360 Ops Hub for Tekmetric - Privacy Policy
Effective September 2, 2026. Last updated September 11, 2026.
Who we are
The 360 Ops Hub for Tekmetric Chrome extension is published by 360 Auto
Group, which operates the 360 Ops Hub shop-operations platform ("we",
"us"). Questions about this policy:
tpennel@360autosvc.org.
Who the extension is for
It is a work tool for employees of automotive repair shops licensed on
360 Ops Hub - currently 360° Auto Service and 360 Transmission &
DriveTrain. It is distributed privately, as an unlisted Chrome Web Store
item and as a self-hosted package for shop computers. Installing it grants
no access by itself. The first time an employee signs in to their
company's 360 Ops Hub dashboard in the same browser, the dashboard sets the
computer up as one of the company's trusted computers; after that, whoever
is signed in uses the extension with their own access. Until a computer is
set up and someone is signed in (or an older setup uses a personal access
token), it only asks the dashboard whether someone is signed in and checks
for updates; it sends no repair-order data. It is not meant for personal or
consumer use, or for children.
In short
- It reads the Tekmetric repair order you are working on, only on
Tekmetric pages. Some of this happens automatically while a repair order
or the job board is open; the rest happens when you use a feature.
- The extension sends that information only to your company's 360 Ops
Hub dashboard at ops.360autoservice.com (or another dashboard address set
on its Setup page).
- For AI-assisted write-ups and questions, the dashboard sends the text
involved to OpenAI, our AI service provider, to produce the result.
- The dashboard records the IP address of shop computers for
security.
- We do not sell this data, use it for advertising, or use it for
anything unrelated to the extension's purpose.
What the extension reads in Tekmetric
The extension runs only on Tekmetric pages (tekmetric.com). It does not
read any other website, your browsing history, cookies, or passwords. On
Tekmetric pages it reads:
- The page address and title - only to work out which
shop and repair order is open. Tekmetric's own shop and repair-order
numbers are sent automatically for the features below; the extension does
not keep or send a list of the pages you visit.
- The repair order, whenever the panel is open - the
repair-order number, job names, totals and approval state, the ticket's
gross-profit figures and goal marker, labor lines (description, technician
name, hours, price), parts (description, part number, quantity, price),
the customer and technician concern text and whether each has a finding,
odometer readings, and whether a VIN has been entered (not the VIN
itself). It is used in the panel on your computer (for example, the
gross-profit strip and the Check-In tab) and is sent to the dashboard only
by the Audit tab.
- The inspection sheet, while the Audit tab is open -
each inspection item's result, notes and photo count. When the Inspections
tab is not the one on screen, the extension loads that repair order's
Inspections page out of sight, in a hidden frame, to read it.
- The text field you are typing in - while the panel is
open, its text is copied into the panel's Rewrite tab on your computer as
you type, so it is ready to rewrite. It is not recorded, and it leaves your
computer only if you choose to rewrite it.
- The customer concern on the ticket, when the Check-In tab
opens - sent to the dashboard to choose which check-in questions
to show. The tab opens by itself when you click into a Customer Concern
box.
- Vehicle Leaving details - the repair-order number,
the customer name and vehicle shown in the ticket heading, and the service
writer and technician names. These are sent automatically when a repair
order opens, so the Vehicle Leaving button is ready, and again when you use
it.
- Job board and repair-order status - automatically,
while the job board or a repair order is open: the repair orders on screen
(to show which have a Vehicle Leaving case or a waiter timer), which of
them are marked as waiting customers, and whether jobs show as approved or
declined. The dashboard acts on these reports only where the feature is
enabled for that computer or, on personal-token setups, for stores the
person can access (Vehicle Leaving also needs a role that can view
it).
The extension writes into Tekmetric only when you click Insert: it places
the text you chose into the Tekmetric field, and Tekmetric saves it only when
you do. It sends no data to Tekmetric; the only Tekmetric page it loads on
its own is the hidden Inspections page described above.
What the extension keeps in Chrome
- Local extension storage on that computer: a random
identifier the extension creates for this browser installation (not a
hardware serial number or network address), the computer's access
credential and its name (or, on older setups, a personal access token),
and the dashboard address if one was set. Nothing is written to Chrome sync, so none of it follows a Google
account to another computer. Revoking or disconnecting the computer
removes its credential; uninstalling the extension removes
everything.
- Session storage, which Chrome clears when the browser
closes: the last repair order and inspection read for the audit
(for the one repair order being worked on), when the dashboard last
answered, update status, whether access was revoked, and the name of the
person the dashboard last said was signed in (so the panel can show who
is using the computer), and when the panel last told the dashboard that
person was still working.
What it sends, and where
The extension connects only to ops.360autoservice.com (or another HTTPS
dashboard address someone sets on its Setup page), over HTTPS. Requests
carry the computer's credential, its random browser identifier, the
extension's version number, and the browser's 360 Ops Hub sign-in (the
dashboard's own sign-in cookie, which Chrome attaches for that site), so the
dashboard knows which computer and which person each request comes from;
the version check carries none of them. The extension never reads browser
cookies itself. The request that sets a computer up carries the same
sign-in, the random browser identifier and the name of the computer's
operating system (for example "Windows"), and nothing else. "Sign out" in
the panel asks the dashboard to end that sign-in.
When the person signed in uses a feature in the panel - an audit, check-in,
a procedure search, a rewrite, a Vehicle Leaving update - and it succeeds,
the extension also tells the dashboard, at most once every five minutes,
that this person is still working, which is recorded with the sign-in so an
administrator can see which computers are in use. Being signed in does not
time out: it lasts until you sign out, an administrator ends your sessions,
your password changes, your account or access changes, or this computer's
access is disabled. "Sign out" in the panel ends it at once, on this
computer and anywhere that sign-in was copied.
That request carries only the credential, browser identifier, version and
sign-in above - no repair-order data - and automatic requests never send it.
Some requests are automatic while
Tekmetric screens are open - Vehicle Leaving preparation, board status and
waiter reports. The rest are sent when you use a feature: the repair order
and inspection for an audit, the ticket's customer concern when the Check-In
tab opens, text you ask to rewrite, check-in answers, questions and searches
you type, and Vehicle Leaving updates you enter.
Version checks carry no personal, customer or repair-order information.
What our dashboard does with it
- Audits, inspection checks and check-in question
matching are worked out and returned to the panel. Nothing from
them is stored.
- Rewrites and check-in write-ups. Text you ask to
rewrite, and the check-in answers you type in the panel, are sent to
OpenAI to produce the rewritten text. Each check-in answer is sent for a
spelling and grammar clean-up when you move to the next box, and the
answers are combined into a draft concern. The result comes back to the
panel; we do not store the text.
- Questions in the Procedures tab. When what you type
reads like a question, the dashboard sends it to OpenAI, together with
excerpts from your company's published procedures and its approved
referral list (business names and contact details), to draft an answer
with its source. We keep a copy of the question, with email addresses and
phone numbers masked, the answer, and which person or computer asked, so
the company can review answer quality. Question logs (the masked question,
a result count and who asked) are deleted after 90 days. Plain procedure
searches are not sent to OpenAI and are not logged.
- Vehicle Leaving. The dashboard checks the repair order
against your shop's own Tekmetric account to confirm it and fill in the
details. The details read from the page are stored only if you start a
case. Cases are saved in your company's 360 Ops Hub records with the time
and the person or approved computer behind each change, and can notify the
employee a case is assigned to.
- Waiter timers, and which repair orders showed as
waiting customers, are saved with their times, because measuring how
quickly waiting customers get an answer is what that feature is for.
- Security and administration. We record each trusted
computer (its name, which employee set it up and when, a one-way hash of
its random browser identifier, extension version and ID, last check-in
time and IP address, and which employee used it most recently and when),
a history entry when the person using a computer changes, setup attempts
the dashboard refused for a signed-in person and why, pairing requests from
extensions older than 1.11 (with the requesting IP address, extension
version, extension ID and time) and the stores and features approved for
them, and a history of setups, approvals, changes, credential rotations
and revocations. Older
personal access tokens record when, and from which IP address, they were
last used. To limit abuse, the dashboard counts requests using a one-way
keyed fingerprint of the IP address and account; the raw IP address is not
kept for that purpose. We use IP addresses only for security and support,
never to locate anyone.
Information about your shop's customers - such as a name, a vehicle or a
concern - appears in this data only because it is part of the shop's own
repair orders.
Service providers
We use service providers to run the dashboard. They process this data on
our behalf, only to provide these features:
- OpenAI produces the AI rewrites, check-in write-ups
and procedure answers, and prepares questions for searching the
procedures. Our rewrite and answer requests ask OpenAI not to store the
response, and carry a one-way hashed identifier instead of the name of the
person or computer.
OpenAI's own
API data
policy says data sent through its API is not used to train its models
unless the customer opts in, and that OpenAI may keep it for up to 30 days
to monitor for abuse. The text itself is whatever you submit, so leave out
customer contact details a write-up does not need.
- Vercel hosts the dashboard. Like most hosts, it may keep
short-lived technical logs of requests, which can include text sent in a
request's address, such as a search, a question or a concern.
- Supabase hosts the dashboard's database.
What we do not do
- We do not sell this data or share it for advertising.
- We do not use it for any purpose unrelated to the extension's purpose,
including to determine creditworthiness or for lending.
- We do not use it to train AI models.
- The extension contains no analytics, advertising or tracking code.
- People at your company with dashboard access see the records the
extension creates, as part of the service. 360 Auto Group staff access
them only to support, secure or maintain the service, or where the law
requires it.
How long it is kept
- In Chrome: as described above.
- Audit, inspection and check-in matching inputs, and rewrite text: not
stored by us.
- Question logs: deleted after 90 days.
- Question-and-answer records, Vehicle Leaving cases, waiter-timer records,
computer setups and approvals and their history, and IP addresses recorded for
security: kept as your company's business and security records. They are
not deleted automatically.
- With OpenAI: under OpenAI's own policy, described above.
Your choices, access and deletion
- An administrator can revoke a computer at any time from the dashboard.
It stops working on its next request and clears its stored credential and
cached repair-order data, for everyone who uses it, and it cannot be set
up again until an administrator allows it. Disabling an employee's 360 Ops
Hub account stops that employee on every computer at their next request;
the computers stay trusted for everyone else.
- Uninstalling the extension removes everything it stored in
Chrome.
- To ask what we hold, or to have it corrected or deleted, contact your
company's 360 Ops Hub administrator or email
tpennel@360autosvc.org. Some
records may need to be kept for your company's business, security or legal
obligations.
Security
Traffic is encrypted with HTTPS. Our servers keep credentials and browser
identifiers only as one-way hashes. A computer's credential works only
together with the browser identifier it was issued to, and only for the
person signed in at that moment: each request reaches exactly what that
person's own account may reach, never what the employee who set the
computer up may reach. A computer on an extension older than 1.11 can reach
only the stores and features its administrator approved, until it updates.
Access is checked again on every request, so a revocation, or a change to
an employee's account, takes effect immediately.
Changes to this policy
When what the extension collects, or how it is used, changes, we update
this page and the date at the top before the change takes effect.
Contact
tpennel@360autosvc.org.
Help with setup and problems:
support
page.