Dealership websites can connect inventory, sales leads, trade-ins, finance, service, parts, chat, analytics, advertising, and customer systems. Privacy work begins by mapping those flows instead of copying a generic notice.

This is a technical planning checklist, not legal advice. Get qualified review for the dealership's data, audience, vendors, and applicable requirements.

Inventory the data flows

List contact, trade-in, finance, service, parts, chat, account, payment, appointment, review, analytics, and cookie collection. Record destination system, vendor, purpose, owner, retention, and access.

Separate sensitive paths

Use approved secure systems for finance or identity information. Keep general inquiries, inventory questions, and service requests within the minimum necessary scope.

Align forms and notices

Make consent, marketing choices, vendor handoffs, response expectations, and privacy contact details understandable at the point of collection. Keep the notice synchronized with actual tools.

Control access and exports

Use role-based access for sales, finance, service, parts, marketing, and vendors. Review inboxes, CRM exports, attachments, analytics access, and former employee accounts.

The privacy policy checklist, cookie guide, and security checklist provide supporting controls.

Review the lifecycle

Document retention, deletion, correction, opt-out, duplicate, sold-vehicle, closed-customer, and vendor-termination scenarios. Assign owners and review triggers.

New dealership tools creating unknown data flows? Ask Vertinus to map the website-to-CRM and vendor path.