Cookie Preferences

We value your privacy

This site sets no cookies of its own — your session is kept in your browser's local storage, not in a cookie. What we are asking about is Google Analytics, which measures how the public pages are used. Its storage stays switched off until you choose, and "Reject Additional Cookies" keeps it off. You can change your mind at any time from "Your Privacy Rights". The full inventory, including what we log without cookies, is in our Cookie Policy.

|
English only

Privacy Policy

Last Updated: August 20, 2026

This policy explains what The DAS Board LLC does with personal data. It opens with the question most privacy policies skip — whose data are we responsible for, and whose is your dealership responsible for — because the answer is different for three groups of people, and it decides who you should ask for what. Sections 2 to 6 set out what we hold, including what we deliberately refuse to hold about vehicle buyers and what we send to an AI provider. Section 8 names every outside company that receives data through the product; the previous version of this policy named four of them. Section 17 sets out the additional rights that apply in the European Economic Area, the United Kingdom, and Switzerland. Where this policy describes a control, it describes something in the running system; where we do not have something, we say so.

1. Who Is Responsible for Which Data

This policy used to open by saying "The DAS Board is the controller of your personal data". That was a blanket statement and it was wrong. The product holds three populations of personal data under two different responsibilities, and which one you are in determines who decides what happens to your data:

  • People who approached us. If you requested a demo, filled in a form, started a signup, or are named on a subscription, we decide why we hold your data and for how long. We are the controller. Ask us directly at privacy@thedasboard.com.
  • Dealership staff. If your employer created your account, we hold your name, work contact details, role, pay plan, commissions, spiffs, goals, schedule, and certifications because your employer instructed us to. Your employer is the controller; we are its processor. Many people in this group never signed up for anything and have never dealt with us at all. We will always help, but the decisions — what is kept, corrected, or deleted — belong to your employer.
  • Vehicle buyers. If you bought a car from a dealership that uses The DAS Board, the dealership may have recorded your name and the vehicle against the deal. The dealership is the controller; we are its processor, and we hold deliberately little (Section 3). Ask the dealership: it has tools inside the product to export or erase your details, described in Section 10.

2. Information We Collect

We collect information that you or your dealership provides directly, information generated as you use the platform, and information we receive from services you connect to The DAS Board:

  • Account information: name, work email, phone number, role or title, dealership or dealer group, and login credentials
  • Deal and performance data: sales figures, F&I product mix, commissions, pay plans, schedules, goals, and similar business metrics you or your team enter
  • Inventory and DMS data: if your dealership enables the optional DMS sync add-on, we ingest vehicle inventory and deal records from your Dealer Management System using the credentials or tokens you authorize
  • Concierge onboarding uploads: documents such as pay plans, roster spreadsheets, or historical deal data that you share with our setup team to configure your tenant
  • Usage data: pages viewed, features used, and session timestamps
  • Device and network information: browser type, IP address, operating system, and the country derived from your IP address
  • Cookies and similar technologies: the application itself sets no cookies, because your session is held in your browser's local storage rather than in a cookie. Google Analytics may set cookies on our public marketing pages, and only after you allow it in the consent banner. Section 11 and our Cookie Policy give the full inventory.
  • Error reports and session replays: when something breaks, the error and the page go to Sentry, our error-tracking provider. These are sent by your own browser directly to Sentry, not relayed through us, and while they are in flight your signed-in identity is attached to them on purpose — your user identifier and your email address, with your role and dealership identifier as tags — because an error we cannot attribute to an account is an error we usually cannot fix. Before an event is sent, the browser drops known-harmless noise and redacts values whose names mark them as credentials, such as tokens, passwords, and cookies; it does not attempt to find and remove email addresses or telephone numbers that happen to appear inside an error message. Sentry also records a replay of the interface for roughly one signed-in session in ten, and for every session in which an error occurs.
  • A second, separate copy of each error goes to our own server endpoint, and that path is scrubbed harder: it removes bearer tokens, API keys, passwords, and any text matching an email address or a telephone number from the message, stack, and breadcrumbs, and it forwards only an opaque user identifier — never your email or name. We are describing the two paths separately because they genuinely differ, and a single sentence covering both would flatter the weaker one.
  • Administrative notes: our support and administration staff can write free-text notes against an account — what a customer asked for during onboarding, what went wrong on a call. They are stored on the account record and visible to our master administrators in the internal support console. They are not shown to you. If you want to know what they say about you, ask and we will tell you.
  • Payment information: billing details are collected and processed directly by Stripe. Card numbers never reach our servers; we receive metadata such as card brand, last four digits, billing country, and subscription status.

3. Vehicle-Buyer Data: What We Hold, and What We Refuse to Hold

A dealership's deal records pass through The DAS Board, so we necessarily hold something about the people who bought the cars. We hold as little as the product can work with. The limits below are structural rather than promised — for most of the second list, the database has no column to put the data in. What a dealership's staff record against a deal:

  • The buyer’s name on a deal record — a last name always, and a full name where the dealership enters one
  • The last eight characters of the VIN, and the full 17-character VIN where a dealership enters one so the vehicle can be decoded
  • Vehicle year, make, model, and whether it was new or used
  • The deal date, deal number, stock number, lender name, and the dealership’s own profit figures on the deal
  • On a showroom visit record: the visitor’s first and last name and the last four digits of a telephone number, used to recognise a return visit within fourteen days
  • Anything a staff member types into the free-text notes field on a deal, which we cannot constrain

What The DAS Board does not collect about a vehicle buyer, in any field, in any plan:

  • Social Security numbers
  • Credit scores, credit reports, or credit applications
  • Dates of birth
  • Driver’s licence numbers
  • Street addresses
  • Complete telephone numbers
  • Email addresses of vehicle buyers
  • Financing terms — the buyer’s APR, amount financed, term, or payment
  • Bank account or payment card details of any kind

One caveat we would rather state than have discovered: every deal has a free-text notes field, and we cannot control what a member of staff types into it. Our Terms forbid entering the categories in the second list anywhere in the Service, including there.

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Calculate commissions, pay, and performance figures from the data your dealership enters
  • Process subscriptions, take payment, and send billing messages
  • Send service messages, and marketing messages where you have agreed to receive them
  • Detect, investigate, and prevent fraud, abuse, and security incidents
  • Diagnose faults, using the error reports and session replays described in Section 2
  • Produce aggregated, de-identified statistics about how the product is used

5. Employee Performance Data

This is employee-performance software, and no wording can soften that. The DAS Board ranks named individuals — salespeople, finance managers — by the deals they wrote, the gross they produced, their product penetration, and in many configurations their pay. It exists so that a dealership can see who is performing and who is not. If your name is in it, these are the things you are entitled to know:

  • Who can see your figures is set by your role and by your dealership's configuration, not by us. Managers see their teams; general managers and dealership administrators see the store; group administrators see the locations assigned to them.
  • Whether salespeople can see pay figures at all is a switch your dealership controls. It is their decision to make and not one we make or override.
  • Dashboards inform management decisions; they do not make them. No pay, disciplinary, or employment outcome is produced automatically by the system — a person reads the number and decides. Section 17 restates this for readers in Europe, where it carries specific legal weight.
  • If a figure about you is wrong, the correction is made by your dealership, because your dealership entered it and is the controller of it. We will help them make it.
  • The AI Advisor described in Section 6 receives employee names alongside their individual figures. If that matters to you, that section says exactly what is sent and to whom.

6. Artificial Intelligence

The product includes two features that use artificial intelligence, and they are not alike. The AI Advisor answers questions about a dealership’s performance using a large language model operated by a third party. The Help assistant, reached from the question mark on each dashboard when you are on a desktop or tablet screen, explains how to use the software and is sent none of your data. Nothing else in the product applies AI to anything. Our Responsible AI page carries the full account; the essentials are:

  • When someone uses it, we send aggregated dealership metrics, the selected question, and a short summary of previous answers to Anthropic, which is currently the only AI provider we have configured. Our code supports two others; neither is enabled, and this policy and the Responsible AI page change in the same commit if that ever does.
  • Employee names go with those metrics, attached to that person's own deal count, gross, and product penetration. The feature exists to identify who to coach, and it cannot do that anonymously.
  • No vehicle-buyer data is sent. No name, no VIN, no telephone number, no financing terms — those fields are not part of what the feature assembles.
  • There is no free-text box. Questions come from a fixed list, which is the simplest available defence against someone steering the model somewhere it should not go.
  • Use is metered per role, between three and fifteen questions a week, and each request is size-capped.
  • The Help assistant is sent only your typed question, your role, which screen you are on as a generic address, and a written guide to the product that ships inside the software. It is sent no deals, no pay figures, no employee names, no vehicle-buyer data, and not even the name of your dealership. The code that assembles that message has no access to any of it, and an automated test asserts the message contains only those four items.
  • The Help assistant is capped at twenty-five questions per person per day, and is deliberately unavailable during live demos, support impersonation sessions, and while an administrator is viewing an employee’s dashboard.
  • Whether a model provider trains on what it receives is governed by that provider's own commercial terms, not by ours. We will tell you what we send and to whom; we will not warrant another company's training practices as though they were a control we hold.

7. Information Sharing and Multi-Tenant Access

We do not sell personal information and we do not share it for cross-context behavioral advertising. Access inside the platform is controlled by tenant and by role. Data goes outside your tenant only in the situations below:

  • Inside your dealership or dealer group: deal, commission, schedule, and performance data is visible to users within your tenant according to their role — dealership administrators and general managers see the store, sales and finance managers see their teams, individual users see their own activity
  • Across dealerships in a group: group-level administrators, such as dealer group admins or area vice presidents, can view performance aggregates for the locations they are assigned to
  • Single Finance Manager plan: if you subscribe to the individual plan, your deal and performance data is isolated to your personal account and is not shared with any dealership tenant
  • Our own staff: our setup team can work inside your tenant to perform concierge onboarding you have asked for, and our administrators can sign in as a user of your dealership to reproduce a reported fault. Those sessions are time-limited — thirty minutes for an impersonation session — and are written to an audit log with who started it, against whom, and when.
  • Service providers: the companies listed in Section 8, each under written data-protection terms
  • Legal and safety: when required by law or valid legal process, or to investigate fraud, abuse, or security incidents and protect our rights, our users, or the public
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to continued protection of your information

8. Service Providers We Use

Every outside company that receives data through the running product, what it is for, and what actually reaches it. The previous version of this policy named four: "Supabase, Netlify, Stripe, email and monitoring providers". The list below is complete as of the date at the top of this page, and two entries appear on it although nothing currently flows to them — our security policy still permits the connection, and we would rather over-disclose than have this page disagree with our own configuration. A unit test in our codebase fails the build if a new external host is added to that policy without being added here.

ProviderWhat it doesWhat reaches it
SupabaseDatabase, authentication, file storage, realtime, and edge functionsAll application data: accounts, dealership and staff records, pay plans, deals, schedules, and uploaded documentsSessions are held in the browser’s localStorage, not in a cookie.
NetlifyWebsite hosting, CDN, and the serverless functions behind checkout, email, and analyticsEvery request to the site, including IP address and user agent, as web-server logs; whatever a given function handlesThe site is served from Netlify, so Netlify sees all traffic by construction.
StripeSubscription billing, checkout, and the customer billing portalBilling name and email, card details entered directly into Stripe (never through our servers), subscription and invoice records
Google Analytics 4Website traffic measurement on the public marketing pagesPage views, referrer, approximate location, device and browser informationThe tag loads before you choose, but analytics and advertising storage stay denied until you grant them, so no analytics cookie is written first.
SentryApplication error tracking and session replayError messages and stack traces, the signed-in user’s id and email address, role and dealership id as tags, and — for sampled sessions — a replay of the interfaceSession replay runs on roughly 1 in 10 signed-in sessions and on every session where an error occurs. In a product that displays pay, that is a processing activity worth naming rather than burying.
Zippopotam.usTurning a ZIP code into a city and state during signup and onboardingThe ZIP code you type. Nothing else — no name, no account identifier.
Browser push services (Google, Mozilla, Apple)Delivering browser push notifications to staff who have enabled themAn encrypted notification payload, routed to whichever push service the recipient’s own browser nominatedWhich company receives it is chosen by the recipient’s browser, not by us: Chrome nominates Google, Firefox Mozilla, Safari Apple.
AnthropicThe AI Advisor — the language model that answers questions about your dealership metricsAggregated dealership performance metrics, including employee names with their individual deal counts and gross, the selected question, and prior advice for context. No customer or consumer data.
OpenAIAlternative AI Advisor provider — supported in code, not currently in useWould receive the same AI Advisor payload as Anthropic if enabledListed because switching a provider must not be the moment this page becomes wrong.
xAIAlternative AI Advisor provider — supported in code, not currently in useWould receive the same AI Advisor payload as Anthropic if enabled
TwilioText messages to dealership staffThe staff member’s mobile number and the message textStaff only. The product never sends a text message to a vehicle buyer.
ResendTransactional email — invitations, welcome messages, verification codes, and alertsRecipient email address, name, and the message content
OCR.spaceReading a business card photograph into contact fieldsThe photograph of the business card, and therefore whatever is printed on itUsed only by our own sales team, on cards collected while selling this product to dealerships. Nothing in a dealership customer’s workflow reaches it.
Lead-research providers (Google Programmable Search, ScraperAPI, ScrapingBee, DuckDuckGo)Finding dealerships to approach about buying The DAS BoardSearch queries about dealership businesses. No customer data and no subscriber data.This is our own outbound prospecting, not a processing activity performed on a customer’s behalf. Listed for completeness because the code exists.

Permitted by our security policy, but not used. Nothing is sent to these and nothing is loaded from them; the allowance exists in our configuration, so it is disclosed here rather than quietly omitted:

  • NHTSA vPIC — The policy permits VIN decoding against this free US government service; no code currently performs it. Listed rather than dropped so the policy and this page cannot disagree.
  • Google Fonts — The Content-Security-Policy still permits these hosts. Listed so the policy and this page cannot disagree; if a webfont is ever added, this row is what changes.

9. Data Retention

Some of the periods below are enforced by jobs running on a schedule in the database. Others are our policy, applied by hand. Those are two different kinds of promise and we are not going to present them as one, so they are in two lists. First, the ones a timer enforces whether anyone remembers or not:

  • A vehicle buyer’s name and full VIN on a deal: erased seven years after the deal date, by a monthly job. The deal’s financial and staff data stays, so commission history is not corrupted by the erasure.
  • Showroom-visit records: the visitor’s name and partial telephone number erased 90 days after the visit, daily. The visit is still counted.
  • Prospect contact records our own sales team collected: deleted after 180 days, daily.
  • IP addresses in audit and demo-access logs: cleared after one year, daily.
  • Our own website analytics — page views and conversion events: deleted after 180 days, monthly.
  • Text messages sent to staff, including the recipient’s number and the message text: deleted 365 days after sending, daily.
  • Security event logs after 180 days; rate-limit records after 7 days; feature-usage counters after 365 days.
  • Our local de-duplication copies of Stripe webhook events: deleted after 90 days, monthly.

And the ones that are policy rather than a timer. Nothing in the system enforces these today — they happen because a person does them, or because you ask. Labelling them is the only honest way to state them:

  • Account and profile data: deleted within 90 days of account closure. There is no scheduled job for this. Ask us and we will do it, and tell you when it is done.
  • Support tickets and the messages in them: three years after resolution.
  • Billing and payment records: held by Stripe under Stripe’s own retention terms for as long as tax and accounting law requires, which is Stripe’s schedule and not ours. The only billing data we keep locally is the de-duplication copy of Stripe’s webhook events listed above, which does expire on a job.
  • Google Analytics data: governed by the retention setting in Google’s own console, which is not in this codebase and not something our jobs can enforce. We are not going to print a number here as though it were ours to guarantee. Rejecting analytics in the cookie banner means nothing is collected in the first place.

Backups are managed by our hosting provider on its own schedule. A deletion from the live database can persist in a backup until that backup rotates out.

10. Your Rights and Choices

Which rights you have, and who you exercise them with, follows from Section 1:

  • If we are the controller — you approached us — email privacy@thedasboard.com to access, correct, delete, or port your data, or to stop marketing. We respond to verified requests within one month.
  • If you are dealership staff, ask your employer. We act on their instruction and will help them carry it out, but the decision is theirs.
  • If you are a vehicle buyer, ask the dealership. It can export everything we hold about you on its deals and erase your name and VIN from them, using functions built into the product for exactly that purpose. Its administrators, general managers, and group administrators can run both, and only against their own dealership's deals.
  • You can change or withdraw cookie consent at any time from the "Your Privacy Rights" panel in the consent banner.
  • You may complain to a data protection authority — Section 17 explains how. We would rather you told us first, but the right is yours either way.

11. Cookies and Tracking

The application sets no cookies of its own. Your session is held in your browser's local storage using an authorization-code flow with PKCE, and it is cleared when you sign out. Everything else that could be called tracking:

  • Google Analytics on our public marketing pages. The tag loads on every page, but Google Consent Mode is configured to deny analytics and advertising storage by default, so no analytics cookie is written and no measurement is sent until you allow it in the banner.
  • Our own page-view counter, which runs whether or not you consent. It records the page, the referrer, any campaign tags, your device category, your country, and a per-tab identifier discarded when you close the tab. It has no visitor identifier, sets no cookie, and cannot recognise you on a later visit.
  • Your language choice and your cookie decision, kept in your browser so we do not ask again for twelve months.
  • We run no advertising, retargeting, or social tracking tags, and we do not load web fonts from a third party.

Our Cookie Policy is the full inventory, including what the consent banner controls and what it does not.

12. Data Security

Every claim below is one we can point at code for. Our Security page has the mechanism in detail, including the list of certifications we do not hold.

  • All traffic runs over TLS. HTTP Strict Transport Security is set for two years with includeSubDomains and preload, and our content security policy forbids any non-HTTPS origin.
  • Data at rest is encrypted by our infrastructure providers, Supabase and Netlify. We do not add an application-layer encryption of our own and we do not claim one.
  • Tenant isolation has two halves, and describing only the first would overstate it. Row-level security is enabled on every application table. But much of the product runs through database functions that execute with elevated rights and therefore bypass those policies by design — for that surface, the control is which of those functions an unauthenticated caller may execute at all. An automated audit compares the live grants against a committed allowlist of 24 functions and fails if anything has been added, or if any such function has an unpinned search path. We wrote that audit because the drift it looks for had already happened three times.
  • Role-based access control, least-privilege service credentials, and an audit log for impersonation and presenter sessions.
  • Rate limiting on sign-in, signup, and password reset, enforced on the server rather than in the browser.
  • Uploaded onboarding documents are held in a private bucket and served only through links that expire after five minutes.
  • Inbound provider webhooks are signature-verified with a constant-time comparison, and a request that fails verification is refused.
  • A hash-based content security policy generated at build time, with violations reported back to us.
  • Roughly 1,250 automated unit tests and 160 end-to-end tests, including specifications that assert one dealership cannot read another's data and that the privileged database functions reject a request for a dealership the caller does not belong to.
  • On administrative access to our own hosting accounts: the previous version of this policy claimed we enforce multi-factor authentication. No code in the product implements that — it would be a setting on our providers' accounts — so the claim has been removed rather than reworded. We will state it here when it is verified and enforceable, and not before.
  • An incident-response process to notify affected customers and, where required, supervisory authorities without undue delay.

13. International Data Transfers

Your information is processed in the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and, where available, adequacy decisions. The service providers that receive data are listed in Section 8; the ones that hold the substance of it — Supabase, Netlify, and Stripe — are bound by the relevant clauses.

14. Children's Privacy

The DAS Board is a business platform intended only for adult dealership staff. We do not knowingly collect personal information from anyone under 18, and — for users in the European Economic Area — we do not offer our services directly to children within the meaning of Article 8 GDPR.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the new policy on this page and update the date at the top. Where a change is material we will also notify subscribers by email or in-product notification, and any change to a legal document is stamped with a new version that is recorded against new subscriptions at checkout.

16. Contact Us

If you have questions about this Privacy Policy, want to exercise your privacy rights, or need to reach our data protection contact, please write to us:

Entity: The DAS Board LLC

Email: privacy@thedasboard.com

Address: Registered address available on request from legal@thedasboard.com

Phone: (650) 663-2323

17. Additional Rights for Users in the EEA, UK, and Switzerland (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation and its UK and Swiss equivalents give you additional rights and require us to provide the following information.

  • Controller or processor: this depends on which group in Section 1 you are in. For your own signup, demo, and billing data, The DAS Board LLC is the controller. For dealership staff data and vehicle-buyer deal data, the dealership is the controller and we are its processor — direct those requests to the dealership, and we will support it in answering them. For any data protection question, we can be reached at privacy@thedasboard.com.
  • EU Representative: we have not appointed a representative under Article 27 GDPR. We are stating that plainly rather than leaving the section blank, because our marketing site is published in ten languages and a reader is entitled to know that the Article 27 contact point does not yet exist. It will be published here when it is appointed.
  • Legal bases for processing: (a) performance of a contract, to deliver the service you or your dealership subscribed to; (b) legitimate interests, to secure the platform, prevent fraud, operate the business, and analyse aggregated usage; (c) consent, for non-essential cookies, analytics, and marketing, which you may withdraw at any time; and (d) legal obligations, for tax, accounting, and fraud-prevention record-keeping. Where we act as a processor, the controller's legal basis is the dealership's to determine.
  • Your GDPR rights: you have the right to access, rectify, erase, restrict processing of, port, and object to processing of your personal data, and to withdraw any consent you previously granted. We respond to verified requests within one month. To exercise a right, email privacy@thedasboard.com.
  • Right to lodge a complaint: you may complain to your local data protection supervisory authority. A current list of EU supervisory authorities is maintained by the European Data Protection Board at edpb.europa.eu.
  • International transfers: your data is hosted in the United States. We rely on the European Commission's Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum, and, where available, adequacy decisions.
  • Automated decision-making: we do not make solely automated decisions producing legal or similarly significant effects about you. This deserves more than a sentence in a product that ranks named employees by pay: the dashboards and the AI Advisor described in Sections 5 and 6 produce figures and text that a manager reads. The decision — a bonus, a coaching conversation, a dismissal — is made by that manager. If your employer were to automate such a decision from our output, your employer would be the one doing it, and it would be their obligation under Article 22.
  • Data Protection Officer: we have not designated a statutory Data Protection Officer. Our privacy contact point for all GDPR matters is privacy@thedasboard.com.

© 2026 The DAS Board LLC. All rights reserved.