Data Storage & Access
Version 6 · Effective
DealerStak Canada Inc.
This document replaces the Data Access & Authorization Agreement (Version 1, May 2026) in its entirety. That version described a Google Drive integration in which the Dealer connected their own storage account and DealerStak acted only as an interface. That integration has been retired. DealerStak now stores Dealer files directly, and the previous document's statement that DealerStak "does not store primary files" is no longer accurate. This document describes how storage actually works.
It forms part of the DealerStak Terms and Conditions. Where it conflicts with the Terms and Conditions, the Terms and Conditions govern.
1. Where Your Files Are Stored
All files uploaded to the DealerStak platform are stored in DealerStak's dedicated tenant with a third-party object-storage provider, in data centres located in Western North America. That provider is identified in DealerStak's subprocessor register, available to any Dealer on request to privacy@dealerstak.com. DealerStak holds the primary copy. There is no third-party storage account for the Dealer to connect, no OAuth authorisation to grant, and no external drive for DealerStak to reach into.
This includes: vehicle photographs, generated and scanned Bills of Sale, dealer compliance documents and licences, signature specimens, expense receipts, imported bank and credit-card statements, invoices, dealership logos, and data-export bundles.
2. Ownership
The Dealer retains sole ownership of all files and data they upload. DealerStak claims no ownership interest, and does not sell, rent, licence or trade Dealer files or their contents to any third party.
DealerStak's role is that of a processor acting on the Dealer's instructions, as set out in the Data Processing Agreement.
3. Separation Between Dealers
Every stored object is namespaced under a prefix unique to the Dealer. Access is enforced both at the storage layer and by row-level security policies in the application database, which restrict every record to the Dealer that owns it. One Dealer's portal cannot enumerate or retrieve another Dealer's files.
4. How Files Are Served
Two different mechanisms are used, and the difference between them matters. Please read this Section.
4.1 — Vehicle photographs are served from a public content-delivery URL at cdn.dealerstak.com. These URLs are not guessable, but they are also not authenticated: anyone who has the URL can open the image without logging in. This is deliberate — it is what allows photographs to load quickly, to appear in StakShare bid links, and to be syndicated to the Dealer's own website and to marketplace listings. Do not upload a document containing personal or financial information as a vehicle photograph.
4.2 — Sensitive documents are served through short-lived signed links. Bills of Sale, void cheques, business licences, bank statements, expense receipts and signature specimens are not publicly reachable. Each request generates a signed URL that expires after ten minutes and is issued only after DealerStak has verified that the requesting User is authenticated and belongs to the Dealer that owns the file.
5. Encryption
Files are encrypted in transit using TLS 1.2 or higher, and at rest using AES-256.
6. Who at DealerStak Can Reach Your Files
Access by DealerStak personnel is limited to what is necessary to operate the platform and to provide support. Administrative access is exercised through the DealerStak Control Panel and is restricted to authorised DealerStak staff. DealerStak does not browse, read, index or analyse Dealer file contents except where the Dealer has invoked a feature that requires it — see Section 7 — or where necessary to investigate a specific support request or a suspected breach of the Acceptable Use Policy.
7. Automated Processing of Uploaded Documents
Certain features work by transmitting a document the Dealer has uploaded to a third-party artificial-intelligence service for automated extraction. This applies to bank and credit-card statement import, Bill of Sale scanning, vendor invoice scanning, licence expiry detection, contact-block parsing, wholesale run-list parsing, and the in-app support assistant.
The subprocessors involved, the categories of information transmitted, and the Dealer's alternatives are set out in Section 6.5 of the Terms and Conditions and Section 5 of the Data Processing Agreement. Every affected feature has a manual-entry alternative.
8. Getting Your Data Out
The Dealer may export their data at any time using the export tool in the platform. An export bundle contains the Dealer's records together with their stored files. Export requests made under the Dealer's or an individual's rights under PIPEDA are handled as described in Section 7 of the Data Processing Agreement.
Export bundles are themselves stored in DealerStak's object storage and are automatically purged after a limited retention window, so a bundle should be downloaded promptly once it is ready.
9. Deletion and Retention
When the Dealer deletes a vehicle, a document or a photograph in the platform, the corresponding object is removed from storage.
Following termination of the subscription, DealerStak retains Dealer data for thirty (30) days to allow for export, and then permanently deletes it. Retention and deletion are governed by Section 6 of the Data Processing Agreement.
10. Legacy Google Drive Links
A small number of vehicle photographs uploaded before the migration to DealerStak's own storage may still be referenced by a Google Drive or googleusercontent.com URL stored against the vehicle record. Those images continue to display but are hosted in the Google account they were originally uploaded to, not by DealerStak. DealerStak cannot guarantee their continued availability and does not treat them as part of the Dealer's stored data for export or deletion purposes. Re-uploading any such photograph moves it into DealerStak's own storage.
11. Dealer Responsibilities
The Dealer is responsible for:
- Managing which of their Users have access to the portal, and removing Users who leave
- Not uploading documents containing personal or financial information into the vehicle-photograph field, given Section 4.1
- Retaining paper copies of all records their regulator requires, as set out in Section 4 of the Acceptable Use Policy
- Ensuring their collection and use of client personal information complies with PIPEDA and applicable provincial privacy legislation
12. Limitations
DealerStak implements the safeguards described above but does not represent that any system is immune from compromise. DealerStak is not liable for unauthorised access resulting from credentials compromised on the Dealer's side, including a shared or reused password or a User account not removed after that person left the dealership.
13. Changes
DealerStak will publish a new version of this document if the storage architecture changes materially, and will notify Dealers in accordance with Section 13 of the Terms and Conditions.
Questions about this document: support@dealerstak.com.
Questions about this document? Email support@dealerstak.com.