EasyRecon Privacy Policy
This policy explains how EasyRecon handles personal information for the website, web app, mobile app, support, billing, AI, and messaging workflows.
1. Scope
- EasyRecon is a business-to-business software service for dealership recon, inventory, service, vendor, and operational workflows.
- This Privacy Policy applies to easyreconauto.com, the EasyRecon web app, any mobile app, support, billing, onboarding, messaging, and related services.
- Dealership customers control the Customer Data they place in EasyRecon. EasyRecon generally acts as a service provider or processor for Customer Data handled on a dealership's behalf.
2. Information We Collect
- Account and user information, including name, work email, phone number, title, dealership name, rooftop, role, login identifiers, and authentication details.
- Dealership operational data, including vehicle records, VINs, stock numbers, mileage, recon stages, work items, parts, approvals, notes, timestamps, assignments, vendor details, and customer report data.
- Photos, attachments, free-form notes, messages, AI prompts, AI outputs, inspection content, and other information users choose to upload or generate in the Service.
- Billing and transaction information handled through Stripe or another payment provider. EasyRecon does not intentionally collect or store full payment card numbers.
- SMS, email, support, and troubleshooting communications, including message content, delivery status, opt-out status, and support context.
- Technical information such as IP address, device and browser type, operating system, app version, log data, crash/error data, session data, and security events.
- Website and product usage information, such as pages viewed, features used, referral source, approximate location inferred from IP address, and interaction timestamps.
3. How We Use Information
- To provide, operate, secure, maintain, troubleshoot, and support the Service.
- To authenticate users, enforce permissions, maintain audit trails, and prevent unauthorized access.
- To process billing, account administration, onboarding, support, renewals, cancellation requests, and service notices.
- To send operational messages requested or enabled by a dealership, including recon workflow messages, vendor or staff notifications, and account/service communications.
- To provide AI-assisted features, such as summaries, recommendations, reports, workflow analysis, or support responses.
- To improve reliability, product quality, performance, security, and usability using aggregated, de-identified, or limited operational data where practical.
- To detect, prevent, and investigate fraud, abuse, spam, security incidents, policy violations, and legal violations.
- To comply with law, lawful requests, tax/accounting obligations, contract enforcement, and dispute resolution.
4. AI Processing
- EasyRecon may use AI service providers to process prompts, vehicle/workflow context, notes, photos, or other Customer Data only as needed to provide AI-enabled Service features.
- EasyRecon does not use Customer Data to train general AI models for other customers.
- AI outputs can be incomplete or inaccurate. Customers and users are responsible for reviewing AI-generated outputs before relying on them for business decisions.
5. How We Share Information
- With authorized users within the relevant dealership account, based on roles, permissions, rooftop access, and workspace settings.
- With service providers that help us provide the Service, including authentication, hosting, database, storage, payment, messaging, AI, analytics, monitoring, security, support, and infrastructure providers.
- With a dealership customer, account administrator, or authorized representative for account management, support, compliance, billing, export, or security purposes.
- With Stripe or another payment provider for payment, billing, invoice, tax, fraud prevention, and subscription administration.
- With Twilio or another messaging provider when SMS or messaging features are used.
- With AI providers when AI-enabled features are used, subject to the limits described in this policy and our agreements with those providers.
- When required by law, subpoena, court order, regulatory request, legal process, or to protect rights, safety, security, and the integrity of the Service.
- As part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and data protection safeguards.
6. No Sale or Advertising Sharing
- EasyRecon does not sell personal information for money.
- EasyRecon does not share personal information for cross-context behavioral advertising or unrelated third-party advertising.
- Messaging opt-in data and SMS consent data are not sold, rented, shared, or bought for unrelated marketing.
7. Cookies and Similar Technologies
- EasyRecon uses cookies, local storage, session storage, and similar technologies for login sessions, security, fraud prevention, product functionality, preferences, billing, and basic site or product measurement.
- Essential cookies are required for authentication, security, and core Service functionality. Disabling them may prevent the Service from working.
- EasyRecon does not currently use third-party advertising or retargeting cookies on the public website. If optional analytics, advertising, or retargeting tools are added, we will update our Cookie Policy and use consent controls where required.
8. Do Not Track, GPC, and Third-Party Tracking
- Some browsers offer Do Not Track signals. Because there is no uniform industry standard for responding to those signals, EasyRecon does not currently respond to Do Not Track signals.
- EasyRecon does not currently permit third-party advertising networks to collect personal information about visitors' online activities over time and across different websites through the public website.
- If EasyRecon later engages in activity that legally requires honoring Global Privacy Control or similar opt-out signals, EasyRecon will update this policy and implement the required controls.
9. Customer Responsibilities
- Dealership customers are responsible for the Customer Data they submit, the users they invite, the access permissions they configure, and the lawful basis for using EasyRecon with their employees, contractors, vendors, and customers.
- If a dealership uses SMS, email, or other messaging features, the dealership is responsible for obtaining and maintaining required consents, honoring opt-outs, and using messaging only for lawful operational purposes.
- Customers should not submit sensitive personal information unless it is necessary for legitimate dealership operations and permitted by law and their agreement with EasyRecon.
10. Retention, Export, and Deletion
- EasyRecon keeps information for as long as needed to provide the Service, comply with law, resolve disputes, enforce agreements, maintain security, and support business records.
- During the subscription and for a limited period after termination, customers may request export of Customer Data in a reasonable machine-readable format.
- After termination and any export period, EasyRecon may delete Customer Data from production systems. Backups may remain for a limited period under normal backup and disaster recovery schedules.
- Certain billing, security, compliance, support, and legal records may be retained longer where needed for legitimate business or legal purposes.
11. Security
- EasyRecon uses reasonable administrative, technical, and organizational safeguards appropriate for its size, stage, systems, and the nature of the data handled.
- Safeguards may include authentication controls, role-based permissions, HTTPS/TLS in transit, provider-supported encryption at rest, logging, monitoring, backups, and limited internal access.
- No system is perfectly secure. EasyRecon cannot guarantee absolute security, and customers are responsible for using strong passwords, protecting devices, and promptly reporting suspected unauthorized access.
12. Privacy Rights and Requests
- Account users may request access, correction, export, or deletion by contacting privacy@easyreconauto.com.
- If EasyRecon processes information on behalf of a dealership customer, the request may need to be handled through that dealership customer.
- EasyRecon may verify requests, reject requests that are unlawful or unverifiable, and retain information where permitted or required by law.
- Depending on location and applicable law, individuals may have additional rights regarding access, correction, deletion, portability, objection, restriction, or opt-out of certain processing.
13. Children
- EasyRecon is not directed to children and is not intended for users under 13.
- Customers may not knowingly submit children's personal information to EasyRecon unless they have the legal authority and all required notices and consents.
14. Changes and Contact
- EasyRecon may update this Privacy Policy from time to time. Material changes will be posted or otherwise communicated before they take effect where required.
- Privacy questions or requests: privacy@easyreconauto.com.
- Support questions: support@easyreconauto.com.