Privacy Policy
Last updated: July 29, 2026
1. Scope and Our Two Roles
[LEGAL ENTITY NAME] ("RevLot," "we," "us") provides a dealer management platform for automotive, powersports, recreational vehicle, marine, trailer, and equipment dealers. This Privacy Policy explains how we handle personal information.
It is essential to understand that RevLot handles personal information in two distinct roles:
1.1 As a Controller / Business
When we collect information about our own customers and prospects — dealership owners, managers, and staff who create accounts, contact sales, visit our website, or use our Services — we act as the controller (or "business" under U.S. state privacy laws). Sections 3 through 12 of this Policy describe those practices.
1.2 As a Processor / Service Provider
When a dealership uses RevLot to store and process information about its own customers — vehicle purchasers, lessees, credit applicants, trade-in customers, service customers, and prospects ("Consumers") — the dealership is the controller and RevLot is a processor / service provider. We process that information only on the dealership's documented instructions and for no independent purpose of our own.
If you are a consumer who bought, leased, financed, or serviced a vehicle from a dealership, this Policy does not describe how that dealership handles your information. RevLot does not have a direct relationship with you, cannot verify your identity, and generally cannot honor your privacy requests directly. Please contact the dealership. If you contact us, we will make reasonable efforts to refer you to the appropriate dealership or forward your request to it. See Section 13.
2. Information We Collect as a Controller
2.1 Account and Business Information
Name, job title, business name, dealer license number, business address, business email, business phone, and account credentials (stored hashed and salted).
2.2 Billing Information
Billing contact, billing address, tax identification information, subscription plan, invoice and payment history, and the last four digits and expiration date of payment cards. We do not store full payment card numbers. Full card data is collected and stored by our PCI-DSS compliant payment processor.
2.3 Usage and Device Information
IP address, browser type and version, operating system, device identifiers, referring and exit pages, pages and features viewed, session duration, clickstream data, timestamps, crash and error logs, and diagnostic data.
2.4 Communications
Emails, chat messages, support tickets, and phone call records with us. Support calls and sessions may be recorded or transcribed for quality and training purposes where permitted by law and with notice.
2.5 Marketing and Website Data
Information collected through our website, forms, webinars, events, advertising platforms, and analytics tools, including cookie identifiers and inferred interests.
2.6 Information From Third Parties
Business contact and firmographic data from data providers, publicly available sources, lead generation partners, resellers, referral partners, and social media platforms.
2.7 Information We Do Not Seek
We do not intentionally collect, as a controller, sensitive personal information such as Social Security numbers, government identification numbers, financial account numbers, precise geolocation, biometric data, health information, or information about race, religion, sexual orientation, or union membership from our business customers.
3. Information Processed on Behalf of Dealerships (as Processor)
Depending on how a dealership configures and uses the Services, Customer Data may include the following categories of Consumer personal information:
| Category | Examples |
|---|---|
| Identifiers | Name, address, phone, email, date of birth, driver's license number |
| Government identifiers | Social Security number, taxpayer identification number (in credit/deal contexts) |
| Financial information | Income, employment, bank and financing details, credit application data, payment history, down payment, trade payoff |
| Consumer report information | Credit scores and credit report data obtained by the dealership from consumer reporting agencies |
| Commercial information | Vehicles viewed, purchased, leased, traded, or serviced; deal structure; F&I products; service history |
| Vehicle information | VIN, HIN, mileage, condition, title and lien status, registration data |
| Internet activity | Website and listing activity captured by the dealership's integrations |
| Communications | Call recordings, SMS and email threads, notes, and CRM activity logged by the dealership |
| Geolocation | Where a dealership enables GPS, telematics, or lot-management features |
| Signatures | Electronic signatures on deal and disclosure documents |
We process this information solely to provide the Services to the dealership. We do not sell it, share it for cross-context behavioral advertising, use it for our own marketing, or combine it with information from other sources for any independent purpose.
Dealership responsibility. The dealership is solely responsible for the lawfulness of its collection of Consumer information, for providing its own privacy notices (including any GLBA privacy notice), for obtaining all required consents, for establishing a permissible purpose under the FCRA before obtaining any consumer report, and for responding to Consumer privacy rights requests.
4. How We Use Information (as Controller)
| Purpose | Description |
|---|---|
| Providing the Services | Creating and administering accounts, authenticating users, delivering features |
| Billing | Processing payments, invoicing, collections, tax reporting |
| Support | Responding to inquiries, troubleshooting, training |
| Security | Detecting, investigating, and preventing fraud, abuse, and unauthorized access; maintaining audit logs |
| Improvement | Analyzing usage to debug, improve reliability, and develop new features |
| Communications | Sending service, security, billing, and transactional notices |
| Marketing | Sending product news, offers, and event invitations, subject to opt-out |
| Legal compliance | Meeting legal, tax, accounting, and regulatory obligations; responding to lawful requests; establishing, exercising, or defending legal claims |
| Corporate transactions | Evaluating or completing a merger, acquisition, financing, or asset sale |
4.1 Legal Bases (Where GDPR or Similar Law Applies)
We rely on: performance of a contract (providing the Services, billing); legitimate interests (security, improvement, B2B marketing, defending claims); consent (certain cookies and marketing, where required); and legal obligation (tax, accounting, lawful requests).
5. Artificial Intelligence and Automated Processing
5.1 How AI Features Work
Certain features use artificial intelligence to generate descriptions, summaries, drafts, translations, classifications, estimates, and recommendations. Data you submit to an AI Feature is transmitted to the applicable model provider for processing and returned as output.
5.2 No Training on Your Data
We do not use Customer Data to train general-purpose or foundation AI models. We contractually require our AI subprocessors not to use data transmitted through our API to train their models. Model providers may retain data briefly for abuse monitoring in accordance with their enterprise terms.
5.3 Human Review Required
AI output may be inaccurate or fabricated. Output is a draft only and must be reviewed by a qualified person before use. See the Terms of Service, Section 7.
5.4 No Automated Decisions With Legal Effects
RevLot does not make automated decisions producing legal or similarly significant effects concerning any individual. We do not make credit decisions, set individual pricing, or determine eligibility for anything. Where a dealership uses the Services in connection with such decisions, the dealership is solely responsible for compliance with the FCRA, ECOA, and all applicable law.
6. How We Disclose Information
We disclose personal information in the following circumstances only:
(a) Service providers and subprocessors. Vendors that perform services for us under written contracts limiting their use of the information to providing those services. See Section 7.
(b) At the direction of the dealership. Where a dealership enables an integration, we transmit Customer Data to that third party at the dealership's instruction. Once transmitted, the receiving party's own privacy practices govern.
(c) Within your organization. Account administrators can access, monitor, export, modify, and delete data associated with users in their account, including message content and activity logs.
(d) Legal and safety. To comply with applicable law, subpoena, court order, or other lawful request; to enforce our agreements; to investigate fraud, abuse, or security incidents; or to protect the rights, property, or safety of RevLot, our customers, or the public. Where legally permitted, we will make reasonable efforts to notify the affected customer before disclosure.
(e) Corporate transactions. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business, subject to the acquirer's agreement to honor commitments materially consistent with this Policy.
(f) Professional advisors. Auditors, attorneys, insurers, and accountants under confidentiality obligations.
(g) Aggregated and de-identified data. We may create and disclose aggregated or de-identified data that cannot reasonably be used to identify any individual, dealership, or Consumer. We commit to maintaining such data in de-identified form and not attempting to re-identify it.
(h) With consent. Where you direct or authorize us to.
6.1 We Do Not Sell Personal Information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act, the Utah Consumer Privacy Act, or similar state laws. We have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of any individual under 16 years of age.
7. Subprocessors
We use the following categories of subprocessors. A current list is available at[SUBPROCESSOR LIST URL] or upon request to[PRIVACY EMAIL].
| Category | Function | Primary Location |
|---|---|---|
| Cloud hosting & infrastructure | Application hosting, storage, databases | United States |
| Payment processing | Subscription billing, card processing | United States |
| Communications | Transactional email, SMS/voice delivery | United States |
| AI model providers | Generative and analytical AI features | United States |
| Analytics & monitoring | Product analytics, error tracking, performance monitoring | United States |
| Customer support | Ticketing, live chat, knowledge base | United States |
| Security | Authentication, fraud detection, logging | United States |
Each subprocessor is bound by a written agreement requiring appropriate confidentiality and security measures and limiting use of the data to providing services to us. We remain responsible for our subprocessors' performance of their data protection obligations.
8. Cookies and Tracking
8.1 Types
- Strictly necessary — authentication, session management, security, load balancing. These cannot be disabled.
- Functional — remembering preferences and settings.
- Analytics — understanding how the Services and website are used.
- Marketing — measuring campaign performance on our public website.
8.2 Choices
Most browsers allow you to block or delete cookies. Blocking strictly necessary cookies will prevent the Services from functioning. Where required by law, we present a consent banner allowing granular choices.
8.3 Global Privacy Control
We honor the Global Privacy Control (GPC) signal on our public website as a valid opt-out of any sale or sharing, where required by applicable law.
8.4 Do Not Track
We do not currently respond to browser "Do Not Track" signals, as no uniform industry standard exists.
8.5 No Tracking Inside the Application
We do not deploy third-party advertising or behavioral tracking technologies inside the authenticated RevLot application.
9. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption in transit (TLS 1.2 or higher) and at rest
- Role-based access controls and the principle of least privilege
- Multi-factor authentication availability for all accounts
- Network segmentation, firewalls, and monitoring
- Audit logging of significant system events
- Regular patching and vulnerability management
- Background screening of personnel with access to production systems
- Written incident response procedures
- Vendor security review prior to onboarding subprocessors
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for the security of your credentials, devices, and networks, and for promptly deactivating departed personnel.
9.1 GLBA Safeguards
To the extent we process nonpublic personal information on behalf of a dealership, we act as a service provider under the GLBA Safeguards Rule (16 C.F.R. Part 314) and maintain safeguards appropriate to that role. Each dealership remains responsible for maintaining its own written information security program, performing its own risk assessments, and overseeing its own service providers.
9.2 Incident Notification
If we confirm a security incident affecting Customer Data within our systems, we will notify the affected dealership without undue delay and provide reasonably available details. The dealership is responsible for determining whether notification to Consumers or regulators is required and for making any such notifications.
10. Data Retention
| Data | Retention |
|---|---|
| Customer Data (active account) | For the duration of the subscription |
| Customer Data (after termination) | Available for export for 30 days; deleted thereafter, subject to Section 10.1 |
| Account and contact records | Duration of relationship plus 3 years |
| Billing, invoice, and tax records | 7 years, or as required by law |
| Security and audit logs | 12–24 months |
| Support tickets and communications | 3 years |
| Marketing contact records | Until opt-out plus a suppression record retained indefinitely to honor the opt-out |
| Backups | Rolling backups retained up to 90 days, then overwritten |
10.1 Exceptions
We may retain information longer where required by law, where necessary to establish, exercise, or defend legal claims, where subject to a litigation hold, or where retained in de-identified or aggregated form.
Dealerships are responsible for their own legal records retention obligations. The Services are not a system of record for legal retention purposes, and dealerships must maintain independent copies of all records they are required by law to keep.
11. Your Privacy Rights
11.1 U.S. State Privacy Rights
Depending on your state of residence — including California, Utah, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and others as their laws take effect — you may have the right to:
- Know / Access — confirm whether we process your personal information and obtain a copy
- Correct — request correction of inaccurate personal information
- Delete — request deletion, subject to legal exceptions
- Portability — receive your information in a portable format
- Opt out — of sale, sharing for cross-context behavioral advertising, targeted advertising, or profiling with legal or similarly significant effects (note: we do not engage in these activities)
- Limit use of sensitive personal information (we do not use sensitive personal information for any purpose requiring this right)
- Non-discrimination — we will not discriminate against you for exercising any right
- Appeal — appeal our denial of a request
11.2 California-Specific Disclosures
In the preceding twelve months, we collected the categories of information described in Section 2 (as a controller), for the purposes in Section 4, from the sources in Section 2, and disclosed them for business purposes to the categories of recipients in Section 6. We did not sell or share personal information. We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.
11.3 GDPR / UK GDPR Rights
Where applicable, you may have rights of access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interests and to direct marketing), withdrawal of consent, and lodging a complaint with a supervisory authority.
11.4 How to Exercise Your Rights
Email [PRIVACY EMAIL] with the subject line "Privacy Rights Request," or write to us at the address in Section 16. We will:
- acknowledge receipt within 10 business days where required;
- verify your identity using information already in our possession — we may request additional information solely for verification;
- respond within 45 days, extendable once by an additional 45 days with notice.
Authorized agents may submit requests on your behalf with proof of authorization and verification of the consumer's identity.
Appeals. If we deny your request, you may appeal by replying to our decision with "Appeal" in the subject line. We will respond within 45 days (or 60 days where state law provides). If your appeal is denied, you may contact your state Attorney General.
11.5 Marketing Opt-Out
Unsubscribe using the link in any marketing email or contact [PRIVACY EMAIL]. You cannot opt out of transactional, service, billing, and security notices while you maintain an account.
12. International Data Transfers
RevLot is based in the United States and processes and stores information on servers located in the United States. If you access the Services from outside the United States, your information will be transferred to, stored in, and processed in the United States, which may have data protection laws different from those in your jurisdiction.
Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical and organizational measures. Copies are available upon request.
13. Consumers of Dealerships
If you are an individual who purchased, leased, financed, traded, or serviced a vehicle at a dealership that uses RevLot:
The dealership — not RevLot — decides what information to collect about you, why, how long to keep it, and who to share it with. The dealership is the controller of your information and is the party that must respond to your privacy rights requests and provide you with a GLBA privacy notice.
Please direct all requests to the dealership. If you contact us, we will attempt in good faith to identify the relevant dealership and forward your request, but we cannot independently verify your identity, cannot determine what information a dealership holds about you, and cannot delete or modify a dealership's records without its instruction.
14. Children's Privacy
The Services are business software intended solely for use by businesses and their personnel. We do not knowingly collect personal information directly from children under 13, and the Services are not directed to children. If we learn that we have inadvertently collected such information as a controller, we will delete it promptly. Contact [PRIVACY EMAIL] if you believe this has occurred.
15. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a revised "Last Updated" date. For material changes, we will provide notice by email or in-product at least thirty (30) days before the change takes effect. Your continued use after the effective date constitutes acceptance. We encourage you to review this Policy periodically.
16. Contact Us
[LEGAL ENTITY NAME]
Attn: Privacy
[MAILING ADDRESS]
Privacy: [PRIVACY EMAIL]
Security: [SECURITY EMAIL]
General: [CONTACT EMAIL]
Phone: [PHONE]
EU/UK Representative (if applicable): [NAME AND CONTACT]
Data Protection Officer (if appointed): [NAME AND CONTACT]
RevLot DMS — Privacy Policy. © [YEAR] [LEGAL ENTITY NAME]. All rights reserved.
