AutoRevolution Privacy Policy
Last Updated:
Effective Date:
Version: v3.1
This Privacy Policy explains AutoRevolution's information handling practices when operating as a business and data controller for its own products, websites, marketing, and operations, and when providing software and related services to automotive dealerships, dealer groups, OEMs, and enterprise customers as a service provider or processor.
Table of Contents
1. Introduction
This Privacy Policy describes how Metzger Enterprises LLC d/b/a AutoRevolution, including its subsidiaries and affiliates, a Texas Limited Liability Company ("Company," "AutoRevolution," "LotPix," "Vehicle Image Studio," "Forward2Phone," "IIManager," "we," "us," or "our"), respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, store, process, retain, and safeguard personal information with the Company's software-as-a-service platform, including website hosting, CMS, CRM, marketing, analytics, applications, SMS communication, artificial intelligence tools, mobile applications, APIs, cloud infrastructure, integrations, and related technology used for vehicle photography, inventory merchandising, dealership operations, and automotive retail workflows (collectively, the "Services").
This Privacy Policy applies to enterprise customers, including automotive dealerships, dealer groups, reseller organizations, auction groups, OEM-affiliated entities, fleet operators, and other authorized business customers ("Customer"), as well as individuals authorized by Customer to access or use the Services ("Authorized Users").
"LotPix", "Vehicle Image Studio", "IIManager", and "Forward2Phone" are products owned and operated by AutoRevolution, a business-to-business (B2B) software-as-a-service (SaaS) company designed solely for use by licensed automotive businesses, including dealerships, dealer groups, resellers, auctions, and fleet operators. It is not intended for consumer, personal, or household use, and may only be accessed and used through the AutoRevolution platform and its authorized systems.
This Policy applies to users across the United States and Canada. It is designed to comply with applicable laws including This Privacy Policy is designed to comply with applicable U.S. federal and state privacy laws, including but not limited to the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), Virginia Consumer Data Protection Act ("VCDPA"), Colorado Privacy Act ("CPA") including AI Act, Texas Data Privacy and Security Act ("TDPSA"), Connecticut Data Privacy Act ("CTDPA"), and other applicable laws.
1.1. Audience
AutoRevolution's Services are designed exclusively for commercial and business use within the automotive industry.
The Services are intended solely for:
- Licensed motor vehicle dealerships and dealer groups;
- Automotive resellers and remarketing organizations;
- Automotive auction companies;
- Fleet operators and fleet management organizations;
- OEM-affiliated entities and authorized automotive partners;
- Authorized employees, contractors, representatives, and agents of Customers.
The Services are not intended for personal, family, or household use and are not marketed directly to consumers.
The Services are not intended for use by individuals under eighteen (18) years of age. AutoRevolution does not knowingly collect personal information directly from minors. If AutoRevolution becomes aware that personal information has been collected directly from a minor in violation of this Policy, reasonable steps will be taken to delete such information in accordance with applicable law.
No consumer accounts are knowingly created, maintained, or supported by AutoRevolution. Individuals whose information may be processed through the Services are typically consumers interacting with our Customers, dealership personnel, business contacts, vendors, or other authorized users of Customer systems.
2. Definitions
Capitalized terms not otherwise defined in this Privacy Policy have the meanings assigned to them in the applicable agreement between Customer and Provider, including any master services agreement, subscription agreement, order form, terms of service, privacy policy, or definitions glossary made available by Provider.
For purposes of this Privacy Policy, the following additional definitions apply:
- Account
- A unique account, profile, credential set, or other registration established by or on behalf of a Customer or Authorized User to access or use the Services.
- Aggregated Data
- Information derived from Customer Data, Usage Data, or other data sources that has been combined with data from multiple sources and modified such that it does not reasonably identify, relate to, describe, or enable the identification of any individual, household, dealership, Customer, or vehicle owner.
- Analytics Data
- Information generated through the use of the Services relating to performance, engagement, utilization, functionality, operational metrics, reporting, benchmarking, trend analysis, or similar statistical information.
- Applicable Law
- All applicable laws, regulations, directives, ordinances, rules, regulatory guidance, industry requirements, and governmental orders governing privacy, data protection, cybersecurity, consumer protection, electronic communications, automotive retail operations, and related matters.
- Authorized User
- An individual who is authorized by a Customer to access or use the Services, including employees, contractors, agents, representatives, administrators, dealership personnel, service advisors, sales personnel, marketing personnel, executives, and other approved users.
- Automotive Data
- Information relating to vehicles, vehicle ownership, vehicle servicing, maintenance history, vehicle identification numbers (VINs), inventory, sales transactions, customer interactions, warranty information, telematics data, dealership operations, or related automotive business activities.
- Browser Information
- Information automatically transmitted by a web browser or device when accessing online services, including browser type, operating system, language preferences, device characteristics, screen resolution, referring URLs, and similar technical information.
- Customer
- A dealership, dealer group, automotive retailer, OEM-affiliated entity, automotive service provider, lender, finance company, insurance provider, vendor, partner, or other organization that purchases, licenses, subscribes to, accesses, or uses the Services for business purposes.
- Customer Data
- Any information, content, records, files, communications, documents, data sets, or other materials submitted, uploaded, transmitted, imported, generated, stored, or otherwise made available to the Services by or on behalf of a Customer or its Authorized Users.
- Consent
- Any freely given, specific, informed, and unambiguous indication of an individual's wishes by which the individual signifies agreement to the processing of Personal Information, where such agreement is required under Applicable Law.
- Consumer
- An individual whose information is processed through the Services, including vehicle purchasers, lessees, service customers, prospects, consumers, website visitors, applicants, guarantors, co-buyers, vehicle owners, and other individuals interacting with a Customer.
- Cookies
- Small text files or similar technologies stored on a browser, device, application, or system that enable functionality, authentication, preferences management, analytics, advertising, security, or other operational purposes.
- Data Controller
- "Controller," or equivalent term means the person or entity that determines the purposes and means of processing Personal Information under Applicable Law.
- Data Processor
- "Processor," or equivalent term means the person or entity that processes Personal Information on behalf of a Data Controller under Applicable Law.
- De-Identified Data
- Information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular individual, household, Customer, dealership, or device, provided that reasonable measures have been implemented to prevent re-identification and such information is maintained and used in accordance with Applicable Law.
- Device Data
- Information relating to a device used to access the Services, including device identifiers, operating system information, hardware model, browser information, mobile device information, network information, application version information, and related technical data.
- Dealer Group
- An organization that owns, controls, operates, manages, or is affiliated with multiple automotive dealerships.
- Dealership
- An automotive retailer, automotive dealer, dealership location, franchise dealership, independent dealership, commercial vehicle dealer, powersports dealer, recreational vehicle dealer, marine dealer, or similar automotive-related retail operation.
- Financial Information
- Information relating to financing, credit applications, lending, payment processing, billing, account balances, transaction histories, or other financial matters.
- Geolocation Data
- Information that identifies or may reasonably be used to determine the geographic location of a person, vehicle, device, dealership, or other asset.
- Government Authority
- Any governmental, regulatory, judicial, administrative, law enforcement, supervisory, or public authority with jurisdiction over a party, the Services, or the processing of information.
- Identifier
- A name, number, online identifier, account identifier, customer number, device identifier, vehicle identifier, or other identifier that identifies, relates to, describes, or may reasonably be linked to a particular individual, household, device, vehicle, dealership, or organization.
- IP Address
- An Internet Protocol address or similar network identifier assigned to a device, network, or internet connection.
- Marketing
- Promotional messages, newsletters, event invitations, product updates, service announcements, surveys, advertising materials, and other communications intended to market products, services, events, or business opportunities.
- Metadata
- Information generated in connection with the creation, transmission, storage, management, access, or use of data, including timestamps, activity logs, audit trails, system events, configuration information, and related technical information.
- OEM
- An original equipment manufacturer, automotive manufacturer, automotive brand owner, affiliated distribution entity, or related organization within an automotive manufacturer ecosystem.
- Personal Information
-
"Personal Data," or similar term means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identified or identifiable individual.
Personal Information may include, depending on context and Applicable Law:
- Names;
- Postal addresses;
- Email addresses;
- Telephone numbers;
- Government-issued identifiers;
- Account credentials;
- Vehicle ownership information;
- Customer records;
- Online identifiers;
- Device identifiers;
- Geolocation information;
- Commercial information;
- Financial information;
- Internet activity information;
- Employment information; and
- Other information protected under Applicable Law.
Personal Information does not include information that has been lawfully anonymized, de-identified, or aggregated in accordance with Applicable Law.
- Processing
- Process," or "Processed" means any operation performed on information or Personal Information, whether by automated means or otherwise, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, dissemination, alignment, combination, restriction, deletion, destruction, or other handling of such information.
- Prospect
- An individual who has expressed interest in purchasing, leasing, financing, servicing, trading, or otherwise engaging in a transaction relating to a vehicle, automotive product, or automotive service.
- Sensitive Personal Information
-
"Sensitive Personal Data," or equivalent term means Personal Information that receives enhanced protection under Applicable Law, including where applicable:
- Government-issued identification numbers;
- Driver's license numbers;
- Financial account information;
- Payment card information;
- Precise geolocation information;
- Account credentials;
- Biometric information;
- Racial or ethnic origin;
- Religious beliefs;
- Citizenship or immigration status;
- Information concerning a person's sex life or sexual orientation;
- Union membership; and
- Other categories designated as sensitive under Applicable Law.
- Service Provider
- A vendor, contractor, subprocesser, consultant, technology provider, hosting provider, analytics provider, communications provider, payment processor, support provider, or other third party engaged to perform services on behalf of the Company.
- Services
- The software, platforms, websites, applications, APIs, integrations, portals, tools, technologies, professional services, support services, and related offerings provided by the Company.
- Subprocessor
- A third-party processor engaged by the Company or one of its Affiliates to process Personal Information on behalf of a Customer in connection with the provision of the Services.
- Telematics Data
- Data generated by, transmitted from, or associated with a connected vehicle, vehicle system, fleet management system, sensor, onboard diagnostic system, mobile application, or related automotive technology.
- Usage Data
- Information relating to how users access, interact with, navigate, configure, or use the Services, including session information, feature utilization, clickstream information, activity logs, performance metrics, and diagnostic information.
- Vehicle Data
- Information relating to a vehicle, including VINs, make, model, trim, year, mileage, maintenance history, service history, ownership information, warranty information, registration-related information, inventory status, inspection records, valuation information, and related automotive information.
- Website
- Any website, portal, landing page, online platform, web application, mobile application, or digital property operated by or on behalf of the Company.
3. Scope & Role
3.1 Scope
This Privacy Policy describes how AutoRevolution collects, uses, discloses, processes, stores, protects, and otherwise handles personal information in connection with:
- Our websites and online properties;
- Our software-as-a-service platform and related applications;
- LotPix, Vehicle Image Studio, IIManager, Forward2Phone, and related products;
- Hosted dealership websites, applications, and customer-facing digital properties operated through the Services ("Hosted Sites");
- Customer support, training, implementation, consulting, and account management activities;
- Business development, marketing, events, and communications; and
- Business relationships with Customers, vendors, partners, and prospective customers.
This Privacy Policy applies only to information for which AutoRevolution serves as a controller, business, service provider, processor, contractor, or similar legal role, depending upon the circumstances of processing.
This Privacy Policy does not apply to:
- Third-party websites, applications, services, or platforms not owned or controlled by AutoRevolution;
- Privacy practices of dealerships, dealer groups, auctions, fleet operators, or other Customers using the Services;
- Information processed solely under Customer direction where a separate agreement governs processing activities; or
- Third-party operating systems, app stores, telecommunications providers, analytics platforms, or cloud services operating under their own privacy policies.
3.2 Controller
AutoRevolution's privacy obligations depend upon the context in which personal information is processed.
AutoRevolution acts as a controller, business, or equivalent role when determining the purposes and means of processing personal information for its own business operations, including:
- Managing customer and vendor relationships;
- Sales, marketing, and business development activities;
- Account administration and billing;
- Website administration and analytics;
- Security monitoring and fraud prevention;
- Regulatory compliance and legal obligations;
- Product development and service improvement; and
- Corporate administration and business operations.
For these activities, AutoRevolution independently determines how and why personal information is processed and is responsible for complying with applicable legal obligations associated with that role.
AutoRevolution does not provide legal advice or compliance certification.
3.3 Service Provider
AutoRevolution acts as a service provider, processor, contractor, or similar role when processing Customer Data on behalf of a Customer through the Services.
In such circumstances:
- The Customer acts as the controller, business, or equivalent legal role;
- The Customer determines the purposes and means of processing Customer Data;
- AutoRevolution processes Customer Data only on documented Customer instructions, contractual obligations, or as otherwise permitted by law;
- AutoRevolution does not independently determine the business purpose for Customer processing activities; and
- AutoRevolution assists Customers with privacy and security obligations as required by applicable agreements and law.
3.4 Responsibilities
Customers are solely responsible for:
- Establishing an appropriate lawful basis for processing personal information;
- Providing legally required notices and disclosures;
- Obtaining required consents and permissions;
- Managing employee and Authorized User access rights;
- Configuring account permissions and security settings;
- Responding to privacy rights requests relating to Customer Data;
- Compliance with industry-specific laws and regulations applicable to their operations; and
- Determining the legality and appropriateness of their use of the Services.
AutoRevolution does not provide legal advice, regulatory certifications, or guarantees that Customer use of the Services satisfies any specific legal or regulatory requirement.
Customer is solely responsible for lawful basis, consents, employee access control, and compliance with applicable law.
3.5 Authorized User
Customer administrators control user accounts associated with their organizations and may access information relating to Authorized User accounts, login activity, audit logs, communications, usage records, and operational data generated through Customer use of the Services.
Authorized Users seeking to exercise privacy rights relating to information controlled by their employer or organization should direct such requests to the applicable Customer.
3.6 Mobile Platforms
Certain Services, including LotPix and related mobile applications, operate on iOS and Android platforms provided by Apple, Google, or other third-party operating system providers.
Device-level information, diagnostics, crash reports, telemetry, analytics, and operating system data may be collected or processed by such providers under their own privacy policies and practices. AutoRevolution does not control the privacy practices of third-party operating system providers.
4. Brands
Metzger Enterprises LLC d/b/a AutoRevolution operates and manages multiple software products, applications, and service offerings, including LotPix, Vehicle Image Studio, IIManager, Forward2Phone, and related technologies.
To provide integrated services and maintain operational efficiency:
- Information may be processed across shared systems and infrastructure;
- Centralized authentication, identity management, security, monitoring, and access controls may be used across products;
- Shared infrastructure may support billing, support, analytics, reporting, compliance, and operational functions;
- Data may be transferred among affiliated products where necessary to provide requested Services; and
- Centralized governance, security, privacy, and compliance controls may apply across AutoRevolution products and services.
The use of shared infrastructure does not alter AutoRevolution's role as either controller or processor, which continues to depend upon the specific processing activity being performed.
5. Collection
The categories of information processed by AutoRevolution vary depending on the Services used, the relationship between the parties, and whether AutoRevolution is acting as a controller, business, service provider, processor, contractor, or similar legal role under applicable law.
Certain information described below may be collected directly by AutoRevolution for its own business purposes, while other information may be processed on behalf of Customers through the Services.
For purposes of this Privacy Policy, AutoRevolution classifies information processed through the Services into the following categories:
5.1 Customer Data
Customer Data may include business records, inventory information, vehicle photographs, communications, marketing information, consumer information, Authorized User information, and other data processed on behalf of a Customer.
Except where required by applicable law, AutoRevolution does not sell, share, retain, use, or disclose Customer Data outside the direct business relationship with the Customer or for purposes other than providing the Services and related business operations authorized by the Customer.
Customer Data includes information submitted to the Services by or on behalf of a Customer and may include Authorized User Data, Consumer Data, vehicle inventory information, vehicle media, communications data, analytics data, and other information processed through the Services.
5.2 Authorized User Data
Authorized User Data relating to employees, contractors, representatives, agents, administrators, or other individuals authorized by a Customer, may include account credentials, contact information, login history, permissions, activity records, audit logs, authentication information, training records, support records, and Service usage information.
5.3 Consumer Data
Consumer Data may include lead information, contact information, appointment information, communications, inquiry records, CRM records, website submissions, messaging records, billing and shipping addresses, transaction records and transaction history, products or services purchased, obtained, or considered, preferences and interactions, end user data processed on behalf of customers, payment-related metadata processed by third-party payment providers, vehicle transaction information, and other information submitted to or collected by Customers through their use of the Services.
5.4 Company Data
Company Data may include the following categories of information.
Business Contact and Relationship Information:
- Names;
- Job titles;
- Employer or dealership affiliation;
- Business email addresses;
- Dealership name and entity details;
- Dealer license numbers;
- Business telephone numbers;
- Business mailing addresses;
- Professional contact preferences; and
- Customer, prospect, vendor, reseller, partner, and referral relationship records.
Account Administration Information:
- User account identifiers;
- Account history;
- Usernames;
- Authentication credentials;
- Password hashes;
- Multi-factor authentication information;
- Account status information;
- User roles and permissions; and
- Account creation and modification records.
Customer Relationship Management (CRM) Information:
- Sales inquiries;
- Product demonstrations;
- Trial requests;
- Lead records;
- Marketing campaign participation;
- Customer communications;
- Meeting notes;
- Account management records; and
- Customer success records.
Billing and Commercial Information:
- Subscription information;
- Service plans;
- Contract information;
- Purchase history;
- Billing contacts;
- Invoice information;
- Payment status information;
- Tax-related business information; and
- Transaction records.
AutoRevolution does not store full payment card numbers. Payment processing services may be provided by authorized third-party payment processors operating under their own privacy and security obligations.
Support and Service Information:
- Help desk tickets;
- Technical support requests;
- Customer service communications;
- Troubleshooting records;
- Product feedback;
- Feature requests;
- Training records; and
- Implementation records.
Website and Online Activity Information:
- IP addresses;
- Browser type and version;
- Device characteristics;
- Operating system information;
- Referring URLs;
- Browsing history;
- Search history;
- Interactions with our Services;
- Pages viewed;
- Referring URLs;
- Clickstream data;
- Session recordings and interaction data;
- Device and usage analytics;
- App version;
- Session logs;
- Audit logs;
- Crash and diagnostic data;
- Device identifiers;
- Website interaction data;
- Session information;
- Cookie identifiers;
- Analytics information; and
- Marketing attribution information.
Geolocation Data:
- GPS location (when enabled);
- Approximate location derived from IP address;
- Approximate location derived from device settings;
- Approximate location derived from photo metadata; and
- Dealership lot metadata.
Location data may be embedded in photos or videos if enabled through device settings.
Device Permissions:
- Camera access;
- Photo library access;
- Microphone access (for video capture); and
- Location services access (optional).
Security and Compliance Information:
- Login records;
- Authentication logs;
- Access logs;
- Audit logs;
- Security event records;
- Fraud prevention records;
- Incident response records;
- Risk assessment information; and
- Compliance records.
Communications Information:
- Email communications;
- Support requests;
- Support logs;
- Training interactions;
- Call recordings for quality assurance purposes;
- Chat communications;
- Video Conferencing communications;
- SMS communications directed to AutoRevolution;
- Event registrations;
- Webinar participation;
- Survey responses; and
- Subscription preferences.
Business Operations Information:
- Vendor records;
- Supplier records;
- Partner information;
- Reseller information;
- Contract administration records;
- Corporate governance records; and
- Legal and regulatory compliance records.
Analytics and Product Improvement Information:
- Service usage analytics;
- Performance metrics;
- Diagnostic information;
- Error logs;
- Crash reports;
- Aggregated and de-identified analytics; and
- Service improvement information.
Recruiting and Employment Information:
- Job applicant information;
- Resume and application materials;
- Employment eligibility information;
- Professional qualifications; and
- Human resources records.
Sensitive Personal Information ("CPRA" Definition)
We may collect limited categories of sensitive personal information, including:
- Precise or approximate geolocation (if enabled and permitted by law);
- Account login credentials; and
- Financial/credit related information related to transactions (if submitted).
We use Sensitive Personal Information only as reasonably necessary to:
- Provide Services;
- Prevent fraud and ensure security;
- Process transactions; and
- Legal compliance.
You may have the right to limit use of sensitive data under applicable law.
Company Data generally does not include Customer Data, Consumer Data, or other information processed solely on behalf of Customers through the Services, except to the extent such information is incorporated into AutoRevolution's own business records, security logs, contractual records, legal compliance records, or other controller activities permitted by applicable law and contractual obligations.
Vehicle Photography, Images, Videos, and Media Content:
As part of providing inventory merchandising, photography, imaging, artificial intelligence, and related Services, AutoRevolution may process:
- Vehicle photographs;
- Vehicle videos and multimedia content;
- Inventory merchandising media;
- Image files and associated metadata;
- Image enhancement and processing information;
- Upload records and timestamps;
- Capture event records;
- Location information embedded within media files where available;
- EXIF metadata and technical image attributes; and
- AI-generated or AI-assisted image processing outputs.
Vehicle photographs may occasionally contain incidental images of individuals, dealership personnel, customers, license plates, or other identifying information depending on Customer use of the Services.
When such information is processed through Customer workflows, AutoRevolution generally acts as a service provider or processor on behalf of the Customer.
AutoRevolution may process information relating to vehicles, inventory, fleet assets, and automotive merchandising operations, including:
- Vehicle Identification Numbers (VINs);
- Vehicle make, model, year, trim, and configuration data;
- Vehicle specifications and options;
- Mileage information;
- Condition reports and reconditioning information;
- Pricing information;
- Vehicle status and availability information;
- Buyer's Guide information;
- Window sticker information;
- Inventory merchandising content;
- Auction and remarketing information; and
- Related inventory management records.
Vehicle inventory information generally does not constitute personal information unless it is linked or reasonably linkable to an identifiable individual.
Aggregated and De-Identified Data:
We may use anonymized, aggregated, or de-identified information for analytics, performance improvement, product development, security monitoring, system optimization, and other lawful business purposes.
5.5 Distinction
AutoRevolution's role depends on the context of processing.
AutoRevolution generally acts as a controller, business, or equivalent legal role when processing information relating to:
- Prospective customers and sales contacts;
- Customer relationship management activities;
- Billing and account administration;
- Vendor and partner management;
- Website administration and analytics;
- Marketing activities;
- Product development and service improvement;
- Security monitoring and fraud prevention;
- Corporate operations; and
- Compliance with legal obligations.
For these activities, AutoRevolution determines the purposes and means of processing and is responsible for complying with applicable obligations associated with that role.
When AutoRevolution processes personal information submitted, uploaded, transmitted, stored, or otherwise made available by a Customer or Authorized User through the Services ("Customer Data"), AutoRevolution generally acts as a service provider, processor, contractor, or similar role on behalf of the Customer.
The Customer remains responsible for determining the purposes and means of processing Customer Data, including providing applicable notices, obtaining required consents, and establishing a lawful basis for processing where required by applicable law.
AutoRevolution processes Customer Data only as necessary to provide, maintain, secure, support, and improve the Services, comply with Customer instructions, enforce contractual obligations, prevent fraud and abuse, and comply with applicable legal requirements.
Where required by applicable law or Customer agreement, AutoRevolution may enter into a Data Processing Addendum ("DPA") governing the processing of Customer Data. A DPA may address matters including confidentiality obligations, security requirements, subprocessors, international transfers, data subject request assistance, breach notification obligations, and other data protection commitments.
AutoRevolution will provide reasonable assistance to Customers in responding to applicable privacy rights requests, regulatory inquiries, or compliance obligations relating to Customer Data, taking into account the nature of the processing and AutoRevolution's role as a service provider or processor.
6. Sources
We collect personal information from:
- You directly (forms, communications, account creation);
- Your employers, organization, or business partners;
- Automated technologies (cookies, pixels, analytics tools);
- Third-party partners, service providers, and integrations (dealerships, marketing providers, data integrations, social media);
- Subprocessors acting on our behalf;
- Billing and payment information (via third-party processors);
- Device identifiers;
- Publicly available sources;
- End User Data (Processed on Behalf of Customers);
We do not control the content or purpose of Customer Data.
7. Purposes
We process personal information only as reasonably necessary to provide, operate, maintain, secure, improve, and support our Services, and for the following purposes:
- Vehicle inventory photography, merchandising, and inventory management workflows.
- Inventory listing creation, publication, optimization, and management.
- Buyer's guide, window sticker, and related vehicle documentation generation.
- Provide, operate, maintain, and improve the Services.
- Process transactions, payments, and fulfill contractual obligations.
- Create, authenticate, manage, and secure user accounts.
- Generate, process, manage, and track leads and customer relationship management (CRM) activities.
- Deliver marketing, advertising, promotional communications, and campaign measurement activities, subject to applicable consent requirements.
- Personalize content, features, and user experiences where permitted by law.
- Conduct analytics, reporting, performance tracking, research, and product development activities.
- Provide SMS, email, and other communication services.
- Respond to inquiries, customer support requests, onboarding activities, and administrative communications.
- Detect, prevent, investigate, and respond to fraud, unauthorized access, security incidents, and illegal activities.
- Maintain platform security, monitor system performance, perform debugging, and improve system reliability.
- Develop new products, services, features, and offerings.
- Comply with applicable laws, regulations, legal obligations, and enforcement requests.
Where required by applicable law, we process personal information based on one or more legal grounds, including contractual necessity, legitimate business interests, consent, and compliance with legal obligations.
We collect, use, retain, and process personal information only to the extent reasonably necessary and proportionate to achieve the purposes described in this Privacy Policy and consistent with applicable law.
8. Cookies
We use cookies, pixels, web beacons, tags, scripts, software development kits (SDKs), local storage objects, APIs, session replay technologies, device identifiers, server-side tracking technologies, and similar technologies (collectively, "Cookies and Tracking Technologies") to operate, secure, maintain, analyze, improve, and market our websites, applications, software-as-a-service (SaaS) platforms, digital retailing solutions, inventory management systems, customer relationship management (CRM) tools, communications platforms, marketing services, customer portals, integrations, APIs, and related services (collectively, the "Services"). These technologies may be deployed directly by us or by our authorized service providers, business partners, integration partners, analytics providers, advertising partners, and other vendors acting on our behalf.
Purposes for Which We Use Cookies and Tracking Technologies
We may use Cookies and Tracking Technologies for a variety of business, operational, security, legal, and commercial purposes, including to:
- Authenticate users and maintain secure sessions;
- Verify account credentials and user permissions;
- Protect against fraud, abuse, unauthorized access, cybersecurity threats, and malicious activity;
- Operate, administer, monitor, maintain, and improve the Services;
- Enable platform functionality, integrations, APIs, and customer-specific configurations;
- Store user preferences, settings, and consent choices;
- Measure platform performance, uptime, availability, reliability, and usage trends;
- Analyze website traffic, engagement metrics, feature utilization, and customer interactions;
- Generate aggregated analytics, benchmarking, reporting, and business intelligence;
- Improve user experience, platform functionality, products, services, and support operations;
- Facilitate lead management, digital retailing, inventory merchandising, communications, and dealership workflows;
- Measure advertising performance, marketing attribution, audience engagement, and campaign effectiveness;
- Personalize content, communications, educational resources, and business-related marketing materials;
- Support customer service, troubleshooting, diagnostics, and technical support;
- Maintain records necessary for legal, regulatory, contractual, audit, and compliance obligations; and
- Develop, test, train, improve, and optimize current and future products, services, automation capabilities, analytics tools, and artificial intelligence or machine-learning-enabled features where permitted by applicable law.
8.1 Categories
Some cookies may perform multiple functions and may therefore fall into more than one category depending on their use.
We may also use session cookies, which expire when a browser session ends, and persistent cookies, which remain on a device for a specified period unless deleted earlier.
We categorize cookies and similar technologies based on their purpose and functionality. Depending on the Services utilized, we may use the following categories of Cookies and Tracking Technologies:
Depending on your location and applicable law, you may be presented with options to manage your cookie preferences and consent choices. You can also control certain tracking technologies through your browser settings and other available privacy controls. Please note that disabling certain cookies may affect the functionality and performance of our website.
| Category | Purpose | Can Be Disabled? |
|---|---|---|
| Strictly Necessary Cookies | These technologies are required for the operation, security, administration, and functionality of the Services and generally cannot be disabled because they are necessary to provide requested functionality, maintain account security, process transactions, administer systems, or comply with legal obligations. | No. These cookies are required for the Services to function properly. |
| Performance and Analytics Cookies | These technologies help us understand how users interact with our Services, identify technical issues, evaluate performance, analyze trends, generate aggregated statistics, improve usability, and optimize the customer experience. | Yes, subject to applicable legal requirements. |
| Functional Cookies | These technologies enable enhanced functionality and personalization, such as remembering preferences, language selections, dealership configurations, user settings, accessibility preferences, and platform customizations. | Yes, subject to applicable legal requirements. |
| Advertising and Marketing Cookies | These technologies may be used to support audience measurement, lead attribution, remarketing, campaign analytics, advertising effectiveness measurement, business communications, and delivery of relevant marketing content across websites, applications, devices, and platforms where permitted by applicable law. | Yes. Users may opt out where required by applicable law. |
8.2 Consent
Where required by applicable law, we obtain consent before deploying certain non-essential Cookies and Tracking Technologies. Depending on your location and applicable legal requirements, you may have the ability to manage preferences through our cookie preference center, consent management platform, browser controls, device settings, or other available mechanisms.
Certain browsers and devices may also permit transmission of privacy preference signals, including the Global Privacy Control (GPC). Where required by applicable law, we will recognize and process such signals as requests relating to targeted advertising, sharing of personal information, sale of personal information, or similar regulated processing activities. Recognition of such signals may be limited to the browser, device, or profile from which the signal is transmitted.
Users may also be able to:,/p>
- Delete or block cookies through browser settings;
- Configure device-level privacy controls;
- Adjust mobile advertising identifier settings;
- Utilize available analytics opt-out tools;
- Modify consent preferences through our Cookie Banner Preferences; and
- Cookie Preference Banner;
- Exercise privacy rights available under applicable privacy laws. AutoRevolution Opt-Out Request Form.
Please note that disabling or restricting certain technologies may affect the availability, functionality, security, performance, or user experience of portions of the Services.
8.3 Responsibilities
Where we provide Services to automotive dealerships, dealer groups, OEM-affiliated entities, marketing agencies, or other business customers, such customers may independently configure tracking technologies, analytics tools, advertising technologies, integrations, lead-generation tools, communication platforms, and third-party services within the Services. In such circumstances, the business customer may act as an independent controller, business, or equivalent legal entity under applicable privacy laws and may bear responsibility for providing required notices, obtaining necessary consents, honoring privacy rights requests, and complying with applicable data protection requirements relating to their use of such technologies.
8.4 Retention
Information collected through Cookies and Tracking Technologies is retained only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, maintain security, support legitimate business operations, and satisfy contractual requirements. Retention periods vary depending on the type of technology, its purpose, applicable legal requirements, customer configurations, and operational needs. Where appropriate, information may be aggregated, de-identified, anonymized, or otherwise transformed so that it no longer identifies an individual.
8.5 Additional Information
For detailed information regarding the categories of Cookies and Tracking Technologies we use, the purposes for which they are deployed, consent mechanisms, third-party providers, advertising and analytics activities, retention practices, privacy rights, opt-out methods, Global Privacy Control recognition, and jurisdiction-specific disclosures, please review our separate Cookie & Tracking Notice:
9. Disclosure
We may disclose personal information, business information, usage information, device information, commercial information, internet or network activity information, geolocation information, professional information, customer records, and other information described in this Privacy Policy to the categories of recipients identified below for legitimate business, operational, contractual, legal, security, compliance, and commercial purposes.
We do not disclose personal information except as described in this Privacy Policy, as authorized by the applicable customer, as required to provide the Services, or as otherwise permitted or required by applicable law.
9.1 Providers
We may disclose personal information to service providers, vendors, contractors, subprocessors, and other third parties that perform services on our behalf, support our business operations, or assist in delivering the Services.
These recipients may include:
- Cloud hosting and infrastructure providers;
- Data center and colocation providers;
- Content delivery network (CDN) providers;
- Website hosting providers;
- Software-as-a-Service providers;
- Customer relationship management (CRM) providers;
- Inventory management and merchandising providers;
- Automotive technology providers;
- Digital retailing and lead management providers;
- Analytics and business intelligence providers;
- Communications and messaging providers;
- Email service providers;
- SMS and telephony providers;
- Call tracking and call recording providers;
- Customer support and help desk providers;
- Payment processors and billing providers;
- Identity verification and authentication providers;
- Cybersecurity and fraud prevention providers;
- Monitoring, logging, and incident response providers;
- IT management and support providers;
- Professional advisors and consultants; and
- Other vendors reasonably necessary to operate, secure, maintain, improve, and support the Services.
These recipients are generally contractually required to process information only for authorized business purposes and to implement appropriate security measures.
9.2 Marketing
We may disclose personal information to advertising networks, analytics providers, marketing partners, audience measurement providers, attribution providers, and similar third parties to:
- Measure marketing effectiveness;
- Analyze website and platform performance;
- Generate reports and analytics;
- Understand customer engagement;
- Deliver and measure advertising campaigns;
- Support audience segmentation and remarketing activities; and
- Improve our products, services, and marketing efforts.
Depending on the jurisdiction and applicable law, certain disclosures involving advertising technologies, cross-context behavioral advertising, targeted advertising, audience matching, remarketing, or similar activities may constitute a "sale," "sharing," or other regulated disclosure of personal information under applicable privacy laws.
Individuals may have rights to opt out of such disclosures as described elsewhere in this Privacy Policy.
9.3 Partners
As a provider of software, websites, digital retailing solutions, CRM systems, communications platforms, marketing technology, inventory tools, and related services to automotive dealerships and automotive businesses, we may disclose information to:
- Automotive dealerships;
- Dealer groups;
- Automotive retailers;
- OEM-affiliated businesses;
- Manufacturer-approved vendors;
- Automotive marketing agencies;
- Inventory syndication partners;
- Lead providers;
- Technology integration partners;
- Software integration partners;
- Resellers;
- Referral partners; and
- Other authorized business partners.
Such disclosures may occur when necessary to provide requested Services, facilitate integrations, support dealership operations, manage customer relationships, process leads, synchronize data, perform reporting functions, fulfill contractual obligations, or enable requested features and functionality.
Where a dealership, dealer group, automotive business, or other customer controls the personal information processed through the Services, that customer may act as an independent controller, business, or equivalent legal entity under applicable privacy laws and may maintain separate privacy practices.
9.4 Legal
We may disclose personal information when we reasonably believe such disclosure is necessary to:
- Comply with applicable laws, regulations, legal processes, subpoenas, court orders, or governmental requests;
- Cooperate with law enforcement agencies, regulatory authorities, or governmental entities;
- Protect the rights, property, safety, security, or operations of our company, customers, users, employees, contractors, vendors, or the public;
- Detect, investigate, prevent, or address fraud, cybersecurity incidents, security vulnerabilities, unauthorized access, illegal activities, or violations of agreements;
- Establish, exercise, or defend legal claims; or
- Enforce our contracts, policies, terms, and other legal rights.
We may also preserve and disclose information where permitted or required by applicable law.
9.5 Corporate
Personal information may be disclosed, transferred, reviewed, or otherwise processed in connection with any actual or proposed:
- Merger;
- Acquisition;
- Asset purchase;
- Financing transaction;
- Investment transaction;
- Reorganization;
- Bankruptcy proceeding;
- Receivership;
- Dissolution;
- Sale of company assets; or
- Other corporate transaction.
In such circumstances, personal information may be transferred as a business asset, subject to applicable confidentiality obligations and legal requirements.
9.6 Internal
We may disclose and use personal information internally among our affiliates, subsidiaries, authorized personnel, contractors, and service providers as reasonably necessary to:
- Operate and administer the Services;
- Maintain infrastructure and business operations;
- Monitor performance and reliability;
- Conduct analytics and reporting;
- Improve products and services;
- Develop new products and features;
- Conduct quality assurance and testing;
- Provide customer support;
- Protect systems and networks;
- Detect and prevent fraud and abuse;
- Comply with legal obligations;
- Manage risk; and
- Conduct other legitimate business activities.
9.7 Advisors
We may disclose personal information to professional advisors and service providers, including:
- Attorneys;
- Auditors;
- Accountants;
- Tax advisors;
- Insurance providers;
- Financial advisors;
- Compliance consultants; and
- Other professional service providers.
Such disclosures are made only as reasonably necessary to obtain professional services, comply with legal obligations, manage risk, protect rights, or support business operations.
9.8 Compliance
Our Services are designed primarily for automotive dealerships, dealer groups, automotive businesses, and related commercial organizations.
Customers remain solely responsible for compliance with all laws, regulations, and industry requirements applicable to their businesses, including consumer protection, advertising, marketing, sales, financing, vehicle disclosures, telecommunications, privacy, and automotive regulatory requirements.
Without limitation, customers are responsible for compliance with all applicable federal, state, provincial, local, and industry-specific requirements, including dealership advertising laws, communications consent requirements, record retention obligations, and any applicable vehicle sales, financing, leasing, warranty, disclosure, or consumer protection regulations.
Our provision of technology, software, websites, communications tools, integrations, digital retailing systems, CRM platforms, marketing services, or related Services does not constitute legal advice and does not relieve customers of their independent compliance obligations.
10. Advertising
Certain U.S. state privacy laws provide consumers with the right to opt out of the "sale" of personal information, the "sharing" of personal information for cross-context behavioral advertising, targeted advertising, profiling in furtherance of decisions that produce legal or similarly significant effects, or similar data processing activities.
Although we do not sell personal information for monetary compensation in the traditional sense, we may disclose personal information, identifiers, online identifiers, device information, internet or network activity information, commercial information, geolocation information, and similar categories of information to certain third parties for advertising, analytics, audience measurement, marketing, attribution, remarketing, lead generation, and related business purposes. Depending on the applicable law and the specific processing activity, such disclosures may constitute a "sale," "sharing," "targeted advertising," or similar regulated disclosure.
These activities may occur through the use of cookies, pixels, web beacons, tags, APIs, SDKs, session identifiers, audience-matching technologies, analytics tools, marketing platforms, advertising technologies, customer relationship management systems, and similar technologies used on our websites, applications, communications platforms, and related Services.
10.1 Third Parties
We may disclose personal information to the following categories of third parties for advertising, analytics, marketing, attribution, audience development, and related purposes:
- Advertising networks and advertising technology providers;
- Digital marketing platforms;
- Marketing automation providers;
- Customer relationship management (CRM) platforms;
- Audience measurement and attribution providers;
- Analytics and reporting providers;
- Social media and social networking platforms;
- Lead generation and lead attribution providers;
- Data enrichment and business intelligence providers;
- Communication and messaging platforms; and
- Other authorized marketing, analytics, and business partners.
10.2 Disclosure
Depending on the Services used and the technologies deployed, we may disclose the following categories of information:
- Identifiers and unique personal identifiers;
- Online identifiers and device identifiers;
- Internet, application, browsing, and network activity information;
- Commercial information and transaction-related information;
- Approximate geolocation information;
- Professional or employment-related information;
- Customer records information;
- Lead submission information;
- Marketing engagement information;
- Advertising attribution information;
- Usage analytics and interaction data; and
- Other information described elsewhere in this Privacy Policy.
10.3 Tracking
We and our authorized partners may use personal information to deliver, optimize, personalize, measure, and analyze advertising, content, communications, promotions, and marketing campaigns across websites, applications, devices, and platforms.
We may also use personal information to create audience segments, evaluate marketing effectiveness, perform attribution analysis, measure campaign performance, identify business interests, improve products and services, support lead management activities, and conduct related analytics.
We do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects concerning consumers unless otherwise disclosed or permitted by applicable law.
10.4 Activities
Not all disclosures of personal information constitute a sale, sharing, targeted advertising activity, or profiling activity.
Many disclosures are made to service providers, contractors, subprocessors, cloud providers, communications vendors, infrastructure providers, cybersecurity providers, payment processors, and other vendors that process information solely on our behalf and subject to contractual restrictions. Such disclosures are generally undertaken to operate, secure, maintain, support, and improve the Services and are not intended to constitute a sale of personal information.
Similarly, where we process information solely on behalf of automotive dealerships, dealer groups, OEM-affiliated businesses, automotive marketing agencies, or other business customers pursuant to a written agreement, we may act as a processor, service provider, or contractor under applicable privacy laws.
10.5 Opt-Out Rights
Subject to applicable law, you may have the right to opt out of:
- The sale of personal information;
- The sharing of personal information for cross-context behavioral advertising;
- Targeted advertising;
- Certain profiling activities; and
- Other regulated disclosures of personal information.
You may exercise these rights through one or more of the following methods:
- Submitting a request through our privacy opt-out request form.
- Using our cookie preference banner or consent management tools, where available;
- Visiting our Do Not Sell or Share page;
- Contacting us using the contact information provided in this Privacy Policy; or
- Enabling a recognized opt-out preference signal, such as Global Privacy Control ("GPC"), where supported and required by applicable law.
10.6 Global Privacy Control
Where required by applicable law, we recognize and process browser-based opt-out preference signals, including Global Privacy Control ("GPC"), as requests to opt out of the sale of personal information, sharing of personal information, targeted advertising, or similar activities regulated by applicable law.
GPC signals are generally applied to the browser and device from which the signal is transmitted and may not apply across all browsers, devices, accounts, or business relationships associated with an individual.
11. AI Governance
AutoRevolution may utilize artificial intelligence ("AI"), machine learning, computer vision, automation technologies, large language models, predictive analytics, and similar technologies in connection with its products, services, applications, and business operations.
This Section explains how AI-enabled technologies may be used, how information may be processed in connection with such technologies, and the roles and responsibilities of AutoRevolution and its Customers.
11.1 Controller
When AutoRevolution Acts as a Controller. AutoRevolution may use AI-enabled technologies as a controller or business for its own legitimate business purposes, including:
- Product development and improvement;
- Service quality monitoring;
- Cybersecurity and fraud prevention;
- System performance analysis;
- Technical support and troubleshooting;
- Internal analytics and reporting;
- Customer support operations;
- Knowledge management; and
- Business operations and administrative functions.
For such activities, AutoRevolution determines the purposes and means of processing and is responsible for complying with obligations applicable to its role as a controller or business.
11.2 Processor
When AutoRevolution Acts as a Service Provider or Processor. AutoRevolution may also provide AI-enabled functionality within the Services that processes Customer Data on behalf of Customers.
In these circumstances:
- The Customer remains the controller, business, or equivalent legal role;
- The Customer determines whether and how AI-enabled features are used;
- AutoRevolution processes Customer Data solely to provide and support the Services and related functionality requested by the Customer;
- AutoRevolution acts as a service provider, processor, contractor, or similar role on behalf of the Customer; and
- Customer responsibilities regarding notices, disclosures, consent, and lawful basis remain unchanged by the use of AI-enabled functionality.
11.3 AI Uses
AI-enabled technologies may be used to support various Service features and operational activities, including:
- Vehicle image enhancement and optimization;
- Background correction, image processing, and photo quality improvement;
- Computer vision analysis of vehicle photographs and inventory media;
- Vehicle merchandising workflows;
- Inventory classification and categorization;
- Vehicle description generation and content assistance;
- Automated content formatting and summarization;
- Workflow automation and operational efficiency;
- Customer support assistance and knowledge retrieval;
- Analytics and reporting;
- Fraud prevention and security monitoring; and
- System administration and performance optimization.
The specific AI-enabled features available may vary by product, Service configuration, subscription level, Customer settings, and future product development.
11.4 AI Data
Customers may elect to use AI-enabled features that process Customer Data, Authorized User Data, Consumer Data, vehicle inventory information, vehicle media, communications data, or other information submitted through the Services.
When AI-enabled features process Customer Data, AutoRevolution processes such information in accordance with applicable agreements, Customer instructions, this Privacy Policy, and applicable law.
AutoRevolution does not use Customer Data to train generalized artificial intelligence models unless:
- The Customer has expressly authorized such use in writing;
- The applicable agreement permits such use; or
- Such use is otherwise permitted by applicable law.
AutoRevolution may use de-identified, aggregated, anonymized, or statistical information that does not identify a Customer, Authorized User, Consumer, or other individual for analytics, security, research, product improvement, benchmarking, and service development purposes where permitted by law and applicable agreements.
AI-enabled features are provided as tools to assist Customers and do not replace the Customer's responsibility to review inventory content, marketing content, consumer communications, regulatory disclosures, pricing information, vehicle descriptions, or other business records prior to publication or use.
11.5 Biometric
Because AutoRevolution's products are designed primarily for vehicle photography, inventory merchandising, and automotive operations, images processed through the Services are generally intended to capture vehicles and related inventory assets.
Vehicle photographs or videos may occasionally contain incidental images of customers, dealership personnel, bystanders, license plates, identifying documents, or other information visible within captured media.
AutoRevolution does not intentionally collect biometric identifiers or biometric information through vehicle photography workflows unless specifically enabled as part of a separately documented product feature and subject to applicable legal requirements.
AutoRevolution does not sell biometric identifiers or biometric information.
Customers remain responsible for determining whether applicable privacy, surveillance, image capture, biometric, employment, consumer protection, or consent requirements apply to their collection and use of images, video, or related media through the Services.
11.6 Profiling
AutoRevolution may use automated technologies to assist with classification, prioritization, routing, organization, analytics, recommendations, content generation, workflow automation, inventory management, and other operational functions.
Such processing may constitute automated processing, profiling, or similar regulated activities under certain privacy laws.
AutoRevolution does not intentionally use AI systems to make decisions producing legal effects or similarly significant effects concerning consumers, employees, applicants, or other individuals solely through automated means unless:
- Such functionality is specifically disclosed;
- Applicable legal requirements are satisfied; and
- Appropriate safeguards are implemented.
Where required by applicable law, individuals may have rights relating to automated decision-making, profiling, or similar processing activities. Requests should generally be directed to the applicable Customer when AutoRevolution processes information on the Customer's behalf.
11.7 AI Oversight
AutoRevolution maintains governance processes designed to promote responsible use of AI-enabled technologies.
Such measures may include:
- Risk-based review of AI-enabled features;
- Vendor and subprocessor assessments;
- Security and privacy evaluations;
- Access controls and data protection safeguards;
- Performance monitoring and quality assurance;
- Testing and validation processes;
- Human review and oversight where appropriate;
- Incident response procedures; and
- Periodic review of applicable legal and regulatory developments.
AI-generated outputs may contain inaccuracies, omissions, or unintended results. Customers and Authorized Users remain responsible for reviewing, validating, and approving AI-generated content before relying upon or publishing such content.
11.8 AI Providers
AutoRevolution may utilize third-party AI providers, cloud providers, subprocessors, or technology partners to deliver AI-enabled functionality.
Such providers may process information solely as necessary to provide services to AutoRevolution and subject to applicable contractual, confidentiality, security, and data protection obligations.
11.7 Emerging AI
AutoRevolution may update its AI practices, disclosures, controls, and governance measures to address evolving legal, regulatory, industry, security, and operational requirements relating to artificial intelligence, automated decision-making, data protection, and privacy.
12. Data Retention
AutoRevolution retains personal information and other data only for as long as reasonably necessary to fulfill the purposes for which it was collected or processed, provide the Services, satisfy contractual obligations, maintain business operations, comply with legal requirements, resolve disputes, enforce agreements, protect rights and interests, and support legitimate business needs.
Retention periods vary depending on the type of information, the nature of the Services provided, applicable contractual obligations, legal requirements, operational needs, security considerations, and whether AutoRevolution is acting as a controller or as a service provider or processor on behalf of a Customer.
12.1 Controller
When AutoRevolution acts as a controller, business, or equivalent legal role, AutoRevolution retains Company Data for periods reasonably necessary to support business operations and comply with applicable legal obligations.
Categories of Company Data may include:
- Customer relationship management records;
- Prospective customer and sales records;
- Vendor and partner records;
- Account administration records;
- Billing and transaction records;
- Customer support records;
- Marketing and communication records;
- Website analytics and operational records;
- Security and audit logs; and
- Legal, compliance, and corporate governance records.
Retention periods for Company Data are determined based on applicable legal requirements, contractual obligations, business necessity, security considerations, audit requirements, dispute resolution needs, and recordkeeping obligations.
12.2 Processor
When AutoRevolution processes Customer Data on behalf of a Customer, AutoRevolution generally acts as a service provider, processor, contractor, or similar role.
Customer Data retention is primarily determined by:
- Customer instructions;
- Applicable agreements;
- Data Processing Addenda;
- Service configurations selected by the Customer;
- Operational and technical requirements of the Services; and
- Applicable legal obligations.
Customer Data may include Authorized User Data, Consumer Data, vehicle inventory information, vehicle media, communications data, analytics data, operational records, and other information submitted through or generated by the Services.
Upon termination or expiration of Services, Customer Data may be deleted, returned, anonymized, archived, or otherwise handled in accordance with applicable agreements, Customer instructions, operational requirements, backup processes, legal obligations, and retention policies.
Certain Customer Data may remain in backup systems, disaster recovery systems, security logs, archives, or compliance records for a limited period after deletion from active systems, subject to appropriate safeguards and access restrictions.
12.3 Authorized User
Authorized User Data may be retained for the duration of the Customer relationship and for a reasonable period thereafter to support account administration, security, audit requirements, compliance obligations, dispute resolution, fraud prevention, and legitimate business operations.
Former Authorized User accounts may be deactivated while certain records, audit logs, permissions history, access records, and security-related information are retained as necessary to maintain system integrity and comply with legal or contractual obligations.
12.4 Consumer
Consumer Data processed on behalf of Customers is retained in accordance with Customer instructions, Customer-configured retention settings where available, applicable agreements, legal obligations, and operational requirements.
Customers are responsible for determining appropriate retention periods for Consumer Data and ensuring compliance with applicable privacy, consumer protection, automotive, employment, communications, and other legal requirements applicable to their operations.
12.5 Communication
Communications records, messaging records, call records, consent records, opt-in records, opt-out records, and related communications information may be retained for periods reasonably necessary to provide Services, maintain operational records, support compliance efforts, investigate disputes, respond to legal requests, and protect the rights of AutoRevolution, Customers, consumers, and other parties.
Retention periods may vary depending on the communication channel, Customer configuration, applicable agreements, carrier requirements, regulatory requirements, and operational needs.
12.6 Records
Financial records, tax records, accounting records, contractual records, litigation records, compliance records, and similar information may be retained for periods required or permitted by applicable law, accounting standards, audit requirements, contractual obligations, insurance requirements, or legal preservation obligations.
12.7 Audit Logs
Security logs, authentication records, access logs, audit trails, fraud prevention records, system event logs, and related security information may be retained for periods reasonably necessary to maintain system security, investigate incidents, detect abuse, support compliance activities, enforce agreements, and protect the Services.
12.8 Inventory
Vehicle photographs, videos, image files, inventory records, merchandising assets, and related metadata may be retained in accordance with Customer instructions, Service configurations, operational requirements, backup procedures, and applicable agreements.
Retention periods may vary depending on Customer workflows, inventory lifecycle requirements, storage settings, archival practices, and contractual arrangements.
12.9 Biometric
Vehicle photographs, videos, image files, inventory records, merchandising assets, and related metadata may be retained in accordance with Customer instructions, Service configurations, operational requirements, backup procedures, and applicable agreements.
Retention periods may vary depending on Customer workflows, inventory lifecycle requirements, storage settings, archival practices, and contractual arrangements.
12.10 Deletion
When information is no longer required for the purposes for which it was collected or processed, AutoRevolution may delete, anonymize, aggregate, de-identify, or otherwise render the information non-identifiable, subject to applicable legal, contractual, security, operational, and recordkeeping requirements.
De-identified, anonymized, aggregated, or statistical information that cannot reasonably identify an individual may be retained and used for lawful business purposes, including analytics, security, product improvement, benchmarking, research, and service development.
13. Data Transfers
AutoRevolution is headquartered in the United States and primarily provides Services to automotive dealerships, dealer groups, auctions, fleet operators, resellers, OEM-affiliated entities, and other authorized business customers located in the United States and Canada.
In connection with providing the Services and conducting business operations, personal information and other data may be collected, accessed, transferred, stored, processed, disclosed, or otherwise handled in the United States and other jurisdictions where AutoRevolution, its employees, contractors, affiliates, subprocessors, service providers, technology partners, or authorized representatives operate.
Because AutoRevolution utilizes cloud-based technologies, distributed personnel, international service providers, and global technology infrastructure, information processed through the Services may be subject to cross-border transfers and remote access from multiple jurisdictions.
13.1 Controller
When AutoRevolution processes Company Data for its own business purposes, including customer relationship management, sales, marketing, account administration, billing, security, analytics, vendor management, legal compliance, and corporate operations, AutoRevolution generally acts as a controller, business, or equivalent legal role under applicable law.
In these circumstances, Company Data may be transferred, accessed, stored, or processed in the United States and other jurisdictions where AutoRevolution personnel, affiliates, contractors, professional advisors, service providers, or technology partners operate.
13.2 Processor
When AutoRevolution processes Customer Data on behalf of a Customer through the Services, AutoRevolution generally acts as a service provider, processor, contractor, or similar role.
In these circumstances, Customer Data may be accessed, transferred, stored, or processed by authorized AutoRevolution personnel and approved subprocessors solely as necessary to provide, maintain, secure, support, troubleshoot, develop, improve, or operate the Services in accordance with applicable agreements, Customer instructions, and legal requirements.
Customers remain responsible for determining whether their use of the Services satisfies any legal, regulatory, contractual, organizational, OEM, manufacturer, lender, or other requirements relating to cross-border transfers, international processing, data residency, localization, or similar obligations.
13.3 International
Information processed through the Services may be accessed or processed across jurisdictions in connection with:
- Customer support and technical assistance;
- Software development and engineering activities;
- Quality assurance and testing;
- Security monitoring and incident response;
- Infrastructure management and cloud operations;
- Product maintenance and troubleshooting;
- Implementation and onboarding services;
- Data backup, recovery, and business continuity activities;
- Analytics and service optimization;
- Artificial intelligence and automation technologies;
- Vendor and subprocessor services; and
- Other operational activities reasonably necessary to provide and support the Services.
13.4 Personnel
AutoRevolution utilizes personnel located in multiple jurisdictions, including the United States and Mexico.
Authorized employees, contractors, and support personnel may access information as necessary to perform their assigned responsibilities, including customer support, account administration, technical support, security operations, software development, implementation services, and related business functions.
Access to information is restricted based on business need, role-based permissions, confidentiality obligations, security requirements, and applicable internal policies and procedures.
13.5 Subprocessors
AutoRevolution may engage third-party subprocessors, cloud providers, hosting providers, communications providers, analytics providers, artificial intelligence providers, payment processors, customer support platforms, monitoring providers, security vendors, software development resources, and other service providers to support the Services and business operations.
Such providers may operate in the United States, Canada, or other jurisdictions and may access, store, transmit, process, or otherwise handle information as necessary to perform services on AutoRevolution's behalf.
AutoRevolution implements appropriate contractual, confidentiality, privacy, and security obligations with applicable service providers and subprocessors consistent with the nature of the services provided and applicable legal requirements.
13.6 Categories
Information that may be transferred, accessed, or processed across jurisdictions may include:
- Company Data;
- Customer Data;
- Authorized User Data;
- Consumer Data;
- Vehicle inventory information;
- Vehicle photographs, videos, and media assets;
- Communications records;
- Support and service records;
- Security logs and audit records;
- Analytics and operational information;
- Artificial intelligence inputs and outputs;
- System-generated metadata; and
- Other information processed through the Services.
13.7 Safeguards
Where required by applicable law, AutoRevolution implements and maintains reasonable administrative, technical, organizational, and contractual safeguards designed to protect information during cross-border transfers and international processing activities.
Such safeguards may include:
- Data processing agreements;
- Confidentiality obligations;
- Contractual data protection commitments;
- Access controls and authentication measures;
- Encryption and security controls where appropriate;
- Vendor due diligence and risk assessments;
- Subprocessor management procedures;
- Security monitoring and auditing activities;
- Incident response processes; and
- Other safeguards required or permitted by applicable law.
13.8 Canadian Residents
Customers located in Canada should be aware that information processed through the Services may be transferred to, stored in, accessed from, or processed in the United States and other jurisdictions outside Canada.
As a result, such information may be subject to the laws, regulations, court orders, governmental requests, lawful access requirements, and disclosure obligations of jurisdictions other than the province or territory in which the information was originally collected.
AutoRevolution implements reasonable safeguards designed to protect information during such transfers and processing activities in accordance with applicable contractual obligations and legal requirements.
13.9 Data Residency
AutoRevolution's primary production infrastructure is hosted in the United States. However, information processed through the Services may be accessed, transferred, stored, backed up, maintained, monitored, or otherwise processed by authorized personnel and service providers located in other jurisdictions.
Unless expressly agreed in writing, AutoRevolution does not guarantee that information will be stored, processed, maintained, or accessed exclusively within any particular country, province, state, territory, or geographic region.
Customers with specific data residency, sovereignty, localization, regulatory, contractual, OEM, lender, governmental, or organizational requirements should contact AutoRevolution prior to using the Services to determine whether such requirements can be accommodated.
13.10 Responsibilities
AutoRevolution's primary production infrastructure is hosted in the United States. However, information processed through the Services may be accessed, transferred, stored, backed up, maintained, monitored, or otherwise processed by authorized personnel and service providers located in other jurisdictions.
Unless expressly agreed in writing, AutoRevolution does not guarantee that information will be stored, processed, maintained, or accessed exclusively within any particular country, province, state, territory, or geographic region.
Customers with specific data residency, sovereignty, localization, regulatory, contractual, OEM, lender, governmental, or organizational requirements should contact AutoRevolution prior to using the Services to determine whether such requirements can be accommodated.
13.11 DPA
Where required by applicable law, contract, or Customer request, AutoRevolution may enter into a Data Processing Addendum ("DPA") or similar agreement addressing cross-border transfers, subprocessors, security measures, confidentiality obligations, customer instructions, and related data protection requirements.
AutoRevolution reserves the right to modify its infrastructure, personnel locations, processing locations, subprocessors, service providers, and transfer mechanisms as business, legal, operational, security, or technical requirements evolve, subject to applicable contractual and legal obligations.
14. Privacy Rights
Depending on your relationship with AutoRevolution, your location, applicable law, and the context in which information is processed, you may have certain privacy rights regarding personal information.
Because AutoRevolution operates as both a controller and a service provider or processor, the method for exercising privacy rights may differ depending on the type of information involved.
14.1 Controller
AutoRevolution generally acts as a controller, business, or equivalent legal role when processing Company Data for its own business purposes, including customer relationship management, sales, marketing, billing, vendor management, website administration, analytics, security, legal compliance, and business operations.
For information processed in this capacity, individuals may submit privacy rights requests directly to AutoRevolution as described below.
14.2 Processor
AutoRevolution generally acts as a service provider, processor, contractor, or similar role when processing Customer Data, Authorized User Data, Consumer Data, vehicle inventory information, communications data, vehicle media, and other information on behalf of a Customer through the Services.
In these circumstances, the applicable Customer determines the purposes and means of processing and is responsible for responding to privacy rights requests relating to such information.
If AutoRevolution receives a request relating to information that it processes solely on behalf of a Customer, AutoRevolution may refer the request to the applicable Customer or assist the Customer in responding in accordance with applicable agreements and legal requirements.
14.3 Available Rights
Subject to applicable law, individuals may have one or more of the following rights:
- Right to Know or Access information about the personal information collected, used, disclosed, or processed;
- Right to Correction of inaccurate personal information;
- Right to Deletion of personal information, subject to legal, contractual, security, and operational exceptions;
- Right to Data Portability and to obtain a copy of certain personal information in a portable format where required by law;
- Right to Opt Out of Targeted Advertising where applicable;
- Right to Opt Out of Certain Profiling Activities where required by law;
- Right to Opt Out of the Sale or Sharing of Personal Information where such rights are provided by applicable law;
- Right to Restrict or Limit Certain Uses of Sensitive Personal Information where applicable;
- Right to Withdraw Consent where processing is based on consent;
- Right to Non-Discrimination for exercising privacy rights where protected by law; and
- Right to Appeal certain privacy-rights decisions where provided under applicable law.
Not all rights apply in all jurisdictions, and certain exceptions, limitations, and legal obligations may affect the availability of particular rights.
14.4 Exercise Rights
Individuals may submit privacy-related requests using the methods below:
- Web Form: a href="https://www.autodealerwebsites.com/opt-out-request-form" aria-label="Fill out our opt-out form"> Opt-Out Request Form.
- Email: compliance@autorevolution.com.
AutoRevolution may request additional information to verify identity, confirm authority to act on behalf of another individual, prevent fraud, maintain security, or comply with applicable legal requirements before responding to a request.
Authorized agents may submit requests where permitted by law, subject to verification and authorization requirements.
14.5 Appeals Process
Where required by applicable law, individuals whose privacy-rights requests have been denied may appeal the decision by contacting:
- Email: compliance@autorevolution.com.
Appeals should include sufficient information to identify the original request and explain the basis for the appeal.
14.6 State Rights
Residents of certain U.S. states may have privacy rights under applicable state privacy laws, including laws in California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Virginia, and other jurisdictions that may enact similar laws.
The availability, scope, and exercise of rights may vary by state and applicable law.
Where required by law, AutoRevolution will honor applicable rights requests and provide required disclosures regarding personal information collected, used, disclosed, retained, and processed.
14.7 California
For California residents, AutoRevolution provides the rights required under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), subject to applicable exemptions and limitations.
Depending on the circumstances, California residents may have rights relating to:
- Access to personal information;
- Correction of inaccurate personal information;
- Deletion of personal information;
- Knowledge regarding categories and uses of personal information;
- Opting out of certain sales or sharing activities;
- Limiting certain uses of sensitive personal information where applicable; and
- Freedom from unlawful discrimination for exercising privacy rights.
AutoRevolution does not sell personal information in exchange for monetary consideration.
14.8 Canadian Rights
Individuals located in Canada may have rights under applicable federal and provincial privacy laws, including rights relating to access, correction, transparency, accountability, and complaint processes.
Where AutoRevolution acts as a processor or service provider on behalf of a Customer, requests relating to Consumer Data or other Customer Data should generally be directed to the applicable Customer.
Where AutoRevolution acts as a controller with respect to Company Data, individuals may contact AutoRevolution directly regarding applicable privacy rights requests.
14.8 Profiling Rights
Certain jurisdictions provide rights relating to automated processing, profiling, artificial intelligence, or automated decision-making activities.
Where required by applicable law, individuals may have rights to request information regarding certain automated processing activities or to object to, opt out of, or appeal certain forms of profiling or automated decision-making.
Additional information regarding AutoRevolution's use of artificial intelligence and automated processing technologies is available in Section 11 of this Privacy Policy.
15. Specialized Legal
Certain information processed through the Services may be subject to specialized federal, state, provincial, industry-specific, or sector-specific legal requirements.
AutoRevolution's obligations and responsibilities may vary depending on whether AutoRevolution is acting as a controller, business, service provider, processor, contractor, vendor, or similar legal role.
15.1 Controller
When processing Company Data for its own business purposes, AutoRevolution is responsible for complying with legal obligations applicable to its role as a controller, business, or equivalent legal role under applicable law.
15.2 Processor
When processing Customer Data, Authorized User Data, Consumer Data, vehicle inventory information, communications data, vehicle media, or other information on behalf of a Customer, AutoRevolution generally acts as a service provider, processor, contractor, or similar role.
In these circumstances, Customers remain responsible for determining their legal obligations and compliance requirements, including any obligations arising under privacy, consumer protection, automotive, financial, employment, communications, surveillance, biometric, lending, advertising, or industry-specific laws.
15.3 Biometric Laws
AutoRevolution's Services are designed primarily for vehicle photography, inventory merchandising, dealership operations, communications, and related automotive workflows.
Vehicle photographs or videos may occasionally contain incidental images of individuals or other identifying information.
AutoRevolution does not intentionally collect biometric identifiers or biometric information through its standard vehicle photography and inventory merchandising workflows.
If Customers utilize the Services in a manner that may involve biometric identifiers, biometric information, facial geometry, voiceprints, fingerprints, retina scans, hand scans, or similar data regulated by applicable law, Customers remain responsible for determining whether applicable notice, consent, retention, destruction, or compliance obligations apply.
15.4 Communication Laws
Customers utilizing SMS, MMS, call tracking, voice, messaging, communications, or similar functionality are responsible for complying with applicable communications laws and regulations, including obtaining legally required notices, disclosures, authorizations, and consents.
AutoRevolution does not determine the content, recipients, timing, purpose, or lawful basis of Customer communications.
Customers remain responsible for compliance with applicable telemarketing, communications, consumer protection, carrier, registration, and messaging requirements applicable to their use of the Services.
19. Equality
AutoRevolution will not unlawfully discriminate against any individual for exercising privacy rights provided under applicable law.
Subject to applicable legal requirements and permitted exceptions, AutoRevolution will not:
- Deny goods or services because an individual exercises privacy rights;
- Charge different prices or rates solely because an individual exercises privacy rights;
- Provide a different level or quality of service solely because an individual exercises privacy rights; or
- Otherwise unlawfully penalize an individual for exercising applicable privacy rights.
Nothing in this Section restricts AutoRevolution from offering lawful programs, benefits, services, incentives, or contractual arrangements permitted by applicable law.
20. Security
AutoRevolution maintains an information security program designed to protect personal information and other data from unauthorized access, acquisition, disclosure, alteration, destruction, loss, misuse, or other unauthorized processing.
20.1 Distinction
Security responsibilities may vary depending on whether AutoRevolution is acting as a controller or as a service provider or processor on behalf of a Customer.
Customers remain responsible for maintaining appropriate security controls relating to their own systems, networks, devices, user accounts, passwords, permissions, business processes, and use of the Services.
20.2 Safeguards
AutoRevolution may implement safeguards including:
- Administrative security controls;
- Technical security controls;
- Physical security measures where applicable;
- Role-based access controls;
- Authentication and authorization controls;
- Encryption and secure transmission technologies where appropriate;
- Security monitoring and logging;
- Vendor and subprocessor oversight;
- Personnel training and awareness programs;
- Incident response procedures;
- Business continuity and disaster recovery processes; and
- Periodic review and improvement of security controls.
The specific safeguards implemented may vary based on the nature of the Services, operational requirements, evolving threats, technological developments, and legal requirements.
No method of transmission, storage, or processing can be guaranteed to be completely secure. Accordingly, AutoRevolution cannot guarantee absolute security of information processed through the Services.
21. Data Breach
AutoRevolution maintains policies and procedures designed to identify, investigate, contain, mitigate, document, and respond to suspected or confirmed security incidents.
21.1 Company Data
If AutoRevolution experiences a security incident involving Company Data for which AutoRevolution acts as a controller, AutoRevolution will provide notifications as required by applicable law.
21.2 Customer Data
When AutoRevolution acts as a service provider or processor and experiences a confirmed security incident involving Customer Data, AutoRevolution may notify the applicable Customer in accordance with applicable agreements, legal obligations, and incident response procedures.
The Customer remains responsible for determining whether notifications to consumers, employees, regulators, governmental authorities, lenders, manufacturers, OEMs, franchise organizations, or other third parties are required.
21.3 Incident Response
Where appropriate and consistent with applicable law, AutoRevolution may:
- Investigate the incident;
- Take steps to contain and remediate the incident;
- Assess the nature and scope of affected information;
- Cooperate with Customers, service providers, regulators, law enforcement, and other authorized parties;
- Implement corrective measures; and
- Provide notifications as required by law or contract.
Notification timing, content, recipients, and procedures may vary based on applicable law, contractual obligations, regulatory requirements, law enforcement requests, and the specific circumstances of the incident.
22. GLBA
Many automotive dealerships, finance providers, lenders, leasing companies, and related organizations are subject to the Gramm-Leach-Bliley Act ("strong>GLBA"), the FTC Safeguards Rule, and related financial privacy and information security requirements.
22.1 Controller
AutoRevolution is generally not a financial institution solely by virtue of providing software and technology services to automotive businesses.
22.2 Processor
When AutoRevolution processes Customer Data on behalf of dealerships, lenders, finance companies, leasing organizations, or other GLBA-regulated entities, AutoRevolution generally acts as a service provider or processor.
The applicable Customer remains responsible for determining:
- Whether information constitutes Nonpublic Personal Information ("NPI");
- Whether GLBA applies to its operations;
- Whether consumer privacy notices are required;
- Whether opt-out rights apply;
- Whether information-sharing restrictions apply; and
- Whether regulatory obligations have been satisfied.
22.3 Protection
To the extent AutoRevolution processes financial information, credit-related information, financing application information, or other information subject to financial privacy requirements, AutoRevolution implements reasonable safeguards designed to protect such information consistent with applicable agreements, legal requirements, and the nature of the Services provided.
AutoRevolution uses such information only as necessary to provide the Services, comply with legal obligations, maintain security, enforce agreements, or otherwise as permitted by applicable law and contractual obligations.
Additional contractual, regulatory, security, or privacy requirements may apply depending on the Customer's industry, business activities, and regulatory obligations.
23. Links
The Services may contain links to, connect with, integrate with, embed content from, or otherwise interact with websites, applications, platforms, products, services, technologies, or resources operated by third parties that are not owned or controlled by AutoRevolution.
Such third parties may include automotive marketplaces, inventory distribution networks, OEM-affiliated systems, dealership management systems (DMS), customer relationship management (CRM) platforms, finance and lending providers, payment processors, analytics providers, communications providers, artificial intelligence providers, mapping services, advertising platforms, social media platforms, technology vendors, business partners, and other external organizations.
23.1 Controller
When AutoRevolution provides links to third-party websites or utilizes third-party services in connection with its own business operations, websites, marketing activities, communications, events, or administrative functions, AutoRevolution may act as a controller, business, or equivalent legal role with respect to information it independently collects and processes.
Information shared directly with a third party remains subject to that third party's privacy practices, terms, policies, and legal obligations.
23.2 Processor
In such circumstances, the Customer determines whether and how information is shared with the third party. AutoRevolution acts solely in accordance with Customer instructions, applicable agreements, and legal requirements.
Customers are responsible for evaluating the privacy, security, compliance, contractual, regulatory, and operational suitability of third-party services they choose to utilize in connection with the Services.
23.2 Websites
The Services may include hyperlinks or references to external websites, resources, documentation, content, advertisements, products, services, or information maintained by third parties.
AutoRevolution does not control and is not responsible for:
- The privacy practices of third parties;
- The content, accuracy, availability, or security of third-party websites;
- The products or services offered by third parties;
- The collection, use, disclosure, retention, or processing of information by third parties;
- The terms, policies, or legal compliance of third parties; or
- Any damages, losses, claims, or liabilities arising from interactions with third parties.
Accessing third-party websites or services is done at your own discretion and subject to the applicable third party's terms and privacy practices.
23.3 Integrations
The Services may support integrations with third-party systems, software applications, APIs, cloud services, communications providers, inventory syndication platforms, OEM systems, DMS providers, CRM providers, analytics tools, artificial intelligence technologies, payment processors, and other connected services.
When a Customer authorizes an integration or connection, information may be exchanged between the Services and the applicable third-party system as necessary to provide the requested functionality.
AutoRevolution does not control how third parties use information once it has been disclosed to or received by those third parties pursuant to Customer instructions, Customer configurations, or Customer-authorized integrations.
23.4 Authentication
The Services may permit authentication through third-party identity providers, single sign-on providers, or federated authentication services.
If a user chooses to authenticate through a third-party provider, AutoRevolution may receive certain account, profile, authentication, or identity-related information from that provider as authorized by the user, the Customer, or the provider's settings.
The collection and processing of information by such providers remain subject to the provider's own privacy practices and terms.
23.5 Responsibility
Customers are responsible for:
- Reviewing the privacy and security practices of third-party providers;
- Determining whether third-party services satisfy applicable legal and regulatory requirements;
- Obtaining any notices, disclosures, permissions, authorizations, or consents required for third-party integrations;
- Managing and approving integration settings and permissions;
- Evaluating risks associated with third-party services; and
- Ensuring compliance with contractual, OEM, lender, franchise, manufacturer, governmental, or other obligations applicable to their business.
23.6 No Endorsement
References to third-party products, services, websites, organizations, platforms, technologies, integrations, or resources do not constitute an endorsement, sponsorship, partnership, certification, recommendation, or guarantee by AutoRevolution unless expressly stated otherwise in writing.
AutoRevolution makes no representations or warranties regarding the availability, security, legality, performance, suitability, or compliance of third-party services.
24. COPPA Notice
AutoRevolution's Services are designed and intended exclusively for use by licensed automotive dealerships, dealer groups, auctions, fleet operators, resellers, OEM-affiliated entities, and other authorized business customers.
The Services are not directed to children, are not intended for personal, family, or household use, and are not designed to attract individuals under the age of 13.
AutoRevolution does not knowingly collect, use, sell, share, or disclose personal information from children under 13 years of age for its own business purposes.
24.1 Requirements
The Children's Online Privacy Protection Act ("COPPA") imposes certain requirements on operators of websites and online services directed to children under 13 years of age and on operators with actual knowledge that they are collecting personal information from children under 13.
AutoRevolution's websites, applications, platforms, products, and Services are intended solely for business users operating within the automotive industry and are not directed to children under 13.
Accordingly, AutoRevolution does not knowingly collect personal information from children under 13 through its own websites, applications, marketing activities, or business operations.
24.2 Controller
When AutoRevolution acts as a controller, business, or equivalent legal role with respect to Company Data, AutoRevolution does not knowingly solicit, collect, maintain, or process personal information from children under 13 years of age.
If AutoRevolution becomes aware that it has collected personal information from a child under 13 in a manner inconsistent with applicable law, AutoRevolution will take commercially reasonable steps to investigate and address the matter, including deletion or other appropriate remediation where required.
24.3 Processor
When AutoRevolution processes Customer Data, Authorized User Data, Consumer Data, communications data, website submissions, lead information, CRM records, or other information on behalf of a Customer, AutoRevolution generally acts as a service provider, processor, contractor, or similar role.
In these circumstances, the Customer controls the collection and use of such information and is responsible for determining whether applicable notice, consent, parental authorization, age-verification, or other legal obligations apply.
AutoRevolution does not independently review all Customer-submitted information to determine the age of individuals whose information may be contained within Customer Data.
24.4 Information
Customers may collect information through dealership websites, lead forms, contact forms, chat systems, CRM systems, inventory platforms, communications tools, SMS functionality, integrations, or other dealership workflows.
Customers are solely responsible for ensuring that their collection and use of information complies with applicable laws, including any laws relating to minors, children, parental consent, education records, youth privacy, advertising, marketing, or communications.
AutoRevolution does not determine the categories of individuals targeted by Customer websites, advertising campaigns, lead generation activities, or communications workflows.
24.5 Discovery
If AutoRevolution becomes aware that personal information relating to a child under 13 has been collected or processed in a manner that requires action under applicable law, AutoRevolution may take appropriate steps, including:
- Investigating the circumstances;
- Restricting access to the information;
- Notifying the applicable Customer where appropriate;
- Requesting corrective action;
- Deleting information where legally required and operationally feasible; or
- Taking other actions reasonably necessary to comply with applicable law.
AutoRevolution reserves the right to retain information where necessary to comply with legal obligations, resolve disputes, investigate incidents, enforce agreements, establish legal claims, maintain security, or otherwise as permitted or required by law.
24.6 Parents
If a parent, legal guardian, or authorized representative believes that a child under 13 has provided personal information directly to AutoRevolution in connection with Company-controlled activities, they may contact AutoRevolution using the contact information provided in this Privacy Policy.
AutoRevolution may request information reasonably necessary to verify the identity and authority of the requesting individual before responding to the request.
24.7 Minors
AutoRevolution's Services are intended for business users who are at least 18 years of age or the age of majority in the applicable jurisdiction.
AutoRevolution does not knowingly create consumer accounts for minors, market its Services to minors, or intentionally design the Services for use by individuals under 18 years of age.
Customers remain responsible for determining whether any age-related restrictions, notices, disclosures, or consent requirements apply to their use of the Services.
25. Policy Changes
AutoRevolution may revise, update, modify, supplement, or replace this Privacy Policy from time to time to reflect changes in our business practices, Services, products, technologies, legal obligations, regulatory requirements, security practices, industry standards, operational needs, or other developments.
We encourage individuals, Customers, Authorized Users, and other users of the Services to review this Privacy Policy periodically to remain informed about our privacy and data handling practices.
25.1 Controller
When AutoRevolution processes Company Data for its own business purposes, AutoRevolution may update this Privacy Policy to reflect changes in how Company Data is collected, used, disclosed, retained, secured, transferred, or otherwise processed.
Such updates may apply to information relating to website visitors, prospective customers, business contacts, Authorized Users, event attendees, marketing recipients, vendors, contractors, and other individuals whose information is processed directly by AutoRevolution.
25.2 Processor
When AutoRevolution processes Customer Data, Authorized User Data, Consumer Data, vehicle inventory information, communications data, media assets, or other information on behalf of a Customer, the applicable Customer generally determines the purposes and means of processing such information.
Changes to this Privacy Policy do not modify the Customer's independent privacy obligations, notices, legal responsibilities, or contractual commitments to consumers, employees, applicants, vendors, or other individuals whose information is processed through the Services.
Customers remain responsible for maintaining their own privacy notices, disclosures, consents, and compliance programs as required by applicable law.
25.3 Notice
When changes are made to this Privacy Policy, AutoRevolution may:
- Update the "Last Updated" date appearing at the top of the Privacy Policy;
- Publish the revised Privacy Policy on the applicable website or Service;
- Provide notice through the Services;
- Notify Customers through account communications;
- Provide contractual notices where required; or
- Use other reasonable methods of communication consistent with applicable law and contractual obligations.
The method, timing, and form of notice may vary depending on the nature of the changes, applicable legal requirements, contractual obligations, and the Services involved.
25.4 Material
If AutoRevolution makes material changes to this Privacy Policy, we may provide additional notice where required by applicable law, contractual obligations, or our internal policies.
Examples of material changes may include significant modifications relating to:
- Categories of personal information processed;
- Purposes for processing personal information;
- Disclosure practices;
- Privacy rights;
- International data transfers;
- Security practices;
- Artificial intelligence and automated processing activities;
- Legal or regulatory compliance obligations; or
- Other significant privacy-related matters.
25.5 Regulatory
Privacy, data protection, artificial intelligence, consumer protection, cybersecurity, communications, and industry-specific laws continue to evolve. AutoRevolution reserves the right to update this Privacy Policy as necessary to address changes in applicable laws, regulations, regulatory guidance, enforcement actions, industry standards, court decisions, governmental requirements, and emerging technologies.
25.6 DPA
Nothing in this Privacy Policy modifies, supersedes, or replaces any separate agreement, subscription agreement, master services agreement, data processing addendum ("DPA"), information security addendum, confidentiality agreement, or other contract between AutoRevolution and a Customer.
In the event of a conflict between this Privacy Policy and a written agreement governing Customer Data, the applicable agreement may control to the extent permitted by law and the terms of such agreement.
25.7 Continued Use
To the extent permitted by applicable law, continued access to or use of the Services following the effective date of an updated Privacy Policy may constitute acknowledgment of the revised Privacy Policy.
Where applicable law requires consent for specific processing activities, AutoRevolution will obtain such consent in accordance with applicable legal requirements.
26. Contact
If you have questions about this Privacy Policy, our privacy practices, data protection practices, information security program, privacy rights, or how personal information is processed through the Services, please contact AutoRevolution using the information below.
26.1 Controller
AutoRevolution may be contacted directly regarding Company Data and other personal information that AutoRevolution processes for its own business purposes, including information relating to:
- Website visitors;
- Prospective customers;
- Business contacts;
- Authorized Users;
- Marketing communications;
- Events and webinars;
- Vendor and partner relationships;
- Billing and account administration; and
- Other information for which AutoRevolution determines the purposes and means of processing.
Privacy rights requests, questions, complaints, and inquiries relating to such information may be submitted directly to AutoRevolution.
26.2 Processor
AutoRevolution generally acts as a service provider, processor, contractor, or similar role when processing Customer Data, Authorized User Data, Consumer Data, vehicle inventory information, communications data, vehicle media, CRM information, lead information, messaging records, and other information processed through the Services on behalf of a Customer.
In these circumstances, the applicable Customer controls the purposes and means of processing and is generally responsible for responding to privacy rights requests relating to such information.
If you are a consumer, customer, prospect, employee, contractor, or other individual whose information was collected by or on behalf of an automotive dealership, dealer group, auction, fleet operator, reseller, OEM-affiliated entity, or other AutoRevolution Customer, you should generally direct your request to the applicable Customer.
Where appropriate and permitted by applicable law, AutoRevolution may assist Customers in responding to privacy requests in accordance with applicable agreements and legal obligations.
26.3 Contact Info
Privacy inquiries, compliance requests, rights requests, complaints, appeals, and data protection questions may be submitted using the contact information below:
Metzger Enterprises LLC d/b/a AutoRevolution
334 East Church Street
Lewisville, Texas 75057
United States
- Phone: 972-243-8460
- Email: compliance@autorevolution.com
26.4 Requests
Individuals seeking to exercise privacy rights under applicable law may submit requests using the contact information identified in this Privacy Policy or through any privacy request mechanism made available by AutoRevolution.
AutoRevolution may request information reasonably necessary to:
- Verify identity;
- Verify authority to act on behalf of another individual;
- Locate relevant records;
- Prevent fraud or misuse;
- Protect information security; and
- Comply with applicable legal requirements.
Authorized agents may submit requests where permitted by applicable law, subject to applicable verification and authorization requirements.
26.5 Reporting
Customers, Authorized Users, security researchers, vendors, and other parties who believe they have identified a security issue, vulnerability, unauthorized access event, privacy concern, or potential security incident involving the Services may contact AutoRevolution using the contact information provided above.
Submission of a report does not create any contractual obligation, admission of liability, or obligation to disclose information beyond what is required by applicable law or contractual commitments.
26.6 Inquiries
Customers, Authorized Users, security researchers, vendors, and other parties who believe they have identified a security issue, vulnerability, unauthorized access event, privacy concern, or potential security incident involving the Services may contact AutoRevolution using the contact information provided above.
Submission of a report does not create any contractual obligation, admission of liability, or obligation to disclose information beyond what is required by applicable law or contractual commitments.
26.7 Timing
Response times may vary depending on the nature of the request, verification requirements, applicable law, contractual obligations, complexity of the request, volume of requests received, and whether AutoRevolution is acting as a controller or a service provider/processor with respect to the information involved.
Where required by applicable law, AutoRevolution will respond within legally required timeframes.
Rev up your sales - Top tips for car dealerships
Blog
SEP 24, 2024
How Dealership Statistics Can Transform Your Sales Strategy
AUG 26, 2024
Drive More Sales to Your Car Dealership with Digital Marketing
Get started now!
Simplify your process with our enhanced dealer solutions
Call 888-263-5580 or complete the form below: