Dealership websites can connect inventory, sales leads, trade-ins, finance, service, parts, chat, analytics, advertising, and customer systems. Privacy work begins by mapping those flows instead of copying a generic notice.
This is a technical planning checklist, not legal advice. Get qualified review for the dealership's data, audience, vendors, and applicable requirements.
Inventory the data flows
List contact, trade-in, finance, service, parts, chat, account, payment, appointment, review, analytics, and cookie collection. Record destination system, vendor, purpose, owner, retention, and access.
Separate sensitive paths
Use approved secure systems for finance or identity information. Keep general inquiries, inventory questions, and service requests within the minimum necessary scope.
Align forms and notices
Make consent, marketing choices, vendor handoffs, response expectations, and privacy contact details understandable at the point of collection. Keep the notice synchronized with actual tools.
Control access and exports
Use role-based access for sales, finance, service, parts, marketing, and vendors. Review inboxes, CRM exports, attachments, analytics access, and former employee accounts.
The privacy policy checklist, cookie guide, and security checklist provide supporting controls.
Review the lifecycle
Document retention, deletion, correction, opt-out, duplicate, sold-vehicle, closed-customer, and vendor-termination scenarios. Assign owners and review triggers.
New dealership tools creating unknown data flows? Ask Vertinus to map the website-to-CRM and vendor path.