Skip to content
Built by active wholesalers who have closed thousands of deals·Trusted by dealers moving serious volume across Alberta·Floorplan cost tracking built in — not bolted on·Professional Bills of Sale already circulating dealer networks province-wide·Dealers across Alberta are already running cleaner operations·Built by dealers who move metal — no bloat, no features you will never use·
SECURITY · PRIVACY · RELIABILITY

Trust at DealerStak

Canadian dealers entrust DealerStak with sensitive business data — vehicle inventory, customer records, financial transactions, regulatory documents. We take that responsibility seriously and have built our platform around three commitments: protect your data, respect your privacy, and stay accountable to the regulators who oversee your business.

Security

Infrastructure

Our platform runs on infrastructure providers that hold current SOC 2 Type II attestations and undergo regular independent audits. All data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256 encryption.

Access Controls

Every dealer's data is isolated at the database level using row-level security policies. We employ the principle of least privilege — team members and systems only access data they specifically need for their role. Multi-factor authentication is required for all DealerStak personnel with administrative access.

Continuous Testing

Every change is checked by automated secret scanning and static analysis before it can reach production. We conduct internal security reviews of our database access rules, permissions and infrastructure on a regular schedule, and remediate findings before release. Independent third-party penetration testing is planned as part of our SOC 2 Type II programme.

Monitoring

Application performance and security events are continuously monitored. Anomalies are reviewed by our team and triaged within published response-time tiers.

Vulnerability Disclosure

Security researchers can report vulnerabilities to us at any time. Our vulnerability disclosure policy is published at /.well-known/security.txt.

Privacy & Data Protection

Your Data Is Yours

Dealers retain ownership of all data uploaded to DealerStak. We act as the data processor; you are the data controller. You can export your complete dataset at any time, in machine-readable format, including all bills of sale, AMVIC documents, deal records, and customer information.

Where Your Data Is Processed

DealerStak's application database and document storage are hosted in North America. Some subprocessors that support the service operate outside Canada, including in the United States — information transferred to them is subject to the laws of that jurisdiction. The complete list, and the protections we require of each, is set out in our Data Processing Addendum. Questions about how your information is collected, used, disclosed or stored can be sent to privacy@dealerstak.com.

Subprocessors

The complete list of subprocessors we use to deliver the service is published in our Data Processing Addendum, available on request. We notify dealers 30 days in advance of any change to this list.

Retention

We retain dealer data only as long as needed to deliver the service or as required by Canadian law (AMVIC and CRA both require 6-year retention of certain records). Dealers can request deletion of their data at any time, subject to those legal retention requirements.

Regulatory Compliance

AMVIC

The platform supports Alberta Motor Vehicle Industry Council record-keeping requirements: every transaction generates a structured record, every bill of sale is retained in original form, salesperson license numbers are captured, and complete records are exportable on audit demand.

CRA

Records are retained consistent with Income Tax Act § 230(4) and Excise Tax Act § 286 requirements. Six-year retention is the default; longer where the dealer's record-keeping practices require.

PIPEDA

Personal information is handled per PIPEDA's ten principles, including consent, limited collection, retention limits, and individual access. Data subjects can request access to their information, request correction, and request deletion, subject to overriding legal retention obligations.

Federal Privacy Reform

When PIPEDA is replaced by CPPA, DealerStak will update its practices accordingly. We monitor legislative developments and plan to be ready when the legislation takes effect.

Reliability

Availability

DealerStak runs on infrastructure with industry-leading uptime track records. Our target for platform availability is 99.9%, with documented exceptions during scheduled maintenance windows announced in advance.

Backups

Production data is backed up daily, with point-in-time recovery covering the most recent 7-day window. We conduct quarterly restore drills to verify backup integrity.

Disaster Recovery

Documented recovery procedures with defined Recovery Time and Recovery Point Objectives. The team conducts quarterly drills against these objectives.

Independent Validation

Our subprocessors (database, hosting, storage, payments) all hold current SOC 2 Type II attestations:

Supabase

SOC 2 Type II

Cloudflare

SOC 2 Type II

Vercel

SOC 2 Type II

Stripe

SOC 2 Type II

Security Review

Internal security reviews cover row-level access policies, privileged database functions and third-party integrations, and are repeated whenever the data model changes. Independent third-party penetration testing is planned as part of our SOC 2 Type II programme; we will publish the date once scheduled.

SOC 2 Roadmap

DealerStak is pursuing its own SOC 2 Type II attestation. Roadmap details available on request.

Contact

SECURITY INQUIRIES

security@dealerstak.com

Vulnerability reports, security questions, audit document requests

PRIVACY INQUIRIES

privacy@dealerstak.com

PIPEDA access requests, deletion requests, data export requests

GENERAL INQUIRIES

hello@dealerstak.com

General questions and partnership inquiries