1. Scope and our role

This policy applies to our public website and the DealerSense software services. For website visitors and business contacts, DealerSense decides why and how the information is used. When a dealership uses DealerSense, the dealership generally controls the business data in its account and DealerSense processes that data to provide the contracted service. Dealership personnel should direct questions about their employer's records to the dealership first.

Our Terms of Service, Data Processing Addendum, and subprocessor list contain additional terms for dealership service data. If those terms conflict with this policy, the Data Processing Addendum controls for that customer's service data.

2. Information we collect

Information you provide

  • Contact details, including your name, company, work email, phone number, and inquiry.
  • The email address you submit when asking us to locate your organization's sign-in page.
  • Account details, support requests, communications, and information you send to us.

Information processed through the service

Depending on the modules a dealership enables, service data may include general ledger entries, accounts receivable records, repair orders, parts and vehicle records, deal information, vendor and invoice documents, employee and commission information, customer contact details, notes, approvals, messages, and audit history. DealerSense receives much of this information from the dealership's DMS or from files and forms submitted by authorized users.

Information collected automatically

Our servers and security providers may collect IP address, browser and device details, timestamps, requested pages, referral information, and security or diagnostic events. Customer deployments use necessary cookies for authentication, preferences, and security.

The public website uses Cloudflare for network security, bot protection, and aggregated traffic measurement. Cloudflare Turnstile verifies that early access requests come from a person rather than an automated script, and Cloudflare may set a short-lived security cookie to distinguish legitimate visitors from automated traffic. Our website analytics are aggregated and do not use advertising cookies, cross-site identifiers, or device fingerprinting for marketing. We do not use the public site for interest-based advertising, and we do not operate an advertising network.

The website loads fonts and interface stylesheets from Google Fonts and jsDelivr. Those providers receive your IP address and browser details as a normal part of serving those files.

3. How we use information

  • Provide, maintain, secure, and improve DealerSense.
  • Route users to the correct dealership sign-in page and administer accounts.
  • Respond to demo requests, support questions, and business communications.
  • Synchronize dealership systems, generate reports, process workflows, and retain audit records.
  • Detect abuse, investigate errors, protect customer data, and meet legal obligations.

DealerSense uses artificial intelligence tools internally to support software development, engineering troubleshooting, and its own business operations. Customer data is not transmitted to any third-party artificial intelligence or model provider, and customer data is never used to train, fine-tune, or improve any model. Where the service presents output that was generated or assisted by artificial intelligence, users must review that output before relying on or posting it.

4. How we disclose information

We may disclose information to:

  • Service providers that support hosting, authentication, email, messaging, object storage, security, error monitoring, and DMS connectivity. These providers include DigitalOcean, WorkOS, Resend, Sentry, and Telnyx, depending on the service and configuration in use. The current list is published at dlrsense.com/subprocessors. The public website separately uses Cloudflare and loads fonts and interface assets from Google Fonts and jsDelivr.
  • The dealership that controls the account and users authorized by that dealership.
  • Professional advisers, regulators, courts, or law enforcement when reasonably necessary.
  • A buyer, investor, or successor in connection with a financing, acquisition, reorganization, or sale.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

5. Dealership financial information and the Gramm-Leach-Bliley Act

A dealership that arranges or facilitates consumer financing is a financial institution under the Gramm-Leach-Bliley Act ("GLBA"). When DealerSense processes information from that dealership, DealerSense acts as a service provider to the dealership, and the dealership remains responsible for the GLBA privacy notices it gives its own customers. DealerSense does not provide GLBA privacy notices on a dealership's behalf.

Nonpublic personal information ("NPI") means personally identifiable financial information about a consumer that a dealership obtains in connection with a financial product or service. Depending on the modules a dealership enables, NPI processed through DealerSense may include deal and financing terms, customer contact and identification details, and documents attached to a deal or accounting record.

DealerSense uses NPI only to perform the services requested by the dealership and as permitted by law. We do not sell NPI, use it for our own marketing, use it to build profiles of consumers, or disclose it except as directed by the dealership, as needed to operate the service through the providers listed above, or as required by law.

We maintain an information security program covering the customer data we process. Current controls include assigned responsibility for security, role-based access controls with least privilege, multi-factor authentication for personnel access to production systems, encryption of data in transit and at rest, isolated customer deployments, restricted infrastructure access, logging and monitoring, backups, secure disposal, and oversight of the service providers listed above. We continue to expand this program as our dealership customers' obligations under the FTC Safeguards Rule require. Customers and prospective customers may request our current security documentation.

NPI is not transmitted to any third-party artificial intelligence or model provider. Artificial intelligence tools are used only for DealerSense's internal software development, engineering troubleshooting, and its own accounts payable. The controls that keep this true are described in Annex B.16 of our Data Processing Addendum.

If we discover a security event affecting a dealership's data, we will notify that dealership without unreasonable delay and cooperate in its own notification obligations. Specific timelines and responsibilities are set out in our Data Processing Addendum.

6. Retention

We retain website inquiries for as long as needed to respond and manage the business relationship. We retain customer service data according to our Data Processing Addendum, dealership instructions, legal requirements, security needs, and backup schedules. Backup copies may remain for a limited period after active data is deleted.

7. Security

We use administrative, technical, and physical safeguards designed for the sensitivity of the information we process. These include access controls, multi-factor authentication for personnel access to production systems, encryption in transit and at rest, isolated customer deployments, restricted infrastructure access, logging, backups, and security monitoring. The full set of measures is described in Annex B of our Data Processing Addendum. No system is completely secure, and we cannot guarantee that unauthorized access or loss will never occur.

8. Your choices and privacy rights

You may ask to access, correct, or delete personal information that DealerSense controls, or object to certain processing. We may need to verify your identity and may retain information when required by law or a customer agreement. If your information belongs to a dealership account, we may refer the request to that dealership.

Depending on where you live, you may have additional rights to obtain a portable copy or to use an authorized agent. DealerSense does not sell personal information or use it for targeted advertising, so we do not offer a sale or targeted-advertising opt-out. Information governed by the Gramm-Leach-Bliley Act is handled under Section 5 and may be exempt from some state privacy rights.

To make a request, email [email protected] with the subject line "Privacy request." We will respond within the period required by applicable law. If we decline your request, our response will explain why, and you may appeal that decision by replying to it or by emailing [email protected] with the subject line "Privacy appeal." We will inform you in writing of the outcome of the appeal and, where applicable law provides one, how to contact your state attorney general with a complaint.

DealerSense is operated from the United States and is intended for customers and visitors in the United States. Information we collect is stored and processed in the United States.

9. Children

DealerSense is a business service and is not directed to children under 18. We do not knowingly collect personal information from children through the website or service.

10. Changes to this policy

We may update this policy as our services or legal obligations change. We will post the revised policy here and update the effective date. We will provide additional notice when required by law or a customer agreement.

11. Contact us

Send privacy questions or requests to [email protected].

DealerSense
a dba of Omnify93, LLC
Colorado, United States