Privacy Policy
Last updated: August 19, 2026
1. Introduction
Shiftix Cloud ("we", "our", or "us") operates a multi-tenant SaaS platform that provides automotive, marine, RV, and powersports dealerships with tools for marketing management, customer relationship management (CRM), reputation monitoring, unified communications (including AI-assisted voice and SMS), inventory management, and billing workflows.
This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in connection with our platform. It applies to dealership staff and administrators who use the platform directly, and it describes how we handle consumer data that dealerships process through our platform on behalf of their customers.
By using Shiftix Cloud, you agree to the practices described in this policy. If you do not agree, please do not use our services.
2. Our Role: Data Controller and Data Processor
Shiftix Cloud operates in two distinct legal capacities depending on whose data is involved:
Data Controller — Dealership Staff Data
For information about dealership staff and administrators who create and use Shiftix accounts, we are the data controller. We determine how and why that information is collected and processed.
Data Processor — Dealership End-Customer Data
For information about a dealership's customers and leads — people who have never created a Shiftix account — we act as a data processor on behalf of the dealership (the data controller). The dealership is responsible for the lawful basis for collecting and using that consumer data. We process it only as directed by the dealership.
3. Platform Functionality
Shiftix Cloud provides the following core capabilities, each of which involves data collection described in Section 4:
- Marketing Analytics: Connect and monitor Facebook Ads and Google Ads campaigns, view performance metrics, and receive AI-powered optimization recommendations.
- Lead CRM: Capture and manage customer leads from Facebook Lead Forms, Google Lead Form Extensions, ADF/XML data imports, and manual entry. Track deal stages, contacts, and sales pipeline.
- Reputation Management: Monitor customer reviews across Google Business Profile and other review platforms.
- Unified Communications: Send and receive SMS messages, make and receive phone calls, deploy an AI voice agent (Aria) for inbound and outbound calling, and manage call recordings and transcripts.
- Inventory Management: Import and display vehicle inventory from dealer feeds; track pricing changes over time.
- Billing and Agreements: Manage subscription billing and obtain e-signatures on agreements via integrated document workflows.
- Website and SEO Tools: Audit online presence, monitor listings consistency, and evaluate website health.
4. Information We Collect
4.1 Dealership Staff Account Information
When a dealership creates accounts for its staff on Shiftix, we collect:
- Name and email address
- Password (stored as a bcrypt hash; plaintext is never stored or accessible)
- Role and permissions within the dealership account
- Two-factor authentication credentials
- Session tokens, login timestamps, and IP addresses (for security purposes)
4.2 Lead and CRM Data (Consumer PII)
Through dealership-configured integrations, we receive and store information about the dealership's customers and prospective customers, including:
- Full name, email address, and phone number(s)
- Vehicle of interest, trade-in details, and deal stage
- Lead source (Facebook Lead Form, Google Lead Form, ADF/XML import, or manual entry)
- CRM notes and activity logs created by dealership staff
- AI-generated lead scores and opportunity insights
This data is processed on behalf of the dealership (as data processor) and is used solely to provide the CRM and lead management features the dealership has configured.
4.3 Communications Data
When dealerships use our unified communications features, we collect and store:
- Call recordings: Audio recordings of inbound and outbound calls handled through the platform. Recordings are stored securely and accessible only to authorized dealership staff.
- Call transcripts: Text transcriptions of calls processed by our AI voice agent (Aria).
- AI call summaries: Structured summaries generated from call transcripts, including caller intent, urgency, and recommended follow-up actions. These are generated using AI and may contain consumer-identifying information derived from the call.
- SMS message content: Full text of inbound and outbound SMS messages exchanged between dealership staff and customers through the platform.
- Phone numbers: Caller and recipient phone numbers associated with call and message records.
- Opt-out status: Records of consumers who have sent a STOP keyword or otherwise opted out of SMS communications. Opt-out status is enforced and cannot be overridden.
Call Recording Notice: Calls made through Shiftix may be recorded. Dealerships are responsible for providing required call recording disclosures to callers in compliance with applicable state and federal law, including two-party consent requirements in states such as California, Florida, and Illinois. Shiftix provides the recording capability; the dealership is responsible for the consent disclosure.
4.4 Shiftix Cloud SMS Program
Consumers may optionally opt in to the Shiftix Cloud SMS Program through the public contact form at https://www.shiftixcloud.com/contact#sms-consent. The SMS consent checkbox is separate from the form submission, is unchecked by default, and is not required to submit an inquiry or make a purchase.
- Program messages: Inquiry follow-up, product information, appointment scheduling, customer care, and occasional promotional messages from Shiftix Cloud.
- Frequency and charges: Message frequency may vary. Message and data rates may apply.
- Opt out: Reply STOP at any time to unsubscribe. A confirmation will be sent and no further messages will be sent unless you opt in again.
- Help: Reply HELP for assistance or email support@shiftixcloud.com.
- Consent: Consent to receive SMS messages is not a condition of purchase.
SMS consent privacy: Your mobile information will not be sold or shared with third parties or affiliates for promotional or marketing purposes. Text messaging originator opt-in data and consent will not be shared with third parties for purposes unrelated to providing the Shiftix Cloud SMS Program. We may share mobile information and consent status only with service providers that help us deliver the program, such as messaging platform providers and phone carriers, and only for that operational purpose.
4.5 Advertising and Marketing Data
- Facebook Ads: Ad account information, campaign structure, performance metrics (reach, impressions, clicks, spend, conversions), and ad creative details — accessed via Facebook Marketing API with dealership authorization.
- Google Ads: Account information, campaign performance metrics (impressions, clicks, conversions, cost), and budget data — accessed read-only via Google Ads API with dealership authorization.
- Facebook Lead Forms: Consumer lead submissions (name, email, phone) captured through Facebook Lead Form integrations configured by the dealership.
- Google Lead Form Extensions: Consumer lead submissions captured through Google Lead Form Extensions configured by the dealership.
- Facebook Conversions API (CAPI): On behalf of dealerships that enable this feature, we transmit hashed conversion event data (which may include hashed email address, phone number, or other identifiers) to Meta to support campaign measurement and optimization. This data is hashed before transmission and used for advertising attribution purposes only.
4.6 Billing and Agreement Data
- Billing contact name and email address
- Subscription plan, payment history, and billing status (payment card details are handled directly by Stripe and are not stored by Shiftix)
- E-signature records: signer name, email address, IP address, timestamp, and signature event log for agreements executed through our integrated e-signature workflow
4.7 Error Monitoring and Session Data
We use Sentry, a third-party error monitoring service, to detect and diagnose application errors. Sentry may capture:
- Error stack traces and diagnostic context
- Authenticated user email address (attached to error reports to help diagnose account-specific issues)
- Session replay data for a sample of user sessions and all error-producing sessions — text content and media are masked and blocked, so no form content, passwords, or sensitive screen content is captured in replays
- Performance trace samples (approximately 10% of production sessions)
4.8 Inventory Data
- Vehicle records imported from dealer inventory feeds (VIN, make, model, year, price, images, description)
- Price change history tracked per vehicle over time
5. How We Use Information
We use the information we collect for the following purposes:
- Platform operation: Providing the features and services the dealership has configured and subscribed to
- CRM and lead management: Storing, organizing, and displaying lead and customer data for dealership staff
- Communications: Routing calls and SMS messages, generating AI call summaries and transcripts, enforcing opt-out preferences
- Analytics and reporting: Generating dashboards, metrics, and performance reports from connected advertising platforms
- AI-powered features: Generating optimization recommendations, lead scores, call summaries, and other AI-assisted insights using data you provide
- Account administration: Managing user accounts, authentication, roles, and permissions
- Billing: Processing subscription payments and managing agreements
- Security: Detecting fraud, unauthorized access, and protecting platform integrity
- Error diagnosis: Identifying and fixing application errors and performance issues
- Legal compliance: Meeting our obligations under applicable law
No data training, no data selling: We do not use your data or your customers' data to train AI or machine learning models, sell or rent data to third parties, or use data for advertising purposes unrelated to your account. AI provider APIs used by Shiftix are engaged under terms that prohibit use of submitted data for model training.
6. Subprocessors and Third-Party Services
We do not sell, trade, or rent personal information. We share data only with the following categories of third-party service providers ("subprocessors") as necessary to operate the platform. Each is engaged under contractual terms that restrict their use of data to providing services to us.
| Provider | Purpose | Data Shared |
|---|---|---|
| Neon (PostgreSQL) | Database hosting | All tenant data |
| Telnyx | Voice and SMS carrier | Phone numbers, call audio, SMS content |
| Retell AI | AI outbound voice campaigns | Phone numbers, call audio during session |
| OpenAI | AI features (live call processing, summaries) | Call transcripts and notes (may include consumer PII) |
| OpenRouter | AI features (post-call classification) | Call transcripts and notes (may include consumer PII) |
| Stripe | Payment processing | Billing contact, subscription state |
| Dropbox Sign (HelloSign) | E-signature | Signer name, email, IP address, signature events |
| Resend | Transactional email | Recipient email address, message content |
| Sentry | Error monitoring and session replay | Error traces, authenticated user email (text/media masked in replays) |
| Meta / Facebook | Ad management, lead forms, CAPI attribution | Ad account metrics, lead submissions, hashed conversion events |
| Ad management, lead forms, reviews | Ad account metrics, lead submissions, review data | |
| Kenect | Dealership messaging integration | Inbound SMS content, lead data |
We may also disclose information when required by law, court order, or to protect the rights and safety of Shiftix, its customers, or others.
7. Data Security
We implement industry-standard technical and organizational measures to protect data:
- All data encrypted in transit using TLS 1.2+
- All data encrypted at rest
- Passwords hashed using bcrypt with salt; plaintext passwords are never stored
- OAuth tokens stored securely with automatic refresh
- Role-based access controls limiting data access to authorized personnel
- Audit logging of administrative and sensitive actions
- Regular security assessments and dependency audits
- Session replay text and media masking in error monitoring
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
8. Data Retention
- Active accounts: Data is retained for the duration of the dealership's active subscription.
- Account closure: Upon account closure or deletion request, tenant data is retained for 30 days to allow re-activation or data export, then permanently deleted.
- Database backups: Automated database backups are purged on a 30-day rolling basis.
- Disconnected integrations: When an advertising account integration is disconnected, associated campaign and performance data is deleted within 30 days.
- Call recordings: Retained for the duration of the subscription unless the dealership deletes them earlier. Deleted with all other account data upon closure.
You may request a data export before account closure by contacting privacy@shiftixcloud.com.
9. Your Rights and Controls
Dealership administrators have the following controls over their account data:
- Access: View data held in your account via the platform dashboard
- Correct: Update account and user information at any time in Settings
- Disconnect integrations: Revoke access to connected advertising accounts at any time
- Export: Request an export of your account data in a portable format
- Delete: Request deletion of your account and all associated data
Dealerships acting as data controllers for their customers' data are responsible for handling data subject requests (access, deletion, correction) from those consumers in accordance with applicable law.
To exercise any of the rights above or to submit a data subject request, contact us at privacy@shiftixcloud.com. We will respond within 30 days.
10. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights regarding your personal information.
Your California Rights
- Right to Know: You may request that we disclose what personal information we have collected about you, the categories of sources, the purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information we maintain about you.
- Right to Opt-Out of Sale or Sharing: We do not sell personal information. We do not share personal information for cross-context behavioral advertising purposes, except where a dealership has explicitly enabled Facebook CAPI (see Section 4.4), in which case the dealership is the party responsible for obtaining appropriate consumer consent.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To submit a CCPA request, contact privacy@shiftixcloud.com with "California Privacy Request" in the subject line. We will respond within 45 days. We may need to verify your identity before processing the request.
11. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) or equivalent legislation may apply to the processing of your personal data.
Legal Bases for Processing
Where we act as data controller, we rely on the following legal bases under GDPR Article 6:
- Contract (Art. 6(1)(b)): Processing necessary to perform our agreement with you — account creation, platform operation, billing, and authentication.
- Legitimate Interests (Art. 6(1)(f)): Processing for security, fraud prevention, error monitoring, and service improvement, where our interests do not override your fundamental rights.
- Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with applicable laws.
- Consent (Art. 6(1)(a)): Where we have obtained your explicit consent, such as for optional communications.
Your GDPR Rights
Where GDPR applies, you have the right to access, rectify, erase, restrict processing of, and port your personal data. You also have the right to object to processing based on legitimate interests. To exercise these rights, contact privacy@shiftixcloud.com. You also have the right to lodge a complaint with your local supervisory authority.
International Data Transfers
Shiftix Cloud is operated from the United States. If you are located in the EEA or UK, your data may be transferred to and processed in the United States. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.
12. Cookies
We use only essential cookies required for platform functionality:
- Session cookies: Maintain your authenticated login session
- Preference cookies: Remember your display preferences (theme, settings)
We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies on our platform. The error monitoring tool (Sentry) may use a session identifier to correlate errors with sessions; this is used solely for error diagnosis and is not used for advertising.
13. Changes to This Policy
We may update this Privacy Policy when our practices change materially. We will notify you of significant changes by updating the "Last updated" date on this page and, for material changes, by sending an email notification to the dealership's primary account contact. Your continued use of our services after the effective date of a revised policy constitutes acceptance of the changes.
14. Contact Us
For questions about this Privacy Policy, to exercise your privacy rights, or to submit a data request, contact our privacy team:
Shiftix Cloud — Privacy
Email: privacy@shiftixcloud.com
We aim to respond to all privacy requests within 30 days.
