Skip to main content
DealersGear logo
AutoLink Website Engine VMM Success Stories Blog Contact Free audit
Log In CMS Log In CRM
Book a strategy call →
— Navigation
01Home→ 02AutoLink→ 03Website Engine→ 04VMM→ 05Success Stories→ 06Blog→ 07About→ 08Contact→ 09Free auditlive→
Book a strategy call → Log In CMS Log In CRM
SYSTEM ● live v 1.0.0
Home / Privacy Policy
LEGAL · PRIVACY

Privacy Policy

Plain language. No dark patterns. This page explains what data DealersGear collects when you visit our website or use our product — and what rights you have over that data. If anything here is unclear, email privacy@dealersgear.com and we'll explain.

Effective date January 15, 2026
Last updated May 12, 2026
Operator AutomotiveAI INC
On this page
  1. 01Scope
  2. 02What we collect
  3. 03How we use data
  4. 04Who we share with
  5. 05Cookies & tracking
  6. 06Retention
  7. 07Your rights
  8. 08International transfers
  9. 09Children's data
  10. 10Changes
  11. 11Contact
01 · SCOPE

Who this policy applies to

This policy covers everything operated under the dealersgear.com domain — the marketing site, the audit tool, the customer dashboard, and the AutoLink, Website Engine, and Vehicle Marketing Multiplier products. It also covers our open-source protocol site at acpspec.org.

DealersGear is operated by AutomotiveAI INC, a Delaware corporation. Where this policy says "we," "us," or "DealersGear," it means AutomotiveAI INC. Where it says "you," it means anyone who visits our site or uses our product — whether you're a dealership shopper, dealer staff, an integration partner, or a developer reading the spec.

This policy does not cover websites operated by our dealer customers. Those sites are governed by each dealer's own privacy policy. If you're on a dealership site powered by Website Engine, that dealership controls the data collected there — not us.

02 · WHAT WE COLLECT

The categories of data we collect

You give us directly

  • Contact info when you book a strategy call, request an audit, or email us: name, email, phone, dealership name.
  • Account info when you sign up for AutoLink: business address, billing details, designated administrator email.
  • Communications — emails, support tickets, call recordings (only with consent), and meeting notes.

We collect automatically

  • Usage data — pages visited, features used, search queries, click paths within our product.
  • Device data — browser type, operating system, screen size, approximate location derived from IP.
  • Performance data — page load times, error logs, API response times.

From dealer customers using our product

  • Inventory data — VIN, make, model, price, photos, descriptions ingested from the dealer's DMS or feed.
  • Lead data — shopper inquiries submitted through the dealer's Website Engine site, routed to that dealer's CRM.
  • Call data — metadata (duration, source number, time) from CallRail or equivalent. Audio recordings stay with the call vendor.
WHAT WE DON'T COLLECT
We do not buy personal data from data brokers. We do not collect biometric identifiers. We do not track you across other unrelated websites with persistent cross-site identifiers. We do not retain credit card numbers (Stripe handles that).
03 · HOW WE USE IT

What we do with the data

We use the data we collect to:

  1. Operate the product — render dealer websites, route leads, generate schema, run audits, return results to AutoLink dashboards.
  2. Improve the product — aggregate usage patterns to identify bottlenecks, A/B test interface changes, debug errors.
  3. Communicate with you — respond to support requests, send transactional emails (account confirmations, billing receipts, audit results), send the weekly summary if you've opted in.
  4. Comply with the law — tax filings, fraud prevention, responses to lawful government requests.
  5. Train AI models — only on the dealer's own data within their own workspace. Your data is never used to train models for other customers. ACP-compliant exports respect this same boundary.

We do not sell your data. We do not rent your data. We do not share your data with marketers.

04 · WHO WE SHARE WITH

The third parties involved

We share data with a small number of service providers we've vetted. Each is contractually bound to the same privacy standards we hold ourselves to. The current list:

Stripe
Payment processing. Handles all credit card data; we never see card numbers directly.
Amazon Web Services
Cloud infrastructure. Data hosted in us-east-1 (Virginia) by default. EU-resident dealers can request eu-west-1 (Ireland).
Postmark
Transactional email delivery (account confirmations, audit results, weekly digests).
Vercel
Edge hosting for marketing site and dealer-facing Website Engine pages.
Sentry
Error tracking. Configured to scrub PII before events are logged.
PostHog
Product analytics (self-hosted on our infrastructure). No data shared with PostHog Cloud.

We may also share data when compelled by law (subpoena, court order, lawful government request) or when needed to protect the safety of our users, the public, or our property. In those cases we'll notify the affected user unless prohibited.

05 · COOKIES & TRACKING

What sits in your browser

Our site uses two categories of cookies:

  • Essential cookies — session tokens for signed-in users, CSRF protection, theme preferences. These cannot be disabled without breaking the product.
  • Analytics cookies — PostHog session IDs to measure feature usage. Anonymized after 30 days. You can opt out via the cookie banner or by sending a "Do Not Track" header.

We do not use third-party advertising cookies. We do not embed Facebook Pixel, Google Ads conversion pixels, or LinkedIn Insight Tag on our marketing site. Dealer sites built on Website Engine may use these pixels at the dealer's discretion, but configuration is the dealer's responsibility.

06 · RETENTION

How long we keep your data

Account data
For the duration of your active subscription, plus 90 days after cancellation for export and reactivation.
Communication records
Two years (for context on future support requests, dispute resolution, and product improvement).
Audit results
Indefinite, unless you request deletion. Audit history is useful when comparing year-over-year improvement.
Usage logs & analytics
13 months in raw form, then aggregated to monthly summaries (no PII).
Billing records
Seven years (US tax retention requirement).

After a retention period ends, data is deleted from production systems within 30 days and from backups within 90 days. Backups follow a 90-day rolling window, so data deletion is fully complete within that timeframe.

07 · YOUR RIGHTS

What you can ask us to do

Wherever you are in the world, you have these rights with respect to your personal data:

  • Right to access — request a copy of all personal data we hold about you, in machine-readable format. ACP-compliant JSON export is built into AutoLink.
  • Right to rectification — correct inaccurate or incomplete data.
  • Right to deletion — request deletion of your personal data. We honor this within 30 days unless legal retention requirements prevent it.
  • Right to portability — receive your data in a portable format and transmit it elsewhere. The whole point of the ACP spec is to make this practical.
  • Right to object — object to processing for marketing purposes, profiling, or any other reason we rely on legitimate interests.
  • Right to restrict — ask us to stop processing while a complaint is being investigated.
  • Right to lodge a complaint — with your local data protection authority. We'd prefer you raise it with us first.

To exercise any of these rights, email privacy@dealersgear.com. We aim to respond within five business days and complete the request within 30 days.

08 · INTERNATIONAL TRANSFERS

Where your data physically lives

By default, DealersGear data is stored in AWS us-east-1 (Virginia, USA). For EU-resident customers and at-request basis, we host in AWS eu-west-1 (Ireland). Backups remain in the primary region.

If you're in the EU, EEA, UK, or Switzerland and your data is processed in the US, we rely on Standard Contractual Clauses approved by the European Commission as the lawful transfer mechanism, plus supplementary technical and contractual measures.

09 · CHILDREN'S DATA

We don't collect data from minors

DealersGear is a B2B product for car dealerships. Our services are not directed at children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data to us, email privacy@dealersgear.com and we'll delete it immediately.

10 · CHANGES

When this policy changes

We update this policy when we change our practices or when laws change. The Last updated date at the top of this page reflects when. For material changes that affect how we use existing data, we'll email account holders at least 30 days before the change takes effect.

The historical text of this policy is preserved in our public Git repository (github.com/AutomotiveAI-INC/legal). Every revision is timestamped and signed.

11 · CONTACT

How to reach us

Questions, requests, or complaints about this privacy policy go to privacy@dealersgear.com.

For postal mail:

AutomotiveAI INC
Attn: Privacy
(Address available upon request via email)

For EU-resident concerns, you may also contact your local data protection supervisory authority. A list is maintained at edpb.europa.eu/about-edpb/about-edpb/members_en.

Questions about your data? Reach out.
Email privacy team →
DealersGear logo

The operating system for dealership marketing. AutoLink, Website Engine, and Vehicle Marketing Multiplier — built to share one source of truth.

Product
AutoLink Website Engine VMM Free AEO audit
Company
About Success stories Blog Contact
Marketing
Vehicle Listing Ads TikTok marketing Spotify advertising Spanish advertising
Legal
Privacy policy Terms & conditions Accessibility
© 2026 DealersGear, Inc.
Privacy Terms Accessibility Sitemap