructure design, and operational workflows.

2. Data Collection & Scope

We only collect data necessary to provide, secure, and improve our services. Data categories include:

  • Account Data: Name, email, secure hashed passwords, 2FA credentials, and preferred vehicle profiles.
  • Transaction Data: Billing addresses, order history, and PCI-compliant tokenized payment references.
  • Usage & Diagnostic Data: Tool usage metrics, guide engagement, OBD2 diagnostic sync logs (anonymized by default).
  • Community Contributions: Forum posts, uploaded repair photos, project logs, and peer reviews.

All data is classified by sensitivity level and stored in isolated environments with appropriate access controls.

3. Technical Safeguards

Our infrastructure employs enterprise-grade protections across every layer:

🔐 Encryption

AES-256 at rest, TLS 1.3 in transit. Zero-knowledge architecture for sensitive user preferences.

🌐 Network Security

Web Application Firewall (WAF), DDoS mitigation, VPC isolation, and strict egress filtering.

👥 Access Control

Role-Based Access Control (RBAC), mandatory MFA for internal systems, just-in-time provisioning.

📊 Monitoring

24/7 SIEM logging, anomaly detection, automated threat hunting, and quarterly penetration testing.

4. User Account Protection

Your account is protected by industry-leading authentication standards:

  • Passwords are hashed using bcrypt with adaptive cost factors and salted per user.
  • Two-Factor Authentication (2FA) is strongly recommended and supported via TOTP, hardware keys, and secure SMS fallback.
  • Session management uses secure, HTTP-only, SameSite cookies with automatic timeout and device fingerprinting.
  • Unauthorized access attempts trigger immediate account lockout and user notification.

5. Payment Security

Automotive DIY does not store raw credit card numbers. All payment processing is handled through PCI-DSS Level 1 certified partners. We utilize:

  • Tokenization for all recurring billing and order history references
  • 3D Secure 2.0 verification for high-risk transactions
  • Real-time fraud scoring and velocity checks

⚠️ Important Notice

We will never request your full card number, CVV, or password via email, phone, or in-app chat. Always verify support communications through official channels.

6. Community & Forum Data

Our DIY community thrives on shared knowledge. We protect contributor data through:

  • Automated PII scanning to prevent accidental exposure of license plates, VINs, or personal addresses in posts
  • Granular privacy controls for project logs and repair uploads
  • Content moderation pipelines that balance safety with open knowledge sharing
  • GDPR-compliant data export and permanent deletion tools for all forum accounts

7. Compliance & Standards

Automotive DIY adheres to globally recognized data protection frameworks:

  • GDPR (EU): Lawful basis mapping, DPO oversight, cross-border transfer safeguards
  • CCPA/CPRA (California): Opt-out mechanisms, sale/sharing disclosures, verified deletion rights
  • PCI-DSS v4.0: Validated annually for all payment-handling subsystems
  • ISO 27001: Certification roadmap in progress, targeting Q3 2025

8. Breach Response Protocol

In the event of a security incident, we follow a strict response timeline:

  1. 0-4 Hours: Containment, forensic isolation, initial impact assessment
  2. 4-24 Hours: User notification preparation, regulatory consultation, remediation deployment
  3. 24-72 Hours: Full transparency report published, affected users contacted via verified channels
  4. Ongoing: Post-incident review, architecture hardening, independent audit scheduling

We prioritize transparency over reputation management. You will always be informed if your data is compromised.

9. User Rights & Requests

You maintain full ownership of your data. Available rights include:

  • Access, export, or correct your personal information
  • Request permanent deletion (subject to legal retention obligations)
  • Opt out of non-essential data processing and marketing
  • Appeal automated decisions affecting your account or content

Submit requests via your account dashboard or contact our privacy team. We respond within 30 days as required by applicable law.

10. Security & Privacy Contact

For security vulnerabilities, policy questions, or data requests:

  • Email: security@automotivediy.com
  • PGP Key: Available at security.automotivediy.com/pgp
  • Bug Bounty: Report via our HackerOne program for eligible findings
  • DPO: Data Protection Officer available for regulatory inquiries

We welcome responsible disclosure and commit to acknowledging all valid submissions within 48 hours.

This document is governed by the laws of Michigan, USA. Automated DIY reserves the right to update this policy with 30 days notice.