Privacy Notice
Last updated: August 26, 2026
1. Who we are
DealIQ is operated by Devin Scott Eugene Smith, a sole proprietor trading as DealIQ. For personal data relating to our own users and website visitors, we act as the data controller. Contact: privacy@deal-iq.app.
Where your dealership enters information about its own customers into DealIQ, the dealership is the controller of that information and we act as a processor, handling it only on the dealership's instructions to provide the service.
2. Personal data we collect and why
- Account data (name, work email, login credentials, dealership/store name, role) — to create and secure your account, control access and seats. Legal basis: performance of a contract.
- Subscription and billing metadata (plan, seat band, subscription status, customer and subscription identifiers from Paddle) — to manage entitlements and renewals. Card details are collected and held by Paddle, not by us. Legal basis: contract and legal obligation.
- Content you enter (deal structures, customer names, ZIP codes, credit-score bands, income figures, trade and inventory data, lender guidelines, notes) — to provide the desking, scoring and reporting features. Legal basis: contract; for customer records, the dealership's own basis as controller.
- Support communications (messages, attachments) — to answer questions and resolve issues. Legal basis: contract and legitimate interests.
- Usage and telemetry (pages viewed, feature use, timestamps, error logs) — to keep the service reliable and improve it. Legal basis: legitimate interests.
- Device and network data (IP address, browser and device identifiers) — for security, abuse and fraud prevention. Legal basis: legitimate interests and legal obligation.
- Marketing contact data (email address if you opt in) — to send product updates. Legal basis: consent; you can withdraw at any time.
3. Sensitive customer information
Deal records may contain financial information about your customers. Do not enter full Social Security numbers, driver's licence images, full bank or card numbers, or other data the service does not need. Use credit-score bands and the fields provided rather than free-text notes for sensitive details.
4. Who we share data with
- Service providers / subprocessors — cloud hosting and database infrastructure, email delivery for transactional messages such as invites, error monitoring and support tooling.
- Merchant of Record — Paddle.com Market Ltd, which handles the sale of subscriptions, subscription management, payments, tax compliance and invoicing.
- Professional advisers — legal, accounting and insurance advisers where necessary.
- Authorities — where required by law, legal process, or to protect rights and safety.
- Successors — a buyer or successor in a merger, acquisition or asset sale, subject to this notice.
We do not sell personal data and we do not share it for cross-context behavioural advertising.
5. International transfers
We are based in the United States and our infrastructure providers may process data in the US and other countries. Where data is transferred from the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or an applicable adequacy decision.
6. Retention
- Account and store data: for the life of the account and up to 30 days after closure, then deleted or anonymised.
- Deal, inventory and lender data: while your subscription is active; exportable for 30 days after it ends.
- Billing and tax records: as required by law, typically up to 7 years.
- Security and error logs: normally up to 12 months.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive it in a portable format, to withdraw consent, and to opt out of marketing. UK/EEA users may complain to their supervisory authority (in the UK, the ICO). US state privacy laws may give you rights to know, delete, correct and opt out, and you will not be discriminated against for exercising them.
To exercise a right, email privacy@deal-iq.app. We respond within one month (or as your local law requires) and may need to verify your identity. If your request concerns data your dealership entered about you as its customer, we will forward it to that dealership as controller.
8. Security
We apply appropriate technical and organisational measures, including encryption in transit, encryption at rest for stored data, row-level access controls that scope data to your store, role-based permissions, and least-privilege access for administrators. No system is perfectly secure, so we cannot guarantee absolute security.
9. Cookies
We use essential cookies and local storage to keep you signed in, remember your active store and secure the session — these cannot be turned off without breaking the app. We use limited analytics storage to understand aggregate feature usage. We do not use advertising or cross-site tracking cookies. You can clear or block cookies in your browser settings; blocking essential cookies will prevent sign-in. Our checkout provider Paddle sets its own cookies during payment.
10. Children
DealIQ is a business tool and is not directed at anyone under 16. We do not knowingly collect their data.
11. Changes
We may update this notice; the date above shows the latest version, and material changes will be notified in-app or by email.