Introduction and Scope
DriveSuite CRM ("DriveSuite," "we," "us," or "our") provides software, websites, public schedulers, lead tools, dashboards, mobile apps, and related services for automotive service businesses. This Privacy Policy applies to account users and visitors to DriveSuite-hosted pages in the United States.
Some public pages are operated for a tenant business. A tenant-provided privacy addendum may appear below this policy and supplements, but does not replace, this policy.
Information We Collect
- Account, business, subscription, authentication, role, and settings information.
- Customer and appointment records provided to a tenant, including contact and vehicle details and operational records.
- Controlled authenticated feature categories, such as customers, appointments, pricing, marketing, settings, dashboard, reports, and team; login counts; feature changes; and periodic activity heartbeats. We do not use full route query strings for this telemetry.
- Public scheduler loads, DriveSuite marketing-link redirects, scheduler progress, submissions, bookings, device/browser details, coarse location, and consent choices.
- Aggregate counts and first/last-view times for secure estimate, invoice, and appointment links. These operational link-view counts do not store a visitor ID, device ID, network-derived ID, or session replay and do not create lead sessions.
- Approximate network identifiers derived from IPv4 /24 or IPv6 /64 prefixes using a versioned keyed hash. These identifiers and exact IP addresses are not displayed in browser admin interfaces.
- Security and abuse evidence, including encrypted raw IP addresses retained for a short period and inferences about request velocity, account sharing, authorization failures, cross-tenant attempts, endpoint enumeration, or scraping behavior.
Cookies, Consent, and Global Privacy Control
Before an optional consent choice, DriveSuite uses only first-party operations needed for booking, authentication, security, abuse prevention, preferences necessary to complete a flow, and aggregate link-load counts. Persistent visitor analytics, marketing storage, and session replay require a separate affirmative choice.
The consent interface provides Accept All, Reject Optional, and Customize choices. Global Privacy Control is honored for applicable sale, sharing, and targeted-advertising opt-outs. Rejecting optional consent does not disable necessary booking and security operations.
How We Use Information
- Provide, authenticate, secure, maintain, and improve DriveSuite.
- Operate scheduling, quoting, customer, appointment, invoice, message, and tenant workflows.
- Measure tenant adoption and booking conversion using aggregates.
- Detect abuse and license or access-control violations using explainable, evidence-based signals.
- Create aggregated or de-identified benchmarks that do not identify an individual or expose a tenant's private records.
- Comply with law, respond to rights requests, enforce agreements, and protect users and the Service.
Administrative Access and Monitoring
Authorized App-Admin personnel may view aggregate tenant activity and risk information for support, security, legal requests, and account operations. Masked customer previews and tenant impersonation require a time-limited break-glass grant, a stated reason, recent authentication, and an append-only audit event. Preview fields are limited and exclude notes, messages, addresses, vehicles, payments, exports, and free text.
Broad feature exploration is treated as neutral product-evaluation activity. Feature exploration, same-network traffic, or IP diversity alone is not sufficient evidence of piracy or misuse. Severe evidence may cause rate limiting of an offending session or network, but does not automatically suspend a tenant.
Retention
- Encrypted raw-IP security evidence: up to 7 days.
- Pseudonymous detailed activity events: up to 90 days.
- Daily tenant aggregates and App-Admin audit events: up to 365 days.
- Legal acceptance and denial records are maintained as business and compliance records as permitted by law.
- Other account and customer records are retained as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements, subject to tenant settings and applicable rights.
Sharing and Service Providers
We share information with the tenant a visitor interacts with, providers that host or secure the Service, payment and communication providers when used, integrations authorized by a tenant, and government or other parties when legally required or necessary to protect rights and safety. We do not sell personal information for money.
U.S. State Privacy Rights
Depending on state law, you may have rights to access, know, correct, delete, or obtain a copy of personal information; opt out of certain sale, sharing, targeted advertising, or profiling; limit certain sensitive-data uses; appeal a decision; and avoid discrimination. Email privacy@drivesuite.com to submit a request. We may verify identity and direct tenant-controlled record requests to the relevant tenant.
Security, Children, and Changes
We use administrative, technical, and physical safeguards designed to protect information, but no system is perfectly secure. DriveSuite is not directed to children under 13. We may update this policy, and authenticated users may be required to acknowledge a new version before continuing.
Contact
DriveSuite CRM Attn: Privacy Team PO Box 535 Marlboro, NY 12542 Email: privacy@drivesuite.com
