Privacy Policy
Draft — pending legal review
This Privacy Policy describes, at a high level, how the LotHelm software (“the app”) handles information when authorized dealership staff use it for internal operations. It is written for the app and its operators.
This page is an early draft and is pending legal review. The wording below may change, and it is not a determination that any particular law applies or has been satisfied.
Scope — app policy, not the dealership's customer notice
This is the app/operator privacy policy. It is not the dealership's customer-facing privacy notice. In particular, it is not the Gramm-Leach-Bliley (GLB) Privacy Notice a dealer provides to a financed buyer — that is a separate document generated as deal paperwork.
Nothing on this page replaces, satisfies, or limits the dealership's own privacy notices, disclosures, or legal obligations to its customers. The dealership remains responsible for its own GLB and other required notices.
Information the app handles
The app processes records that authorized dealership staff create and enter while doing their work. At a high level this includes:
- Account and contact information for app users (for example, name, email, and role).
- Dealership operational records that operators enter into the app.
- Customer, vehicle, deal, payment, document, and audit-trail data the app is used to manage.
- Application logs and error telemetry generated while the app runs.
- Files and documents uploaded to or stored through the app.
How information is used
Information is used to provide the app's features to the dealership — recording and organizing operational data, generating dealership paperwork from the data operators enter, supporting follow-up and reporting, and keeping the app running and secure.
The app is an internal operations tool. It is not a public-facing consumer service, and it does not exist to market to the dealership's customers.
Controls already in place
The app applies the following controls today, described at a high level:
- Authenticated access — staff sign in before reaching app data.
- Role-based permissions — what each user can see and do is limited by their assigned role.
- Audit logging — sensitive actions are recorded to an audit trail.
- Production error redaction — known sensitive fields are scrubbed from error telemetry before it leaves the app.
Data retention
Operational records generally remain in the app for as long as they are needed for dealership operations. Specific retention periods have not yet been defined here and will be added after review.
Your choices and requests
Access to records is managed through dealership administrators and the app's role-based permissions. Self-service data export or deletion workflows are not described here; any such request is handled through the dealership and the app operator. This section will be expanded after review.
Contact and review
Questions about this draft policy should be directed to the dealership owner or administrator who provided access to LotHelm.
Effective date: Pending owner/counsel review. This policy is a draft, is not legal advice, and is not yet final; the dealership owner and counsel may revise it before it is finalized.