Trust & Security
How ARC handles dealer and customer data.
We never open the glovebox. Here is what that means in practice — specific enough to forward to your accountant or attorney.
Last reviewed: July 15, 2026
01 — Scope
What we touch — and what we never touch.
We work with lead contact details, inquiry content, appointment scheduling, and the service and sales history already in your CRM or DMS.
No credit applications. No SSNs. No F&I data — ever, in writing.
Finance messages are status-only: “your update is ready — call us.” We never handle the underlying financial records.
02 — GLBA
GLBA and the FTC Safeguards Rule.
Dealerships are financial institutions under GLBA, which is why finance data carries the exposure it does.
ARC is scoped to operate outside NPI entirely. Handling of the non-NPI data we do touch is GLBA/Safeguards-aware.
03 — TCPA
TCPA and texting.
TCPA consent and DNC handling are built into every text.
Opt-outs are honored immediately. We send no cold texts to numbers without consent on file.
04 — AI & retention
AI and data retention.
We use zero-retention AI: providers are configured not to retain or train on dealer data.
Processing runs on US-region hosting.
05 — Agreements
Agreements, before we see anything.
An NDA and a data-processing agreement are ready before we see a single record.
Both are available on request before any call is booked.
06 — Questions
Questions.
Questions go straight to a founder. Email hello@arcaitech.com and one of us replies personally.
Or call or text +1 (737) 371-7412 or +1 (737) 271-7860.
Want the DPA or NDA before you talk to us? Ask and we’ll send both. Book a 15-minute call →