Privacy notice
Last updated: 26 August 2026
Information ShowroomArc processes
The service can process dealership profile and billing details; staff names, work contact details, roles and sign-in records; customer and lead contact details; vehicle, deal, task, note and document information; communication history; uploaded files; integration identifiers; and technical security, audit and diagnostic records.
Why the information is used
- Provide the CRM, stock, workshop, communications, automation and reporting features requested by the dealership.
- Authenticate users, enforce permissions, prevent abuse and maintain audit history.
- Connect services selected by the dealership, such as email, Facebook, WhatsApp and signed webhooks.
- Operate backups, recover from faults, investigate failures and improve reliability.
- Meet contractual, accounting, regulatory and legal obligations that apply to the service provider.
Connected services
When an authorised dealership administrator connects a provider, ShowroomArc exchanges only the information needed for the selected feature. Provider access credentials are encrypted at rest and are not displayed back to staff. Facebook Page and WhatsApp connections can receive messages, lead-form data and delivery events and can send staff replies. Email connections can synchronise, read, send and archive messages according to the permissions granted.
Each external provider also processes information under its own terms and privacy notice. A dealership administrator can test, reconnect or disconnect a provider from Settings → Integrations. Disconnecting retains existing CRM history unless the dealership separately deletes it under its own retention obligations.
Google account and Gmail data
When a dealership administrator chooses Connect Google, ShowroomArc uses Google OAuth to identify the authorised mailbox and request Gmail access. The Gmail permission is used only to provide the dealership's requested email features: synchronising message and conversation content and metadata, showing attachments, composing and sending messages, replying, changing read state and archiving or restoring conversations.
- Google account data and Gmail content are shown only to authorised users of the dealership workspace, subject to their ShowroomArc permissions.
- ShowroomArc does not sell Google user data, use it for advertising or use it to train general-purpose artificial-intelligence models.
- Google user data is shared only with infrastructure providers required to operate the service, when directed by the dealership, for security or support with appropriate access controls, or where disclosure is legally required.
- OAuth access and refresh tokens are encrypted at rest. Synced mailbox records and cached attachments remain in the dealership's tenant-isolated storage and are protected by server-side access controls.
- A dealership administrator can disconnect a mailbox in ShowroomArc. The Google account holder can also revoke access from their Google Account connections page.
ShowroomArc's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Sharing and international processing
Information is shared only with authorised dealership users, infrastructure and communications providers needed to run the service, professional advisers, or public authorities where legally required. Some connected providers may process information outside the United Kingdom. The contracting parties are responsible for using the appropriate transfer safeguards where required.
Retention and deletion
Dealership records are retained for the subscription term and according to the dealership's configured or contractual retention requirements. Operational logs and backups are retained for limited security and recovery periods. Closing a dealership account uses a controlled grace period, verified backup and recoverable quarantine before final deletion. See the data deletion page for request routes.
Security
ShowroomArc uses tenant-isolated storage, server-side permissions, CSRF controls, encrypted integration credentials, signed webhook validation, private uploads, rate limiting, audit records and verified backups. No internet service can guarantee absolute security, so suspected incidents should be reported promptly.
Your rights and questions
Customers and leads should normally contact the dealership they dealt with, because that dealership controls the CRM record and can identify it safely. Dealership staff should contact their administrator. Contract, privacy or Meta data-deletion questions for the ShowroomArc service can be sent to privacy@showroomarc.com.
