Privacy Policy
Last updated: October 3, 2026
DealerGuard ("we", "us") provides a cybersecurity risk-assessment platform for automotive dealerships. This policy explains what we collect, why, and the choices you have.
Information we collect
- Account information: dealership name, owner / security manager name, email address and password. Passwords are hashed by our authentication provider and are never visible to us.
- Business information: number of employees and locations, and the systems you use (email provider, CRM, DMS).
- Assessment responses: your answers to our questionnaire, and the Security Score and risk list calculated from them. We ask whether you store sensitive data (e.g. SSNs) — never for the data itself.
- Support and contact messages: messages sent through our contact form and any "resolve this risk" requests, including the contact details you provide.
- Technical data: standard server logs (IP address, browser type, timestamps) kept by our hosting provider for security and reliability.
How we use it
- To calculate and show your Security Score, risks, action plan and report.
- To let our team follow up on requests you submit.
- To operate, secure and improve the service, and to communicate about your account.
Where your data lives and how it is protected
Data is stored in a PostgreSQL database hosted by Supabase, Inc., and the website is served by Vercel Inc. — both act as our service providers. Connections are encrypted (HTTPS). Each dealership can only read its own data; this is enforced by the database itself. Only authorized DealerGuard administrators can see data across dealerships, administrator access requires two-factor authentication, and administrator actions are recorded in an audit log.
We also use: an email delivery provider (Resend) to notify us when you send a message through the contact form, and the Have I Been Pwned password-range service, which checks at sign-up whether a password appears in a known breach — only the first five characters of a one-way hash are sent, never your password.
Cookies
We use only strictly necessary cookies to keep you signed in. We do not use advertising or analytics cookies. See our Cookie Policy.
Sharing
We do not sell or rent your personal information, and we do not share it for advertising. We share data only with the service providers needed to run DealerGuard (currently Supabase, Vercel and Resend), or when required by law.
Retention
We keep your data while your account is active. You can delete your assessment data or your whole account at any time from your Dashboard; deleted data is removed from our database (encrypted backups may persist for up to 30 days). Contact-form messages are deleted automatically after 12 months, and the administrator audit log after 24 months.
Your rights
Depending on where you live (for example California, or the EU/UK), you may have the right to access, correct, delete or export your personal information, and to object to or limit certain processing. You can delete your data yourself from the Dashboard, or make any request through our contact form; we will respond within the time required by law.
Children
DealerGuard is a business service and is not directed to anyone under 18.
International transfers
Our providers may process data in the United States and other countries, with appropriate safeguards where required.
Changes
We may update this policy and will post the new version here with a new "Last updated" date.
Contact
Questions? Use our contact form.