DealerRev Data Processing and Use Agreement
Your data is yours. DealerRev hosts and protects it, uses it to run your service, studies it only in de-identified, combined form, and never sells it. This agreement is part of the DealerRev Terms of Service and controls wherever the two differ on data.
At a glance
This summary is for convenience; the numbered sections control.
| DealerRev will | DealerRev will never |
|---|---|
| Host your data in the United States, encrypted in transit and at rest | Sell, rent or trade your data or your customers' data |
| Use it to run, support and secure your DealerRev service | Share it with lenders, manufacturers, distributors, data brokers or other dealers for their own use |
| Publish studies only from de-identified data combined across at least [five] dealers | Use it for advertising, or market to your customers for anyone but you |
| Tell you within 72 hours of discovering a security incident | Let AI providers train their general models on it |
| Give you a full export whenever you ask, and when you leave | Publish anything that identifies your store or a consumer without your written OK |
| Delete it after you leave, and confirm in writing on request | Keep your paper originals, or keep scan copies after upload is verified |
1. Scope and roles
1.1 Parties. This Data Processing and Use Agreement (the "DPA") is between DealerRev LLC ("DealerRev") and the Customer named on the Order Form. Capitalized terms not defined here have the meanings in the DealerRev Terms of Service (the "Terms").
1.2 Customer decides; DealerRev processes. Customer determines why and how Customer Data is used. DealerRev processes Customer Data on Customer's behalf and on its documented instructions, which are the Agreement, the Service's settings, and Customer's written requests.
1.3 Legal roles. Under the California Consumer Privacy Act as amended ("CCPA") and similar state privacy laws, Customer is the "business" or "controller" and DealerRev is its "service provider" or "processor." Under the Gramm-Leach-Bliley Act ("GLBA") and the FTC Safeguards Rule (16 C.F.R. Part 314), where Customer is a financial institution, DealerRev is Customer's "service provider."
1.4 Applicable Data Protection Laws means all laws that apply to either party's processing of Customer Data, including GLBA and the FTC Safeguards Rule, the CCPA, the Montana Consumer Data Privacy Act, the Colorado Privacy Act, other state privacy and data-breach notification laws, and the Driver's Privacy Protection Act.
2. The data covered
This DPA covers all Customer Data. Because some of it is highly sensitive, the table below sets out the categories and how each is treated.
| Category | Examples | Handling |
|---|---|---|
| Consumer contact and profile | Names, phone numbers, emails, addresses, preferences, family links | Standard protections |
| Vehicle and service | VINs, units owned, service and repair history, odometer readings, parts orders | Standard protections |
| Deal and finance ("Nonpublic Personal Information") | Credit applications, Social Security numbers, driver's licenses, income, credit reports, deal jackets | Restricted fields and document storage; access limited by role; treated as NPI under GLBA |
| Communications | Call recordings and transcripts, texts, emails, web chats, consent and opt-out records | Standard protections; consent records kept as proof of consent |
| Staff | Authorized User names, emails, phones, roles, activity logs, timeclock records | Standard protections |
| Business | Inventory, pricing, costs, gross, financial reports, supplier catalogs and pricing | Confidential Information of Customer |
| Credentials | Distributor API keys, carrier tokens, integration logins | Encrypted at the field level; see Section 10 |
3. What DealerRev may do with Customer Data
3.1 Run the Service. DealerRev may process Customer Data to provide, maintain, support and secure the Service for Customer, including importing, storing, displaying, sending communications Customer initiates, generating reports, and running AI features for Customer.
3.2 Improve the Service. DealerRev may use Customer Data internally to fix defects and to build and improve the Service, as long as it does not build a profile of any consumer for use in another customer's account. Nonpublic Personal Information is used only to perform the Service for Customer, not for this purpose.
3.3 Protect and comply. DealerRev may process Customer Data to detect and prevent fraud, abuse and security incidents, and to comply with law or a valid legal order (subject to Section 9.4 of the Terms).
3.4 Studies and analysis on de-identified data. DealerRev may create Aggregated Data from Customer Data and use it for analysis, benchmarking, industry studies, research, product development and training DealerRev's own models. "Aggregated Data" means data derived from Customer Data that meets all of these conditions:
- it has been de-identified so that it cannot reasonably be used to identify, or be linked to, any consumer, household or device, including meeting the CCPA's definition of "deidentified";
- it does not identify Customer, its employees or its location, and any published or shared figure combines data from at least [five (5)] dealerships;
- DealerRev publicly commits, and hereby commits, to keep it in de-identified form and not to attempt to re-identify it;
- anyone DealerRev shares it with is contractually bound to the same commitments; and Nonpublic Personal Information — such as credit applications, Social Security numbers and credit reports — is never used to create it.
3.5 Customer's benchmark choice. Customer may opt out of inclusion in published industry reports at any time by written notice. Opting out does not affect de-identified internal product analysis.
3.6 Ownership of results. DealerRev owns Aggregated Data and the studies, benchmarks and models built from it. Customer may receive benchmark reports that compare its own results to the de-identified market.
4. What DealerRev will never do
4.1 DealerRev will not:
- sell, rent, license or trade Customer Data, for money or any other valuable consideration;
- share Customer Data for cross-context behavioral advertising or targeted advertising;
- disclose Customer Data to any third party for that party's own purposes — including lenders, manufacturers, distributors, insurers, warranty providers, marketers, data brokers or other dealerships — except to subprocessors under Section 6, or as Customer directs (for example, sending a credit application to a lender Customer selects);
- use one customer's leads, prices or consumer records to benefit another DealerRev customer;
- contact Customer's consumers for any purpose other than delivering Customer's own communications;
- retain, use or disclose Customer Data outside the direct business relationship with Customer, or for any purpose other than those in Section 3;
- combine Customer Data with personal information from other sources, except as Applicable Data Protection Laws permit for a service provider; or
- allow its AI providers to use Customer Data to train or improve their general-purpose models.
4.2 Certification. DealerRev certifies that it understands and will comply with the restrictions in this Section 4. DealerRev will comply with the obligations Applicable Data Protection Laws place on it, and will give Customer Data the same level of privacy protection those laws require of Customer.
4.3 Notice and remedy. DealerRev will tell Customer within [five (5) business days] if it determines it can no longer meet its obligations under Applicable Data Protection Laws. Customer may then take reasonable steps to stop and fix any unauthorized use, including suspending DealerRev's processing of the affected data.
5. Security program
5.1 Standard. DealerRev maintains a written information security program with administrative, technical and physical safeguards appropriate to the sensitivity of Customer Data and designed to meet the requirements the FTC Safeguards Rule places on service providers. DealerRev names [name/title] as the person responsible for it.
5.2 Safeguards. At a minimum, DealerRev will:
- Encrypt Customer Data in transit (TLS 1.2 or higher) and at rest, and encrypt credentials and carrier tokens at the field level with keys kept separately from the database;
- Host in the United States on the providers listed in Section 6, and not move Customer Data outside the United States without Customer's written consent;
- Limit access by role inside the Service, and limit DealerRev personnel access to those who need it to provide or support the Service;
- Require multi-factor authentication for DealerRev personnel with administrative or production access and make it available to every Authorized User so Customer can require it;
- Log every creation, change and deletion of Customer Data in an append-only change history, and log every instance of DealerRev personnel accessing Customer's account for support;
- Back up Customer Data at least [daily], keep backups encrypted, and test restoration at least [annually];
- Patch and monitor systems, keep dependencies current, and review security alerts;
- Bind personnel to confidentiality obligations and train them on security and privacy at hire and at least annually; and
- Assess risk at least annually and update safeguards in response.
5.3 No reduction. DealerRev will not materially reduce the overall protection of Customer Data during the term.
6. Subprocessors
6.1 Authorization. Customer authorizes DealerRev to use the subprocessors below. DealerRev will bind each by written contract to data-protection obligations substantially similar to those in this DPA and remains responsible for their performance.
| Subprocessor | Purpose | Data location |
|---|---|---|
| Fly.io | Application hosting and managed database | United States |
| Tigris Data | File storage: documents, scans, photos, call recordings | United States [confirm region] |
| Twilio (including SendGrid) | Calling, texting, email delivery, carrier registration | United States |
| SignalWire | Calling and texting (planned) | United States |
| Stripe | Subscription billing (Customer's payment details only) | United States |
| Anthropic | AI features (drafting, summaries, analysis) | United States |
| xAI | AI features | United States [confirm] |
6.2 Changes. DealerRev will notify Customer at least [30] days before adding or replacing a subprocessor. If Customer objects on reasonable data-protection grounds, the parties will work in good faith on an alternative; if none is found, Customer may terminate the affected Service and receive a refund of prepaid fees for it.
7. Security incidents
7.1 Notice. DealerRev will notify Customer without unreasonable delay, and in any case within 72 hours, after discovering unauthorized access to, or acquisition, loss or disclosure of, Customer Data in DealerRev's or a subprocessor's systems (a "Security Incident"). DealerRev will not wait to finish its investigation before giving this first notice.
7.2 Content. The notice will describe, as far as then known, what happened, when, the data and number of consumers affected, the steps taken to contain it, and a contact person. DealerRev will update Customer as it learns more.
7.3 Response. DealerRev will contain and investigate the Security Incident, fix its cause, and preserve relevant evidence.
7.4 Customer's notifications. Customer decides whether and how to notify consumers and regulators, including any notice to the FTC the Safeguards Rule requires for an incident affecting 500 or more consumers. DealerRev will supply the information Customer reasonably needs to do so and will not notify Customer's consumers about the incident without Customer's approval, unless the law requires it.
7.5 Costs. Where a Security Incident results from DealerRev's breach of this DPA, DealerRev will reimburse Customer's reasonable, documented costs of legally required notices, call-center support and [12 months of] credit monitoring for affected consumers, subject to the data-protection cap in Section 12.3 of the Terms.
8. Assistance, audits and Safeguards Rule support
8.1 Consumer requests. If DealerRev receives a request from a consumer to access, correct, delete or opt out of use of their information, DealerRev will forward it to Customer within [5 business days] and will not respond itself except to direct the consumer to Customer. The Service lets Customer find, export, correct and delete a consumer's records; where it cannot, DealerRev will help within [10 business days].
8.2 Deletion of history. The Service keeps an append-only change history. When Customer must delete a consumer's data by law, DealerRev will delete or irreversibly redact it from the live records and the history, on request from an owner or manager.
8.3 Oversight information. On request, and no more than once a year unless there is a Security Incident, DealerRev will complete Customer's reasonable security questionnaire and provide a summary of its security program, so Customer can oversee DealerRev as a service provider under the Safeguards Rule.
8.4 Audits. If the information in 8.3 is not reasonably sufficient, Customer, or an independent auditor bound by confidentiality, may audit DealerRev's compliance with this DPA once a year on 30 days' written notice, during business hours, at Customer's cost, and without access to other customers' data.
8.5 Customer's program. Customer will name a Qualified Individual responsible for its own information security program and give DealerRev that person's contact details.
9. Onsite document scanning
9.1 Scope. If Customer asks, DealerRev will visit Customer's premises on an agreed date to scan the paper records Customer designates — for example the current year's deal jackets, repair orders and title work — into Customer's DealerRev account.
9.2 Custody. Originals never leave Customer's premises. Scanning happens on site, in a space Customer provides, with a Customer representative available. Customer remains the custodian of its originals and responsible for keeping them as the law requires.
9.3 Equipment and copies. DealerRev will use encrypted, password-protected devices that it controls. Scans upload directly to Customer's account. DealerRev will verify each batch has uploaded and then delete any copies on scanning devices within [48 hours] of the visit, and will confirm deletion in writing.
9.4 Sensitive documents. Scanned documents that contain Nonpublic Personal Information are stored in restricted document storage and treated as NPI under this DPA.
9.5 Personnel. Only DealerRev personnel bound by written confidentiality obligations will scan. DealerRev will give Customer their names before the visit.
9.6 Customer's authority. Customer confirms it may lawfully provide the designated records to DealerRev for this purpose.
10. Third-party credentials
10.1 Use. DealerRev will use the credentials, API keys and delegated access Customer provides — for distributors, manufacturers, carriers, registrars and other Third-Party Services — only to perform the Service, as Customer's agent.
10.2 Transfer. Customer should send credentials only through the secure onboarding page or upload link DealerRev provides, never by ordinary email or text. DealerRev will never ask for Customer's banking password.
10.3 Storage. DealerRev stores credentials encrypted, limits who can view them, and does not display them in full in the Service after entry.
10.4 Revocation. Customer may revoke or rotate credentials at any time. When the Agreement ends, DealerRev will delete all credentials, and Customer should rotate any it shared.
11. Retention, return and deletion
11.1 During the term. DealerRev keeps Customer Data for as long as Customer keeps it in the Service. Customer controls retention through the Service's settings; deleting change history requires an owner or manager's approval.
11.2 Return. Customer may export Customer Data at any time. For 30 days after the Agreement ends, DealerRev will provide a complete export — records in CSV or JSON, and documents, scans and recordings in their original formats — on request, at no charge.
11.3 Deletion. Within [60] days after that 30-day export window, DealerRev will delete Customer Data from its live systems, including the change history. Encrypted backups will expire on their normal rotation within [35] more days and will not be restored in the meantime except to recover from a disaster, after which the data will be deleted again. DealerRev will confirm deletion in writing on request.
11.4 Exceptions. DealerRev may keep (a) Aggregated Data; (b) billing records and the Agreement; and (c) data it must keep under law or a legal hold, which remains subject to this DPA until deleted.
12. Liability and insurance
12.1 Liability. Each party's liability under this DPA is subject to Section 12 of the Terms, including the separate data-protection cap in Section 12.3.
12.2 Insurance. DealerRev will maintain cyber liability and technology errors-and-omissions insurance with limits of at least [$1,000,000] per claim, and will provide a certificate on request.
12.3 Customer's data. Customer is responsible for the lawfulness of the Customer Data it provides and of its own instructions to DealerRev.
13. Term and precedence
13.1 Term. This DPA lasts as long as DealerRev processes Customer Data, including after the Agreement ends until deletion under Section 11 is complete.
13.2 Precedence. If this DPA conflicts with the Terms or an Order Form on anything concerning Customer Data, this DPA controls.
13.3 Changes in law. If Applicable Data Protection Laws change, the parties will amend this DPA in good faith as needed to comply.
13.4 Acceptance and contacts. This DPA is accepted when Customer accepts the DealerRev Terms of Service. Customer names its Qualified Individual and security contact on the onboarding page; DealerRev's security and privacy contact is [name, security@dealerrev.app].
End of document · DealerRev Data Processing and Use Agreement · version 2026-09