Vendor privacy terms

What should a dealership check in a software vendor's privacy terms?

Whether the vendor can use your customer data for anything beyond providing the service to you. The clauses that matter are secondary use, aggregation, model training, sharing with affiliates and what survives termination. A provider permitted to use dealership customer data for its own products is a different commercial relationship from one that is not.

Direct answerSeptember 1, 2026 reviewedNeutral evaluation
01

Secondary use and aggregation

Look for permission to use data in de-identified or aggregated form. That is common and often reasonable, but confirm the de-identification standard and whether the output is sold.

02

Model training

Establish explicitly whether your customer data can train models used for other customers, and whether you can opt out. Silence is not an answer.

03

Affiliates and subprocessors

Ask for the current subprocessor list and notification obligations when it changes. Data flowing to a parent company or sibling product is a disclosure your customers may not expect.

04

What survives termination

Confirm retention periods after the relationship ends, deletion commitments and whether any licence to use the data persists. Perpetual licences to dealership customer data should be negotiated out.

Decision checklist

What to verify

Open procurement templates →

Look for secondary use and aggregation permissions

Ask explicitly about model training and opt-out

Request the subprocessor list and change notifications

Confirm what licence and retention survive termination

Related market maps

Continue the research

People also research

Related dealership technology questions