Privacy Policy

How Dealr collects and uses personal information.

Effective October 1, 2026

This Privacy Policy explains how Dealr, Inc. (“Dealr,” “we”) handles personal information on our websites (dealr.com, dealr.cloud, dealertitlesolutions.com, dealr.tax), in our sales and marketing, and in our customer accounts. Dealer Title Solutions is a Dealr, Inc. brand, not a separate company.

Two roles. Read this first.

  • Our own data (we decide how it’s used): this policy applies. It covers information about website visitors, prospects, and the people at our business customers (account, billing, support, and marketing data).

  • Our customers’ platform data (the customer decides): this policy does not apply, except as noted below.

    • Our customers (vehicle dealerships, service centers, and other businesses) use our products to run their operations. The deal, consumer, title, and financing records inside a customer’s account belong to and are controlled by that customer.

    • We process that data as the customer’s service provider under our Data Processing Addendum (our data-handling contract with the customer).

    • If you are a consumer doing business with one of our customers, that business’s own privacy policy primarily governs this platform data. The exception is the Consumer transaction surfaces section below (Section 8), which covers what Dealr itself collects and processes on the consumer-facing pages it operates. Our Consumer Privacy Notice is the surface-level notice for the Dealr-hosted pages you may interact with (payment portals, e-signature, credit applications).

    • Separately, Dealr also processes certain platform data for its own legal, regulatory, and state-contract obligations. Examples are e-signature audit logs, fraud-prevention and security records, and records Dealr must keep under its government-program and state-contract commitments. That Dealr-controlled processing is described in the Consumer transaction surfaces section below and in our Consumer Privacy Notice.

1. Information we collect

You provide it: name, business contact details, business affiliation and role, account credentials, records of apps you connect to your account, billing information, support requests, chat messages, event registrations, and content of calls and meetings with us (see Section 4).

Collected automatically: device and usage data on our sites and marketing pages (IP address, identifiers, pages viewed, referral source) via cookies and similar technologies (Section 5), including analytics and session-replay tools.

From other sources: business-contact data from data providers and lead-list vendors, from marketing partners and events, and from public sources. Our current vendors provide business contact information about our customers’ owners and personnel; we do not purchase information about their retail customers. If we adopt additional enrichment providers, this policy and our cookie disclosures will be updated.

2. How we use it

We use personal information:

(a) to provide and secure our products and websites;

(b) to create and manage accounts, billing, and support;

(c) to communicate about products, updates, and marketing (with opt-out);

(d) to run and measure advertising;

(e) to improve our products and train our teams (Section 4);

(f) to create aggregated or de-identified statistics (e.g., industry benchmarks such as average days-to-sale) that do not identify any customer or person, and to use those statistics in our products and services (including paid features and offerings), share them, or publish them;

(i) Any such statistics we publish or share are provided only in aggregated, de-identified form.

(ii) Where such statistics are derived from customer platform data, we create and use them only as permitted by our customer agreements and Data Processing Addendum, from data that has been aggregated or de-identified before any such use;

(g) to comply with law and our government-program obligations; and

(h) to protect rights, safety, and security.

We maintain and use de-identified information only in de-identified form and do not attempt to re-identify it, except as permitted by law to test that our de-identification is effective.

3. How we share it — and what we don’t do

We do not sell personal information for money. Like many companies, we use advertising cookies and pixels, and we upload contact lists to advertising platforms, which may be considered a “sale” or “sharing” of personal information under some state privacy laws (Cal. Civ. Code §1798.140(ad), (ah)). To opt out, email privacy@dealr.cloud with “Do Not Sell or Share” in the subject line. We will remove you from our advertising-list uploads and, where we can identify you, stop sharing your information with advertising platforms. You can also limit advertising cookies with the browser and platform controls described in Section 5. We do not knowingly sell or share the personal information of consumers under 16.

We share personal information only with:

(a) service providers working for us, under contracts limiting their use. These are hosting, analytics, CRM/marketing, support, payments, communications, document processing and e-signature, address validation, and fraud prevention/security providers;

(b) third parties you or your business direct us to send data to in using our products. Examples are transmitting a credit application to a lender the customer selects and AI applications a user connects to their account. These transfers happen at the customer’s direction, to serve the customer’s needs, and the recipient’s own privacy policy applies;

(c) government authorities and program partners where our title/registration services or law require it;

(d) parties to a corporate transaction (merger, financing, acquisition) under confidentiality;

(e) professional advisors;

(f) advertising platforms (such as Meta and Google). They receive data from the advertising cookies and pixels on our websites (Section 5). For our own marketing, we also upload contact details from our marketing lists (such as email address or phone number, which the platform matches in hashed form) so we can show ads to, or measure ads for, people who already have a relationship with us or resemble them. This may be a “sale” or “sharing” of personal information under some state privacy laws. You can opt out by emailing privacy@dealr.cloud, and we will remove you from future uploads;

(g) others when you direct or consent to the disclosure; and

(h) other parties as needed to enforce our agreements, collect amounts owed, or protect the rights, safety, and security of Dealr, our customers, or others.

We may also use, share, or publish the aggregated, de-identified statistics described in Section 2(f); sharing information in that form is not a sale or sharing of personal information under state privacy laws.

4. Calls, meetings, and recordings

We record and analyze our own sales, support, demo, and training calls and meetings, with disclosure, for quality, training, and service improvement. We provide notice at or before the start of any recorded call or meeting. By remaining on a call or meeting after notice of recording, you consent to the recording and to our analysis of it for these purposes. If you prefer not to be recorded, tell the host at or before the start and we will not record you, or you may disconnect.

5. Cookies and analytics

Our sites use cookies and similar technologies, including pixels, tags, software development kits (SDKs), and browser storage such as localStorage. They fall into these categories:

  • essential: login, security, and anti-abuse tools, plus payment-page and feature-configuration technologies. The anti-abuse tools include CAPTCHA and the device-recognition checks that protect account sign-in;

  • analytics: site and session analytics, including session replay, on dealr.cloud, dealertitlesolutions.com, and dealr.tax;

  • marketing and CRM: form handling and page tracking for our own sales and marketing;

  • support chat: live-chat and messaging widgets;

  • advertising: ad-campaign pixels;

  • call tracking: dynamic phone-number insertion, on dealr.tax; and

  • scheduling: embedded appointment booking.

The specific vendors and technologies in each category are listed in our Cookie & Tracking Technology Notice. That notice shows the data each technology receives and its retention. We update it when our tools change (see its effective date). These technologies currently load when you visit our sites; we do not currently offer a cookie consent banner. You can block or delete cookies through your browser settings or use private browsing, though some site functions may stop working. You can also limit ad personalization through the advertising platforms’ own controls, such as Google’s My Ad Center and Meta’s Ad Preferences.

Our advertising pixels may involve a “sale” or “sharing” of personal information as some state privacy laws define those terms (Section 3). You can opt out as described in Section 3. Our websites do not currently respond to Global Privacy Control (GPC) or other browser “Do Not Track” signals.

6. Your privacy rights

Depending on your state, you may have rights:

  • to access, correct, delete, or obtain a copy of your personal information;

  • to opt out of targeted advertising, sale, or profiling; and

  • in some states (including Oregon, Minnesota, Delaware, and Connecticut), to obtain a list of the specific third parties to which we have disclosed personal data.

How to submit a request. Submit requests by email to privacy@dealr.cloud or by phone at 720-772-7706. We will verify your identity and respond within 45 days, extendable once by an additional 45 days where reasonably necessary (we will notify you of any extension). Authorized agents may submit requests on your behalf where your state permits.

Appeals. If we deny your request, you may appeal by replying to our decision or by emailing privacy@dealr.cloud with “Appeal” in the subject line. We will respond to your appeal within the period your state’s law requires (in most states, 45–60 days). If we deny your appeal, we will provide you with a method to contact your state Attorney General regarding the result.

We do not discriminate against you for exercising your rights. If your request concerns one of our customers’ records about you as a consumer (for example, a dealership you bought a vehicle from), we will tell you which business was involved and how to reach it. Our contracts with these businesses require us to forward your request to the business involved, as our Data Processing Addendum provides.

7. Retention and security

We keep personal information as long as needed for the purposes above, then delete or de-identify it. Generally that is the life of the account relationship plus applicable legal retention periods. Records of your interactions with AI features (such as chat history with AI assistants) are kept for up to six months on a rolling basis; when an account is deleted, any remaining records are deleted within 90 days at the latest. If you connect an AI application to your Dealr account, we keep records of the connection and of the requests it makes (not the content of your conversations with that application) for up to 90 days, for security, abuse prevention, and support. We maintain a written security program audited annually under SOC 2 Type II; see our Security Summary.

8. Consumer transaction surfaces

This section describes the personal information Dealr itself collects and processes on the consumer-facing pages it operates for its business customers — payment portals, electronic-signature (e-sign) ceremonies, credit applications, and the related deal paperwork. On these pages Dealr acts primarily as the service provider of the business you are transacting with (for example, a dealership), processing this information on that business’s behalf and at its direction. That business (and, for financing, the lender) is the controller or business responsible for it. Our separate Consumer Privacy Notice is the surface-level notice presented on these pages and serves as the notice at collection for consumers who use them. The categories, purposes, retention criteria, and sold/shared statements below mirror that notice.

What Dealr collectsWhy we collect itHow long we keep itDo we sell or share it?
Contact and identity details — name, address, email, phone number, date of birthTo identify the consumer, prepare the transaction paperwork, and communicate about the transactionFor as long as the transaction record must be kept under the business’s and our legal retention obligations (title and registration records carry multi-year retention laws), then deletedNo
Sensitive personal information — Social Security number; driver’s license or state ID number; citizenship status; bank account or payment card detailsOnly for the credit applications submitted, the payments authorized, and the title/registration filings that legally require themKept with the transaction records they belong to, under the same legal retention criteria. Payment card details are processed by our secure payment providersNo
Financial, employment, and residence information — employer, position, and time on the job (current and previous); gross income and other income sources; housing type, monthly housing payment, and landlord or mortgage company; current and previous addresses and time at each; marital status; number of dependents; names and contact details of listed referencesTo complete the credit applications the consumer submits and send them to the lenders the business chooses, and to prepare the deal paperworkSame retention criteria as the transaction recordsNo
Vehicle and deal information — VIN, price, trade-in, financing termsTo prepare, sign, and file the deal documents and the government filings the transaction requires. We also create de-identified, aggregated statistics (such as average days-to-sale) that do not identify any consumer or transactionSame retention criteria as the transaction recordsNo
Page-use records — session replay and product analytics of how consumers use these pages (clicks, scrolling, page views). Typed text is masked, and Social Security number, driver’s license or state ID number, bank account and payment card details, income, and citizenship status are excluded entirelyTo find and fix problems and improve these pages3 monthsNo
Documents, signature records, and device data — documents uploaded or signed (such as proof of income, residence, identity, or insurance); the e-sign audit data that makes electronic signatures valid (time, IP address, consent); and the device and connection data used to keep these pages secureTo make electronic signatures legally valid, to keep the records the law requires, to secure these pages against fraud and abuse, and to improve the accuracy of the document-reading tools used in these services (see below)For as long as the signed documents must remain verifiable under applicable law, then deleted; security records are kept only as long as needed for fraud prevention; document copies used to improve the document-reading tools are kept only while needed for that purposeNo

We do not sell this personal information and do not share it for cross-context behavioral advertising, as those terms are defined by California law. This is true for every category above. As the table notes, we also use copies of transaction documents to teach the document-reading tools that recognize document types and read fields in these services; those copies can include the personal details shown on the documents, are used only to make the document tools accurate, are kept only while needed for that purpose, and are never used for advertising, never sold, and never shared for others’ use. This use is disclosed to, and governed by our contracts with, the businesses whose transactions these pages serve. As noted in the table, we also create the de-identified, aggregated statistics described in Section 2(f), only in that de-identified form; they cannot be used to identify you or to target advertising to you. Requests about a business’s records concerning a consumer should go to that business. For the limited records Dealr keeps for its own legal and security purposes (such as e-signature audit logs and fraud-prevention records), requests may be sent to us directly. The Consumer Privacy Notice explains all of this at the surface level.

9. Miscellaneous

Our services are for U.S. businesses, and we host them in the United States. Some of our service providers process data in other countries. Our websites are not directed to children under 13 and we do not knowingly collect their data. Financial-privacy note: some information we handle for our customers in connection with vehicle financing is subject to the federal Gramm-Leach-Bliley Act (GLBA). Many state privacy laws exempt personal information collected, processed, or disclosed subject to the GLBA. Where such a data-level exemption applies, GLBA’s protections govern that information instead of the state-law rights described in Section 6. These exemptions vary by state and do not limit your rights in personal information that is not subject to GLBA.

10. Changes and contact

We will post changes here with a new effective date and, for material changes, give notice on the site or by email. Contact: privacy@dealr.cloud · Dealr, Inc., 1050 Eagle Dr., Loveland, CO 80537.