CarConnectiveConnected Vehicle Intelligence
How it worksConnected VehicleOEM CompatibilityThe ProductThe NODEThe 38 ModulesIntegrationsImplementation
PricingSecurity
AboutResultsRent vs OwnTrust CenterInsightsFAQCareers
Book a Demo
Product
How it worksConnected VehicleOEM CompatibilityThe ProductThe NODEThe 38 ModulesIntegrationsImplementation
Pricing & Security
PricingSecurity
Company
AboutResultsRent vs OwnTrust CenterInsightsFAQCareersBook a Demo
Legal

Privacy Policy

Last updated: July 2026
Working draft. This document reflects how CarConnective is built and operated, and is provided for review. It should be reviewed and finalized by qualified legal counsel before you rely on it. Bracketed items [ ] need completing (legal entity, governing-law state, effective date).

Contents

  1. Scope & who we are
  2. Information we collect
  3. Connected-vehicle data
  4. How we use information
  5. Regulatory framework
  6. How we share information
  7. Retention
  8. Security
  9. Your rights & choices
  10. International transfers
  11. Children
  12. Changes
  13. Contact

1. Scope & who we are

This Privacy Policy explains how CarConnective (“CarConnective,” “we,” “us”) — operated by CarConnective, Inc., a Delaware C corporation — collects, uses, discloses and protects information in connection with our connected-vehicle intelligence platform and this website (together, the “Services”).

Much of the data we process belongs to our dealer customers and to the vehicle owners and consumers those dealers serve. For that data the dealer is the controller and CarConnective acts as a service provider / processor on the dealer's behalf and under our agreement with them (see our Data Processing Addendum). This policy describes our own practices and applies to information we control directly — including website visitors and prospective customers.

CarConnective serves dealers in both the United States and the United Kingdom. Where obligations differ by jurisdiction, this policy says so explicitly.

2. Information we collect

Dealer & business data

Account and contact details, and the operational records a dealer connects to the platform — deals, repair orders, customer and vehicle records, and market data — provided by or on behalf of the dealer to deliver the Services.

Consumer data (processed for dealers)

On behalf of dealers, we process information about their customers necessary to run the Services — for example contact details, vehicle ownership, service history and consent status — strictly to provide the contracted functionality. CarConnective does not use this data for its own marketing or sell it to third parties.

Connected-vehicle telemetry

With the explicit consent of the vehicle owner, we read signals from connected vehicles via manufacturer APIs. The types of data read are described in Section 3 below.

Website & prospect data

When you visit this site or request a demo, we collect the information you submit (name, work email, dealer group, role) and standard technical data (IP address, device and browser identifiers, pages viewed, referral source) to operate and improve the site and to follow up on your enquiry.

Usage data

When dealers use the platform, we collect logs of actions, features used, and system events to provide support, improve the Services, and maintain security.

3. Connected-vehicle data

Connected-vehicle access is owner-consented and software-only— there is no hardware, no dongle, and no OBD device. Vehicle owner credentials are never stored by CarConnective; access is granted and can be revoked by the owner at any time through a single tap.

With the owner's explicit consent, the signals we may read include:

  • Odometer — software-verified mileage reading
  • Engine oil life — remaining oil-life percentage
  • Tire / tyre pressure — per-wheel TPMS readings
  • Fuel level — tank percentage
  • Battery & charge state — EV state of charge, estimated range, and where available, charging session detail
  • Diagnostics — active fault codes (DTCs), where the OEM exposes them
  • Location — last-known vehicle coordinates
  • VIN & service history — vehicle identity and OEM-held service records, where available

We limit connected-vehicle processing to delivering the functionality the dealer and vehicle owner have contracted for. We do not build profiles unrelated to the dealer relationship, and we do not share telemetry with data brokers or advertisers. An owner may disconnect their vehicle at any time; reads stop immediately on revocation.

Signal availability varies by make, model and market. See our OEM Compatibility page for the full matrix.

4. How we use information

  • To provide, operate, secure and improve the Services for our dealer customers.
  • To surface the right action at the right moment — valuations, service scheduling, outreach — within the dealer's own workflows.
  • To enforce consent, Do-Not-Call / TPS suppression, quiet hours and other compliance controls on outbound communications.
  • To maintain an immutable evidence trail of communications and data-processing events for dealer compliance purposes.
  • To communicate with you about a demo, an engagement, or this website.
  • To maintain security, prevent abuse, detect fraud, and meet legal obligations.
  • To conduct internal analytics and product improvement on aggregated, de-identified data.

We do not use information to train general-purpose AI models, sell data to third parties, or engage in targeted advertising.

5. Regulatory framework

United States

The Services are designed to operate within the regulations that govern US dealer data and outreach:

  • TCPA — consent capture, Do-Not-Call suppression and contactable-hours enforcement on every outbound message.
  • GLBA — safeguards for non-public personal financial information across the deal flow, aligned to the FTC Safeguards Rule.
  • DPPA — vehicle title, odometer and service history only; owner PII obtained from DMV records is never used for marketing purposes.
  • FTC / UDAP — advertising, pricing and disclosure checks on material representations.
  • CCPA / CPRA — for California consumers: the right to know, delete, and opt out of sale or sharing of personal information. CarConnective does not sell personal information. California consumers may submit requests to privacy@carconnective.com.
  • Other applicable U.S. state privacy laws, including Virginia VCDPA and Colorado CPA, are addressed in our dealer agreements.

United Kingdom

For our UK dealer customers and UK-resident individuals whose data we process, we operate under:

  • UK GDPR & Data Protection Act 2018 — a lawful basis for each processing activity, purpose limitation, data minimisation, and full data-subject rights. We act as a processor for dealer customer data and as a controller for our own operations and website.
  • PECR — electronic-marketing consent and screening against the Telephone Preference Service (TPS) before any proactive call or SMS.
  • FCA Consumer Duty — the platform generates and retains fair-value and commission-disclosure evidence on regulated motor finance, supporting dealers' good-outcome obligations since the DCA ban.
  • ICO accountability — records of processing activities (RoPA), Data Protection Impact Assessments (DPIAs) for high-risk processing, and an immutable evidence trail available on request for ICO enquiries.

CarConnective's connected-vehicle data layer is independently certified to ISO 27001(information security management) and ISO 27701 (privacy information management), and our own SOC 2 Type II audit is underway. See our Security page and Trust Center for detail.

6. How we share information

We do not sell personal information. We share information only in the following circumstances:

  • With the dealer customer — data processed on a dealer's behalf is shared with and accessible to that dealer.
  • With sub-processors — vetted technology providers that help us provide the Services (such as cloud infrastructure, authentication, and communications providers), each bound by a Data Processing Agreement and reviewed against their security posture. A current list of sub-processor categories is available on request; material additions are notified to customers.
  • As required by law — where we are legally required to do so, such as in response to a court order or lawful government request, and where permitted, we will notify the affected dealer.
  • Business transfers — in the event of a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction; affected parties will be notified as required by law.

7. Retention

We retain information for as long as needed to provide the Services and to meet legal, accounting or reporting obligations. Data processed on a dealer's behalf is retained and deleted according to our agreement with that dealer. On termination, the dealer's data is returned or deleted as described in our DPA, and vehicle-owner consent and connected data is deleted or anonymised. Prospect and website visitor data is retained for up to 24 months from last interaction, unless we have an ongoing commercial relationship.

8. Security

CarConnective is engineered to the SOC 2 control set (Type II audit underway). Security measures include:

  • Row-level security: each dealer can only access its own data.
  • Server-only privileged API keys: the browser bundle contains no secrets; all privileged calls go to our backend.
  • AES-256 encryption at rest and TLS in transit.
  • Short-lived JWTs with server-revocable rotating refresh tokens.
  • Hardened security headers, a controlled change pipeline, and annual third-party penetration testing.

The connected-vehicle data layer we read through is independently certified to ISO 27001 and ISO 27701. See our Security page for the full control matrix.

If you discover a potential security vulnerability, please report it responsibly to security@carconnective.com.

9. Your rights & choices

US residents

Depending on your state, you may have rights to access, correct, delete or obtain a copy of your personal information, and to opt out of certain processing. For data we control (e.g., website or prospect data), contact us using the details in Section 13. For data we process on a dealer's behalf, please contact that dealer directly, and we will assist them in honouring your request.

UK and EEA residents

Under UK GDPR and EU GDPR you have the right to: access your personal data; correct inaccurate data; request erasure where there is no lawful basis to retain it; restrict or object to processing; receive your data in a portable format; and to withdraw consent at any time where processing is consent-based. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or with your local supervisory authority.

To exercise any of the above rights, contact us at privacy@carconnective.com. We will respond within 30 days (US) or one calendar month (UK / EEA), as required by applicable law.

10. International data transfers

CarConnective, Inc. is based in the United States. Where we transfer personal data of UK or EEA residents outside the UK or EEA, we do so under appropriate safeguards — including the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) as applicable — or on the basis of an adequacy decision. Details of the transfer mechanisms in place are available on request.

11. Children

The Services are designed for business use by automotive dealers and are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children.

12. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or applicable law. Material changes will be reflected by an updated “Last updated” date at the top of this page and, where appropriate, communicated directly to dealer customers. Continued use of the Services after any update constitutes acceptance of the revised policy.

13. Contact

For questions about this policy, to exercise your rights, or to report a concern:

  • Email: privacy@carconnective.com
  • Post: CarConnective, Inc. — Privacy, c/o registered agent, Delaware, USA
  • UK enquiries: privacy@carconnective.com (we will respond within the required UK GDPR timescale)
Own the intelligence

Stop renting your stack. Own it.

Book a Demo →
CarConnective

The most advanced AI infrastructure in automotive retail — one connected brain beneath sales, service, F&I and reputation, engineered to SOC 2 standards.

Founder-led · building with design partners

Platform

How It WorksConnected VehicleOEM CompatibilityThe ProductThe NODEThe 38 ModulesIntegrationsImplementationSecurity & SOC 2Trust Center

Company

AboutResultsROI MethodologyRent vs OwnPricingInsightsFAQCareers

Get Started

Book a DemoTalk to the FounderContact us
© 2026 CarConnective, Inc. · Connected Vehicle IntelligencePrivacyTermsDPACookiesSecurityUS & UK