Auto Advocate Inc and its affiliates (collectively, “our,” “us,” or “we”) operate websites, provide information, products, and services through mobile and other applications, and develop software. We refer to these as “site(s),” “service(s),” or “our sites and services.”
1. Personal Information that You Provide to Us
Personal information is information that can be used to identify, locate, or contact an individual, and includes other information that may be associated with personal information. When you interact with our sites and services, depending on the site or service, we may collect the following personal information directly from you:
- Account or Registration Information where needed to use our sites and services, and may include your name, address, email address, telephone number, birthday, user account name, and password;
- Contact Information, which generally includes your name, addresses, email addresses, social media website user account names, and/or telephone numbers;
- Payment Information retained by our third party payments processing service provider where needed to process payments and generally includes your credit or debit card number, expiration date, and card CVC number;
- Personal Profile or Service Information, which may include areas of interest, information from social media interactions (such as, for example, Facebook, Twitter, or Google), preferences, physical characteristics (such as height, weight), photographs and, biographical and/or demographic information (such as gender);
- Transaction Information, which may include information about how you interact with and use our sites and services, email, other communications, and applications, and how you interact with merchants, dealers, business partners, and service providers;
- Geographic Location Information, but only if your device transmits location data and/or your IP address and you have activated a location-enabled site or service;
- Access to Your Data, but only if you use certain services, interactive tools, or authorize us to retrieve information from another database, user, or other third party on your behalf, such as integrating a practice management system with your services;
- Your Submissions, which generally includes information you voluntarily provide through free form text boxes, forums, document upload, or data retrieval or import;
In each of the above instances, you will know what personal information we collect through our sites and services because you voluntarily and directly provide it to us.
2.Other Information We Automatically Collect through Cookies and Other Technologies
We or our third-party service providers may collect and store certain technical information when you use our sites and services. For example, our servers receive and automatically collect information about your computer and browser, including, for instance, your IP address, browser type, domain name from which you accessed the site or service, device size, and other software or hardware information. If you access our sites and services from a mobile or other device, we may collect a unique device identifier assigned to that device (UDID), type of device, general GPS location, or other transactional information for that device in order to serve content to it and to improve your experience in using the sites or services.
In addition, we or our third-party service providers may collect information about how you use our sites, including but not limited to, the date and time you visit the sites, the areas or pages of the sites that you visit, the amount of time you spend viewing the sites, the number of times you return to the sites, visits to sites outside our network, preferred language, and other click-stream data.
2.2 Do Not Track
We currently do not respond to “Do Not Track” browser signals. Accordingly, your navigation on our sites and services may be tracked as part of our efforts to gather user information described above. If you arrive at our sites and services by way of a link from a third-party site that does respond to “Do Not Track” browser signals, such “Do Not Track” browser signal recognition will end as soon as you reach our sites and services.
3. Our Bases for Processing Information
We will only collect and process personal information, including sharing it with third parties, where we have a legal basis for such collection and processing. We rely on a number of legal bases, including:
- our legitimate interests in providing and improving our sites and services;
- our legitimate interests in keeping our sites and services safe and secure;
- our third party service providers’ legitimate interests as described in “Other Information We Automatically Collect Through Cookies and Other Technologies” above;
- your consent to the processing of your personal information, which you can revoke at any time;
- where the processing of your personal information is required to protect your vital interests or those of another person, such as other users of our sites and services;
- where the processing of personal information is necessary to comply with a legal obligation such as a law, regulation, search warrant, subpoena, or court order.
4. How We Use Personal Information
4.1 Personal Information that You Provide to Us
We may use the personal information that you provide in one or more of the following ways:
- to carry out our obligations arising from your purchase of, or subscription to, our services or any other contract entered into between you and us;
- to enable site features such as geographically specific pricing or logging, and retrieving and providing data analysis;
- to send you important notices, such as communications about changes to your account, and our sites’ and services’ terms, conditions, or policies;
- to process payments and to send you emails, invoices, receipts, notices of delinquency, alerting you if we need different or updated payment card information or other communications in connection with processing and collecting payments;
- to verify the information you provide through our sites and services,;
- to retain your personal information for the length of time determined by us or by applicable law;
- to solicit input and feedback to improve our sites and services and customize your user experience;
- to enable you to communicate with other site or service users via private messaging or other service specific communication channels;
- to contact you via email, telephone, text or chat in a manner required by law;
- to meet contractual obligations;
- to send you reminders, technical notices, updates, security alerts, support and administrative messages, and service bulletins;
- to inform you about new products or promotional offers, or other opportunities which we feel will be of interest to you, and to provide advertisements to you through our sites, email messages, text messages, applications, or other methods of communication;
- to manage our sites’ and services’ administration, forum management, or fulfillment;
- to provide customer service and technical support;
- to administer surveys, sweepstakes, giveaways, contests, or similar promotions or events sponsored by us or our partners;
- for internal purposes such as auditing, data analysis, and research to improve our products, services, and communications;
- to allow you to apply or sign-up for special offers from third parties through our sites and services;
- to perform services in conjunction with interactive tools, such as integrating practice management systems, making a referral; and
- to run (or authorize third parties to run) statistical research on individual or aggregate trends.
In addition to the uses described above, we may use personal information that we collect for other purposes that are disclosed to you at the time we collect the information, or with your consent.
4.2 Other Information We Automatically Collect Through Cookies and Other Technologies
We may use information collected from you through cookies and other tracking technologies in one or more of the following ways:
- to remember you when you return to our sites;
- to understand and analyze trends, to monitor usage, and learn about user behavior;
- to gather demographic information about our user base as a whole;
- to customize ads, content, or offers on our sites and services; and
- to conduct market research and measurement in order to improve our sites, content, and services and to make our sites, content, and services more useful for users.
5. Sharing Personal and Non-Personal Information
We may share your personal information with third parties in the following circumstances:
- when we engage third parties to perform services on our behalf. Such services include maintenance, hosting, data storage, security, analytics and data analysis, payment processing, marketing, email and text message distribution, customer service, and surveys and sweepstakes;
- when you communicate with us by email, submit an online form through our sites and services, request a quote or information, purchase a product or service, or otherwise submit a request through our sites and services, the personal information you provide may be shared with third parties to process or respond to your request, provide you with the products or services you requested, or complete a transaction, including a third party broker, aggregator, or other referral service to share or sell your information to a lender, dealer, or other financial institution in connection with your online request.
- where necessary to operate our sites and services, your personal information and the contents of all of your online communications on or through our sites and services may be accessed and monitored:
- to satisfy any applicable laws or regulations,
- to defend ourselves in litigation or a regulatory action,
- when we have a good faith belief that we are required to disclose the information in response to legal process (for example, a subpoena, court order, or search warrant),
- where we believe our sites and services are being used in the commission or possible commission of a crime, including to report such criminal activity or to exchange information with law enforcement and other companies and organizations for the purposes of fraud protection and risk management, and
- when we have a good faith belief that there is an emergency that poses a threat to the health and/or safety of you, another person, or the public generally;
- in the event of a merger, acquisition, debt financing, restructure, sale of our assets by or with another company, or a similar corporate transaction, we may need to disclose and transfer all information about you, including personal information, to the successor company;
- we may share information about you with our subsidiaries and affiliates and companies acquired by or merged with us and our affiliates, including without limitation, to enable such acquired or merged companies to advertise to you products and services in which you may be interested.
- We may share personal information about you for any other purpose(s) disclosed to you at the time we collect your information or with your consent.
- Non-personal information may be shared with our partners who referred you to our site(s) and who may use the data for their market research and measurement purpose. User information may also be shared with our partners who help us deliver ads to you on websites not controlled by us; for instance, when we put a pixel on a conversion page on our site and a marketing partner uses that pixel to optimize the traffic that they send to us.
6. Accessing and Updating Personal Information
We encourage you to keep your personal information up-to-date and accurate. The methods for accessing, viewing, correcting, and deleting your personal information will depend on which sites or services you use and their features. You have several choices; for instance:
- to view and change the personal information that you directly provided to us, you can return to the web page on our site where you originally submitted the data and follow the instructions on that web page;
- to correct or update your account information, you can log into the site or service where you are registered and navigate to your account;
- to close your account, you can log into the site or service where you are registered and navigate to your account;
- to change your email preferences, you can visit the email preferences page for the relevant site or follow the opt-out or unsubscribe instructions included in each email (for more information about email preferences, please see “Email and Other Communications” below); or
You can also manage certain aspects of information collection and use, including disabling geo-location, by going to the settings of your mobile device and reviewing the permissions of each application.
If you have questions about your options, please email us at privacy@CarEdge.com. Protecting your privacy and security is important and we also take reasonable steps to verify your identity before granting access to your data.
7. Storing Personal Information
8. Email and Other Communications
Our sites and services may allow us to communicate with you through our in-product instant messaging services, service-branded emails, SMS, and other electronic communication channels. You consent to receive such messages in such media using your email address or cell phone number that you provide to us.
8.1 Text Messaging
We may make available text messaging services in which you can receive messages from us and send messages to us on your mobile phone.
8.2 Opting Out of Requested Communications
Requested communications include, for instance, email newsletters and software updates that may be expressly requested by you or which you consented to receive. After you request such communications, you may “opt-out” of receiving them by using one of the following methods:
- selecting the email “opt-out” or “unsubscribe” link, or following the opt-out instructions included in each email communication;
- returning to the web page(s) where you originally registered your preferences and following the opt-out instructions; or
- Emailing us at privacy@CarEdge.com.
8.3 Opting Out of Transactional or Relationship Communications
Communications that are sent by or on behalf of a user are indicated as being from that user. Communications that are sent by us are indicated as being from us or one of our third party support providers. Either type of communication may be “real time” communications or communications triggered automatically upon the occurrence of certain events or dates. You may not be able to opt-out of receiving certain email messages, although our services may provide a means to modify the frequency of receiving them.
8.4 Opting Out of General or Promotional Communications
General communications provide information about products, services, and/or support and may include special offers, new product information, or invitations to participate in market research. You may opt-out of receiving these general communications by using one of the following methods:
- selecting the email “opt-out” or “unsubscribe” link, or following the opt-out instructions included in each email communication; or
- Emailing us at privacy@CarEdge.com.
9. Protecting Personal Information
To prevent unauthorized access, maintain data accuracy, and ensure the appropriate use of the information we collect, we deploy a wide range of technical, physical, and administrative safeguards, including: Transport Layer Security (TLS), firewalls, system alerts, and other information system security technologies; and regular evaluation and enhancement of our information technology systems, facilities, and information collection, storage, and processing practices. We use reasonable and appropriate administrative, physical, technical, and data security procedures and controls to safeguard your personal information against unauthorized access, disclosure, loss, misuse, and alteration. Under applicable law, we are required to apply reasonable and appropriate measures to safeguard the confidentiality, integrity and availability personal information residing on and processed by our sites and services.
We use third-party service providers to manage credit card and payment processing. These service providers are not permitted to store, retain, or use billing Information except for the sole purpose of credit card and payment processing on our behalf. When you enter payment information to be processed by our third party service providers, we encrypt the transmission of that information using transport layer security (TLS) technology and do not store it on our systems.
It is important to remember, however, that no system can guarantee 100% security at all times. Accordingly, we cannot guarantee the security of information stored on or transmitted to or from our services. We cannot assume responsibility or liability for unauthorized access to our servers and systems. When disclosing any personal information, you should remain mindful of the fact that it is potentially accessible to the public and, consequently, can be collected and used by others without your consent. Accordingly, you should carefully consider if you want to submit sensitive information that you would not want disclosed to the public and should recognize that your use of the Internet and our sites and services is solely at your risk. You are ultimately responsible for maintaining the secrecy for all your personal information, including your protected health information. We have no responsibility or liability to anyone for the security of your personal information transmitted via the Internet.
10. Linked Websites and Services
We may also provide social media features on our sites and services that enable you to share personal information with your social network(s) and to interact with our sites and services. Depending on the features, your use of these features may result in the collection or sharing of personal information about you. We encourage you to review the privacy policies and settings on the social media site(s) with which you interact.
11. Children’s and Minor’s Privacy
Children under the age of 13 are not permitted to use our sites and services. We do not knowingly collect personal information from children under the age of 13 or utilize plug-ins or ad networks that collect personal information through child-directed third-party websites or online services. If we learn that we have collected personal information from a child under 13, we will take steps to promptly delete such information.
Our sites and services generally require users to be at least 18 years of age. Unless our sites and services contain the “Privacy Rights for California Minors in the Digital World” supplemental terms, our sites and services do not collect age from users under 18. Without limiting the generality of the foregoing, our services may allow users above the age of 18 (such as parents, and guardians) to submit personal information of minors. Such users assume full responsibility over their submission, use, and transmission of such information.
We are headquartered in the United States. Our sites and services are intended for users in the United States and are hosted and administrated in the United States or hosted with cloud service providers who are headquartered in the United States and in other countries. If you are located outside the United States, be aware that information you provide to us or that we obtain as a result of your use of our sites and services may be processed in, transferred to, and stored in the United States and in any other countries from where our cloud service providers operate. Please be aware that the privacy laws and standards in certain countries may differ from those that apply in the country in which you reside. By using our sites and services or providing us with your information, you consent to the transfer of your information for processing and storage to the United States and any other country from where our cloud service providers operate.
13. California Privacy Rights
This section is provided pursuant to the California Consumer Privacy Act of 2018 (the “CCPA”) and other applicable California privacy laws. This section applies solely to our users who are California residents as defined under applicable California privacy laws.
13.1 Information We Collect
Within the last twelve (12) months, we have or may have collected the following categories of information from our users and/or consumers:
- identifiers, such as a name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account name, or other similar identifiers;
- characteristics of protected classifications under California or federal law;
- commercial information, such as records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies;
- Any data from your usage of services in connection with our sites or services;
- biometric information;
- Internet or other similar network activity, such as browsing history, search history, usage of, and information regarding your interaction with our sites or services;
- geolocation data. When you use our sites or services, we may access, collect, monitor, and/or remotely store session and geolocation information from your device to connect you with dealers in your area. Geolocation information includes data such as your device’s physical location and may include GPS-based, WiFi-based or cell-based location information.;
- professional or employment-related information;
- Audio information may be collected when you place a call with our customer service or accounting centers for quality control purposes;.and
- inferences drawn from any of the information identified in this section to create a profile about users reflecting user preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes, which we use for product and service enhancement and optimization purposes.
13.2 Categories of Sources from Which Information is Collected
We obtain the categories of personal information listed above from the following categories of sources:
- directly from users, such as you, as described above under “Personal Information that You Provide to Us”;
- indirectly from other users of our sites and services;
- indirectly from third-parties that interact with us in connection with the services that we perform; and
- directly and indirectly through cookies and other technologies, as described above under Section 2 “Other Information We Automatically Collect through Cookies and Other Technologies.”
13.3 Using and Sharing of Personal Information
The personal information described in the categories above may be used for the business purposes listed above under Section 4, “How We Use Personal Information.”
We disclose your personal information for a business purpose to the following categories of third parties: (a) service providers and (b) third parties to whom you authorize or direct us to disclose your personal information in connection with our sites and services. In the preceding twelve (12) months, we have disclosed the personal information described in the categories above for the business purposes listed above under “Sharing Personal and Non-Personal Information.” We also may share personal information about you for any other purpose(s) disclosed to you at the time we collect your information or with your consent.
13.4 Personal Information “Sold” to Third Parties
We may share information that we have about you, such as a cookie ID or IP address, with third-party marketing partners who may use this information, on our behalf, to help us deliver advertising on our sites as well as on third-party websites.
In the preceding twelve (12) months, we have made available personal information included in the categories described above to third parties, including our third-party marketing partners to deliver advertising.
We do not sell the personal information of consumers that we know are minors under 16 years of age without affirmative authorization as required under the CCPA.
13.5 Your Access and Deletion Rights under the CCPA
As of January 1, 2020, California residents, as defined under applicable California privacy laws, may take advantage of the following rights:
- You may request, up to two (2) times each year, that we disclose to you, once we receive and confirm your verifiable consumer request, the: (i) categories and specific pieces of personal information that we have collected about you; (ii) categories of sources from which your personal information is collected; (iii) business or commercial purpose for collecting your personal information; (iv) categories of personal information that we disclosed for a business purpose; (v) categories of personal information that we sold about you; (vi) categories of third-parties with whom we have shared your personal information; and (vii) business or commercial purposes for selling your personal information.
- Subject to certain exceptions and up to two (2) times each year, you may request that we delete any of your personal information that we collected from you. Once we receive and confirmed your verifiable consumer request for deletion, we will delete (and direct our service providers to delete) such personal information from our records, unless an exception applies.
- We will deliver personal information that we are required by law to disclose to you in the manner required by law within 45 days after receipt of a verifiable request, unless we notify you that we require additional time to respond, in which case we will respond within such additional period of time required by law. We may deliver the personal information to you through your account, if you maintain an account with us, or, if not, electronically. If electronically, then we will deliver the information in a portable and, to the extent technically feasible, in a readily useable format that allows you to transmit the information from one entity to another without hindrance.
13.6 Exercising Your Access and Deletion Rights under the CCPA
To exercise the access and deletion rights described above, please submit a request to us by sending an email to privacy@CarEdge.com.
You will be asked to provide certain identifying information, such as your name, email, and residency. You will also be asked to validate your request by clicking a validation link in an email that will be sent to the email address you provided. While processing your request, we may ask you to provide further verifying documentation, such as proof of residency and identity. We will only use personal information provided in a request to verify the requestor’s identity or authority to make the request.
Your request must: (i) provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or that you have authority to make the request; and (ii) describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
Only you or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child. If you are making a request through an authorized agent acting on your behalf, such authorized agent must provide proof of written authorization to do so, and you must verify your identity directly with us, unless such authorized agent provides proof of a power of attorney pursuant to Probate Code sections 4000 to 4465.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
13.7 Opting-out of the Sales of your Personal Information
Subject to certain exclusions under the CCPA, you have the right to opt-out of the sale of your personal information. Once we receive your request, we will not sell your personal information, unless an exclusion applies.
To i) opt-out of the sale of your personal information that we collect through cookies and other technologies; or ii) to opt-out of the sale of your personal information that we collected directly from you or other third-parties, please submit a request to us by sending an email to privacy@CarEdge.com.
We may deny your request to opt-out if we have a good-faith, reasonable, and documented belief that the request is fraudulent.
We will not discriminate against you for exercising any of your rights under the CCPA. Accordingly, and unless permitted by the CCPA, we will not:
- deny you goods or services;
- charge you different prices or rates for goods or services, including through the use of discounts or by imposing penalties;
- provide you a different level or quality of goods or services; or
- suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
We may charge a different price or rate or provide a different level of service if the difference is reasonably related to the value provided by your personal information.
13.9 Other Applicable California Privacy Laws
Section 1798.83 of the California Civil Code requires select businesses to disclose policies relating to the sharing of certain categories of your personal information with third parties. If you reside in California and you have provided us with your personal information, you may request information about our disclosures of certain categories of your personal information to third parties for direct marketing purposes. To make such a request, please send a request to us by sending an email to privacy@CarEdge.com. We will not accept requests via the telephone, mail, or by facsimile, and we are not responsible for notices that are not labeled or sent properly, or that do not have complete information.
In accordance with Section 22581 of the California Business and Professions Code if you are a California resident under the age of 18, you may request and obtain the removal of content or information you have publicly posted. To make such a request, please send a request to us by sending an email to privacy@CarEdge.com.. Please specify the site(s) or service(s) to which your removal request relates, including any URLs where the content or information is posted, and the specific content or information you posted for which you are requesting removal. Please be aware that such a request does not ensure complete or comprehensive removal of the content or information you have posted and that there may be circumstances in which the law does not require or allow removal even if requested.
14. Nevada Privacy Rights
FOR RESIDENTS OF NEVADA ONLY. In accordance with SB 220, Nevada consumers may opt-out of the sale of their personal information to third parties. If you reside in Nevada and you have provided us with your personal information, you may choose to opt-out of the sale of such personal information by sending an email to privacy@CarEdge.com, with “Nevada Privacy Right” in the subject line. We may request for additional information from you in order to verify your identity and/or the authenticity of your request.
15. Contacting Us
Last Updated: July 10, 2020