All policies

Cookie & Tracking Technology Notice

What cookies and similar tools Dealr uses, and why.

Effective October 1, 2026

How this page works. This notice is the current-tool inventory referenced in Section 5 (cookies and analytics) of the Dealr Privacy Policy. It supplements that policy; it does not replace it. It describes the principal cookies, pixels, tags, software development kits (SDKs), browser-storage technologies, and similar technologies we use. It covers three kinds of surface: Dealr’s public websites (dealr.com, dealr.cloud, dealertitlesolutions.com, dealr.tax); the authenticated Dealr, Dealer Title Solutions, and dealr.tax applications; and the Dealr-hosted consumer transaction surfaces described in our Consumer Privacy Notice. See Your choices below for how to limit the non-essential technologies.

Categories we use

  • Essential — required to operate the sites and applications: sign-in and session cookies; security and anti-abuse tools; payment-page technologies; and feature-configuration services. Security and anti-abuse tools include CAPTCHA challenges and device-recognition checks used to protect account sign-in against fraud and unauthorized access. These run without consent because the service cannot function securely without them.

  • Analytics — how the sites and applications are used, including session replay.

  • Marketing & CRM — form handling, page tracking, and contact management for Dealr’s own sales and marketing.

  • Advertising — ad-campaign pixels. These may involve a “sale” or “sharing” of personal information under some state privacy laws, as described in Section 3 (how we share it) of our Privacy Policy. To opt out, email privacy@dealr.cloud (see Section 3 of our Privacy Policy) or use the browser and platform controls under Your choices below.

  • Call tracking — dynamic phone-number insertion to measure which page a call came from.

  • Support chat — live-chat and messaging widgets.

  • Scheduling — embedded appointment booking.

Technology inventory — public marketing sites

Google Analytics 4 · third-party tag + cookies
Purpose: Site usage analytics (Analytics)
Data received: Device/usage data, IP, identifiers
Retention: Per Google’s data-retention settings
Where it runs: All four sites
Your choices: Loads on page visit; block via browser settings

Google Tag Manager · third-party tag container
Purpose: Loads and controls other tags (varies by tag)
Data received: Per contained tag
Retention: None (container only)
Where it runs: All four sites
Your choices: Container only; loads the tags listed on this page

Meta Pixel · third-party pixel
Purpose: Ad measurement (Advertising)
Data received: Page events, matching identifiers. May be a “sale” or “sharing” under some state privacy laws
Retention: Per Meta’s cookie policy
Where it runs: All four sites
Your choices: Loads on page visit; limit via browser settings or Meta’s Ad Preferences

FullStory · third-party SDK + browser storage
Purpose: Session replay and product analytics (Analytics)
Data received: Session interactions, with typed text and personal information masked
Retention: Recordings kept for 3 months
Where it runs: dealr.cloud; dealertitlesolutions.com; dealr.tax public pages (see the applications section for the dealr.tax application)
Your choices: Loads on page visit; block via browser settings

HubSpot tracking + forms · third-party cookies + SDK
Purpose: Form handling, page tracking, CRM for Dealr’s own marketing (Marketing & CRM)
Data received: Form submissions (contact, business name, role, phone, state, message, attribution), page activity
Retention: Per HubSpot’s cookie policy
Where it runs: dealr.com, dealr.cloud, dealertitlesolutions.com
Your choices: Loads on page visit; block via browser settings

Intercom messenger · third-party SDK + cookies
Purpose: Support/sales chat widget (Support chat)
Data received: Chat content, visitor identifiers
Retention: Session and device cookies per Intercom’s cookie policy; visitor records auto-deleted after 9 months of inactivity
Where it runs: Public sites that show the chat widget
Your choices: Loads on page load (not consent-gated). Chats are handled by our support platform and may be recorded. A notice to that effect appears in the Messenger itself. You can decline to use the chat; it sets no advertising cookies.

Google reCAPTCHA · third-party SDK
Purpose: Anti-abuse / bot protection on forms (Essential — security)
Data received: Device and interaction signals
Retention: Per Google
Where it runs: dealr.cloud, dealr.tax, form pages
Your choices: Essential — runs without consent (see the Essential category above)

CallRail dynamic number insertion · third-party SDK + cookies
Purpose: Call attribution to page/campaign (Call tracking)
Data received: Number displayed, session source, call metadata
Retention: Per CallRail’s cookie policy
Where it runs: dealr.tax
Your choices: Loads on page visit; block via browser settings

Calendly embed · third-party iframe + cookies
Purpose: Demo/appointment scheduling (Scheduling)
Data received: Booking details entered by the visitor
Retention: Per Calendly
Where it runs: dealertitlesolutions.com /get-started
Your choices: Loads when the scheduling page is opened

Google Fonts · third-party font loading
Purpose: Typeface delivery (Essential)
Data received: IP address of font request
Retention: Not stored by Dealr
Where it runs: All four sites
Your choices: Essential

Technology inventory — authenticated applications (dealr.cloud / DTS / dealr.tax)

Intercom · third-party SDK
Purpose: In-app support chat (Support chat). Intercom processes data on Dealr’s behalf and appears on our published subprocessor list
Data received and retention: User identity, support conversations. Retention: cookies per Intercom’s cookie policy; visitor records auto-deleted after 9 months of inactivity.
Consent basis: Governed by your business’s agreement with Dealr and the terms you accept at sign-in, not by a cookie consent choice

Intercom — dealr.cloud and DTS login pages · third-party SDK; loads pre-authentication
Purpose: Support widget presented on the login shells before sign-in, in an anonymous visitor context (Support chat — support/functional)
Data received and retention: Anonymous visitor identifiers and any chat content the visitor enters; same Intercom retention as the row above
Consent basis: Disclosed here rather than consent-gated. The widget stays on the login pages, and this row is the disclosure.

FullStory — in-app · third-party SDK
Purpose: In-app session replay (Analytics)
Data received and retention: Session interactions — typed text masked; consumer sensitive fields excluded — see the consumer-surfaces section below; recordings kept for 3 months
Consent basis: Governed by your business’s agreement with Dealr and the terms you accept at sign-in, not by a cookie consent choice

FullStory — dealr.tax application
Purpose: Session replay (Analytics)
Data received and retention: Session interactions on the tax application, with typed text and personal information masked; recordings kept for 3 months
Consent basis: Governed by your business’s agreement with Dealr and the terms you accept at sign-in, not by a cookie consent choice

Device-recognition check · first-party browser script — an open-source library; no data is sent to the library’s vendor
Purpose: Sign-in security: checks whether a sign-in attempt comes from a device we recognize (Essential — security)
Data received and retention: Device characteristics evaluated in the browser for the recognition check
Consent basis: Essential — runs without consent (see the Essential category above)

LaunchDarkly · third-party server/client SDK
Purpose: Feature-flag configuration (Essential — configuration)
Data received and retention: Flag-evaluation context — end-user email on dealr.cloud; end-user full name and company name on dealr.tax rate lookups
Consent basis: Essential

New Relic browser monitoring · third-party SDK; dealr.cloud application
Purpose: Page-load and front-end performance monitoring (Essential — diagnostics). Session Replay is not enabled
Data received and retention: Page-load timing, browser and device type, page URLs, and front-end errors; retention per New Relic’s data retention settings
Consent basis: Essential — runs without consent (diagnostics required to operate the service)

Sentry error tracking · third-party SDK; client-side on the dealr.tax application
Purpose: Application error and diagnostic reporting (Essential — diagnostics)
Data received and retention: Application error and diagnostic reports; pipelines are configured to filter and minimize personal data
Consent basis: Essential — runs without consent (diagnostics required to operate the service)

Technology inventory — Dealr-hosted consumer transaction surfaces

On these surfaces (payment portal, e-sign ceremonies, credit applications, digital deals), we use FullStory session replay and product analytics to find and fix problems and improve the pages. Recording is configured so that the text you type is masked, and sensitive fields — Social Security number, driver’s license or state ID number, bank account and payment card details, income, and citizenship status — are excluded entirely and never sent to FullStory. Card numbers are entered in the payment provider’s secure fields, which session replay cannot record. Recordings are kept for 3 months. Session replay on these surfaces does not depend on a cookie consent choice. We also use product analytics on these surfaces to understand how the pages are used (for example, page views and where people stop). Our analytics tools receive page-use data only — never the contents of form fields — and are configured so the provider cannot use it for its own advertising. We do not use advertising pixels or tags on these surfaces, and we do not use information from these pages to advertise to you. The technologies that operate on these surfaces are:

Payment-provider hosted fields · third-party cross-origin iframes + SDK, incl. Apple Pay / Google Pay
Purpose: Card entry and tokenization on the consumer payment portal — card numbers are entered directly into the payment provider’s fields and never reach Dealr’s servers (Essential — payment)
Data received: Card number and CVV (tokenized by the provider). Apple Pay and Google Pay payment tokens may pass through Dealr’s systems on their way to the payment provider for processing

E-signature provider embeds · third-party iframes during signing ceremonies
Purpose: Document execution within e-sign ceremonies (Essential — legal record)
Data received: Signature events and session data within the provider’s embed, per the e-signature providers on our published subprocessor list

FullStory · third-party SDK
Purpose: Session replay and product analytics (Analytics)
Data received: Page interactions, with typed text masked and the sensitive fields listed above excluded; recordings kept for 3 months

Google reCAPTCHA · third-party SDK
Purpose: Anti-abuse on consumer finance forms (Essential — security)
Data received: Device and interaction signals

E-sign audit capture · first-party
Purpose: Signature-validity records (time, IP, consent) — see E-Sign Consent and Consumer Privacy Notice (Essential — legal record)
Data received: Time, IP address, consent events

Saved-form browser storage — finance applications · first-party localStorage
Purpose: Optional, visitor-initiated saving of an in-progress finance application on the visitor’s own device — nothing is saved unless the visitor chooses to save; the saved copy is cleared automatically on submission or expiry (Essential — form continuity)
Data received: Finance-application form fields other than Social Security numbers

Your choices

Our websites do not currently display a cookie consent banner; the technologies listed above load when you visit, except the essential ones, which always run. You can block or delete cookies through your browser settings or use private browsing, though some site functions may stop working. You can also limit ad personalization through the advertising platforms’ own controls, such as Google’s My Ad Center and Meta’s Ad Preferences. To opt out of sales or sharing, email privacy@dealr.cloud with “Do Not Sell or Share” in the subject line (see Section 3 of our Privacy Policy). Our websites do not currently respond to Global Privacy Control (GPC) or other browser “Do Not Track” signals.

Customer websites

Businesses that use Dealr’s website products operate their own sites and are responsible for their own legal compliance, including cookie/tracking-consent requirements, as their agreements with Dealr provide. Dealr will identify Dealr-deployed scripts or pixels on request and offers consent-management tooling as a feature. Deploying and configuring that tooling is that business’s responsibility. This notice does not cover customer-operated sites.