Skip to main content

Trust & Security

How ARC handles dealer and customer data.

We never open the glovebox. Here is what that means in practice — specific enough to forward to your accountant or attorney.

Last reviewed: July 15, 2026

01Scope

What we touch — and what we never touch.

We work with lead contact details, inquiry content, appointment scheduling, and the service and sales history already in your CRM or DMS.

No credit applications. No SSNs. No F&I data — ever, in writing.

Finance messages are status-only: “your update is ready — call us.” We never handle the underlying financial records.

02GLBA

GLBA and the FTC Safeguards Rule.

Dealerships are financial institutions under GLBA, which is why finance data carries the exposure it does.

ARC is scoped to operate outside NPI entirely. Handling of the non-NPI data we do touch is GLBA/Safeguards-aware.

03TCPA

TCPA and texting.

TCPA consent and DNC handling are built into every text.

Opt-outs are honored immediately. We send no cold texts to numbers without consent on file.

04AI & retention

AI and data retention.

We use zero-retention AI: providers are configured not to retain or train on dealer data.

Processing runs on US-region hosting.

05Agreements

Agreements, before we see anything.

An NDA and a data-processing agreement are ready before we see a single record.

Both are available on request before any call is booked.

06Questions

Questions.

Questions go straight to a founder. Email hello@arcaitech.com and one of us replies personally.

Or call or text +1 (737) 371-7412 or +1 (737) 271-7860.

Want the DPA or NDA before you talk to us? Ask and we’ll send both. Book a 15-minute call →