Summary
The Dealer Agent Protocol project does not offer user accounts, newsletters, advertising, payment processing, or behavioral analytics on these public sites. We collect pilot application details only when you choose to apply. We do not sell personal information. The public gateway contains synthetic data and is not intended to receive personal, confidential, or production dealer data.
Information processed
Website and network data
When you request a page or endpoint, the hosting and security provider may process standard network information such as IP address, date and time, requested URL, user agent, routing data, and security events. This is used to deliver the service, prevent abuse, diagnose failures, and protect availability.
Dealer pilot applications
If you apply for the founding dealer pilot, we collect the contact name, work email, dealership or dealer group name, public dealership website, role, rooftop range, stated pilot goal, optional timing, consent, submission time, and application status. We use this information to evaluate fit, prevent abuse, contact the applicant, plan the pilot, and maintain an application record. Do not include customer information, credentials, or confidential dealer data in the application.
Reference gateway requests
The public MCP reference may process the request body, protocol metadata, timestamps, response status, and error information needed to answer, rate-limit, secure, and debug requests. Do not include names, contact information, credentials, customer records, unpublished dealer data, or other sensitive information.
Information you publish
If you contribute through GitHub, GitHub processes the account and contribution information you choose to publish under its own terms and privacy policy. Public issues and pull requests are public records of the project.
Service providers
Cloudflare hosts and protects the websites and may process network data under the Cloudflare Privacy Policy. Google Fonts supplies web-font files; a browser request to Google may disclose network and browser information under the Google Privacy Policy. GitHub hosts the public source repository and contribution workflows under the GitHub Privacy Statement.
Use, disclosure, and retention
Operational information is used only to deliver and secure the services, investigate failures or abuse, and improve interoperability. Pilot application information is used to evaluate, contact, select, and plan with applicants. It may be disclosed when required by law, to protect the project or others, or to providers performing those functions. The project does not sell this information or share it for targeted advertising.
Applications that do not proceed may be deleted or de-identified after approximately 180 days. Information for selected dealers may be retained for the duration of the pilot relationship and as reasonably needed for records, security, and legal obligations. Infrastructure data follows provider settings and is retained only as reasonably needed for its stated purpose.
Your choices and rights
Privacy rights vary by location. To ask about information associated with a request, open a repository issue containing no sensitive information and ask a maintainer to establish a private channel. We may need enough information to verify and locate the request, and some network records may be controlled by infrastructure providers.
Children
These developer and standards resources are not directed to children under 13, and the project does not knowingly collect personal information from children.
Changes and contact
Material changes will be posted on this page with a revised effective date. For privacy questions, use the public issue tracker without including private data and request a private channel. Security reports should follow the repository’s private vulnerability-reporting instructions.
This is a transparency statement for an open-source project, not legal advice. The project should obtain qualified legal review before adding accounts, analytics, commercial services, or production data.