DealerHive
Products How it works Integrations Dashboard
Contact Book a Demo
← Back to home
Last updated · July 31, 2026

Privacy & Security

DealerHive handles voice calls, transcripts, and customer records for franchise auto dealerships. This document explains what we collect, how we use it, and how we keep it safe — for dealerships, end callers, and our team.

On this page
  1. Overview
  2. Information we collect
  3. How we use information
  4. Voice recording & AI
  5. Text messaging (SMS)
  6. Sharing & service providers
  7. Data retention
  8. Security practices
  9. Your privacy rights
  10. Dealer obligations
  11. Cookies & analytics
  12. International transfers
  13. Children's privacy
  14. Changes to this policy
  15. Contact us

1. Overview

InsightHive Technologies Inc, doing business as DealerHive ("DealerHive", "we", "us"), operates an AI voice platform that answers, qualifies, and routes phone calls on behalf of automotive dealerships. We process two kinds of personal information: information about dealership users who administer the service, and information about end callers (your customers) who interact with the AI agents.

This Privacy & Security notice applies to dealerhive.ai, the DealerHive dashboard, and all calls handled by our AI agents. It does not cover dealership websites, third-party CRMs, or telephony providers we integrate with — those have their own policies.

Quick summary

We record and transcribe calls to provide the service. We never sell personal information. End callers are notified that the call is handled by an AI before any qualifying conversation begins. Dealers control retention and can delete records on request.

2. Information we collect

2.1 From dealership account holders

  • Account details: name, work email, role, dealership name and rooftop locations.
  • Billing information: payment method handled by our PCI-DSS-compliant processor; we don't store full card numbers.
  • Configuration: agent persona settings, business hours, scripts, routing rules, and integrations you enable.

2.2 From end callers (your customers)

  • Audio recordings of inbound and outbound calls handled by the AI.
  • Transcripts generated from those recordings.
  • Contact details the caller volunteers during conversation: name, phone number, email, ZIP code.
  • Vehicle interest signals: make, model, year, trade-in details, budget, timing, financing intent.
  • Call metadata: caller ID, time, duration, routing outcome, sentiment.

2.3 Collected automatically

  • Usage analytics in the dashboard: page views, feature interactions, performance metrics.
  • Device & network data: IP address, browser, operating system, log timestamps.
  • Cookies and similar technologies — see Section 11.

3. How we use information

  • Operate the service: answer calls, qualify leads, book appointments, route to the right department, and write outcomes back to your CRM.
  • Provide reporting to dealership account holders.
  • Improve our AI, with de-identified data and only after aggregation. We do not train shared models on dealer-specific scripts or named customer identifiers.
  • Detect fraud and abuse on the platform.
  • Communicate service announcements, security notices, and (with consent) product updates.
  • Comply with law and respond to lawful requests.

4. Voice recording, transcripts & AI behavior

4.1 Call recording disclosure

Calls are recorded for service operation. Where law requires two-party consent (including but not limited to California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington), our AI announces that the call is being handled by an AI assistant and recorded before any qualifying conversation begins.

Dealers may not disable the AI disclosure announcement.

4.2 AI-generated voice

Our default agent voices are synthetic and were never trained on a specific person without consent. Optional voice cloning of a dealership employee requires:

  • The employee's written consent on file with the dealership.
  • A 60-second sample uploaded by the dealership, with attestation that the dealership has rights to use it.
  • DealerHive review and approval before the cloned voice is enabled in production.

4.3 AI mistakes

AI agents are designed to acknowledge uncertainty and route to a human when out of scope. They will not provide legal, financial, or medical advice. Dealerships remain responsible for the accuracy of inventory, pricing, and offer information they configure.

5. Text messaging (SMS)

DealerHive is operated by InsightHive Technologies Inc, doing business as DealerHive ("DealerHive," "we," "us"). Participating dealerships use DealerHive to send transactional and customer-care text messages to customers who have opted in. Messages include appointment confirmations and reminders, missed-call follow-ups, responses to vehicle and service inquiries, and dealership contact information.

How you opt in. You provide express consent by checking an unchecked-by-default box on our inquiry forms (including the test-drive request form and the "Talk to Lisa" chat widget) after entering your mobile number, or verbally when you call a participating dealership and agree to be texted at the number provided.

No sharing of mobile information. DealerHive and participating dealerships do not sell, rent, or share mobile phone numbers or SMS opt-in/consent information with third parties or affiliates for their own marketing or promotional purposes. Mobile opt-in data is used solely to deliver the messages described above.

Frequency, rates, and opt-out. Message frequency varies. Message and data rates may apply. Reply STOP at any time to opt out, or HELP for assistance. Consent to receive text messages is not a condition of purchasing any vehicle, product, or service.

6. Sharing & service providers

We share personal information only with parties who help us deliver the service, or where required by law.

6.1 Sub-processors

  • Cloud infrastructure: Amazon Web Services (US regions).
  • Telephony & voice AI: Vapi and Twilio (in service of call placement and signal routing).
  • Speech-to-text and language models operated under enterprise data-processing terms that prohibit training on our customer data.
  • Customer success tooling: Linear, Slack, HubSpot (account contacts only — never end-caller transcripts).

6.2 Dealer's choice integrations

When a dealership connects VinSolutions, an Xtime instance, a Tekion DMS, or any other third-party tool, we exchange the data required for that integration to function. The third party's privacy policy governs what they do with the data once it arrives.

6.3 Legal & safety

We may disclose information if compelled by valid legal process, or if disclosure is necessary to prevent fraud, abuse, or risk of harm. We never sell personal information.

6.4 Business transfers

If DealerHive is acquired or merged, customer data may transfer to the new entity. We'll notify dealership account holders before such a transfer takes effect.

7. Data retention

Default retention periods, unless your contract specifies otherwise:

  • Audio recordings: 90 days, then deleted from primary storage.
  • Transcripts & call metadata: 18 months in your dashboard, archived for 36 months total.
  • Lead records: retained for the life of the dealership account, then deleted within 90 days of account termination unless legal hold applies.
  • Backups: rolling 30-day retention; deletion requests applied to backups at next rotation.

Dealerships can request earlier deletion of any specific call or lead record from their dashboard, or by emailing infosec@dealerhive.ai.

8. Security practices

  • Encryption in transit using TLS 1.2+ for all client and inter-service traffic.
  • Encryption at rest using AES-256 for audio, transcripts, and database records.
  • Least-privilege access controls with SSO and MFA required for all employee access to production systems.
  • Audit logging of every access event and configuration change.
  • Vulnerability management: continuous dependency scanning, quarterly penetration testing, and a private bug-bounty program.
  • Incident response: 24-hour breach notification to affected dealerships, with detailed post-mortem.
  • Compliance: SOC 2 Type II audit in progress; report available to enterprise customers under NDA when complete.
Report a security issue

Found a vulnerability? Please email infosec@dealerhive.ai. We acknowledge reports within one business day.

9. Your privacy rights

9.1 California residents (CCPA / CPRA)

You have the right to know what personal information we collect, to delete it, to correct it, and to opt out of sharing for cross-context behavioral advertising. We do not sell personal information. To exercise these rights, see Contact us. We will verify your identity before processing.

9.2 EEA / UK residents (GDPR)

Where we act as a data controller, the legal bases for processing are: (a) consent for marketing communications; (b) contract performance for dealership accounts; (c) legitimate interests for fraud prevention, security, and aggregated analytics; and (d) legal obligations.

You may request access, rectification, erasure, restriction, portability, or object to processing. You may also lodge a complaint with your supervisory authority. Where we act as a data processor on behalf of a dealership, please direct requests to the dealership first.

9.3 All users

Regardless of jurisdiction, you can ask us to delete specific call records, transcripts, or contact details that pertain to you, even if you are not a DealerHive customer. We will verify the request and act on it within 30 days.

10. Dealer obligations

Dealerships using DealerHive for outbound calling must independently comply with the Telephone Consumer Protection Act (TCPA), Do-Not-Call registry rules, and any state-specific telephony or call-recording requirements. DealerHive provides tooling to support compliance — including consent capture and a do-not-call suppression list — but the dealership is the responsible party.

When integrating customer data from your DMS or CRM into DealerHive, you confirm that you have the lawful right to do so and to share that data with our service for the purposes described here.

11. Cookies & analytics

We use a small set of cookies and similar technologies:

  • Strictly necessary: session and authentication state.
  • Preferences: dashboard layout, theme, time zone.
  • Analytics: aggregated usage data via privacy-preserving telemetry. No third-party advertising cookies are set by DealerHive.

You can manage cookies via your browser settings; some features may not work if strictly-necessary cookies are blocked.

12. International data transfers

DealerHive's primary infrastructure is hosted in the United States. If you access the service from outside the United States, your information will be transferred to, stored, and processed in the United States. For EEA / UK transfers, we rely on the Standard Contractual Clauses where applicable.

13. Children's privacy

DealerHive is a B2B service intended for use by adult dealership employees. We do not knowingly collect personal information from anyone under 16. If we learn we have, we'll delete it.

14. Changes to this policy

We update this notice when we change how we handle data. Material changes will be communicated to dealership account holders by email and via an in-app banner at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.

15. Contact us

For privacy questions, requests, or to exercise any rights described above:

  • Email: infosec@dealerhive.ai

This document is provided for informational purposes. It is not legal advice. Consult counsel about how data-protection law applies to your business.

DealerHive © 2026 InsightHive Technologies Inc
Privacy & Security Terms