AutoShowroom
Privacy at AutoShowroom

Designed around a sealed vehicle tender.

This policy explains how AutoShowroom collects, uses, holds and discloses personal information. It is written for the platform we are actually building: customer identity is separated from dealer RFQs until an offer is accepted.

Last updated 3 September 2026

1. Scope and current operating status

This policy applies to the AutoShowroom website, customer account, vehicle-request workflow, dealer RFQ workflow, accepted-deal handoff, operator support and contact enquiries.

AutoShowroom is in production setup before commercial launch. The final operating entity details used on fee-bearing agreements and invoices are being finalised separately. This policy does not create a vehicle-sale contract or final brokerage-fee agreement.

We have deliberately written the privacy policy around the platform's actual data boundaries rather than waiting for a later legal template.

2. Personal information we collect

Depending on how you use AutoShowroom, we may collect:

  • account identifiers such as verified email address and, if mobile authentication is enabled, mobile number;
  • handoff contact details such as name, contact email and mobile number;
  • vehicle requirements including make, model, variant, condition, quantity, colour, options and timing;
  • buyer and fulfilment information such as buyer type, postcode, pickup/delivery preference and optional business ABN;
  • transaction indicators such as trade-in or finance interest;
  • dealer business, franchise and published business-contact information used to route RFQs;
  • dealer quotes, availability, handover timing, delivery terms, quote conditions and acceptance/handoff records;
  • contact, privacy-request and complaint correspondence; and
  • technical and security information processed by our hosting, authentication and communications providers.

AutoShowroom's application-level rate-limit storage does not store raw IP addresses, customer IDs, emails or bearer tokens. Hosting and security providers may still process technical request metadata as part of delivering and protecting the service.

3. Why we collect and use information

We use information to:

  • authenticate customers and protect accounts;
  • create and operate a sealed vehicle request;
  • match an RFQ to relevant dealer businesses and contacts;
  • collect, validate and normalise dealer offers;
  • present anonymous competing offers to the customer;
  • release identities and create the dealer/customer introduction after an offer is accepted;
  • operate reminders, recovery and exception workflows;
  • respond to enquiries, privacy requests and complaints;
  • prevent abuse, investigate errors and maintain audit records;
  • improve dealer matching using operational performance evidence; and
  • meet legal, regulatory and record-keeping obligations.

We do not sell personal information. We do not use a vehicle request or support enquiry for unrelated behavioural advertising. Any future direct marketing must be handled separately and in accordance with applicable privacy and electronic-message rules.

4. How the sealed tender protects identity

Before acceptance

Dealers receive the vehicle requirement and information needed to quote, but not the customer's direct name, email, mobile number or street address. Customers compare normalised offers without dealership names or direct dealer contact details.

After acceptance

When the customer accepts one offer, AutoShowroom records an explicit identity-release event. The successful dealership and customer can then receive the contact information required to complete the dealer transaction. Losing dealers do not receive the customer's handoff identity.

5. Service providers and overseas processing

AutoShowroom uses specialist infrastructure and communications providers to operate the service. The current codebase is designed for Vercel hosting, Supabase authentication/database, Resend email and optional Stripe service-fee invoicing.

Those providers may process information in Australia and overseas, including the United States and other countries where their infrastructure or subprocessors operate. The exact production regions depend on the final provider/project configuration. We will keep this policy updated if those arrangements materially change.

We may also disclose information where required or authorised by law, or where reasonably necessary to protect the platform, users or other people.

6. Security and retention

AutoShowroom uses server-side authorisation, row-level database controls, hashed bearer-token handling, bounded requests, rate-limiting, no-store rules for sensitive surfaces and auditable identity-release state.

We retain information for as long as reasonably required to operate the service, maintain transaction/audit evidence, resolve disputes and meet legal obligations. Information that is no longer required should be deleted or de-identified where appropriate and lawful.

7. Access and correction

You can ask to access personal information AutoShowroom holds about you or ask for inaccurate information to be corrected. Use the Contact page and choose “Privacy request”. We may need to verify identity before providing or changing personal information.

8. Privacy enquiries and complaints

Use the Contact page and select “Privacy request” or “Complaint”. We will review the issue and respond within a reasonable period.

Once the final operating entity is confirmed, this policy will be updated with any additional business/contact details required for commercial operation.

If the Privacy Act applies to the matter and you remain dissatisfied after giving AutoShowroom a reasonable opportunity to respond, you may also have the right to complain to the Office of the Australian Information Commissioner.

9. Automation, dealer matching and AI assistance

AutoShowroom uses deterministic software rules for transaction states such as dealer eligibility, reminders, offer presentation, acceptance and identity release. Historical dealer response and competitiveness metrics may influence future dealer matching after minimum sample thresholds are reached.

AI may assist with tasks such as extracting or classifying dealer communications, but it is not permitted to bypass identity shielding, required validation, offer acceptance or payment controls. Human operators handle defined exception cases.

We will review this policy as Australian privacy obligations for automated decision disclosures evolve and before any materially different automated decision process is introduced.