LEVELS DEALER OS · LEGAL
Privacy Policy
Last updated September 5, 2026
- Effective date: September 5, 2026
- Operated by: Levels Tech LLC, doing business as "Levels" ("Levels", "we", "us")
- Website: https://levels.dealer
- Privacy contact: admin@levels.dealer · 5151 N Oracle Rd Ste 125, Tucson, AZ 85704
This policy explains what personal information Levels Dealer OS collects, how we use it, who receives it, and the choices you have. It is written in plain English on purpose. Where a feature is optional, not yet switched on, or does less than it will later, we say so. It describes the product as it is built today, and we update it when the product changes.
For dealership customers: the short version
If you contacted, bought from, financed with, or consigned a vehicle to a dealership that uses Levels, here is what matters most.
- The dealership decides what information to ask you for. Levels is the software the dealership uses to store and work with that information.
- Your information sits in that dealership's own separated area of our system. Other dealerships cannot see it.
- Social Security numbers and driver's license numbers are stored encrypted. Staff normally see only the last four digits. Revealing a full Social Security number requires the highest access level and is logged every time. Your full license number is used only to fill paperwork that requires it.
- A credit check runs only after you agree to a written notice that names the dealership and the credit bureau. Website prequalification checks are soft inquiries and do not affect your score.
- Texts and calls come from the dealership's own phone number. Reply STOP to stop texts from the number that sent them. Calls with the dealership may be recorded and transcribed.
- We never sell your personal information. We do not put advertising cookies or tracking pixels on dealer websites.
- Dealer websites do remember your browser with a random ID. If you fill out a form, or open a link the dealership texted you, the dealership can see which vehicles you viewed.
- To see, correct, or delete information a dealership holds about you, contact the dealership. You can also write to us at admin@levels.dealer and we will route your request.
1. Who we are and what this policy covers
Levels Dealer OS is a software platform for independent used-car dealerships. We call the platform "Levels Dealer OS" or simply "Levels".
This policy covers personal information handled through:
- the staff application at https://levels.dealer, including the dealer web app and the mobile app promoted at dealers.app;
- dealer websites we host for free at
{dealer}.levels.dealerand on dealership-owned domains connected to Levels; - customer-facing pages we run for dealerships: the customer portal, payment and deposit links, appointment booking links, e-signature links, trade-in and consignment forms, and test-drive authorization pages;
- the Levels AI shopping layer, which includes our agent API and our ChatGPT connector, for dealerships that opt in;
- Levels' own marketing pages, including levels.dealer, dealers.app, and bids.bot;
- the pages at https://levels.dealer/privacy and https://levels.dealer/terms themselves, which load fonts from Google Fonts (see Section 10.10).
This policy does not cover the dealership's own practices outside our software. Each dealership is a separate business with its own privacy notice. Each dealer website we host also shows a short privacy page and a text-messaging page for that dealership. Those pages describe the dealership's program in short form. They incorporate this policy for everything Levels does with your information, and if the two ever differ, this policy governs Levels' practices. This policy also does not cover third-party sites you reach by clicking a link, such as CARFAX, AutoCheck, or Google Maps, or the ChatGPT product itself.
2. Who this policy is about
We handle information about five groups of people:
- Dealership staff. Owners, managers, salespeople, lot and service staff who use Levels. The dealership is our subscriber.
- Dealership customers. People a dealership deals with: shoppers, leads, buyers, borrowers, co-buyers, finance applicants, consignors, test drivers, and job applicants. Dealerships enter this information, import it, or collect it through the websites and links we host.
- Website visitors. Anyone who browses a dealer website we host, even without submitting a form.
- AI-assistant shoppers. People who use an AI assistant such as ChatGPT to search a participating dealership's inventory through our connector.
- Prospective dealerships and people who contact Levels. Dealership businesses we market to, people who join a waitlist, and people who register a Levels account.
3. Dealerships are in charge of their customers' data; Levels is their service provider
The dealership decides. A dealership decides what to collect from its customers, which features to turn on, which outside systems to connect, and how long to keep records. Under privacy laws, the dealership is the "business" or "controller" for its customers' information. Levels is the dealership's "service provider" or "processor".
What that means for us. We process dealership customer information only to run the software the dealership has chosen to use. We follow the dealership's instructions. We do not combine one dealership's customer records with another's. We do not use dealership customer information for our own marketing. We do not sell it.
What that means for the dealership. The dealership is responsible for giving its customers any notices and getting any consents the law requires. That includes credit-authorization language, text-message consent, call-recording notices, and permission to publish a customer's photo. Levels builds consent steps into the software where we can, but the dealership is responsible for using them correctly.
Where Levels acts on its own behalf. We are the controller of information about dealership staff accounts, dealership billing, platform security and audit logs, aggregate product usage, our own marketing to dealerships, the shopper profiles created through our AI shopping layer (Section 7), and our own part in the credit-check notice described in Section 9.1.
4. Information we collect from dealerships and their staff
Account information. Full name, work email, phone number, role (owner, manager, sales, lot, service), department, and a password we store only as a one-way hash. The dealership's owner may assign each staff member a credit-data access level, and each staff member sets their own 4-digit deal-vault PIN, which is stored as a hash.
Business information. Dealership name, street address, lot addresses and map coordinates, phone numbers, website, timezone, business hours, dealer license number, sales-tax registration numbers, and, for text-messaging registration with carriers, the legal business name, EIN, business type, and an authorized representative's name, email, and phone.
Connections to other services. If a dealership connects QuickBooks Online, a credit-report provider, a Google Business Profile, Craigslist, a DMS lead-import address, or Keys.app, we store the credentials or tokens needed to use that connection. QuickBooks, credit-provider, and Google tokens are encrypted at rest.
Activity and audit records. We record who did what inside the platform. For sensitive actions we also record the IP address and browser type. Examples include viewing a credit report, revealing a full SSN or license number, changing a vehicle price, signing a document, exporting tax records, and accepting a locksmith agreement. Staff who clock in and out share their phone's location at that moment so the dealership can see whether the punch happened on the lot.
Device diagnostics. When the in-app license or VIN scanner fails to read a barcode, it may send the failed image and device details (camera resolution, browser type, app version) to a diagnostics area on our own servers that only the dealership's owners and managers can open. Diagnostic images are deleted after 30 days.
Billing. Plan tier, billing cycle, trial dates, and promo code. Subscription fees and prepaid bundles are charged to a payment card the dealership keeps on file with Stripe, our payment processor. Card details are entered on Stripe's own pages and go directly to Stripe under Stripe's privacy policy; Levels stores only the card brand, last four digits, and expiration to show the dealership, plus Stripe's customer, subscription, and invoice references. The dealership chooses auto-pay (charged on the due date) or an emailed invoice. Stripe emails receipts and invoices to the dealership's billing email.
Prospective dealerships. Levels markets to dealership businesses. We obtain business contact details (dealership name, phone, email, website, address, license number) from public dealer directories and similar sources. We may text, email, or message these businesses from Levels' own number and email address. We log the outreach and whether a demo link was opened. Replying STOP to Levels' own number stops our texts, and we do not contact businesses marked do-not-contact.
Support access by Levels staff. Authorized Levels employees can enter a dealership's workspace to provide support. Inside, they see what the dealership's owner sees, including customer records. Every support entry is limited to one hour, is written to a permanent audit log, and shows a visible "HQ support session" banner in the app.
5. Information dealerships collect about their customers through Levels
The dealership chooses which of these features to use. This section describes what each feature collects.
Contact and lead information. Name, phone, email, the vehicle you asked about, your message, a preferred appointment time, and how you found the site (search terms, campaign, referring site). Leads also arrive from marketplaces the dealership advertises on, such as CARFAX, CarGurus, AutoTrader, Cars.com, Edmunds, TrueCar, and Facebook, by email to a dealership address we host.
Price alerts. Name and phone or email, plus the vehicle you asked to watch. The dealership texts or emails you a link right away and again each time the price drops, until the watch is turned off.
Appointments. Name, phone or email, chosen time, notes, and any reason you give for cancelling. You receive confirmation and reminder messages with a link to reschedule or cancel.
Financing and credit. Everything on a credit application: name, phone, email, date of birth, Social Security number, driver's license number and state, current and previous address, employer, job title, time on the job, monthly income, housing status and payment, down payment, and the vehicle. Prequalification requests collect similar identity fields plus a self-reported financial profile. Section 9.1 explains how this data is protected and when a credit bureau is contacted.
Identity documents. A dealership may scan your driver's license at the counter for a test drive or a sale. The barcode is decoded on the device to capture your name, address, date of birth, and license expiration. A photo of the front of the license may be stored privately for identity verification. See Section 9.2.
Deals and signed paperwork. Vehicle, price, taxes and fees, payments, trade-in details, co-buyer details, and the documents you sign. E-signatures are drawn on screen and stored as images with the evidence described in Section 9.6. The signed packet is delivered to you, the dealership, and the salesperson.
In-house loans and payments. If the dealership finances you directly, we store the loan terms, a payment ledger, and reminders sent to you. Payment records include the amount, method (cash, check, card in person, or link), and any signed receipt. See Section 9.7 for what we do and do not handle about payment cards.
Requested documents ("stips"). If the dealership asks you for documents such as pay stubs or proof of residence, you upload them through a private link. Only the dealership's staff can open them.
Communications. Texts you exchange with the dealership, including photos you send; calls to and from the dealership, including recordings, voicemails, and transcripts; and emails we send on the dealership's behalf. See Sections 9.3 and 9.4.
Trade-ins and consignments. Name, phone, email, vehicle year, make, model, VIN, mileage, condition, photos you upload, lien and payoff information, and, for consignments, the price you hope for and the signed consignment agreement. Your signed consignment agreement, which shows your name, contact details, vehicle, signature, IP address, and device, and the photos you upload are currently stored at unlisted web addresses on the dealership's site that anyone holding the exact link can open. We are moving these behind signed links.
Test drives. Who took which vehicle, when it left and returned, the odometer, the dealer plate used, and your name and address from your license. If you authorize it, your phone's location during a solo drive. See Section 9.5. Dealerships may print state-required plate audit records from this log.
Delivery photos. After a sale, the salesperson may take a photo of you with your new vehicle and upload it through a link we text them. Photos uploaded this way are published on the dealership's public website "happy customers" section with your first name and vehicle by default. Staff can remove a photo from the gallery or delete it at any time. Levels does not collect your consent for this publication; the dealership is responsible for asking your permission before uploading, and you can ask the dealership or us to remove a photo.
Job applications. Name, phone, email, and experience you describe on a dealership's careers page.
Records imported from the dealership's old systems. A dealership may upload its existing customer and lead lists into Levels. We keep the original rows for the dealership's reference. We carry over any opt-out flags in the file and never treat an imported record as having opted in.
Your customer file. Dealership staff see one combined file for you that brings together your leads, deals, loans, messages, calls, appointments, documents, credit prequalification tier, and website activity linked to you.
The dealership's vendors. When a dealership sends a vehicle to an outside repair shop, requests a tow, or asks a title agency for a status check, we text or email that vendor the vehicle's stock number, VIN, year, make, model, and the dealership's notes. A title-status request also includes the customer's name.
6. Website visitors: cookies, local storage, and linking browsing to a person
What we store in your browser. Dealer websites do not use third-party analytics cookies, advertising cookies, or tracking pixels. They do store a few values in your browser's own storage:
- a random visitor ID (no name or contact details) that persists until you clear your browser storage;
- a per-tab session key and where the visit came from (search terms, campaign tags, referring site);
- conveniences such as recently viewed vehicles, your chosen list view, and a temporary prequalification result token.
What we record about your visit. As you browse, the site sends events to our servers: page views, searches, filters, vehicles viewed, photo swipes, price-breakdown opens, and button clicks such as "call" or "text". Each event carries your random visitor ID, the session key, and the source of the visit. We do not store your IP address or browser type with these browsing events; we use your IP address in memory only to limit abusive traffic. We do record your IP address and browser type when you give a consent or sign something, as Sections 9.1, 9.5, and 9.6 describe.
How browsing gets linked to you. This is the part most sites do not explain, so we will. Your browsing is anonymous until one of two things happens:
- You submit a form on the site (a lead, price alert, application, prequalification, or trade-in). At that moment your visitor ID is linked to the record you created, including the vehicles you looked at before you submitted the form.
- The dealership texts you a link to a vehicle and you open it on your phone. The link carries a signed one-time token. Opening it links that phone's browser to your customer record.
Once linked, dealership staff can see which vehicles you viewed, how many times, and when, and your earlier and later browsing under that visitor ID is attributed to you. The dealership may use this to follow up, for example by texting you about a vehicle you viewed several times, subject to the consent rules in Section 9.4. If several people identify themselves on the same browser, we stop attributing that browser's activity to any one person.
Your choices. Clearing your browser storage, or using a private window, resets the visitor ID. Replying STOP to a dealership's texts stops texts from that number. You can ask the dealership to remove browsing history from your file.
Third-party resources the site may load. Depending on the dealership's design choices, your browser may load fonts from Google Fonts, video players from YouTube (in privacy-enhanced mode), and links to Google Maps for directions. When those load, Google receives your IP address and browser type under Google's privacy policy. Vehicle history buttons open CARFAX or AutoCheck with the vehicle's VIN; those sites see your visit under their own policies.
Search engines. Dealer websites are public and indexable. They publish the dealership's name, address, phone, and live inventory, and the "happy customers" section described in Section 5.
7. Shopping through an AI assistant (ChatGPT connector)
Levels offers an AI shopping layer that lets AI assistants search participating dealerships' inventory. This layer is off by default. It works only for dealerships that have opted in, and only for the capabilities each dealership has switched on (inventory search, lead creation, messages, appointments, prequalification, trade-ins).
Browsing is anonymous. Searching inventory, comparing vehicles, and estimating payments do not require your identity. We keep a session record with a hashed IP address, browser or client type, locale, your search criteria, and your location if you provide a ZIP code or coordinates. Sessions expire after 30 days.
Contacting a dealership requires verification. Before anything reaches a dealership, you verify a phone number or email address with a one-time code. On success we create a Levels shopper profile (name, phone, email, verified dates). This profile is held by Levels at the platform level, not by any one dealership, so you can contact several dealerships without re-verifying. Dealerships see it only through the leads, messages, and appointments you send them. You may also link your shopper profile to the assistant through an OAuth connection.
What the dealership receives. When you ask to be contacted, send a message, submit a trade-in, or confirm a test drive, we create a normal lead in that dealership's CRM marked as coming from the AI assistant. The dealership gets your name, contact details, your message or note, and a structured summary of what you were looking for. We never store or forward the conversation transcript.
What the assistant receives. The assistant receives inventory and dealership details, payment estimates, your verified name, and, when you confirm an appointment, the appointment details including your phone or email. If you start a prequalification from the assistant, you complete it on the dealership's secure Levels page, never in chat. Afterward the assistant may receive only the status, a Levels planning tier, the bureau name, and, if the dealership has chosen to display scores, your score and score range. It never receives your Social Security number, date of birth, address, income, or credit report.
OpenAI is not our service provider. Your conversation with ChatGPT is handled by OpenAI under OpenAI's privacy policy and your own ChatGPT data settings. The information we return to the assistant goes to OpenAI at your direction, as part of the product you chose to use. Levels receives only the tool requests the assistant sends to our connector.
Disconnecting. You can disconnect a linked Levels shopper profile by removing the Levels connection in your AI assistant's settings, which revokes the assistant's access tokens. Your shopper record, and any leads, messages, or appointments you sent to a dealership, remain unless you ask us at admin@levels.dealer to remove the record.
Records we keep. Verification codes are deleted one day after they expire. Per-request records are kept in a log that strips out names, phone numbers, emails, and free text. Shopper profiles and saved vehicles are kept until you ask us to delete them; deletion requests are carried out manually by Levels staff, and we confirm to you when they are complete.
8. How we use information
We use personal information to:
- provide the software: store records, run dealer websites, deliver messages, connect calls, prepare documents, and process the features described above;
- carry out the dealership's instructions, such as sending an application to the dealership's DMS, or syncing sales to its QuickBooks;
- run credit prequalifications and credit reports that you authorize (Section 9.1);
- keep the platform secure, prevent fraud and abuse, and keep audit trails of sensitive actions;
- provide support, including Levels staff access described in Section 4;
- notify dealership staff about new leads, replies, tasks, and jobs;
- generate summaries and drafts with AI features (Section 10.8), where Levels has enabled them;
- bill dealerships and run our own business;
- market Levels to dealerships (not to dealership customers);
- comply with law and enforce our agreements.
We do not use dealership customer information to build profiles for advertising. Levels does not train AI models on your data, and Anthropic is contractually barred from training on what we send it. Information returned to ChatGPT is subject to OpenAI's policies and your own ChatGPT settings (Section 7).
9. Sensitive information
9.1 Social Security numbers, credit checks, and credit reports
Consent comes first. A credit check never runs without your affirmative agreement, recorded on your prequalification or credit application before the bureau is contacted. For a prequalification, you must accept a written notice that names the dealership as the party requesting the check, identifies Levels Tech LLC as the service provider that transmits the request to the bureau on the dealership's behalf, and names the credit bureau that will be used. We store the exact notice text you saw, its version, the time you agreed, your IP address, and your browser type. For a full credit application, you give a separate written authorization on the website form, on a link the dealership texts or emails you, or on paper that the dealership attests to. Prequalification consent is not treated as authorization for a full credit pull; the dealership must obtain that separately.
Permissible purpose. Credit reports are obtained under the Fair Credit Reporting Act for the purpose you request: a prequalification you initiate, or a credit application you submit in connection with buying or financing a vehicle. Testing a dealership's bureau connection never pulls a consumer file.
Levels' role. Levels holds the account with the credit-reporting provider so that each dealership does not need its own, and requests the report as the dealership's agent under your written instructions and the dealership's certification of its purpose. The report is delivered only to the dealership you dealt with. Levels does not review, use, resell, or combine credit reports for any purpose of its own, and complies with every obligation the Fair Credit Reporting Act places on it in this role. A dealership may instead connect its own credit-provider account.
Soft inquiries. Website prequalifications are soft inquiries. They do not affect your credit score. The notice you accept says so and states that a prequalification is not an application for credit.
Who runs the check. When a dealership has enabled credit features and a live credit-report provider is connected, we send your identity to CRS Credit API (StitchCredit), an authorized reseller that fronts Experian and Equifax. The dealership chooses which bureau. The check returns a FICO Auto score and report. If the dealership has not enabled credit features, your request is recorded as pending and the dealership's finance team follows up with you directly.
What we send to the bureau. Name, date of birth, full Social Security number, current address, phone, email, and, when available, your IP address and browser type, which the provider uses for fraud detection.
How your SSN is handled.
- On a prequalification, your full SSN is held encrypted for at most 20 minutes to complete the check, then deleted. We keep only the last four digits on the consent record.
- On a credit application, your full SSN is stored encrypted in the database using a key held in the application's configuration, outside the database. Only the last four digits are stored in readable form.
- Staff screens show your SSN masked to the last four digits. Only a staff member with the highest credit-access level can reveal the full number, and each reveal is written to a permanent log with the staff member's name and the time.
- Your SSN is never written to application logs, never returned to an AI assistant, and never included in what we send to a dealership's DMS.
How your credit report is handled. The bureau's raw response is scrubbed of your full SSN and date of birth, then encrypted with AES-256-GCM before storage. A normalized version of the report (score, factors, tradelines, and related data) is stored in readable form inside the dealership's isolated database partition, protected by the access controls below, per-user credit-access levels, and audit logging, but it is not separately encrypted. Every request to the bureau, every report view, and every access-level change is written to permanent audit logs that include the staff member, time, IP address, and browser type.
Who at the dealership can see it. The dealership's owner assigns each staff member a credit-access level: none, summary, full, or admin. "Summary" sees only a tier such as Prime or Near-Prime. "Full" sees the score and factors. "Admin" can additionally open the encrypted raw file after entering a personal PIN, and that view is logged and watermarked.
What you see. After a prequalification you can open your result through a link that works for 72 hours. The dealership decides whether the result shows your score and the factors that affected it.
Where the tier goes. Your prequalification tier is copied onto your lead and any later credit application, appears in alerts to the dealership's sales staff, and is visible on your customer file. If you started from an AI assistant, see Section 7 for what the assistant receives.
Sending your application onward. If the dealership has connected its own dealer management system (DealerCenter), we email your application to the dealership's own lead-import address in a standard format. That email includes your contact details, address, employer, income, housing, down payment, and the time you authorized a credit check. It never includes your SSN or date of birth. Applications queued while email delivery was not yet live are sent automatically once it is. Submission to lender networks such as CUDL is not switched on today; when it is, it will require your recorded credit authorization and the dealership's opt-in.
Retention. Consent records, bureau request logs, report views, and reveal logs are append-only and cannot be edited or deleted by dealership staff. We keep credit application data and reports for as long as the dealership's account is active and afterward as required for legal and FCRA compliance. Stored reports are not automatically deleted today.
9.2 Driver's license scans and images
Why. Dealerships scan licenses to verify identity before a test drive or sale, to warn about expired licenses, to fill required deal paperwork, and to keep the plate-audit records some states require.
How. The barcode on the back of the license is decoded on the device itself; nothing is sent to a cloud scanning service. A photo of the front is compared to the barcode on the device to check that they match. Only the match result is kept, not the text read from the photo. If the scanner cannot read the barcode, the failed image, which may show your license, is uploaded to a diagnostics area on our own servers that only the dealership's owners and managers can open; it is deleted after 30 days.
What is stored. Your name, address, date of birth, and license expiration are stored with the test drive, deal, or lead. Your license number is encrypted, with only the last four digits and issuing state readable. The full number is decrypted only to fill required deal paperwork or when an authorized staff member reveals it on a credit application, which is logged. The front-of-license photo is stored in a private area that only that dealership's logged-in staff can open.
Deletion. Scanner photos are deleted from the live system 90 days after capture. Failed-scan diagnostic images are deleted after 30 days. A license photo attached directly to a deal record is kept with the deal. Decoded identity fields and the encrypted license number are kept as part of the transaction record. See Section 12 for how backups affect deletion.
9.3 Call recordings, voicemails, and transcripts
Each dealership has phone numbers provisioned through our telephony provider, Twilio. When you call a dealership line, the greeting states that the call may be recorded. Calls forwarded to staff are recorded, and voicemails you leave are recorded and transcribed.
When the dealership calls you through Levels, whether a salesperson clicks to call, a new web inquiry triggers an immediate call-back, or the call is part of a call campaign, both sides of the call are recorded and transcribed. Recording cannot be turned off for these calls. Our system speaks the recording notice to the dealership employee before your line is dialed; the system does not play a notice to you. The dealership is responsible for telling you at the start of the call that it is being recorded where the law requires your consent, and you may hang up or ask the dealership to call you from a line that is not recorded.
Recordings are stored with Twilio and transcribed by Twilio's transcription service. The full transcript, labeled by speaker, is stored with the dealership's call log and shown to its staff. Dealership staff play recordings through short-lived signed links; the raw storage address is never exposed. Recordings and transcripts are kept for as long as the dealership's account is active and afterward as needed for legal purposes.
If you call and no one answers, the dealership's line may automatically text you back once, at most once per hour.
9.4 Text messages, consent, and STOP
Texts come from the dealership's own number, not from Levels. There are two kinds.
Texts about something you asked for. When you give a dealership your mobile number on a form, in a signed agreement, or by texting it first, the dealership may text you about that request: replies from staff, links you asked for (applications, signing, payments, appointments, photo uploads), appointment and payment reminders, price-drop alerts for a vehicle you asked to watch, and a review request after a purchase.
Marketing texts. A dealership may send marketing texts (for example new arrivals, price drops on a model you named, trade-up offers, service reminders, or a follow-up about a vehicle you viewed on its website) only if you have given that dealership prior express written consent to receive marketing texts sent with automated technology. Consent to marketing texts is never a condition of buying, financing, or servicing a vehicle. Message frequency varies. Message and data rates may apply.
STOP and HELP. Reply STOP to any text to stop texts from the dealership number that sent it. Our messaging provider blocks further texts from that number to yours. Levels does not currently record a STOP reply on your customer file, so if the dealership uses more than one number, reply STOP to each, and a STOP does not stop calls or email. To stop those, or to have your record flagged as opted out across the dealership's numbers, tell the dealership or write to us at admin@levels.dealer. Reply HELP for help. Opt-out flags carried over from a dealership's previous system are honored for reminders, alerts, marketing messages, and staff-typed texts, but are not currently applied to automatic missed-call text-backs, automated replies, or texted application, authorization, and receipt links.
Do-not-call. Calls placed through the dialer and immediate call-backs are not made to numbers marked do-not-call in the dealership's records. Call campaigns built from lead lists do not currently apply the do-not-call flag; the dealership is responsible for excluding those numbers before starting a campaign.
Automated replies. If the dealership turns on auto-replies, a reply to your text may be composed automatically, including by an AI model (Section 10.8), when no staff member is active on the conversation. Automated replies are composed from the dealership's records about you (your name, vehicles you bought, any in-house loan balance, title status, your inquiry, and your recent messages). Automated replies never respond to STOP messages.
Immediate call-backs. If the dealership enables it, submitting a web inquiry with your phone number can trigger an immediate call that connects you to the first available salesperson. If no one answers, or it is after hours, you receive a text instead.
Every text sent or received is stored with your number and the message content in the dealership's records.
9.5 Location during a solo test drive
This feature is off unless a dealership turns it on. When it is on and you take a vehicle out alone, the dealership may text you an authorization link. The page shows you the dealership, the vehicle, the check-out time, and the salesperson, and asks you to authorize the drive and share your location while it is active.
Nothing is collected until you tap the authorization button. We record the time, your IP address, and browser type for that tap. Your phone then sends its position roughly every 8 seconds. We accept positions only while the drive is open, meaning until the vehicle is checked back in or 6 hours pass, and we cap collection at 2,000 points per drive. When the drive ends, the page stops sharing and the link stops working. The dealership's staff can view the route on a satellite map. Route data is kept with the test-drive record.
9.6 E-signature evidence
Before you sign anything electronically, you agree to conduct the transaction electronically under ESIGN and UETA. We record that agreement, and for every step of the signing process (link sent, packet opened, document viewed, document signed, documents delivered) we record the time, the channel (in person or remote), your IP address, and your browser type. We store your drawn signature and initials as images, your typed legal name, and a cryptographic hash of each document. A Certificate of Completion listing this evidence is appended to the signed packet. These records are append-only and cannot be altered by dealership staff.
9.7 Payment cards and bank accounts
Online deposits and portal payments are processed by Stripe on Stripe's own checkout page. Your card number, expiration date, and security code are entered on Stripe's page and go directly to Stripe under Stripe's privacy policy; Levels never receives or stores them. Levels receives from Stripe only the payment's status, amount, and Stripe's reference numbers, which we store on the deposit or loan record so the payment appears on your account and a receipt can be sent to you. Bank (ACH) payments are not offered yet.
No page operated by Levels asks you for card or bank details. If a page ever does, it will name the payment processor that receives them, and we will update this policy first. Payments the dealership collects in person are recorded by its staff.
9.8 Financial privacy (Gramm-Leach-Bliley Act)
Dealerships that arrange or provide financing are financial institutions under the Gramm-Leach-Bliley Act. Credit applications, loan records, income, Social Security numbers, and credit tiers are "nonpublic personal information" under that law. Levels receives this information from dealerships only as their service provider. We use it solely to provide the services the dealership has chosen; we do not disclose it to anyone else except as the dealership directs, as this policy describes, or as the law permits or requires; and we maintain a written information security program with the administrative, technical, and physical safeguards described in Section 13. Our agreement with each dealership contains the service-provider commitments required by the FTC Safeguards Rule.
10. Who receives personal information
We share personal information only with the parties below, only for the purposes described, and only to the extent the dealership has enabled the relevant feature. Each provider handles data under its own privacy policy and our agreement with it.
10.1 Hosting and infrastructure
- Amazon Web Services (United States). Our application, database, uploaded files, and backups are hosted on AWS in the United States. All personal information we store resides there.
- Let's Encrypt. Issues TLS certificates for levels.dealer, dealer subdomains, and dealer-connected domains. Receives hostnames only.
10.2 Messaging and telephony
- Twilio. Provides dealership phone numbers, sends and receives texts and picture messages, connects and records calls, records voicemails, transcribes calls, and registers each dealership's business identity with carriers for text messaging. Twilio receives phone numbers, message content, attached media, call audio, and, for carrier registration, the dealership's legal name, EIN, address, website, and representative contact.
- Transactional email provider. SendGrid (a Twilio company), or another transactional email provider we designate (Resend, Postmark, or Twilio's email service), delivers email we send on a dealership's behalf, such as receipts, reminders, appointment confirmations, application links, signed document packets, and consignment agreements, and receives inbound lead emails from marketplaces on the dealership's hosted lead address. The provider receives recipient addresses, subject, message content, and attachments. Emails are sent from a Levels address with the dealership's email as the reply-to.
10.3 Credit reporting and lending
- CRS Credit API (StitchCredit), fronting Experian and Equifax. Receives your identity, including full SSN, to run a credit check you authorized (Section 9.1). A soft inquiry is recorded on your bureau file. Levels holds a platform account that dealerships may enable; a dealership may instead connect its own account.
- Lender networks (CUDL/Origence) and other credit providers (700Credit, Credit Bureau Connection, MeridianLink, Experian direct). Selectable in dealership settings but not connected today. No data is sent to them.
10.4 The dealership's own systems and vendors
- DealerCenter or another DMS. If the dealership saves its DMS lead-import address, we email credit applications to that address as described in Section 9.1. This goes to the dealership's own system.
- The dealership's vendors. Repair shops, tow companies, and title agencies the dealership chooses receive the vehicle details described in Section 5.
10.5 QuickBooks Online (Intuit)
A dealership may connect its own QuickBooks Online company. Here is exactly what that connection does.
- What Levels does in QuickBooks. Levels writes the dealership's own settled sales, customer payments, refunds, and vehicle costs into the dealership's own QuickBooks company. To post them correctly it reads back only what it needs: it looks up existing customer and vendor records by display name so it does not create duplicates, and it looks up or creates a small set of accounts and service items (for example "Vehicle Sales", "Vehicle Reconditioning", "Cash on hand", "Dealer Credit Card", "Vehicle Sale", and "Restocking Fee"). Levels does not import the dealership's QuickBooks transactions, reports, employee data, bank feeds, or contact lists into Levels.
- What Intuit receives. Customer names (as QuickBooks customer records), vendor names, amounts, dates, payment types, and memos containing stock numbers, vehicle year, make, model, and the customer's name. Vehicle purchase prices, sales-tax filing detail, and in-house loan ledgers are not sent.
- Authorization and tokens. The dealership's owner or manager authorizes the connection on Intuit's own consent screen, with the accounting scope only. The resulting OAuth tokens are encrypted at rest with a key held outside the database and are decrypted only inside that dealership's isolated session at sync time. Tokens are refreshed as Intuit requires and are never displayed to anyone.
- After disconnect. An owner or manager can disconnect at any time. We revoke the token with Intuit so Levels is removed from the dealership's connected apps, then delete our copies of the tokens from the live system (backup copies age out under Section 12). Levels keeps its own log of what it posted (document type, amount, customer or vendor name, QuickBooks document ID) as the dealership's audit history; that log holds information the dealership entered into Levels, not data taken from QuickBooks.
- No other use. Information from the dealership's QuickBooks company is stored only in that dealership's account, is never visible to another dealership, is never used in any cross-customer dataset, and is never used for advertising or to train models.
- Intuit's terms govern QuickBooks. Once data is in QuickBooks, Intuit's privacy statement governs it. Levels is not affiliated with Intuit.
10.6 Keys.app
Keys.app is a locksmith and key-parts network integrated into Levels for dealerships that use it. Keys.app is operated by Keys Inc., doing business as Keys, a separate company under common ownership with Levels, which makes it an affiliate of Levels; it handles what it receives under its own privacy policy, and Levels uses Keys.app data only for the dealership's key and locksmith jobs. When a dealership looks up keys, orders parts, or books a locksmith, we send Keys.app the dealership's name, phone, email, lot addresses, the requesting staff member's name, the vehicle's VIN and description, key part numbers, shipment tracking, and any notes the staff member types. Customer identity, license data, and deal information are never sent to Keys.app. Payments to Keys.app are made by the dealership on a Stripe-hosted checkout page operated by Keys.app; Levels stores only the payment status.
10.7 Payments
- Stripe. Processes online deposits and loan payments made by dealership customers (Section 9.7) and dealership subscription billing (Section 4). Stripe receives card details directly on its own pages, plus the payer's name and email, the amount, and a reference to the deposit or loan. Levels receives the payment status and reference numbers. A dealership that connects its own bank gives Stripe its business details, owner identity, and bank account on Stripe's own onboarding pages (Stripe Connect); Levels stores only Stripe's account identifier and whether payments and payouts are enabled. Dealerships paying Keys.app use a separate Stripe page hosted by Keys.app.
10.8 AI providers
- Anthropic (Claude). When Levels has enabled AI features, we send Anthropic text to generate or classify. Uses: a morning dashboard summary for dealership staff (which can include names of leads, in-house-finance borrowers, credit applicants, and test-drive customers, loan payment amounts and due dates, insurance carrier and policy dates, and which staff are clocked in); automatic text replies when a dealership turns them on (the customer's name, purchase and loan status, lead interest, matching inventory, and the last several messages in the thread); classifying public online reviews and drafting responses (review text, rating, and dealership staff names, not the reviewer's name); reading staff work-order texts on an internal tasks line; and drafting a headline from a new dealership's existing website. Credit scores, credit reports, Social Security numbers, license data, signed documents, and the financial details of credit applications are never sent to Anthropic. There is currently no per-dealership switch for the morning summary; a dealership that does not want customer financial information sent to a model provider can ask us to disable model-backed features for its account. Where AI features are not enabled, rule-based software performs these tasks. Anthropic processes text for us as a service provider under commercial API terms that prohibit it from using the data for its own purposes or to train models.
- OpenAI (ChatGPT). See Section 7. Only when a dealership opts in, and only at the shopper's direction.
10.9 Marketplaces and listing sites the dealership chooses
- Inventory feeds. Dealerships can give marketplaces (CarGurus, CARFAX, AutoTrader, and others) a feed URL. Feeds contain the dealership's name, phone, website, and vehicle listings with photos. No customer data. Levels may also register a combined feed of participating dealerships' inventory with a marketplace.
- Inbound leads. Marketplaces send consumer inquiries to a dealership email address we host; we receive your name, contact details, vehicle interest, and message.
- Craigslist. When a dealership connects Craigslist, we post vehicle ads with the dealership's contact details and photos using the dealership's or Levels' Craigslist account.
- Facebook Marketplace. A browser extension fills listing forms inside the dealership's own logged-in Facebook session. Levels has no server connection to Facebook. No customer data is involved.
10.10 Vehicle data, maps, and web resources
- NHTSA and EPA (U.S. government). Receive VINs and year, make, and model to decode build sheets, safety ratings, recalls, and fuel economy. Consumer-entered VINs on trade-in and consignment pages are decoded the same way.
- Vehicle manufacturers (Stellantis, Ford, GM). Receive VINs to fetch original window stickers.
- CARFAX and AutoCheck. Link-outs only; the VIN is in the link you click. No API connection exists.
- Zippopotam.us, U.S. Census Geocoder, OpenStreetMap Nominatim. Receive ZIP codes or dealership lot addresses to look up coordinates.
- Esri (ArcGIS). Supplies satellite map tiles to dealership staff browsers for lot maps and test-drive route maps. Esri sees the staff member's IP address and the map area viewed.
- Google. Google Fonts (on dealer sites, on levels.dealer, and on these legal pages), YouTube (privacy-enhanced embeds), and Google Maps links as described in Section 6; and, if a dealership connects its Google Business Profile, we pull the dealership's public reviews using tokens we encrypt at rest.
- The dealership's previous website or feed host. During onboarding we may fetch the dealership's existing inventory and photos from its old provider.
10.11 Levels personnel
Authorized Levels employees may access personal information to operate, secure, and support the platform, as described in Section 4. Access is logged.
10.12 Legal requirements and business changes
We may disclose personal information when required by law, subpoena, or court order, to protect the rights and safety of people, or to enforce our agreements. If Levels is involved in a merger, acquisition, or sale of assets, personal information may transfer to the successor, who will be bound by this policy.
11. We do not sell or share personal information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not place advertising cookies or pixels on dealer websites or on levels.dealer.
Because some data flows can look like sales, here is how we see them:
- Marketplaces receive vehicle listings and the dealership's business contact details, not consumer data.
- Google, YouTube, and Esri receive your IP address only because your browser loads a font, video, or map tile. We do not send them your identity.
- Anthropic processes text for us as a service provider under commercial API terms that prohibit it from using the data for its own purposes or to train models. OpenAI is not our service provider. When you shop through ChatGPT, the information we return to the assistant (inventory, your verified name, appointment details, and the prequalification summary described in Section 7) goes to OpenAI at your direction, as part of the product you chose to use, and is governed by OpenAI's privacy policy and your ChatGPT data settings.
- Publishing a delivery photo with your first name on a dealer website is a public posting by the dealership, not a sale by Levels.
We treat a Global Privacy Control signal from your browser as a request to opt out of the sale or sharing of your personal information. Because dealer websites and levels.dealer do not sell or share personal information, that request is already honored and nothing on the site changes. We do not respond to "Do Not Track" browser settings, which have no standard meaning.
12. How long we keep information
Default rule. We keep personal information for as long as the dealership's account is active, and afterward as needed for legal, accounting, tax, and compliance purposes. Many records in Levels are append-only audit trails and cannot be edited or deleted by dealership staff.
Specific deletion schedules that run automatically:
- Driver's license scanner photos: deleted from the live system 90 days after capture.
- Failed-scan diagnostic images: deleted after 30 days.
- Full SSN held for a website prequalification: deleted within 20 minutes.
- AI-assistant verification codes: deleted one day after expiry.
- Uploaded customer-list import files: deleted when the import completes or is canceled.
- QuickBooks tokens: deleted from the live system when the dealership disconnects.
- Temporary sign-in and one-time links expire on their own: payment links after 7 days, deposit links after 14 days, receipt links after 90 days, signed document links after 365 days, signing links after 7 days, media links after 4 hours.
Records with no automatic deletion. Leads, customer files, deals, signed documents, license photos attached to a deal, loans and ledgers, messages, call logs with recordings and transcripts, website activity, consent and audit logs, credit application data and reports, and AI-assistant shopper profiles are kept under the default rule until deleted at the dealership's or your request, or as required by law. Access, correction, and deletion requests are fulfilled manually by our staff from the underlying records; there is currently no self-service export or delete button.
Backups. We take a full backup of the database every night and keep the 14 most recent copies. Uploaded files are copied into the backup nightly and deletions are deliberately not propagated, so a file removed from the live system, including a license photo deleted on schedule, remains in the backup copy until we remove it by hand. Backups, including a copy of the server configuration that holds our encryption key, are stored on the same server as the application in a directory readable only by the system administrator, and are not separately encrypted.
13. Security
We use the following measures. No system is perfectly secure, and we cannot guarantee that unauthorized access will never occur.
- Encryption in transit. All connections to Levels and dealer websites use HTTPS with automatically renewed certificates.
- Encryption at rest for the most sensitive fields. Social Security numbers, driver's license numbers, credit-provider credentials, QuickBooks tokens, and Google tokens are encrypted in the database with a key held in the application's configuration file, outside the database. Raw credit-bureau responses are encrypted with AES-256-GCM before they reach the database. The normalized credit report is protected by access controls and audit logging rather than encryption (Section 9.1).
- Separation between dealerships. Every dealership's records are tagged with its ID, and the database enforces that boundary on every query. Cross-dealership reads are limited to a small set of controlled functions used for sign-in and support.
- Passwords and PINs. Stored only as one-way hashes. Sign-in tokens expire after 12 hours.
- Role-based access. Dealership owners control roles and credit-data access levels. Viewing a raw credit file requires the highest access level plus a PIN step-up.
- Audit logs. Sensitive actions, including credit views, SSN and license reveals, price changes, document signing, tax exports, and Levels support access, are written to append-only logs with the actor, time, IP address, and browser type.
- Log hygiene. We do not write Social Security numbers, credit files, passwords, or request bodies to application logs; database logging of query parameters on errors is disabled; and error messages sent to browsers never expose database details.
- File storage. License images, receipts, uploaded customer documents, and private vehicle documents are stored outside the public web root and served only to logged-in staff or through short-lived signed links. Vehicle photos and blank dealer forms are public by design. Some documents, including deal documents imported from a prior system and signed consignment agreements, are currently stored at long, unguessable addresses rather than behind a login; we are moving them behind signed links.
- On-device processing. License barcodes, license photos, VIN scans, and receipt photos are read on the device or on our own server, not by a cloud scanning vendor.
- Abuse controls. Prequalification, consignment, guest-workspace, credit-report, and Levels administrator sign-in requests are rate-limited, and a bot trap protects the consignment form. Incoming webhooks from Keys.app are signature-verified. When Twilio is live, its webhooks for inbound texts, delivery receipts, immediate call-backs, and call campaigns are signature-verified; the phone-menu, voicemail, recording, and transcription callbacks are authenticated by matching the dealership's number and call identifier.
14. Your privacy rights
14.1 Rights under California law (CCPA/CPRA) and other state laws
If you live in California, you have the right to know what personal information we collect and how we use and disclose it, to access it, to correct it, to delete it, to receive it in a portable format, to opt out of sale or sharing (we do neither), to limit the use of sensitive personal information (we use it only to provide the services you requested), and not to be discriminated against for exercising these rights. Residents of other states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others, have similar rights, and we honor them.
Some information handled through Levels, such as credit reports and credit application data, is governed by federal laws such as the Fair Credit Reporting Act and the Gramm-Leach-Bliley Act and may be exempt from state privacy laws. We will still route your request as described below.
14.2 Requests about information a dealership holds
For information a dealership collected about you (leads, deals, applications, messages, documents), the dealership is the business responsible for deciding how to respond. Contact the dealership using the details on its website. Because deletions and exports from Levels are carried out by Levels at the dealership's direction, you may also send your request to us at admin@levels.dealer; we will confirm receipt, forward it to the dealership within 10 business days, and carry out the dealership's instructions. Consent records, audit trails, and signed transaction documents must be retained by law and cannot be deleted on request.
14.3 Requests about information Levels holds directly
For information Levels controls (your Levels shopper profile from an AI assistant, a waitlist signup, a dealership staff account, or Levels' marketing to your business), contact us at admin@levels.dealer or by mail at Levels Tech LLC, 5151 N Oracle Rd Ste 125, Tucson, AZ 85704.
14.4 How we handle requests
We will verify your identity before acting, usually by confirming control of the email or phone number on the record. You may use an authorized agent if you give the agent written permission and we can verify your identity. We respond within 45 days, and we will tell you if we need more time. If we deny a request, we will explain why, and you may appeal by replying to our decision. We do not charge for requests unless they are excessive or repetitive.
14.5 Marketing choices
Reply STOP to stop texts from the dealership number that sent them, or from Levels' own number. Dealership marketing emails are sent at the dealership's direction; ask the dealership to stop them, or write to us and we will flag your record as opted out. Levels' own product-update emails to dealership owners can be stopped by replying or writing to admin@levels.dealer.
15. Children
Levels and the dealer websites we host are not directed to anyone under 18. Buying or financing a vehicle requires an adult. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information through Levels, contact us at admin@levels.dealer and we will delete it.
16. Changes to this policy
We may update this policy as the product changes. The current version is always available at https://levels.dealer/privacy, and that page is linked from every dealer website we host, from the ChatGPT connector, and from our QuickBooks app listing. We will post each new version there with a new effective date. For material changes, we will email dealership owners before the change takes effect. Dealerships are responsible for updating their own customer notices when our practices change.
17. Contact us and governing law
- Privacy contact: admin@levels.dealer
- Mail: Levels Tech LLC, 5151 N Oracle Rd Ste 125, Tucson, AZ 85704
- Second request method: by mail to the address above
This policy is governed by the laws of Arizona, and any dispute about it will be brought in the courts of Pima County, Arizona, without regard to conflict-of-law rules.