This Privacy Policy explains how DriveUpSales INC ("DriveUpSales.ai," "we," "us") handles information in connection with our website, our platform, and the telephony, call recording, transcription and dealership intelligence services we provide (together, the "Services").
1. Two roles, two sets of rules
Almost every privacy question about our company depends on which of two roles we are playing.
1. We act for ourselves when we run driveupsales.ai, market to dealerships, respond to demo requests, and administer accounts for the dealership staff who log in. For that information we decide the purposes of processing, and this Policy describes what we do.
2. We act for our dealership customers when we carry, route, record, transcribe and analyze their phone calls and process the CRM, inventory and customer records they connect. In that role we are a service provider (or "processor") acting on the dealership's instructions. The dealership decides which calls are recorded, why, and how long the data is kept; the dealership's own privacy notice governs how it treats consumer information.
If you called a dealership and want your recording, transcript or data removed, the fastest path is to contact that dealership directly — it controls the data and can instruct us. You can also write to carson@driveupsales.ai and we will route your request to the right dealership and support it in responding, but we generally cannot delete a customer's records without that customer's authorization.
2. Information we collect
Website visitors and prospective customers
- Contact and business details you give us — name, work email, phone number, dealership or company name, role, and anything you type into a demo, waitlist or contact form.
- Communications — emails, support tickets, and notes about our conversations with you.
- Device and usage data collected automatically — IP address, browser and device type, operating system, referring page, pages viewed, and timestamps.
Dealership users of the platform
- Account information — name, work email, phone number or extension, job title, department, store assignment, role and permissions.
- Authentication data — hashed credentials, session tokens and multi-factor settings.
- Product usage and audit data — logins, pages and records viewed, actions taken, calls handled, and configuration changes. Dealerships can see this activity for their own users.
Call participants
When a call runs on a number we provision for a dealership, we may process, on that dealership's behalf:
- Call metadata — the calling and called numbers, direction, date and time, duration, ring and hold time, which department and which rep the call reached, how it was routed and escalated, whether a person or a voicemail answered, and disposition.
- Call audio — a dual-channel recording of connected calls, where recording is enabled for that number, and voicemail messages left on our system.
- Transcripts — a machine-generated, speaker-separated text version of the call.
- Content of the conversation — whatever the participants say, which can include names, phone numbers, addresses, email addresses, vehicles of interest, trade-in details, appointment times, budget and payment discussion, and anything else volunteered on the call.
- Derived analysis — AI-generated summaries, call scores and quality metrics, intent and sentiment signals, detected objections, extracted fields such as the vehicle discussed or appointment set, and coaching notes for the rep.
- Voice characteristics — see Section 4.
Data from dealership systems
When a dealership connects a CRM, DMS, inventory feed or email system, we ingest the records it sends us — customer contact details, lead source and history, activity and appointment records, sales rep assignments, deal and inventory data. We process these records only to provide the Services to that dealership.
What we ask dealerships not to send. The Services are not designed for payment card numbers, Social Security numbers, driver's license or other government identification numbers, credit report data, or health information, and our agreements prohibit submitting them into fields not built for them. If sensitive content is spoken on a recorded call, it may be captured in the audio and transcript — which is one reason dealerships should configure recording carefully and train staff on what not to collect over the phone.
3. Call recording and disclosure
Call recording is regulated, and in some states every party to a call must consent before it can be recorded. Two things follow from that.
We play an automated disclosure. On inbound calls, before any recording begins, our system plays a notice to the caller that the call may be recorded and analyzed for quality and training purposes. Recording is configurable per number and per department, and can be switched off entirely at a dealership's request.
The dealership is responsible for consent. Under our Terms of Service, the dealership decides which calls are recorded and is contractually responsible for providing every notice and obtaining every consent applicable law requires — including under state two-party consent and wiretap statutes, and biometric privacy laws — and for honoring objections and revocations. We provide the disclosure and configuration tools; we do not determine the legality of a given dealership's recording practices.
If you are on a call and do not want to be recorded, say so. The dealership's staff should stop the recording or end the call, and you can ask the dealership to delete any recording already made.
4. Voice characteristics and biometric identifiers
To separate the rep from the customer on a dual-channel recording, attribute each line of a transcript to the right speaker, and let managers coach by rep, our system can compute a numerical representation of a speaker's voice — a voice embedding — from recorded audio. Depending on the state, a voice embedding may be a biometric identifier or "sensitive personal information."
Our commitments on voice embeddings:
- Purpose is limited to speaker identification. We use them to tell speakers apart within a dealership's own calls. We do not use them to identify people across dealerships, to infer emotion or personality traits as a standalone product, or for advertising.
- We never sell, lease or trade them, and we do not otherwise profit from them.
- They are not shared except with the infrastructure providers who host them for us, or as Section 7 otherwise requires.
- They are retained no longer than the underlying recordings, and are deleted when the recording is deleted, when the purpose is satisfied, or when law requires, whichever comes first.
- Dealerships can turn the feature off. A dealership may instruct us in writing not to generate voice embeddings for its account.
Because it is the dealership that collects the voice, the dealership is responsible for providing any biometric notice and obtaining any written release the law requires — including under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and comparable statutes.
5. How we use information
We use information to:
- Provide the Services — route calls, record and transcribe them where enabled, generate summaries, scores and coaching, match leads to inventory, send alerts and reminders, and power the dashboards our customers use.
- Operate and secure our platform — authenticate users, monitor availability and quality, debug failures, prevent fraud and abuse, maintain audit logs, and protect against security incidents.
- Support our customers — respond to tickets, investigate a specific call, and help with configuration. Our staff access customer data only as needed for support, troubleshooting, security or as a customer instructs.
- Improve the Services — measure transcription and scoring quality, tune routing and detection logic, and develop new features. Where we use call content for this purpose we do so under our customer agreements, on a limited-access basis, and we prefer de-identified or aggregated data wherever it will do the job. See Section 6 for what we do not do.
- Communicate with you — send service, security and billing notices, and, where permitted, marketing about our products. You can opt out of marketing at any time.
- Comply with law — meet legal, tax and regulatory obligations, respond to lawful requests, enforce our terms, and establish or defend legal claims.
6. AI and automated processing
The Services use automated speech recognition and generative AI models to produce transcripts, scores, summaries and suggestions. Two points matter here.
We do not train foundation models on your calls. Call audio, transcripts and other customer data are not used to train general-purpose or third-party AI models. The model and speech-recognition providers we use are engaged under enterprise terms that prohibit them from using our customers' content to train or improve their own models, and that require them to process it only to return a result to us.
Output is advisory. Transcripts contain errors, and scores and summaries can mischaracterize a conversation. Our customers agree not to use this output as the sole basis for any decision with a legal or similarly significant effect on an individual — including employment decisions about their staff — and to review it before acting. We do not use these systems to make automated decisions about consumers on our own behalf.
7. How we share information
We disclose information only as follows.
- With the dealership whose calls and records they are, and with the users that dealership authorizes.
- With service providers and subprocessors who run parts of the platform for
us under contract, are limited to our instructions, and may not use the data for their own
purposes. Our principal subprocessors today are:
- Telnyx — telephone numbers, call carriage and recording capture.
- Google Cloud Platform — application hosting, recording and file storage, speech-to-text transcription, and the Gemini models used for call analysis.
- Supabase — the managed Postgres database behind the platform.
- Cloudflare — delivery and protection of our website and APIs.
- With systems a dealership connects — when a dealership enables an integration, we exchange data with that system at its direction.
- For legal reasons — to comply with a subpoena, court order, warrant or other lawful request; to cooperate with law enforcement where legally required; to enforce our agreements; or to protect the rights, safety or property of any person. Where we are permitted to do so, we notify the affected customer before disclosing its data and will seek to narrow or challenge overbroad demands.
- In a corporate transaction — in connection with a merger, acquisition, financing or sale of assets, subject to this Policy continuing to apply to the transferred information.
- Aggregated or de-identified data — statistics and benchmarks that do not identify any dealership, user or individual, and that we do not attempt to re-identify.
8. We do not sell your data
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and similar state laws. We do not sell, rent or trade call recordings, transcripts, voice embeddings or consumer records, and we do not use call content to target advertising.
9. Retention and deletion
We do not age recordings out on a rolling schedule. Call data stays available for as long as the dealership's subscription is active, and is deleted within thirty (30) days after that subscription ends. Unless a customer's agreement provides otherwise, our defaults are:
| Data | Default retention |
|---|---|
| Call audio and voicemail | Life of the subscription; deleted within 30 days after it ends |
| Transcripts, call metadata and derived analysis | Life of the subscription; deleted within 30 days after it ends |
| Voice embeddings | No longer than the recording they were derived from |
| CRM and dealership records | As the dealership instructs; deleted within 30 days after the subscription ends |
| Account and audit logs | Life of the subscription, plus the period needed for security and legal purposes |
| Website and marketing contact data | Until you ask us to delete it, or it is no longer needed |
| Billing and tax records | As required by law, typically seven years |
A dealership can ask us to delete a specific recording earlier, or to shorten these defaults for its account. Deleted data may persist briefly in encrypted backups before those backups age out, and we retain information longer where a law, regulation, litigation hold or lawful request requires it.
10. Security
We maintain administrative, technical and physical safeguards designed to protect the information we hold, including encryption in transit and at rest, role-based access control and least-privilege staff access, tenant isolation so one dealership cannot see another's data, signed and verified webhooks from our carrier, audit logging, and vendor security review.
No system is perfectly secure, and no transmission over the internet can be guaranteed secure. If you believe you have found a vulnerability, please report it to carson@driveupsales.ai. If a security incident affecting personal information occurs, we will notify affected customers and, where required, individuals and regulators, without undue delay.
11. Your privacy rights
Depending on where you live, you may have the right to know what personal information is held about you, to access or receive a copy of it, to correct inaccuracies, to request deletion, to opt out of sale, targeted advertising or certain profiling, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights.
How to exercise them:
- If you are a consumer who called or was contacted by a dealership, contact that dealership. It controls the data. You may also write to carson@driveupsales.ai and we will identify the relevant dealership, forward your request, and assist it in responding.
- If you are a dealership user, prospect or website visitor, email carson@driveupsales.ai and we will handle your request directly.
We will acknowledge a request promptly and respond within the time the applicable law allows — generally forty-five (45) days, extendable once where permitted. We need enough information to verify your identity and locate your records; for a call-related request that usually means the phone number used, the dealership called, and an approximate date. We will not use verification information for any other purpose. An authorized agent may submit a request on your behalf with proof of authorization. If we deny a request, we will explain why and, where the law provides one, tell you how to appeal.
12. California notice
This section supplements the rest of the Policy for California residents under the California Consumer Privacy Act, as amended by the CPRA.
Categories we collect. Identifiers (name, phone number, email, IP address); commercial information (vehicles of interest, appointment and deal activity); internet and network activity (site and product usage); audio and electronic information (call recordings, voicemails, transcripts); professional or employment-related information (job title, dealership, department); inferences (call scores, intent and sentiment signals, lead scores); and sensitive personal information limited to biometric information in the form of voice embeddings used for speaker identification.
Sources, purposes and disclosures are described in Sections 2, 5 and 7. We collect sensitive personal information only for the purposes permitted under CCPA section 7027(m) — providing the Services and ensuring their quality and security — and we do not use or disclose it to infer characteristics about you.
No sale or sharing. We have not sold personal information or shared it for cross-context behavioral advertising in the preceding twelve months, and we do not knowingly sell or share the personal information of consumers under 16. We offer no financial incentive in exchange for personal information.
Service provider role. With respect to dealership call and CRM data, we act as a service provider and process that information only to perform the services specified in our customer agreements, as CCPA requires.
Retention is described in Section 9. Rights and how to exercise them, including the right to appeal, are described in Section 11.
13. Other state notices
Colorado, Connecticut, Delaware, Iowa, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah and Virginia. Residents of states with comprehensive privacy laws have the rights described in Section 11, including access, correction, deletion, portability, and opting out of targeted advertising, sale and certain profiling. We do not conduct targeted advertising or sales of personal information, and we do not engage in profiling in furtherance of decisions producing legal or similarly significant effects on consumers. Where your state provides an appeal process, we will tell you how to use it if we deny your request.
Nevada. Nevada residents may submit a verified request that we not sell covered information. We do not sell it, but you may submit a request to carson@driveupsales.ai.
Illinois, Texas and Washington biometric laws. Our practices for voice embeddings, including purpose limits, no sale, and retention and destruction, are described in Section 4.
14. Cookies and tracking
Our website uses cookies and similar technologies that are strictly necessary to serve and secure the site, remember your preferences, and measure aggregate traffic so we can improve it. Our logged-in application uses cookies and local storage for authentication and session management; the application will not work without them.
You can block or delete cookies in your browser settings, though parts of the site may stop working. Where we use any analytics or advertising technology that qualifies as "sharing" or targeted advertising under state law, we will honor a Global Privacy Control signal sent by your browser. We do not respond to Do Not Track headers, which have no agreed standard.
15. Children's privacy
The Services are business tools intended for use by adults in a commercial context. We do not knowingly collect personal information from children under 16. If you believe a child's information has reached us — for example, on a recorded call — contact carson@driveupsales.ai and we will work with the relevant dealership to delete it.
16. Where data is processed
We are based in the United States and process and store information on infrastructure located in the United States. Our Services are offered to businesses in the United States. If you access them from elsewhere, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those of your country.
17. Third-party sites
Our website may link to sites we do not operate. This Policy does not cover them, and we are not responsible for their content or privacy practices. Review their policies before providing information.
18. Changes to this policy
We may update this Policy as our Services and the law change. We will post the revised version with a new "Last updated" date, and for material changes we will provide additional notice by email to account contacts or in the application before the change takes effect. Continued use of the Services after the effective date means you accept the updated Policy.
19. Contact us
Privacy requests, security reports and legal notices all reach us at carson@driveupsales.ai.
DriveUpSales INC
N7176 Lakeshore Ave, Elkhorn, WI 53121
See also our Terms of Service.
