No behavioral ad network
Infrastructure sees ordinary request metadata. Public forms create a local email draft and submit nothing automatically.
Privacy policy
This policy describes how the current VehicleDesk website and managed workspace handle information today. It separates implemented behavior from future integrations and does not turn planned controls into production claims.
At a glance
VehicleDesk processes shop operating data for enabled workflows. The public site does not intentionally use behavioral advertising trackers. Plaid Link and Plaid consumer data are not part of the current production application.
Infrastructure sees ordinary request metadata. Public forms create a local email draft and submit nothing automatically.
Roles and capabilities limit access to customer, vehicle, service, payment, consent, and operational records.
VehicleDesk stores consent and suppression evidence. Those controls do not create universal consent for every CRM record.
Plaid Link, access-token storage, synchronization, and Plaid financial records are not deployed in production.
This policy covers the live VehicleDesk marketing website and authenticated VehicleDesk workspace. VehicleDesk is a managed operating layer for independent repair shops; enabled workflows, support expectations, data roles, and integrations depend on the shop's approved implementation or commercial arrangement.
This page describes current production behavior. It does not claim that draft legal documents, repository-only checks, future integrations, or planned workflows are already operating.
The authenticated workspace can process information needed for enabled shop workflows, including:
Shopmonkey remains authoritative for supported source repair and financial records imported through configured integration paths. VehicleDesk separately stores locally managed workflow, audit, consent, suppression, and operational records required for its own features.
VehicleDesk stores communication-consent and suppression evidence, including contact-point status, authorized recurring-SMS categories, disclosure references, consent and revocation timestamps, and source-document references.
When an approved recurring-SMS disclosure is available, the customer portal requires the user to select categories and affirmatively agree before enrollment. It also provides a stop action. Staff may record that a customer requested a reminder without silently changing the customer's SMS consent.
VehicleDesk shares information only as needed to operate an enabled feature, follow an authorized shop instruction, protect the service, or meet an applicable legal obligation.
The public website does not intentionally use a behavioral advertising network. VehicleDesk does not currently represent personal information as sold for behavioral advertising.
VehicleDesk does not claim that every database field is individually encrypted, that every hosted security workflow is currently executing, or that the service is SOC 2 certified.
VehicleDesk does not currently publish a universal time-based retention schedule covering every application table, provider log, backup, export, and subprocessor. Records follow their implemented product lifecycle, shop operations, source-system behavior, and provider configuration.
Before Plaid is enabled, VehicleDesk requires a separately approved pre-Link notice and consent flow, product and account minimization, encrypted token custody, authorization history, retention, disconnection, export, deletion, backup, and operational evidence.
A monitored public privacy-request mailbox or public privacy-request form is not configured in the current production environment. Outside privacy requests are not accepted through the public website today.
Existing workspace users should use the approved implementation or commercial support channel supplied to their shop. A shop remains responsible for requests concerning customer data it controls.
VehicleDesk is a business application for repair shops and staff and is not directed to children.
This policy will be reverified when the production release, hosting architecture, public contact configuration, provider activation, retention or deletion behavior, shop agreement, or privacy practices materially change.
This is a current operational policy, not legal advice or a compliance certification. It has not been represented as reviewed by external privacy counsel.