SECURITY · PRIVACY · RELIABILITY
Trust at DealerStak
Canadian dealers entrust DealerStak with sensitive business data — vehicle inventory, customer records, financial transactions, regulatory documents. We take that responsibility seriously and have built our platform around three commitments: protect your data, respect your privacy, and stay accountable to the regulators who oversee your business.
Security
Infrastructure
Our platform runs on infrastructure providers that hold current SOC 2 Type II attestations and undergo regular independent audits. All data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256 encryption.
Access Controls
Every dealer's data is isolated at the database level using row-level security policies. We employ the principle of least privilege — team members and systems only access data they specifically need for their role. Multi-factor authentication is required for all DealerStak personnel with administrative access.
Continuous Testing
Every change is checked by automated secret scanning and static analysis before it can reach production. We conduct internal security reviews of our database access rules, permissions and infrastructure on a regular schedule, and remediate findings before release. Independent third-party penetration testing is planned as part of our SOC 2 Type II programme.
Monitoring
Application performance and security events are continuously monitored. Anomalies are reviewed by our team and triaged within published response-time tiers.
Vulnerability Disclosure
Security researchers can report vulnerabilities to us at any time. Our vulnerability disclosure policy is published at /.well-known/security.txt.
Privacy & Data Protection
Your Data Is Yours
Dealers retain ownership of all data uploaded to DealerStak. We act as the data processor; you are the data controller. You can export your complete dataset at any time, in machine-readable format, including all bills of sale, AMVIC documents, deal records, and customer information.
Where Your Data Is Processed
DealerStak's application database and document storage are hosted in North America. Some subprocessors that support the service operate outside Canada, including in the United States — information transferred to them is subject to the laws of that jurisdiction. The complete list, and the protections we require of each, is set out in our Data Processing Addendum. Questions about how your information is collected, used, disclosed or stored can be sent to privacy@dealerstak.com.
Subprocessors
The complete list of subprocessors we use to deliver the service is published in our Data Processing Addendum, available on request. We notify dealers 30 days in advance of any change to this list.
Retention
We retain dealer data only as long as needed to deliver the service or as required by Canadian law (AMVIC and CRA both require 6-year retention of certain records). Dealers can request deletion of their data at any time, subject to those legal retention requirements.
Regulatory Compliance
AMVIC
The platform supports Alberta Motor Vehicle Industry Council record-keeping requirements: every transaction generates a structured record, every bill of sale is retained in original form, salesperson license numbers are captured, and complete records are exportable on audit demand.
CRA
Records are retained consistent with Income Tax Act § 230(4) and Excise Tax Act § 286 requirements. Six-year retention is the default; longer where the dealer's record-keeping practices require.
PIPEDA
Personal information is handled per PIPEDA's ten principles, including consent, limited collection, retention limits, and individual access. Data subjects can request access to their information, request correction, and request deletion, subject to overriding legal retention obligations.
Federal Privacy Reform
When PIPEDA is replaced by CPPA, DealerStak will update its practices accordingly. We monitor legislative developments and plan to be ready when the legislation takes effect.
Reliability
Availability
DealerStak runs on infrastructure with industry-leading uptime track records. Our target for platform availability is 99.9%, with documented exceptions during scheduled maintenance windows announced in advance.
Backups
Production data is backed up daily, with point-in-time recovery covering the most recent 7-day window. We conduct quarterly restore drills to verify backup integrity.
Disaster Recovery
Documented recovery procedures with defined Recovery Time and Recovery Point Objectives. The team conducts quarterly drills against these objectives.
Independent Validation
Our subprocessors (database, hosting, storage, payments) all hold current SOC 2 Type II attestations:
Supabase
SOC 2 Type II
Cloudflare
SOC 2 Type II
Vercel
SOC 2 Type II
Stripe
SOC 2 Type II
Security Review
Internal security reviews cover row-level access policies, privileged database functions and third-party integrations, and are repeated whenever the data model changes. Independent third-party penetration testing is planned as part of our SOC 2 Type II programme; we will publish the date once scheduled.
SOC 2 Roadmap
DealerStak is pursuing its own SOC 2 Type II attestation. Roadmap details available on request.
Contact
SECURITY INQUIRIES
security@dealerstak.comVulnerability reports, security questions, audit document requests
PRIVACY INQUIRIES
privacy@dealerstak.comPIPEDA access requests, deletion requests, data export requests