Privacy Policy
Effective Date: March 23, 2026
1. Introduction
Dealer Data Solutions ("DDS," "we," "us," or "our") provides a cloud-based dealership management platform that includes customer relationship management, communications, credit application processing, deal structuring, and inventory management tools (the "Platform"). This Privacy Policy explains how we collect, use, disclose, and protect information through our Platform and website at dealerdatasolutions.com (the "Site").
By using our Platform or Site, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use our services.
2. Information We Collect
2.1 Information Provided by Dealership Users
- Account Information: Name, email address, phone number, dealership name, and role/title.
- Customer Records: Names, contact information, vehicle preferences, interaction history, pipeline status, and notes entered by dealership staff.
- Deal Information: Vehicle details, pricing, trade-in information, payment structures, and lender selections.
- Inventory Data: Vehicle identification numbers (VINs), stock numbers, vehicle descriptions, pricing, and reconditioning status.
2.2 Consumer Financial Information
When consumers submit credit applications through the Platform, the following information may be collected:
- Social Security Numbers (SSNs)
- Dates of birth
- Income and employment information
- Residential addresses and housing payment details
- Employer information
This information is classified as Nonpublic Personal Information ("NPI") under the Gramm-Leach-Bliley Act (GLBA) and is subject to enhanced protections described in Section 5 below.
2.3 Automatically Collected Information
- Usage Data: Pages visited, features used, timestamps, and session duration.
- Device Information: Browser type, operating system, screen resolution, and IP address.
- Communication Records: Call logs, SMS/text message records, message content, phone numbers, timestamps, opt-in/opt-out status, and voicemail transcriptions generated through the Platform's integrated communications features.
2A. SMS/Text Messaging Data
When consumers interact with a dealership via text message through the Platform, we collect and process the following data:
- Mobile phone numbers
- Message content (sent and received)
- Opt-in and opt-out records (consent status)
- Message delivery status and timestamps
This data is used solely to facilitate communication between the dealership and the consumer. We do not sell, rent, or share phone numbers or SMS opt-in data with third parties for marketing or advertising purposes. Messaging consent data is not shared with any third party.
3. How We Use Your Information
We use collected information for the following purposes:
- Provide and maintain the Platform: Operating CRM, communications, credit processing, deal structuring, and inventory features.
- Process credit applications: Facilitating the submission of consumer credit applications to dealership staff and, at the dealership's direction, to lending institutions.
- Communications: Enabling calls, text messages, and other communications between dealership staff and their customers.
- Security and compliance: Monitoring for unauthorized access, maintaining audit trails, and ensuring regulatory compliance.
- Support and troubleshooting: Responding to inquiries and resolving technical issues.
- Product improvement: Analyzing aggregate usage patterns to improve Platform functionality.
4. How We Share Your Information
We do not sell personal information. We may share information in the following limited circumstances:
- With dealership staff: Customer and deal information is accessible to authorized users within the same dealership account based on role-based access controls.
- Service providers: We use trusted third-party services for hosting (Cloudflare), database management (Supabase), and communications infrastructure. These providers are contractually required to protect your data.
- Legal requirements: When required by law, regulation, legal process, or enforceable governmental request.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate confidentiality protections.
We do not share consumer credit application data with any party other than the dealership that collected it, except as directed by the dealership or required by law.
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption at rest: Sensitive financial data, including Social Security Numbers, dates of birth, and income information, is encrypted using AES-256-GCM encryption before storage.
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Access controls: Role-based access controls limit data access to authorized personnel. Sensitive data access is logged in audit trails.
- Multi-tenancy isolation: Each dealership's data is logically isolated. Row-level security policies prevent cross-tenant data access.
- Rate limiting: API rate limiting and access monitoring protect against unauthorized bulk data extraction.
- Session management: Authenticated sessions are time-limited and monitored for suspicious activity.
While we strive to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
6. GLBA and FTC Safeguards Rule Compliance
Dealer Data Solutions is designed to help dealerships comply with the Gramm-Leach-Bliley Act (GLBA) and the FTC Safeguards Rule (16 CFR Part 314). Our compliance measures include:
- Encryption of all Nonpublic Personal Information (NPI) at rest and in transit.
- Role-based access controls that restrict NPI access to authorized personnel.
- Audit logging of all access to sensitive financial data.
- Secure disposal practices for data no longer needed.
- Regular security assessments and monitoring.
Dealerships using our Platform remain responsible for their own GLBA compliance programs, including employee training, incident response plans, and vendor oversight.
7. Data Retention
We retain information as follows:
- Account data: Retained for the duration of the dealership's active subscription plus 90 days.
- Customer and deal records: Retained as directed by the dealership, subject to applicable legal retention requirements.
- Credit application data: Retained in encrypted form for the period required by applicable law, then securely deleted.
- Communication records: Call logs and message history are retained for the duration of the subscription.
- Audit logs: Retained for a minimum of one year for compliance purposes.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate personal information.
- Deletion: Request deletion of your personal information, subject to legal retention requirements.
- Opt-out of communications: Unsubscribe from marketing communications at any time.
Consumers who have submitted credit applications through a dealership using our Platform should contact the dealership directly to exercise their rights regarding that data.
To exercise any of these rights, contact us at Inquiry@dealerdatasolutions.com.
9. Cookies and Tracking
Our Site uses only essential cookies required for authentication and session management. We do not use third-party advertising trackers or sell browsing data to advertisers.
10. Children's Privacy
Our Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or through the Platform. The "Effective Date" at the top of this page indicates when the policy was last revised.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Dealer Data Solutions
Email: Inquiry@dealerdatasolutions.com