Trust
Compliance
What applies to us today, what we commit to contractually, and what we do not hold. In that order, because that is the order it matters in.
Last updated August 19, 2026
The short version
Your dealership is a covered financial institution under the FTC Safeguards Rule. That makes us your service provider, and we give the written commitment the Rule requires you to obtain — and we will sign your addendum.
Four subprocessors, all named. No SMS, by design. Privacy rights granted to everyone regardless of thresholds.
No SOC 2, no ISO. Stated up front rather than discovered in procurement, with the actual controls published on the security page instead.
The FTC Safeguards Rule (GLBA)
This is the load-bearing one for a US franchise dealership, and it applies today.
Dealerships that arrange financing are covered financial institutions under the Gramm-Leach-Bliley Act, and the amended Safeguards Rule requires you to take reasonable steps to select service providers capable of maintaining appropriate safeguards, and to require those safeguards by contract. We are such a service provider. That is a contractual posture, not a certification, and the honest version of it is:
- We implement and maintain administrative, technical and physical safeguards appropriate to the sensitivity of the customer information we handle for you. The specifics are published, not asserted — see security.
- We use your customer information only to provide the service to you. Not to build products, not to train models, not to sell.
- We will notify you without undue delay of a security event affecting your customer information, with what we know and what we are doing about it.
- We will sign your service-provider addendum. Send it to info@dealertech.io. If your compliance vendor has a standard form, that is easier for both of us than negotiating ours.
The Rule’s logic is also why the product treats consent the way it does: every consent change is stored as a dated, sourced event with the exact disclosure text shown, and where a store cannot prove consent the screen says so rather than assuming.
TCPA — no SMS, by design
DealerTech.io does not send text messages. Not throttled, not opt-in-gated — the capability is not built.
When an advisor sends a customer their service menu, they copy the link and send it from whatever channel the store already uses and already has consent for. That keeps the dealership’s existing TCPA posture intact instead of creating a new sending identity with new consent obligations attached to our infrastructure.
Consent is still recorded, because the dealership needs the record whether or not we do the sending. If we add outbound messaging, it will arrive with consent capture and revocation built in first, and this page will say so.
Subprocessors
The complete list. There is no fifth.
Supabase
Postgres database, authentication, and the private bucket customer documents are stored in. This is where dealership data lives.
Stripe
Subscription billing. Stripe holds the card; we never receive or store card numbers.
Anthropic
The model that reads uploaded service contracts and answers Co-Pilot questions. API data is not used to train models.
Netlify
Hosting and the scheduled jobs that run overnight.
All four are US-based services and dealership data is hosted in the United States. Adding a subprocessor means updating this page and the privacy policy in the same change, and telling dealerships under contract.
Privacy law
CCPA / CPRA
The thresholds that make California’s law binding — revenue and consumer volume — are almost certainly not met by a company this size. We grant the rights anyway: know, access, correct, delete, and no retaliation for asking. We do not sell personal information and do not share it for cross-context behavioural advertising, which is why there is no “Do Not Sell My Information” page on this site — the honest version is a sentence in the privacy policy.
GDPR
Does not apply. We sell to US franchise dealerships, we have no EU establishment, and we do not offer the service to people in the EU or UK. If that changes, this sentence changes with it and the machinery gets built before the offering opens, not after.
Data processing agreement
We act as a service provider for everything inside the product; the dealership is the controller. The processor commitments — purpose limitation, the subprocessor list above, breach notice, assistance with individual requests — are stated here and in the terms. A countersignable DPA is available on request rather than as a download; ask and we will execute yours.
Modern Slavery statement
A UK statutory requirement above a turnover threshold. It does not apply to us, and we are not going to publish one for decoration.
AI governance
Increasingly the question a dealer group asks second. Our answer is a mechanism rather than a framework name, because we hold no AI certification and the mechanism is checkable:
- Fields a model extracts are stored as unverified and are never trusted on their own.
- The coverage engine lowers its confidence on anything machine-read and tells the advisor why, on screen.
- Every human confirmation is written to an append-only audit log with the actor.
- No customer data is used to train models.
The whole story, including what a confirmation deliberately does not mean, is on the Responsible AI page.
What we do not hold
No SOC 1, no SOC 2 Type I or Type II. No ISO 27001, 27701 or 42001. No PCI attestation of our own — card data never reaches our application, so the requirement sits with Stripe. No HITRUST, no FedRAMP, no third-party security audit, no formal penetration-testing programme, and no compliance team.
A SOC 2 becomes worth its cost when enough dealerships depend on us to justify it — that is a customer count, not a marketing decision, and we are not naming a timeline we have not committed to.
Every vendor list has a column for this. Ours says no. What it also says is that the controls an auditor would examine are published in specifics on the security page, which is more than most attestation summaries disclose.
The questionnaire, answered
These are the questions a dealer group’s IT department asks every vendor. Including the ones we answer badly, because a skipped question on a trust page reads as a no.
Is data encrypted in transit and at rest?
In transit, yes: the site is served over HTTPS only. At rest, our database, storage and backups are encrypted by our hosting providers.
We deliberately do not restate their cipher suites or TLS version floors as though they were ours to guarantee — we do not operate that layer, and a vendor quoting numbers it does not control is a vendor you cannot rely on. Supabase, Netlify and Stripe publish their own encryption and compliance documentation, and that is the authoritative answer for anything at that level.
Who at DealerTech can see our data?
Our staff can access dealership data only to operate and support the service. The team is currently very small — this is a founder-run product — so the practical answer is that access is limited to the people who build and run it, and a support grant is written to an append-only audit log when it is made and when it is revoked.
Inside the product, a dealership’s staff see only their own dealership’s data, enforced by the database rather than by our queries.
Where does our data live?
In the United States, with Supabase (database and document storage) and Netlify (hosting). We do not replicate dealership data outside the US.
What are your backup and disaster recovery arrangements?
Database backups are managed by Supabase on their platform, including point-in-time recovery on their paid tiers, and the application itself is stateless — it redeploys from source. So the recovery story is: the code is reproducible, and the data is on a managed Postgres with the provider’s backup regime.
What we do not have is a documented RPO and RTO we have tested by rehearsing a full restore. Publishing one we had not practised would be worse than saying this. It is on the list ahead of a certification, because it is the thing that would actually matter at three in the morning.
What is your incident response process?
If we determine a security event has affected a dealership’s customer information, we notify that dealership without undue delay, with what we know, what we do not yet know, and what we are doing. We contain first, then investigate, then write it up.
It is not a rehearsed playbook run by a team on rotation, and it would be dishonest to describe it as one. The compensating fact is that the person who would answer the phone is the person who wrote the code.
Do you monitor your own vendors?
With four subprocessors, monitoring means reading their status and security notices and keeping the list on this page true. That is proportionate at four. It would not be at forty, which is one of several reasons the list stays short.
Do you screen employees?
Not through a formal background-check programme — there is no hiring pipeline to run one against yet. When we hire people with production access, screening comes before the access does, and this answer changes.
What does your development process look like? Do you pen-test?
Strict TypeScript, roughly 1,400 unit tests, and the security seams — tenant isolation, route protection, the whitelist governing what a customer’s screen may receive — each have tests written specifically to fail if the seam moves. Tenant isolation is tested against a real Postgres rather than a mock. Secrets live in the hosting platform’s environment, never in the repository, which is private.
There is no third-party penetration test. When one happens, this page will say who did it and when.
Can we get a copy of our data out?
Yes — ask and we will export it, while the account is open and deliberately after it closes too. The billing state that ends an account keeps export permitted, because a service history is your asset and holding it hostage is not a business we want to be in. Today the export is something we run for you rather than a self-serve button; the button is on the roadmap, and the commitment is not waiting for it.
Do you send text messages to our customers?
No. See the TCPA section above. Links are copied and sent by a person, from your store.
Do you use our data to train AI models?
No. Neither do we permit our AI provider to — Anthropic’s commercial API terms state that API data is not used for model training.
Ask us something this page does not answer
The DAS Board LLC operates DealerTech.io. Send a questionnaire, an addendum, or a single awkward question to info@dealertech.io. If the answer is bad, we would rather tell you now than have you find out later.
This document was written from the software it describes, and has not been reviewed by counsel. It is the honest starting text, not legal advice. If a term here matters to your dealership’s decision, tell us and we will get it right rather than argue it later.