DealerTasker by ShiftScale

● LEGAL

Data Processing & Security

Effective July 8, 2026. ShiftScale Digital LLC. Headquartered in Michigan, US.

Effective date: July 8, 2026
Last updated: July 8, 2026

This page explains how ShiftScale Digital LLC (“ShiftScale,” “we,” “us”) accesses, processes, and protects data in connection with the DealerTasker platform (the “Services”), including data drawn from a dealership’s connected business systems. It supplements our Privacy Policy and is intended to satisfy the data-handling disclosure requirements of the integration marketplaces through which our application may be listed.

1. Our role

For data about a dealership’s own customers and prospects (“Consumer Data”), the dealership (“Dealer”) is the controller and ShiftScale is a service provider / processor. We process Consumer Data only:

  • on the Dealer’s documented instructions;
  • to provide, maintain, secure, and improve the Services for that Dealer; and
  • as required by applicable law.

We do not sell Consumer Data, do not use it for our own independent marketing, and do not use it to build profiles for purposes unrelated to serving that Dealer.

2. Data from connected dealership systems

With the Dealer’s authorization — granted through the Dealer’s own accounts and, where applicable, the relevant integration marketplace’s authorization flow — the Services connect to third-party dealership management, CRM, scheduling, inventory, recall/vehicle-data, and communications systems.

  • Least-privilege access. We request only the data fields and permissions necessary to deliver the features the Dealer has enabled.
  • Purpose limitation. Data retrieved from a connected system is used solely to provide the Services to that Dealer.
  • Direction of flow. Depending on the feature, we read data from and/or write data back to connected systems, always at the Dealer’s direction.
  • Authorization and revocation. The Dealer controls the connection and may revoke it at any time through the connected system or by contacting us; revoking access stops further data exchange.
  • No onward misuse. We do not repackage or resell connected-system data, and we do not share it except with the sub-processor categories below or as directed by the Dealer.

3. Categories of data processed

Depending on enabled features: business and account details; user credentials/identifiers; consumer contact details; vehicle information; sales, service, and appointment records; communications content and metadata (calls, texts, emails, chat); and usage/technical data. We instruct Dealers not to send special categories of sensitive data that the Services are not designed to handle.

4. Sub-processors (by category)

We engage vetted third parties to help deliver the Services. They may process data only to perform services for us and are bound by confidentiality and data-protection obligations. Categories include:

  • Cloud hosting and database infrastructure (United States).
  • Communications infrastructure for voice, SMS, and email delivery.
  • AI/model providers that generate summaries, messages, and recommendations from provided content.
  • Payment processing for billing.
  • Analytics, logging, and error-monitoring to operate and secure the Services.

We identify sub-processors by category rather than by name. Where an integration marketplace, a Dealer agreement, or applicable law requires a named, itemized sub-processor list, we will maintain and provide one on request.

5. Security measures

We maintain administrative, technical, and organizational safeguards appropriate to the nature of the data, including:

  • Encryption of data in transit (TLS) and at rest;
  • Access controls — role-based, least-privilege access for our personnel, and per-Dealer data isolation so one Dealer cannot access another’s data;
  • Secrets management for credentials and API keys;
  • Authentication controls for platform access;
  • Auditing and logging of significant actions;
  • Network and application controls with reputable U.S.-based infrastructure providers; and
  • Change management and monitoring, including automated alerting on integration health.

No safeguards can guarantee absolute security. We describe our actual operational controls above and will update this page if our certifications change.

6. Data retention and deletion

Consumer Data is retained for the duration of the Dealer’s engagement and deleted or returned upon termination as set out in the applicable agreement, subject to legal retention requirements and routine, time-limited backups. Dealers may request export or deletion of their data by contacting us.

7. Incident response

We maintain procedures to detect, investigate, and respond to security incidents. If we become aware of a breach affecting Consumer Data, we will notify the affected Dealer(s) without undue delay and cooperate as required by applicable law and our agreements.

8. International processing

The Services are hosted and operated in the United States. By using the Services, Dealers acknowledge that data is processed in the United States.

9. Contact

Security or data-processing questions: support@shiftscaledigital.com · (810) 788-7810
ShiftScale Digital LLC, headquartered in Michigan, US.

This page is provided for general informational purposes and does not constitute legal advice.

Build your package.