Legal
Privacy Policy
Last updated: April 22, 2026
Short version.
We collect the minimum we need to help you find and buy a car. We never sell your information. We share only with the sub-processors listed below. You can see, correct, export, or delete your data by emailing dallin@dealerkeyauto.com.
1. Who we are
DealerKey Auto is a Utah-licensed motor-vehicle dealer operating dealerkeyauto.com (the “Site”). Our principal place of business is 1096 N 450 W, Springville, UT 84663. This policy describes how DealerKey Auto (“DealerKey,” “we,” “us”) handles the personal information of Site visitors, subscribers, and Done-For-You clients.
2. What we collect
We collect three categories of information:
2.1 Information you provide.
- Lead form fields: name, email, phone, Utah city, vehicle(s) you are shopping, drive-out budget, timeline, consent;
- Account credentials for Auction Insider and Deal Analyst subscriptions;
- Payment details (processed by Stripe; DealerKey does not see or store full card numbers);
- Done-For-You Bid Authorization parameters: target vehicle spec, maximum approved bid, delivery ZIP, and, when the vehicle is won, the information required for Utah MVED title transfer (driver license, insurance, registration details);
- Messages you send by text, email, form, or during a scheduled call (calls are not recorded unless we tell you in advance).
2.2 Information collected automatically.
- Device and browser metadata (IP address, user agent, referrer, language);
- Pages viewed, searches run, listings clicked, and approximate city-level geolocation from IP;
- Cookies, local storage, and similar technologies for session management and aggregate analytics.
2.3 Information from third parties.
- Wholesale auction inventory and Manheim Market Report (MMR) values;
- Retail comparable listings from public dealer sites;
- NADA and J.D. Power valuation datasets;
- Vehicle history snapshots (where included with an auction listing).
Third-party vehicle and market data is not personal information about you.
3. Why we use it
- To respond to your inquiry and help you find a vehicle;
- To operate Auction Insider and Deal Analyst subscriptions (authentication, saved searches, alerts, exports);
- To execute the Done-For-You Bid Service and the Utah MVED title paperwork that follows a winning bid;
- To send transactional SMS and email (bid updates, alerts you have saved, title handoff);
- To send limited marketing email if you have opted in (weekly market-movers digest, new-tier announcements) — always with a one-click unsubscribe;
- To detect fraud, enforce our Terms, and debug the Site;
- To meet legal obligations (dealer recordkeeping, tax, subpoena response).
We never use lead form data to retarget ads for unrelated products, and we never run “advertising lookalikes” from our client list.
4. Who we share it with
We do not sell personal information. We share only with the service providers we need to operate the business, and only the data each provider needs:
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Name, email, billing address, card token |
| Twilio, Inc. | SMS delivery | Phone number, message body, delivery receipts |
| SendGrid (Twilio) | Transactional email | Email address, message body |
| Loops, Inc. | Lifecycle / marketing email | Email address, name, tier, opt-in status |
| Calendly, Inc. | Call scheduling | Name, email, scheduling preferences |
| Google (Analytics + Ads) | Aggregate traffic analytics + campaign measurement | Hashed identifiers, pageview events |
| Meta Platforms | Ad measurement (Meta Pixel) | Hashed identifiers, pageview events |
| Amazon Web Services | Hosting (us-west-2) | All operational data, encrypted at rest |
| Wholesale auction operators | Done-For-You Bid Service execution | Name, license number, Bid Authorization parameters |
| Licensed transporters | Vehicle delivery | Name, delivery address, phone |
| Utah MVED / County DMV | Title + registration | Info required for title transfer |
We may also disclose information to law enforcement or a regulator (including Utah MVED) when legally compelled, or to defend a claim. If DealerKey is involved in a merger, acquisition, or asset sale, user information may transfer to the surviving entity; we will notify affected users by email at least 30 days before the transfer.
5. How long we keep it
- Lead-only records (never purchased, never subscribed): 24 months from last interaction, then deleted or anonymized.
- Active subscription accounts: retained for the life of the subscription plus 36 months (to service tax and dispute records).
- Done-For-You transaction records: retained for 7 years under Utah dealer recordkeeping rules (Utah Code §41-3-301) and IRS retention.
- Marketing opt-outs and SMS STOP records: retained indefinitely so we can honor your preference.
- Raw server logs: 90 days.
6. How we protect it
DealerKey uses reasonable administrative, technical, and physical safeguards: TLS in transit, encryption at rest (AWS KMS), access controls with unique credentials, and a small number of human operators with need-to-know access. No system is perfectly secure; report a suspected breach to dallin@dealerkeyauto.com immediately.
7. Cookies & tracking
We use a small set of cookies and similar technologies:
- Strictly necessary: session, CSRF, and authentication cookies. Cannot be disabled while logged in.
- Analytics: Google Analytics 4 in measurement-mode with IP-anonymization.
- Advertising: Meta Pixel and Google Ads conversion tags. Fire only on public pages and conversion events, never on authenticated account pages.
You can block or delete cookies through your browser. We honor the Global Privacy Control signal — when detected we treat it as an opt-out of cross-context behavioral advertising.
8. Your choices & rights
Regardless of where you live, you may:
- Request a copy of your data;
- Correct inaccurate information;
- Delete your account and associated lead data (subject to the dealer-recordkeeping retention above);
- Opt out of marketing email (every email has an unsubscribe link);
- Opt out of SMS (reply STOP to any text).
Email requests to dallin@dealerkeyauto.com with the subject line “Privacy Request.” We respond within 30 days.
8.1 California residents (CCPA / CPRA).
California residents have the right to know the categories of personal information collected, to request access or deletion, to opt out of sale or sharing (we do not sell or share in the CCPA sense), to correct inaccurate data, and to limit the use of sensitive personal information (we do not collect sensitive PI in the CCPA sense beyond driver-license data used for the required title transfer). We do not discriminate against California residents who exercise these rights.
8.2 Other states (CO, CT, VA, TX, OR, etc.).
Residents of states with comparable privacy laws have similar access, correction, deletion, and opt-out rights. Submit the same request to dallin@dealerkeyauto.com; we apply the rights of your state of residence.
8.3 Authorized agents.
An authorized agent may submit requests on your behalf with written proof of authorization.
9. Children
The Site is not directed to children under 18 and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, email us and we will delete it.
10. International visitors
DealerKey is a Utah-only service: we only deliver vehicles within 200 miles of Springville, Utah. If you visit from outside the United States, your information will be transferred to and processed in the United States.
11. Do Not Track & GPC
We do not respond to traditional Do Not Track browser signals because no consistent industry standard exists. We do honor the Global Privacy Control (GPC) opt-out signal as described in Section 7.
12. Changes to this policy
Material changes will be announced on the Site at least 14 days before taking effect. The “Last updated” date above always reflects the current version.
13. Contact
Privacy questions or requests:
DealerKey Auto — Attn: Privacy
1096 N 450 W
Springville, UT 84663
Email: dallin@dealerkeyauto.com
Related policies: Terms, SMS Terms, Dealer Disclosures, Disputes & Refunds.
This policy is a plain-language draft and is not legal advice. Review with privacy counsel before publishing under any specific regulatory framework (GDPR, PIPEDA, etc.) if the business expands beyond Utah.