Legal · NexusMotive
Privacy Policy
Last updated: May 17, 2026
This Privacy Policy explains how NexusMotive, Inc. collects, uses, protects, and discloses information — both about visitors to our corporate site at nexusmotive.com and about consumers whose data we process on behalf of automotive dealerships using our platform.
1. Who We Are
NexusMotive, Inc. (“NexusMotive,” “we,” “us,” or “our”) operates the NexusMotive Automotive Retail Operating System — a multi-tenant software platform that automotive dealerships (“Dealer Partners”) license to power their websites, identity graphs, marketing attribution, audience activation, and dealer-management workflows.
This Privacy Policy describes the information NexusMotive collects through our corporate website at nexusmotive.com, our marketing properties, our administrative consoles, our pixel and beacon infrastructure, and the platform services we provide to Dealer Partners. It does not cover the privacy practices of any individual Dealer Partner on their own consumer-facing website — each Dealer Partner publishes its own privacy policy that governs how that dealership collects and uses consumer information.
2. Our Role: Service Provider to Dealers
For data that flows through the NexusMotive platform on behalf of a Dealer Partner — including names, contact information, vehicle interest, test-drive requests, finance applications, service appointments, deal records, and the behavioral signals our pixel collects on a Dealer Partner’s website — the Dealer Partner is the “business” or “controller” under California and other state privacy laws. NexusMotive operates as the “service provider” or “processor.”
What this means in practice:
- We process consumer personal information solely on behalf of, and under the written contractual obligations of, the Dealer Partner.
- We do not retain, use, or disclose that personal information for any purpose other than performing the services in our Dealer Partner agreement, except as expressly permitted by law.
- We do not sell or share (as those terms are defined under California and other state laws) personal information processed on behalf of a Dealer Partner. We do not use it for cross-context behavioral advertising outside the originating Dealer Partner’s authorization.
- If you are a consumer who interacted with a Dealer Partner’s site, your rights to access, correct, delete, port, or opt out of certain processing flow through that Dealer Partner. Their privacy policy lists the contact channel for those rights. NexusMotive will support the Dealer Partner’s response in full per our contract and applicable law.
For data NexusMotive collects directly — for example, business contacts who visit nexusmotive.com, sales prospects, billing contacts at our Dealer Partners, or job applicants — NexusMotive is the “business” or “controller.” The sections below describe those direct-relationship practices.
3. Information We Collect Directly
When you interact with NexusMotive directly (not through a Dealer Partner’s site), we may collect the following categories of personal information:
- Identifiers: name, business email, business phone, company name, job title, mailing address.
- Commercial information: records of demos requested, materials downloaded, product interest expressed.
- Internet or network activity: IP address, browser type and version, operating system, pages viewed on nexusmotive.com, referring URL, session duration, and time-stamped event records.
- Geolocation (coarse): approximate city / state derived from IP, used to route inbound inquiries to the right sales representative. We do not collect precise GPS coordinates.
- Professional / employment information: when you apply for a position with NexusMotive (resume, work history, references you provide).
- Audio / electronic information: if you call our sales line and the call is recorded (with notice), or if you participate in a recorded video demo.
- Inferences: account-fit scores and engagement scores we derive from the above for sales prioritization.
We do not knowingly collect sensitive personal information (as defined by California or other state laws) about visitors to nexusmotive.com. We do not process biometric identifiers, precise geolocation, social security numbers, financial-account numbers, health information, sexual orientation, immigration status, religious beliefs, or contents of private communications through our corporate site.
4. How We Use Direct-Relationship Information
We use the information described in Section 3 for the following business purposes:
- Responding to inquiries, scheduling demos, and providing requested information.
- Operating, maintaining, securing, and improving our website and platform.
- Account management, billing, and customer support for active Dealer Partners.
- Sending you product updates, service notifications, and (with appropriate consent) marketing communications about NexusMotive.
- Conducting research, analytics, and product development.
- Recruiting, evaluating, and onboarding job applicants and employees.
- Detecting and preventing fraud, abuse, security incidents, and unauthorized use of our services.
- Complying with our legal obligations, enforcing our agreements, and protecting the rights, property, or safety of NexusMotive, our Dealer Partners, or others.
5. How We Disclose Information
We disclose information in the following limited circumstances:
- Service providers (sub-processors): infrastructure vendors (AWS for hosting, computation, and storage), email-delivery vendors (SendGrid), payment processors (Stripe for our own subscription billing), observability vendors (Sentry / DataDog class), and similar partners that act under written contracts requiring them to protect personal information and use it only for the limited purposes we direct.
- Dealer Partners:if you express interest in our platform on behalf of a specific dealership, we may share your contact information with that dealership’s NexusMotive account team.
- Corporate transactions: in connection with a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, information may be transferred to the successor or acquirer as part of due diligence and the transaction itself, subject to comparable confidentiality protections.
- Legal obligations: when required by law, subpoena, court order, or other governmental request; or when we believe disclosure is necessary to protect our rights, comply with judicial process, prevent harm, or respond to a security incident.
We do not sell personal information.We do not “share” personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act, Colorado Privacy Act, Connecticut Data Privacy Act, Virginia Consumer Data Protection Act, or comparable state laws.
6. Cryptographic PII Isolation Between Dealer Partners
NexusMotive runs a multi-tenant platform — multiple Dealer Partners share infrastructure. Cross-tenant intelligence (for example, aggregate benchmarking of marketing performance across the network, or k-anonymized signal lift) is a core product capability. We design that capability so it cannot, by construction, expose one Dealer Partner’s consumer personal information to another Dealer Partner or to NexusMotive’s own operations team.
Specifically:
- Each Dealer Partner’s consumer personally identifiable information (PII) is encrypted at rest with a per-tenant data encryption key (DEK), wrapped under a per-tenant AWS Key Management Service (KMS) customer master key (CMK) that is distinct per Dealer Partner.
- The IAM policy on those per-tenant CMKs denies the decrypt operation to NexusMotive’s platform administrators and general engineering roles. Only services running in the Dealer Partner’s own runtime context can decrypt that Dealer Partner’s consumer PII.
- Cross-tenant analytics queries operate on hashed identifiers (SHA-256 of normalized email, phone, or other key) and on cohorts that are gated to a minimum sample size before any aggregate metric is published. Individual records and individual consumer identities are never surfaced across the tenancy boundary.
- Every access to encrypted PII is logged through a tamper-evident audit trail. Material access events are reviewable on request.
This architectural posture is independently verifiable by a Dealer Partner’s security team. We treat it as a contractual guarantee, not a marketing claim.
8. Your Rights Under California Law (CCPA / CPRA)
If you are a California resident and we collect personal information about you in our role as a business (rather than as a service provider to a Dealer Partner), you have the rights described below. These rights are subject to verification of your identity and to exceptions provided by law.
- Right to know: request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collection, and the categories of third parties to which we disclosed it in the prior twelve months.
- Right to delete:request that we delete personal information we collected from you, subject to the exceptions in Cal. Civ. Code § 1798.105(d).
- Right to correct: request that we correct inaccurate personal information we maintain about you.
- Right to opt out of sale or sharing: NexusMotive does not sell or share personal information as those terms are defined under the CCPA / CPRA. There is no opt-out to exercise because the activity does not occur.
- Right to limit use of sensitive personal information:we do not collect sensitive personal information through nexusmotive.com in a way that is subject to this right.
- Right to non-discrimination: we will not deny you services, charge a different price, or provide a different level of quality because you exercised your privacy rights.
- Right to designate an authorized agent: you may designate someone to submit requests on your behalf, subject to our verification procedures.
To exercise any of these rights, email privacy@nexusmotive.com or submit a request through our contact form. We will confirm receipt within ten business days and respond substantively within forty-five days as required by California law, subject to one forty-five-day extension when reasonably necessary.
9. Your Rights Under Other U.S. State Privacy Laws
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Tennessee (TIPA), and other states with comprehensive privacy laws have rights substantially similar to those described in Section 8. Where the applicable law grants additional or different rights — for example, the right to appeal a decision about a privacy request — we honor those rights for residents of the applicable state.
To exercise rights granted by another state’s law, use the same contact channels listed in Section 8 and include the state of residence so we can route the request under the correct legal framework.
10. GLBA and the FTC Safeguards Rule
Several of our Dealer Partners are “financial institutions” under the Gramm-Leach-Bliley Act (GLBA) because they offer or arrange consumer financing. When we process a Dealer Partner’s consumer information that is non-public personal information under GLBA, we do so as a service provider under written contract that meets the FTC Safeguards Rule (16 C.F.R. Part 314) requirements for service-provider oversight.
NexusMotive maintains a written information security program with:
- A designated qualified individual responsible for the program.
- Risk assessments updated at least annually and on any material system change.
- Encryption of customer information in transit and at rest (TLS 1.2+ in transit, AES-256 at rest, per-tenant KMS keys for consumer PII as described in Section 6).
- Access controls under the principle of least privilege, multi-factor authentication for administrative access, and periodic access reviews.
- Continuous monitoring or annual penetration testing, plus vulnerability assessments at least every six months.
- Secure software development practices, change management, and patching processes.
- Incident response, business continuity, and disaster recovery plans, with tabletop exercises at least annually.
- Vendor and sub-processor oversight, including security review before onboarding and at least annual reassessment.
- Personnel training on information security and privacy at hire and annually thereafter.
A summary of our security program is available to authorized Dealer Partner contacts under NDA; contact security@nexusmotive.com to request a copy.
11. Information Security
NexusMotive maintains administrative, technical, and physical safeguards designed to protect the personal information we collect or process against unauthorized access, alteration, disclosure, or destruction. Our infrastructure runs on Amazon Web Services with isolated VPCs, network segmentation, IAM least privilege, KMS-managed encryption keys (including the per-tenant customer master keys described in Section 6), audit logging via CloudTrail, and continuous monitoring.
We are pursuing SOC 2 Type II attestation and maintain a security program designed to satisfy SOC 2 Trust Services Criteria. Our current attestation status is available on request to qualified Dealer Partner security teams under NDA.
To the limited extent NexusMotive processes payment-card information for our own subscription billing, that processing is performed by a PCI DSS Level 1 service provider (Stripe). NexusMotive never stores raw cardholder data in our own systems.
No method of transmission over the internet or method of electronic storage is one hundred percent secure. We cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify affected individuals as required by applicable law.
12. Data Retention
For direct-relationship information described in Section 3, we retain personal information only for as long as needed to fulfill the purposes described in this policy, comply with our legal obligations, resolve disputes, and enforce our agreements. Typical retention windows are:
- Marketing-prospect contact records: thirty-six months after last engagement, or until you opt out, whichever is sooner.
- Active Dealer Partner billing records: term of the agreement plus seven years for tax and audit purposes.
- Server logs: thirteen months in active storage, then aggregated.
- Recruiting records: twelve months after the position is filled or withdrawn, unless you opt in to a longer retention for future consideration.
For Dealer Partner customer data processed in our service-provider role, retention is governed by the Dealer Partner’s agreement and policy. We delete or de-identify that data on the Dealer Partner’s instruction or at contract termination under the timelines specified in our standard agreement.
13. Children’s Privacy
NexusMotive’s platform and corporate website are intended for business users (Dealer Partners and their personnel) and for adult consumers interacting with Dealer Partner sites. We do not knowingly collect personal information from children under thirteen years of age. If you believe we have inadvertently collected such information, contact us at privacy@nexusmotive.com and we will take prompt steps to delete it.
14. Geographic Scope
NexusMotive operates within the United States. Our infrastructure is hosted in U.S. AWS regions and our platform serves U.S.-located automotive dealerships and their U.S. customers. We do not offer services to consumers in the European Economic Area, the United Kingdom, or Switzerland. This Privacy Policy is not intended to comply with the General Data Protection Regulation, UK GDPR, FADP, or analogous non-U.S. comprehensive privacy laws.
15. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, products, or applicable law. When we do, we will revise the “Last updated” date at the top of this page. For material changes, we will provide additional notice (such as a banner on nexusmotive.com or email to active Dealer Partner billing contacts) before the changes take effect.
16. How to Contact Us
For privacy questions, to exercise a right described in this policy, or to request our security program summary, contact:
NexusMotive, Inc.
Attn: Privacy Officer
Email: privacy@nexusmotive.com
Security inquiries: security@nexusmotive.com
If you are interacting with a Dealer Partner’s website and your question relates to that Dealer Partner’s data practices (rather than NexusMotive’s direct relationship with you), please contact the Dealer Partner using the channel listed on their privacy page. We will support the Dealer Partner’s response per our contract.