Privacy Policy
The short version.
SoldIQ is software that dealerships use to answer their own customers. Most of the personal information in our system belongs to a dealership's buyers and is processed on that dealership's instructions. Our browser extension reads only the text a salesperson highlights and right-clicks — it has no ability to read a page on its own. We never ask a dealership for a DMS or CRM login. We do not sell personal information, and we never share phone numbers or text-messaging consent with anyone else for their own marketing. You can ask us for a copy of your data or ask us to delete it.
1. Who this policy covers
This policy describes how SoldIQ handles personal information in the SoldIQ platform: our website, our dashboard at app.soldiq.app, our browser extension, and the messaging our customers send through us.
It is not a dealership's own privacy policy. Each dealership that uses SoldIQ publishes its own privacy and text-messaging terms on its own website. If you are a buyer who received a message, the dealership named in that message is the business you are dealing with, and its policy governs how it uses your information. This policy explains what we do as its service provider.
2. Controller and processor
For personal information about buyers and leads — the people who message or call a dealership — the dealership is the controller and SoldIQ is the processor (a "service provider" under US state privacy laws). We process that information only to provide the service to that dealership, under our agreement with them, and not for our own independent purposes.
For personal information about our own customers — the dealership's owner, managers and staff who hold SoldIQ accounts — we are the controller, and this policy describes our own handling.
3. Information we collect
3.1 Dealership account data (we are the controller)
- Name, work email, phone number and role of each user we create an account for.
- Business details supplied for carrier registration: legal business name, tax ID/EIN, business address, website and authorized-representative contact. This is required by mobile carriers before a business can send text messages, and it is passed to our messaging provider and to the carriers for vetting.
- Dealership configuration: business hours, quiet-hour settings, message templates, sales playbook, team membership and inventory records the dealership imports.
- Billing contact details. Payment card details are handled by our payment processor; we do not store full card numbers.
3.2 Buyer and lead data (processed for the dealership)
- Name or profile display name as it appears in the conversation.
- Phone number, when the buyer provides one.
- The content of messages exchanged with the dealership, and the channel and timestamps.
- Inquiry details: which unit the buyer asked about, appointment times, and notes or tasks a salesperson records.
- Consent records: when and how the buyer gave a phone number, submitted a form or called in, and any STOP or START they send.
- A coarse time zone derived from the area code of the phone number, used only to keep messages inside permitted hours.
- Calls, where a dealership routes its phone number through SoldIQ: the caller's number, the time, and whether the call was answered. If that dealership switches voicemail on, the recording — and its transcript, if that is also switched on — is stored with the conversation. Callers hear a spoken recording notice before the tone, every time, and it is not a setting a dealership can turn off.
- Trade-in details, where a buyer fills in the trade form we text them a link to: the vehicle's year, make, model, condition answers and up to eight photos they choose to upload.
- An audit trail of automated messages: what was sent, what was suppressed, and why.
We do not ask for and do not want government identifiers, financial account numbers, credit applications, health information, or precise location. If a buyer sends something like that in a message, it is stored as part of that message; the dealership can delete it, and we ask dealerships to route credit and financing conversations off the platform.
3.3 Technical data
- Standard server and security logs: IP address, timestamp, request path, browser user agent, and errors.
- An audit log of actions taken in the product — who sent what, who changed a setting, which automated messages were sent or suppressed and why.
Our marketing site uses no analytics cookies, no advertising trackers and no third-party scripts; its fonts are served from our own domain. The dashboard uses only the cookies or local storage required to keep you signed in.
4. The browser extension: what it can see, and what it cannot
A salesperson answering a buyer on Facebook Marketplace or Messenger installs a Chrome extension. It is the narrowest piece of the product, deliberately, and this is what it does.
When a salesperson selects text in a conversation and clicks an item in our right-click menu, three things are sent to that dealership's own SoldIQ backend:
- The text they highlighted.
- The title and web address of the tab they were looking at, which is how we tell one buyer's conversation from another's — the title carries the buyer's display name.
- Their SoldIQ sign-in, to prove the request came from one of that dealership's salespeople.
That is the whole list. And the following are not limitations we have chosen to apply — they are things the extension has no technical ability to do:
- It does not read pages. There is no content script, no page reader, no scraping and no polling. The extension holds no Facebook or Messenger permissions at all, so nothing reaches it unless a human selects text and clicks our menu item.
- It reads the selection and nothing around it — not the thread above it, not the rest of your inbox, not your other tabs, not your browsing history.
- It never sends, posts, replies, likes or types anything on Facebook. Drafts come back to the salesperson's clipboard, and a human pastes and sends them.
- It never asks for, receives or stores a Facebook password. It runs inside the session the salesperson is already signed into.
- It talks to one host — the dealership's own SoldIQ backend. There is no analytics SDK, no telemetry, no crash reporter and no advertising network in it.
One narrow exception, and it is worth stating precisely: when a very long passage is selected, Chrome may hand the extension a truncated copy. In that case only, the extension asks the salesperson's permission to run a single function in that tab, whose entire job is to return the text they selected. It reads nothing else and keeps nothing. If they decline, the product carries on with the shorter text.
On the salesperson's own machine the extension keeps their sign-in in local storage, which is never synced to a Google account or another computer; which SoldIQ backend to call; and the last draft it received, in session storage that Chrome erases when the browser closes.
5. What we never ask a dealership for
We do not ask for, and will not accept, a login to your DMS, your CRM or your website's admin panel. This is a standing rule, not a current limitation.
The reason is that a DMS login is not an inventory credential. It is the account that can read customer credit applications, social security numbers and deal jackets, and there is generally no read-only version of it to hand out. Inventory reaches us as a feed instead — a file you send or a listing URL we read. A feed is scoped to inventory, you can revoke it, and it exposes nothing that is not already on your own website.
Where a dealership does give us a credential — a Facebook Page token, a feed key — it is stored in a separate table that no dashboard user can read, including the owner, and is used only by our server-side functions.
6. How we use information
- To provide the service: drafting replies, sending and receiving messages on a dealership's behalf, handling missed calls, scheduling appointments and reminders, and showing the dealership its own conversations.
- To enforce messaging rules: consent checks, opt-out suppression, quiet hours, sending caps, and the audit trail that proves all of it.
- To register and maintain messaging campaigns with our messaging provider and mobile carriers, as those parties require.
- To support, secure, debug and improve the platform, and to detect abuse.
- To bill our customers and communicate with them about their account.
- To comply with law and to respond to lawful requests.
We do not use buyer message content to train our own models or any third party's models, and we do not use one dealership's data to benefit another. Aggregate, de-identified counts (for example, "median response time across the platform") may be used to improve the product.
7. Automated message drafting
SoldIQ uses Google's Gemini API to draft replies. When a reply is generated, the relevant conversation history, the dealership's own inventory and settings, and the buyer's message are sent to Google through its commercial API for the sole purpose of producing that reply. It is the only language-model provider we use.
We use the paid API tier, chosen because Google's terms for it state that content submitted through it is not used to improve Google's models. Drafts for personal-Messenger conversations are always reviewed by a human before they are sent. Automated replies sent by text are subject to the consent, opt-out and quiet-hour controls described below and in our messaging policy.
The system is built not to invent facts about money or stock: prices and availability come only from the dealership's own inventory records, and a reply containing a figure the model did not verify against those records is held back rather than sent.
8. Text messages, consent and opt-outs
Every outbound text passes through one gate in our code, and it will not send unless all of the following are true. The messaging policy covers this from a buyer's point of view; this is what happens in the system.
- There is a consent record. Each one stores what actually happened and when — a number given in a Messenger thread is recorded differently from a submitted lead form, which is recorded differently again from an inbound phone call. The evidence is stored with it, so a claim about consent can be checked rather than asserted.
- The person has not opted out. STOP is honoured at the carrier and written to our database in the same moment, so nothing already scheduled can slip out afterwards. An opt-out lasts indefinitely, applies across channels — telling a dealership to stop in a Messenger thread suppresses its texts too — and blocks even a first message to someone who opted out before. Only an explicit START undoes it.
- It is within quiet hours. Automated messages go out between 9:00 am and 8:00 pm in the recipient's own time zone, worked out from their area code. A message that would land outside that window is rescheduled to the next permitted time rather than dropped. The one exception is a reply to someone who messaged or called in the last few minutes and is waiting for an answer.
- It is under the per-recipient daily cap.
- It is written to the audit log, along with every message the gate suppressed and the reason it did.
9. Service providers (subprocessors)
We use a small number of vendors to run the platform. Each is bound by contract to process data only to provide its service to us. This is the whole list — we have no others, and we have no analytics or advertising vendors at all.
- Supabase — hosts our database and our server-side functions. Everything described in section 3 is stored there.
- Twilio — sends and receives text messages and handles calls, provides the phone numbers, handles carrier-level opt-out, and carries out the business registration and vetting that mobile carriers require. US mobile carriers necessarily receive the messages themselves.
- Google — two separate services. The Gemini API generates draft replies, as described in section 7. Google Calendar receives appointment details, but only for a dealership that connects a calendar.
- Resend — delivers our transactional email: account mail, and the alerts that tell a dealership a conversation needs a human.
- Meta — where a dealership connects its Facebook Page, Instagram account or lead ads, those messages are exchanged through Meta's official APIs and are also subject to Meta's own terms and privacy policy. Note that this does not apply to a salesperson's personal Messenger conversations, which never pass through us at all.
- Vercel — hosts this marketing website. It sees ordinary web-server request logs for visits to these pages, and no customer or buyer data.
- Stripe — not currently in use. The product has a deposit feature that is switched off. If it is ever switched on and a dealership turns it on, the payment is made to that dealership's own Stripe account using a key they supply: we never hold a buyer's money, take no cut, and never see a card number. If that changes, this policy changes first.
10. What we do not do with your information
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not share phone numbers or SMS consent with third parties or affiliates for their own marketing purposes. Consent to be texted by a dealership stays with that dealership and is used only for its conversations with you.
- We do not send marketing text messages of our own to a dealership's buyers.
- We do not disclose a dealership's conversations, leads or inventory to another dealership.
- We do not ask any dealership for a DMS or CRM login, as described in section 5.
We may disclose information when required by law, to enforce our agreements, to protect the rights or safety of any person, or as part of a merger or acquisition — in which case the acquirer is bound by commitments no weaker than these.
11. Where our data is
SoldIQ is operated from the United States and serves dealerships in the United States. Our vendors above are US-based or run the service for us on US infrastructure. If you use the service from elsewhere, you are sending your information to the United States, where privacy law may differ from your own.
12. Retention
- Conversations, leads, calls, trade-in submissions and appointments are kept for as long as the dealership's account is active, because the dealership needs its own customer history. On account closure they are deleted or returned within 90 days, except as noted below.
- Consent and opt-out records are kept for at least four years after the account closes, because they are the evidence that a message was permitted. A record that someone opted out is kept indefinitely, so that we never message them again.
- Audit and security logs are kept for 12 months.
- Billing records are kept as long as tax and accounting law requires.
13. Your choices and requests
If you are a buyer: reply STOP to any text to stop messages immediately, or HELP for contact details. To see, correct or delete the information a dealership holds about you, contact that dealership — it is the business that collected it, and it can delete your record itself. You can also write to us at hello@soldiq.app and we will route your request to the right dealership and act on their instruction, or handle it directly where the law requires us to. Tell us the phone number or the name of the dealership so we can find you.
If you are a SoldIQ customer or user: email hello@soldiq.app to access, correct, export or delete your account information, or to close your account and have its data removed.
Depending on where you live you may have rights to access, correct, delete, port or limit the use of your personal information, and to appeal a refusal. We do not discriminate against anyone for exercising these rights. We verify requests before acting on them, and we respond within the time the applicable law allows.
14. Security
We encrypt data in transit with TLS and at rest at the storage layer. Access to production data is restricted to the people who need it, over multi-factor-authenticated accounts. Each dealership's data is isolated at the database level by row-level security, so one customer's queries cannot reach another's records. Privileged keys are held only by server-side functions, never by the browser extension or the dashboard, and per-dealership credentials live in a table that no signed-in user can read. Sensitive actions are written to an audit log. Inbound webhooks from our messaging and platform providers are signature-verified.
No system is perfectly secure. We do not hold SOC 2, ISO 27001 or any other security certification, and we do not claim one. If a breach affects personal information we process, we notify the affected dealership without undue delay and support their notification obligations.
15. Children
SoldIQ is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn that we hold information from a child under 16, we delete it. If you believe a child's information has been submitted, write to hello@soldiq.app.
16. Changes
We will update this policy when the product or our vendors change. The effective date at the top always reflects the current version, and we notify account holders by email before a material change takes effect.
17. Contact
First Round Games LLC
513 US Highway 60 E, Unit #889
Republic, MO 65738
hello@soldiq.app · (417) 413-4454