Privacy Policy
1. Who we are
Camber Automotive is a trade name used by Christopher Kohanyi, a sole proprietor located in Florida ("Camber", "we", "us", "our"). We are a marketing company serving franchised automobile dealerships. We operate our own software platform rather than reselling third-party tools, which means we are both a service provider and a software provider.
Questions about this policy, about privacy, or about security should go to security@camberautomotive.com.
2. What this policy covers, and what it does not
This policy describes three different relationships. Keeping them separate matters, because our obligations differ in each.
Visitors to camberautomotive.com. If you browse our website or contact us, this policy describes what we collect and why. We decide the purposes of that collection, so we are the controller of it.
Users of the Camber platform. If you are an employee of a dealership that uses our platform and you log in to it, sections 4 and 5 describe the account, activity, and security data we hold about you. We decide to collect and retain that data for the integrity and security of the platform, so we are the controller of it, not your employer.
Consumers whose information a dealership sends us. If you are a customer of a dealership that uses Camber, we may process information about you on that dealership's instructions, for that dealership's marketing. We do not have a direct relationship with you and we did not decide what to collect. The dealership is the controller. We act as its processor, under a written data processing agreement, and we use that information only as the dealership instructs. If you want to know what a dealership holds about you, to correct it, or to have it deleted, contact the dealership directly. If you contact us, we will pass the request to them.
This policy does not describe websites we build and operate for our dealership clients. Those sites have their own privacy policies, published by the dealership that owns them.
3. Information we collect from website visitors
Our website currently collects only what you send us. If you email us or complete a contact form, we receive your name, your email address, any other information you choose to include, and the content of your message. We use it to respond to you and to keep a record of our correspondence.
This website sets no cookies. It is static, carries no analytics, no tag manager, no advertising technology, and makes no external requests. Nothing here tracks you or follows you to another site.
4. Information we collect about platform users
If you hold an account on the Camber platform, we hold:
- Account and authentication data. Your email address and authentication credentials, held through our authentication provider. We do not store your password in a form we can read.
- Multi-factor authentication enrolment. We require a second factor for sensitive operations.
- Role and membership. Your role, which is one of salesperson, manager, marketing lead, or administrator, and the store or organization you belong to.
- Activity records. An immutable, tamper-evident record of actions you take in the platform, including creating, editing, submitting, reviewing, and approving content.
- IP address. The network address you were using at the moment you took an audited action, recorded alongside that action.
- Content you upload. Photographs, video, and documents you capture or upload in the course of your work, held in private storage.
- Voice consent records. If your recorded voice is used to produce narration, we record your name and the date you consented. We do not store a voiceprint or a biometric template.
5. How we use platform user information, and how long we keep it
We use account and role data to operate the platform and to enforce who may do what. We use activity records and IP addresses for security, for accountability, and because certain content in our platform requires two separate people to approve it, which is only meaningful if we can show who they were.
Our activity log is deliberately immutable. Each entry is cryptographically chained to the entry before it, so that no entry can be altered or removed without detection. This is a security property, not an oversight.
The activity log does not record your account identity directly. Each entry identifies the actor by an internal pseudonym, and the link between that pseudonym and your account is held separately. If you ask us to delete your information, we can deactivate your account and sever that link, after which the retained record can no longer be resolved to you. We keep the record itself because a tamper-evident audit trail that can be selectively erased is not a tamper-evident audit trail; what we sever is its connection to a person, not the history of the actions.
6. Information we process on behalf of dealerships
When a dealership engages us for services that require its customer data, that dealership may send us information about its customers, which can include names, postal addresses, email addresses, telephone numbers, vehicle identification numbers, and purchase or service history.
The following statements describe how our platform is built, and they are commitments, not aspirations.
Each client is isolated. Every dealership client receives its own database and its own deployment. Client data is not pooled, combined, or stored alongside another client's. A query cannot reach across clients because there is no connection between them.
We do not accept motor vehicle record data. Information derived from state motor vehicle records is subject to the federal Driver's Privacy Protection Act. Our system does not merely discourage such data, it prevents it: every source of customer information must be registered with a stated legal basis before any record can be accepted from it, a source declared as vehicle-record derived is permanently marked impermissible, and the database physically rejects any record that references it. Changing that requires a deliberate, documented change to the system.
We do not accept credit or finance data. We do not ask for, and our clients agree not to send us, credit applications, credit scores or tiers, financing terms, payment amounts, or payment instrument details. If we discover such information in material a client has sent us, we may delete it.
We use it only as instructed. We do not use dealership customer data for our own purposes, we do not use one client's data to serve another, and we do not sell or share it.
7. Cookies and similar technologies
On camberautomotive.com, we set no cookies at all. The site is static and makes no external requests.
On the Camber platform, the only cookies are those strictly necessary to keep you signed in, set by our authentication provider. Our software sets no cookies of its own and uses no browser storage. We set no analytics cookies, no advertising cookies, and nothing that follows you between sites, so there is nothing to consent to beyond the session itself.
8. Things we do not do
These are unusual enough to be worth stating plainly.
- We do not use third-party analytics, advertising pixels, session replay, heatmaps, or tag managers anywhere in our platform.
- We do not use an external error tracking or application monitoring service, so no third party receives our application errors or the data inside them.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not use personal information to train artificial intelligence models, and our AI providers do not receive dealership customer records.
- We do not track whether you open our emails or click links in them. Our email provider disables open and click tracking by default, and our software sends no tracking parameters, so this is true of how the system is built and not only of our policy.
- Image processing, document extraction, and content similarity analysis happen on our own infrastructure rather than through a third-party service.
- We do not automatically obscure license plates that appear in photographs. Where photographs are published, human review is the control.
9. Service providers
We use the following providers. Those marked as handling personal information are engaged under terms that restrict them to processing it on our instructions.
| Provider | Purpose | Handles personal information? | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Yes, primary store | United States, us-east-1 |
| Fly.io | Background processing | Yes, in transit through processing | United States, Ashburn VA |
| Anthropic | Generation of marketing copy and scripts | Vehicle facts and generated text only; no consumer records | United States |
| Vercel | Hosting for the platform and for this website | Yes, in transit | United States |
| Resend | Transactional email to platform users | Recipient address and message content; no open or click tracking | United States |
| ElevenLabs | Narration audio | Script text only | United States |
| GitHub | Source code | No | United States |
| NHTSA vPIC | Vehicle identification number decoding | No; a VIN only | United States, government service |
| Squarespace | Domain registration and DNS only | No | United States |
| Google Workspace | Our own business email | No client data | United States |
All of our infrastructure is located in the United States. We do not transfer personal information internationally.
10. YouTube API Services
Our platform uses YouTube API Services to publish video to a dealership's own YouTube channel, at that dealership's direction and using its own authorization.
By using those features you are also agreeing to the YouTube Terms of Service. Google's handling of information collected through YouTube API Services is described in the Google Privacy Policy.
You can revoke our access to your Google account at any time through the Google security settings page. Revoking access will stop us publishing to your channel.
We request only the permissions needed to publish content you have approved. We do not read your viewing history, your subscriptions, or your private videos.
11. Retention and deletion
Platform user data is retained for as long as your account is active and for a reasonable period afterwards, subject to the audit log provisions in section 5.
Dealership customer data is retained according to our agreement with that dealership. At the end of an engagement, because each client occupies its own separate database and deployment, we delete the entire client environment rather than performing a selective purge.
Backups are the exception, and we would rather be accurate than reassuring. Our database provider maintains point-in-time recovery, which retains a copy of data for a rolling window after deletion. Deleted information therefore persists in backup for up to seven days before it is gone. We do not claim immediate erasure, because it would not be true.
Our service providers keep their own copies for their own periods, which are longer than ours and which we do not control. The longest is ninety days after an account with that provider ends. Those periods are listed in the subprocessor exhibit to our client data processing agreement.
We do not currently operate an automated retention or purge schedule.
12. Security
We take the following measures. They are described specifically rather than generally, so that they can be checked.
- Data is encrypted in transit and at rest, including the storage volume used for background processing.
- Row-level security is enforced on every table in our database, and an automated check fails our build if any table lacks it.
- Our web application holds only a public key with no privileged access, and our build fails if a privileged key is present in it.
- Credentials for third-party services are readable only by our background worker and are never exposed to the browser.
- Multi-factor authentication is enforced for sensitive operations.
- Customer-facing content requires approval by two separate people, and the approval is cryptographically bound to the exact content approved, so that any later edit invalidates it.
- We scan our dependencies for known vulnerabilities and our source history for exposed credentials, and we block commits containing detected secrets.
- Two-factor authentication is required for every account with access to our source code.
- Our sending domain is protected by SPF, DKIM, and DMARC, so that mail claiming to come from us can be authenticated.
No system is perfectly secure, and we do not claim ours is.
13. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information about you, and to appeal a decision we make about such a request.
- If you are a platform user, contact us at security@camberautomotive.com. We will verify your identity before acting.
- If you are a customer of a dealership, please contact that dealership. It decides what happens to its customer information. If you contact us, we will forward your request and tell you we have done so.
We will not discriminate against you for exercising these rights.
14. Children
Our platform and our website are intended for business use by adults. We do not knowingly collect personal information from children.
15. Changes to this policy
If we change this policy we will update the date at the top and, for material changes affecting platform users, notify the dealership that administers your account.
16. How to contact us
security@camberautomotive.com