Camber Automotive security@camberautomotive.com

Privacy Policy

Effective August 1, 2026. Last updated August 2, 2026.

1. Who we are

Camber Automotive is a trade name used by Christopher Kohanyi, a sole proprietor located in Florida ("Camber", "we", "us", "our"). We are a marketing company serving franchised automobile dealerships. We operate our own software platform rather than reselling third-party tools, which means we are both a service provider and a software provider.

Questions about this policy, about privacy, or about security should go to security@camberautomotive.com.

2. What this policy covers, and what it does not

This policy describes three different relationships. Keeping them separate matters, because our obligations differ in each.

Visitors to camberautomotive.com. If you browse our website or contact us, this policy describes what we collect and why. We decide the purposes of that collection, so we are the controller of it.

Users of the Camber platform. If you are an employee of a dealership that uses our platform and you log in to it, sections 4 and 5 describe the account, activity, and security data we hold about you. We decide to collect and retain that data for the integrity and security of the platform, so we are the controller of it, not your employer.

Consumers whose information a dealership sends us. If you are a customer of a dealership that uses Camber, we may process information about you on that dealership's instructions, for that dealership's marketing. We do not have a direct relationship with you and we did not decide what to collect. The dealership is the controller. We act as its processor, under a written data processing agreement, and we use that information only as the dealership instructs. If you want to know what a dealership holds about you, to correct it, or to have it deleted, contact the dealership directly. If you contact us, we will pass the request to them.

This policy does not describe websites we build and operate for our dealership clients. Those sites have their own privacy policies, published by the dealership that owns them.

3. Information we collect from website visitors

Our website currently collects only what you send us. If you email us or complete a contact form, we receive your name, your email address, any other information you choose to include, and the content of your message. We use it to respond to you and to keep a record of our correspondence.

This website sets no cookies. It is static, carries no analytics, no tag manager, no advertising technology, and makes no external requests. Nothing here tracks you or follows you to another site.

4. Information we collect about platform users

If you hold an account on the Camber platform, we hold:

  • Account and authentication data. Your email address and authentication credentials, held through our authentication provider. We do not store your password in a form we can read.
  • Multi-factor authentication enrolment. We require a second factor for sensitive operations.
  • Role and membership. Your role, which is one of salesperson, manager, marketing lead, or administrator, and the store or organization you belong to.
  • Activity records. An immutable, tamper-evident record of actions you take in the platform, including creating, editing, submitting, reviewing, and approving content.
  • IP address. The network address you were using at the moment you took an audited action, recorded alongside that action.
  • Content you upload. Photographs, video, and documents you capture or upload in the course of your work, held in private storage.
  • Voice consent records. If your recorded voice is used to produce narration, we record your name and the date you consented. We do not store a voiceprint or a biometric template.

5. How we use platform user information, and how long we keep it

We use account and role data to operate the platform and to enforce who may do what. We use activity records and IP addresses for security, for accountability, and because certain content in our platform requires two separate people to approve it, which is only meaningful if we can show who they were.

Our activity log is deliberately immutable. Each entry is cryptographically chained to the entry before it, so that no entry can be altered or removed without detection. This is a security property, not an oversight.

The activity log does not record your account identity directly. Each entry identifies the actor by an internal pseudonym, and the link between that pseudonym and your account is held separately. If you ask us to delete your information, we can deactivate your account and sever that link, after which the retained record can no longer be resolved to you. We keep the record itself because a tamper-evident audit trail that can be selectively erased is not a tamper-evident audit trail; what we sever is its connection to a person, not the history of the actions.

6. Information we process on behalf of dealerships

When a dealership engages us for services that require its customer data, that dealership may send us information about its customers, which can include names, postal addresses, email addresses, telephone numbers, vehicle identification numbers, and purchase or service history.

The following statements describe how our platform is built, and they are commitments, not aspirations.

Each client is isolated. Every dealership client receives its own database and its own deployment. Client data is not pooled, combined, or stored alongside another client's. A query cannot reach across clients because there is no connection between them.

We do not accept motor vehicle record data. Information derived from state motor vehicle records is subject to the federal Driver's Privacy Protection Act. Our system does not merely discourage such data, it prevents it: every source of customer information must be registered with a stated legal basis before any record can be accepted from it, a source declared as vehicle-record derived is permanently marked impermissible, and the database physically rejects any record that references it. Changing that requires a deliberate, documented change to the system.

We do not accept credit or finance data. We do not ask for, and our clients agree not to send us, credit applications, credit scores or tiers, financing terms, payment amounts, or payment instrument details. If we discover such information in material a client has sent us, we may delete it.

We use it only as instructed. We do not use dealership customer data for our own purposes, we do not use one client's data to serve another, and we do not sell or share it.

7. Cookies and similar technologies

On camberautomotive.com, we set no cookies at all. The site is static and makes no external requests.

On the Camber platform, the only cookies are those strictly necessary to keep you signed in, set by our authentication provider. Our software sets no cookies of its own and uses no browser storage. We set no analytics cookies, no advertising cookies, and nothing that follows you between sites, so there is nothing to consent to beyond the session itself.

8. Things we do not do

These are unusual enough to be worth stating plainly.

  • We do not use third-party analytics, advertising pixels, session replay, heatmaps, or tag managers anywhere in our platform.
  • We do not use an external error tracking or application monitoring service, so no third party receives our application errors or the data inside them.
  • We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • We do not use personal information to train artificial intelligence models, and our AI providers do not receive dealership customer records.
  • We do not track whether you open our emails or click links in them. Our email provider disables open and click tracking by default, and our software sends no tracking parameters, so this is true of how the system is built and not only of our policy.
  • Image processing, document extraction, and content similarity analysis happen on our own infrastructure rather than through a third-party service.
  • We do not automatically obscure license plates that appear in photographs. Where photographs are published, human review is the control.

9. Service providers

We use the following providers. Those marked as handling personal information are engaged under terms that restrict them to processing it on our instructions.

ProviderPurposeHandles personal information?Location
SupabaseDatabase, authentication, file storageYes, primary storeUnited States, us-east-1
Fly.ioBackground processingYes, in transit through processingUnited States, Ashburn VA
AnthropicGeneration of marketing copy and scriptsVehicle facts and generated text only; no consumer recordsUnited States
VercelHosting for the platform and for this websiteYes, in transitUnited States
ResendTransactional email to platform usersRecipient address and message content; no open or click trackingUnited States
ElevenLabsNarration audioScript text onlyUnited States
GitHubSource codeNoUnited States
NHTSA vPICVehicle identification number decodingNo; a VIN onlyUnited States, government service
SquarespaceDomain registration and DNS onlyNoUnited States
Google WorkspaceOur own business emailNo client dataUnited States

All of our infrastructure is located in the United States. We do not transfer personal information internationally.

10. YouTube API Services

Our platform uses YouTube API Services to publish video to a dealership's own YouTube channel, at that dealership's direction and using its own authorization.

By using those features you are also agreeing to the YouTube Terms of Service. Google's handling of information collected through YouTube API Services is described in the Google Privacy Policy.

You can revoke our access to your Google account at any time through the Google security settings page. Revoking access will stop us publishing to your channel.

We request only the permissions needed to publish content you have approved. We do not read your viewing history, your subscriptions, or your private videos.

11. Retention and deletion

Platform user data is retained for as long as your account is active and for a reasonable period afterwards, subject to the audit log provisions in section 5.

Dealership customer data is retained according to our agreement with that dealership. At the end of an engagement, because each client occupies its own separate database and deployment, we delete the entire client environment rather than performing a selective purge.

Backups are the exception, and we would rather be accurate than reassuring. Our database provider maintains point-in-time recovery, which retains a copy of data for a rolling window after deletion. Deleted information therefore persists in backup for up to seven days before it is gone. We do not claim immediate erasure, because it would not be true.

Our service providers keep their own copies for their own periods, which are longer than ours and which we do not control. The longest is ninety days after an account with that provider ends. Those periods are listed in the subprocessor exhibit to our client data processing agreement.

We do not currently operate an automated retention or purge schedule.

12. Security

We take the following measures. They are described specifically rather than generally, so that they can be checked.

  • Data is encrypted in transit and at rest, including the storage volume used for background processing.
  • Row-level security is enforced on every table in our database, and an automated check fails our build if any table lacks it.
  • Our web application holds only a public key with no privileged access, and our build fails if a privileged key is present in it.
  • Credentials for third-party services are readable only by our background worker and are never exposed to the browser.
  • Multi-factor authentication is enforced for sensitive operations.
  • Customer-facing content requires approval by two separate people, and the approval is cryptographically bound to the exact content approved, so that any later edit invalidates it.
  • We scan our dependencies for known vulnerabilities and our source history for exposed credentials, and we block commits containing detected secrets.
  • Two-factor authentication is required for every account with access to our source code.
  • Our sending domain is protected by SPF, DKIM, and DMARC, so that mail claiming to come from us can be authenticated.

No system is perfectly secure, and we do not claim ours is.

13. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information about you, and to appeal a decision we make about such a request.

  • If you are a platform user, contact us at security@camberautomotive.com. We will verify your identity before acting.
  • If you are a customer of a dealership, please contact that dealership. It decides what happens to its customer information. If you contact us, we will forward your request and tell you we have done so.

We will not discriminate against you for exercising these rights.

14. Children

Our platform and our website are intended for business use by adults. We do not knowingly collect personal information from children.

15. Changes to this policy

If we change this policy we will update the date at the top and, for material changes affecting platform users, notify the dealership that administers your account.

16. How to contact us

security@camberautomotive.com