Data ownership

Your shop data should leave with you

Customers, vehicles, ROs, photos, documents, messages, payments, and audit history belong to the shop’s operating record. Ownership is meaningful only when the owner can retrieve usable information.

By AutoHoundUpdated August 23, 20269 minute read
THE SHORT ANSWER

Ask for a sample export before signing. Verify the records, relationships, images, and documents you need are retrievable in usable formats, learn whether media is separate, and know exactly when access ends after cancellation.

Ownership is a contract and operating question

A software agreement may separate:

  • Data the shop enters or uploads
  • Data created by employees while using the software
  • Files received from customers, insurers, vendors, or estimating systems
  • System logs and audit history
  • Aggregated or de-identified usage data
  • The vendor's software, formulas, reports, and intellectual property

A fair agreement should state which data is the shop's, the vendor's operating rights, what happens at termination, and how the shop retrieves records.

Have qualified counsel review the agreement when the stakes are high. The operating team should ask: what can we export, who can do it, how long does it take, what does it cost, and can we use the result?

The eight data groups a collision shop should map

1. Customers, contacts, and vehicles

At minimum, the export should preserve customer names, companies or fleet accounts, phone numbers, email addresses, mailing addresses, vehicles, VINs, plates, unit numbers, and the relationship between each customer and vehicle.

Ask how fleet and customer-vehicle relationships are represented, not only whether a customer CSV exists.

2. Repair orders and repair history

Repair-order data should include identifiers, open and closed dates, status, production stage, promised dates, totals, insurers, claims, assignments, notes, and links to the related customer and vehicle.

If the system stores a permanent timeline, ask whether the export includes event dates, types, and the responsible employee. A readable PDF and structured file serve different needs. A strong export may provide both.

3. Estimates and supplements

Ask for the original source files when available, plus the parsed information used by the management system. That may include estimate versions, supplement versions, labor hours, parts, claim information, totals, and approval status.

Verify the actual file types and version history, not only an on-screen summary.

4. Photos and documents

This group includes repair photos, marked-up evidence, scans, signed forms, authorizations, releases, invoices, receipts, sublet reports, PDFs, and other attachments.

The shop should know whether an export provides:

  • Original files or reduced previews
  • Original file names
  • Capture or upload dates
  • Captions and categories
  • The related repair-order number
  • Markup or annotation files
  • A manifest that connects each file to its record

A folder of randomly named images is technically an export. It is not a useful one.

5. Parts and vendor records

Useful parts data includes purchase orders, vendors, part numbers, descriptions, quantities, prices, status, ETAs, receipts, returns, credits, invoice matches, and related repair orders.

If the product stores a photographed or uploaded vendor invoice, confirm that the original image or PDF is included, not only the extracted amount.

6. Customer and adjuster communication

Ask whether the export includes message direction, sender, recipient, date and time, delivery status, template used, attachments, consent status, and the repair order connected to the thread.

For public status pages or approval links, clarify whether the underlying records and evidence are exportable even if the hosted link itself stops working after cancellation.

7. Payments and accounting references

The shop should be able to retain invoices, balances, payments, refunds, processor references, payout or settlement reports, and accounting-sync status as appropriate.

That does not mean a system should hand over raw card numbers or security codes. The FTC advises businesses not to keep credit-card information without an essential business need because retention increases fraud and identity-theft risk. See its guide to protecting personal information.

For migration purposes, the shop usually needs business records and transaction references, not reusable payment credentials.

8. Users, permissions, and audit trails

Employee names, roles, status, and attribution history may matter during a dispute or audit. Ask whether deactivating a user preserves that person's name on past actions and whether the export keeps the association.

Avoid exporting passwords, PINs, authentication secrets, or full payment credentials. Those are security controls, not portable business records.

What a usable export looks like

Different records need different formats.

DataUseful exportWhy it matters
Customers and vehiclesCSV or structured JSONCan be searched, cleaned, and imported
Repair ordersCSV or JSON plus readable PDFSupports both migration and human review
Photos and documentsOriginal files plus a manifestPreserves quality and record relationships
Estimates and supplementsOriginal source files plus version metadataKeeps the record the estimator actually used
MessagesCSV, JSON, or readable thread exportPreserves date, direction, and repair context
Parts and invoicesCSV plus original invoice filesConnects financial detail to proof
PaymentsTransaction and settlement reportsSupports reconciliation without exposing card data
Audit historyTimestamped structured exportShows who changed what and when

CSV is not always enough. Original images and PDFs are not always enough either. The best export preserves both the content and the relationships between records.

Twelve questions to ask a software vendor

Ask these questions before signing, not only when leaving:

  1. Can a shop administrator start a complete export without contacting support?
  2. Does the export include structured data, documents, and full-resolution images?
  3. Are file relationships preserved through repair-order numbers or a manifest?
  4. Which records are omitted, summarized, or available only by special request?
  5. Is there a charge for an export?
  6. Is there a limit on export frequency or size?
  7. How long does a full export take?
  8. Does export access continue during the cancellation period?
  9. How long is data retained after termination?
  10. How is the export protected in transit and at rest?
  11. Which data may the vendor keep after the shop leaves, and why?
  12. Can the vendor show a sample export before the shop buys?

The FTC recommends putting vendor expectations in writing, including data use, sharing, retention, and deletion, then verifying compliance. See its Cybersecurity for Small Business guidance.

Export access is not migration readiness

Run a small exit drill while the relationship is healthy.

Export a customer list, several repair orders, a supplement-heavy job, a photo-heavy job, a parts invoice, and a message thread. Then ask a manager who did not run the export to find:

  • A vehicle by VIN
  • The final estimate and latest supplement
  • A signed authorization
  • A specific photo
  • A customer reply
  • A parts return or credit
  • The amount paid and the transaction reference
  • The person who changed the promised date

If the manager cannot find those items, document what is missing and ask the vendor to explain.

This is the same principle used in backup planning: a copy is not proven until it can be restored and used. NIST recommends regular backups, keeping a frequently updated set offline, and testing that backed-up data can be restored. See the NIST CSF 2.0 Resource and Overview Guide.

Build a simple shop data policy

The shop should decide:

  • Which system is authoritative for each record type
  • Who may export data
  • How often a full export or backup is taken
  • Where protected copies are stored
  • Who checks that the copy opens
  • How long each record category is retained
  • How outdated records are securely deleted
  • What happens when a vendor or employee relationship ends

Do not keep everything forever by habit. The FTC advises businesses to inventory sensitive information, keep only what they need, protect what they retain, and dispose of it securely when it is no longer needed. Tax, insurer, employment, state, and contract rules may require longer periods for specific records, so use a written retention schedule rather than one deletion date for everything.

Red flags in a software agreement or sales answer

Slow down if you hear:

  • "You own it" without an export list
  • "We can probably get that for you" without timing or cost
  • "Everything is in CSV" when the product stores images and PDFs
  • "Your data is always available" but only while the account is active
  • "We keep backups" without a process for the shop to retrieve records
  • "No one has ever asked to leave"
  • "Our standard contract does not discuss deletion"
  • "You can print each RO one at a time"

Printing records one by one is not a reasonable exit plan for a working shop.

What AutoHound does

AutoHound gives a shop self-service tools to export shop data and download its documents and images. No support case or ticket is required. Complete and verify both before account access ends.

That promise is separate from the shop's decision about how long to retain each record. The shop remains responsible for its legal, tax, insurer, and contract requirements. AutoHound's role is to avoid making access to the shop's operational records depend on asking permission.

Read Your Data Is Yours, review AutoHound security and data protection, and see the switching process. The repair-order page shows the customer, vehicle, documents, and permanent timeline that make a useful operational record.

Data portability checklist

  • The agreement identifies shop-provided data clearly
  • Export rights survive cancellation long enough to retrieve records
  • An administrator can start an export without a support ticket
  • Structured data is included
  • Original documents and images are included
  • Record relationships are preserved
  • Audit history and timestamps are available
  • Export cost and timing are written down
  • Post-termination retention and deletion are explained
  • Sensitive credentials are excluded
  • A sample export has been opened and tested
  • The shop has a retention and backup owner

The strongest data-ownership promise is not a slogan. It is a working export button, a clear contract, files that preserve the repair record, and a shop that has tested the process before it urgently needs it.

Sources and further reading

TRY AUTOHOUND

Put the guide to work in a real repair

Open a private demo shop and follow the repair from booking through payment.