How we handle data

A plain account of what each product stores, where it lives, and how to delete it. The legal version is in our privacy policy.

The short version

Product by product

Cardinal VerifiedCardinal RelayCardinal Owe
Where it runsIn your browserOur server, hosted by Render in the United StatesOur server, hosted by Render in the United States
Customer dataWhatever is in your export, processed only on your computerFirst name, last initial, stock number, new or used, deal typeFirst name, last initial, stock number, vehicle description
Staff dataSign-in email, managed by Netlify IdentityName, role, optional email, PIN stored as a keyed hashName, role, optional email, PIN stored as a keyed hash
Stored whereThat browser's local storageA database on the server, with daily backups kept 14 daysA database on the server, with daily backups kept 14 days
Contacts customersNoNoNo. It drafts messages for your team to send
How to deleteClear that browser's site dataAsk us. Deleted within 30 days of the end of serviceAsk us. Deleted within 30 days of the end of service

If you are subject to the FTC Safeguards Rule

Dealerships that arrange financing are treated as financial institutions under the FTC Safeguards Rule and have to oversee the service providers that handle customer information. We designed our products to keep that oversight simple: Verified is not a place your customer financial data ever sits, and Relay and Owe hold no customer financial or contact information at all.

Because Verified runs in the browser, the results live on the computer that ran it. Securing that computer, and the export files on it, stays with your dealership. We are happy to complete a vendor security questionnaire. Email cameron@cardinalhall.co.

How we protect what we do hold

Reporting a security problem

If you believe you have found a security issue in any Cardinal Hall product, email cameron@cardinalhall.co with "Security" in the subject. We will acknowledge it within two business days.