Privacy policy
The short version: we collect an email address so you can have an account, we publish only what you choose to publish, and we never ask where you live.
Draft. This describes what the software actually does today, and it has not been reviewed by a lawyer. It is not yet a complete GDPR or CCPA disclosure, and it will be replaced before any large-scale launch.
Last updated 25 August 2026
Who handles your data
Garage Setups is owned and operated by PGBDIC LLC, an Illinois limited liability company. PGBDIC LLC is the controller of the personal data described here, and is who a question or a deletion request is addressed to.
What we collect
If you only browse
No account is needed and we ask you for nothing. We do use Google Analytics 4 to count visits and see which pages get used, which sets a first-party cookie in your browser to tell repeat visits from new ones. It runs only on the live site — local and preview builds load no analytics script and set no analytics cookie. Advertising storage, ad personalisation and ad-user-data signals are switched off in code, not merely left unconfigured. Our hosting provider keeps standard server request logs. The planning tools store their working state in your own browser’s local storage; that never leaves your device and we cannot read it.
If you create an account
- Email address and password. Handled by our authentication provider (Supabase Auth). Your password is stored as a hash; we never see it. Your email address is never displayed publicly anywhere on the site.
- A session cookie. Strictly necessary to keep you signed in. The analytics cookie described below is set only if you agree to analytics, and never before. There is no advertising cookie of any kind.
- Anything you send us through the contact page. The message itself, the reply address you give us, and which topic you chose. It is stored so a person can read and answer it — it is not emailed anywhere, not added to a mailing list, and never shown publicly. Only the site operators can read it.
- Whatever you put in your profile. Display name, optional handle, bio, general location, website. All optional except the display name, all under your control, all deletable.
If you publish a build
Everything on a setup profile is content you entered and chose to publish: dimensions, dates, costs, product links, write-up and photographs. Each of these has a visibility control described below.
What we never ask for
- Your street address. There is no field for one anywhere in the product.
- Your phone number.
- Payment details. There is nothing to pay for.
- Any special-category data (health, biometrics, and so on).
Location precision is yours to set
Every build has one of three location settings, and the default is the middle one:
- Hidden. No location appears anywhere on the public page — no city, region or country.
- Region only. A state or region code, nothing narrower.
- City and region. Only if you explicitly choose it.
This is enforced in the database view that public pages read from, not just in the interface. If you set a build to “hidden”, the location data is not sent to the browser at all.
Photographs and metadata
Photographs are decoded and re-encoded in your browser before upload. That process discards all EXIF metadata, including GPS coordinates, camera serial numbers and timestamps. The original file never leaves your machine.
Uploads land in a private storage bucket that has no public read access. Images become publicly viewable only when you include them on a published build, and even then they are served through short-lived signed links rather than permanent public URLs. Draft, unpublished and moderator-rejected images have no public path at all.
Cost privacy
You choose whether your public page shows an exact total, a total plus an itemised breakdown, a broad band only, or nothing. Individual cost lines can be marked private within an otherwise public breakdown. Amounts you have kept private are not included in the data sent to any visitor’s browser.
Who we share data with
We use these processors, and no others:
- Supabase — database, authentication and file storage.
- Vercel — application hosting and content delivery.
- Google Fonts — webfont delivery for the site’s typography.
- Google Analytics 4 — audience measurement, on the live site only.
We do not sell personal data. There are no advertising networks and no data brokers. Analytics is limited to Google Analytics 4, and what we send is a fixed list of page views and interaction names: which tool was used, that a build was saved, that a product link was clicked. Those events carry no cost amounts, no location strings, no build titles, no email addresses and no free text of any kind. That restriction is enforced by the event contract in the code rather than by convention.
Analytics runs only if you say yes. The first time you arrive we ask, once; until you answer, no analytics script is requested and no analytics cookie is set. If you decline, nothing is loaded at all — not the script, not a request carrying your IP address — and the site works exactly as it otherwise would. Your answer is kept in your browser’s local storage, not in a cookie, so it is never sent to us. Clearing your site data clears the answer and we will ask again.
You can also use Google’s opt-out browser add-on if you would rather block it everywhere.
Outbound links
Merchant links go through a redirect on our own domain that validates the destination and sends a no-referrer header, so the merchant does not learn which setup you came from.
Retention and deletion
You can unpublish or delete any setup from its editor. Deleting a setup removes the setup, its stages, cost lines, product links, photographs (including the stored files) and any questions on it.
Full self-service account deletion is not built yet. Ask us through the contact page and we will delete the account and everything attached to it manually. We would rather tell you that than put a button here that quietly does nothing.
Contact messages are kept until the thing they are about is resolved, and then for as long as we need them to show what we did and why — a takedown or privacy request is a record we may have to be able to account for. Messages marked as spam are not correspondence and are discarded once we have finished dealing with the abuse they came from. Deleting your account does not delete a message you sent us, but it does detach it from your account. You can ask us to delete a specific message.
Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to processing. Most of that is already self-service through account settings and the build editor. For anything else, contact us and we will action it.
Children
This site is not intended for anyone under 16, and accounts should not be created by them.
Contact
Privacy questions and deletion requests go through the contact page, which puts them in a queue we read. The address hello@garagesetups.com is ours but its mailbox is not yet receiving mail, so please use the form rather than emailing it. We are saying so here rather than on the contact page alone, because a deletion request that silently goes nowhere is worse than no address at all. You can also delete or unpublish any setup yourself from its editor at any time, without contacting us. See the contact page for current status.