DealerTasker by ShiftScale

● SECURITY + COMPLIANCE

How we handle your data and your customers'.

Dealerships handle consumer financial information under GLBA, the FTC Safeguards Rule, TCPA, state privacy laws, and OEM data agreements. Vendors handling that data are in scope. Here's how our production controls line up.

● IN PLACE TODAY

Production controls.

DATA STORAGE

US-hosted, encrypted at rest and in transit.

Production data resides in US-based cloud infrastructure. AES-256 encryption at rest, TLS 1.2+ in transit. Per-dealer logical isolation — your dealership's data is segregated from every other customer's data at the database row level.

TCPA + STATE PRIVACY

Quiet hours, STOP/HELP, opt-out by default.

Outbound SMS and voice respect per-state quiet hours, including dual-time-zone handling for traveling customers. STOP/UNSUBSCRIBE triggers immediate opt-out across all channels. HELP returns a contact-info reply. CCPA, Virginia CDPA, and Colorado CPA rights requests supported.

A2P 10DLC

Brand + campaign registration handled.

We handle A2P 10DLC brand registration with The Campaign Registry and per-use-case campaign registration end-to-end during onboarding. Most BDC competitors leave this to the dealer.

AI MODEL DATA

No customer data trains foundation models.

AI agents are powered by current-generation models from leading providers. Customer conversation content stays within your dealership's data perimeter — we do not train foundation models on your data, and we do not share conversations across customers.

VENDOR OVERSIGHT

Third-party processor controls.

Each sub-processor is contractually bound to comparable data-handling standards. Annual review of each vendor's posture. Full sub-processor list available on request.

INCIDENT RESPONSE

Documented escalation, customer notification.

Documented incident response procedure with named escalation contacts. Customers are notified of incidents affecting their data within carrier-mandated and state-mandated windows. Post-incident report shared with affected customers.

FTC SAFEGUARDS

Aligned to the Safeguards Rule.

The FTC Safeguards Rule (effective June 2023) applies to financial institutions including dealers with F&I operations. We operate as a service provider under that rule with a designated Qualified Individual, a written information security program, and annual review documented.

CONTROL MAPPING

Mapped to industry trust principles.

Our production controls are mapped to widely adopted trust principles covering security, availability, processing integrity, confidentiality, and privacy. Full controls matrix available under NDA.

● ROADMAP

What's next.

FORMAL ATTESTATION

Third-party attestation on the roadmap.

Formal third-party attestation of our control environment is on the roadmap. Controls are already mapped and operating; independent observation is the next step.

TCPA LITIGATOR SCRUB

Blacklist Alliance integration roadmapped.

Pre-send scrubbing against known TCPA-litigator databases is on the roadmap. Today, consent capture, opt-out enforcement, and quiet-hours discipline form the primary layer of defense; litigator-list scrub is the next layer.

OEM VENDOR PROGRAMS

Approvals in motion per customer.

OEM Digital Vendor Program approvals are pursued per customer as needed. If your OEM requires vendor certification, we'll walk it through with you during onboarding.

Want the controls matrix?

Full control mapping (against industry trust principles + FTC Safeguards Rule + state privacy laws) available under NDA. Email support@shiftscaledigital.com or request on your demo call.

Build your package.