Privacy Policy

Effective Date: June 3, 2026  ·  Last Updated: June 3, 2026

1. Introduction

CognoSales ("we," "us," or "our") provides a SaaS platform for automotive dealerships. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding that information.

This Policy applies to Subscribers (dealerships and business entities that hold a CognoSales account), End Users (dealership staff who access the Service), and Contacts (customers and leads whose data Subscribers manage within the Service).

2. Information We Collect

Account and Subscriber Information. When a dealership creates an account, we collect business name, address, contact details, billing information (processed by our payment provider — we do not store raw card numbers), account credentials, and subscription details.

Customer and Lead Data. Subscribers upload or generate data about their dealership customers and leads, which may include names, email addresses, phone numbers, vehicle preferences, purchase history, communication history, and CRM notes. CognoSales acts as a data processor for this data; the Subscriber is the data controller.

Usage and Technical Data. We automatically collect log data (IP addresses, browser type, pages visited, timestamps), device information, session data, and error reports.

Analytics and Advertising Data via Third-Party Integrations. When Subscribers connect third-party platforms, we retrieve and store performance data on their behalf:

  • Google Analytics 4 / Search Console: Website traffic metrics, search query performance, impressions, clicks, and conversion data.
  • Google Ads API: Campaign, ad group, keyword, and ad performance metrics; impressions, clicks, cost, conversions, and ROAS; account-level spend and budget information.
  • Meta Ads API (Facebook / Instagram): Campaign, ad set, and ad performance metrics; impressions, reach, clicks, spend, and conversion data; aggregated audience demographic breakdowns.

3. How We Use Information

We use collected information to:

  • Provide, operate, and maintain the Service
  • Process payments and manage subscriptions
  • Send transactional communications (account alerts, billing notices)
  • Display analytics and advertising performance data to Subscribers
  • Improve the Service through usage analytics and error monitoring
  • Respond to support requests
  • Enforce our Terms of Service and comply with legal obligations

We do not use Customer Data or advertising API data to serve targeted advertisements to individuals, build or sell user profiles to third parties, or train AI models without explicit Subscriber consent.

AI-Powered Features. Certain features (email generation, AI chatbot) send relevant content to OpenAI's API for processing under OpenAI's API terms. This data is not used to train OpenAI's general models. Subscribers may disable AI features in account settings.

4. Google API Services — Limited Use Disclosure

CognoSales' use of information received from Google APIs — including Google Analytics 4, Google Search Console, and Google Ads — adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

  • Google API data is used only to display analytics and performance information to the Subscriber who authorized the connection.
  • We do not transfer Google API data to third parties except as necessary to provide the Service, with user consent, or as required by law.
  • We do not use Google API data to serve advertisements.
  • We do not allow humans to read Google API data unless the user has given explicit permission, it is necessary for security purposes, or it is required by law.

5. Meta Ads API Data Use

CognoSales' access to Meta advertising data is governed by Meta's Platform Terms. Data retrieved from the Meta Ads API is:

  • Used exclusively to display advertising performance insights to the Subscriber who connected the account.
  • Not used to retarget individuals or build advertising audiences outside of the Subscriber's own campaigns.
  • Not shared with or sold to third parties.
  • Deleted when the Subscriber disconnects the integration or closes their account.

6. Information Sharing and Disclosure

We do not sell your personal information. We share data only with trusted sub-processors who help us deliver the Service:

Sub-ProcessorPurpose
TwilioSMS delivery and Conversations API
SendGrid (Twilio)Transactional and marketing email
OpenAIAI email generation and chatbot responses
Google LLCAnalytics and Ads API integrations
Meta Platforms, Inc.Meta Ads API integration

All sub-processors are bound by data processing agreements restricting their use of data to the purpose for which it was shared. We may also disclose information where required by law, court order, or to protect the rights, property, or safety of CognoSales, our users, or the public.

7. Data Retention and Deletion

We retain Customer Data and Subscriber account data for as long as your account is active and for a reasonable period thereafter to support billing or dispute resolution.

When an account is closed:

  • Access to the account and all associated data is revoked on the date of closure.
  • All Customer Data, advertising API data, and Subscriber data is permanently deleted from active systems within 30 days.
  • Residual data in encrypted backup archives is purged within 90 days.
  • Written confirmation of deletion is available upon request.

We do not retain Customer Data after these periods except where required by applicable law (e.g., tax records, fraud investigation). Anonymized or aggregated usage data not linked to identifiable individuals may be retained indefinitely.

8. Data Security

We implement industry-standard technical and organizational measures including encryption of data in transit (TLS/HTTPS), encrypted storage for sensitive fields, access controls limiting data access to authorized personnel, and regular security reviews. No method of transmission or storage is 100% secure; we cannot guarantee absolute security but are committed to addressing incidents promptly.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete personal information
  • Delete your personal information (subject to legal retention requirements)
  • Withdraw consent for processing where consent was the legal basis
  • Receive your data in a machine-readable format

To exercise any of these rights, contact us at hello@cognosales.com. We will respond within 30 days.

PIPEDA (Canada): Individuals in Canada have rights under the Personal Information Protection and Electronic Documents Act. Our Privacy Officer can be reached at hello@cognosales.com.

CASL Compliance: All commercial electronic messages sent through the Service are sent on behalf of Subscribers. Subscribers are responsible for obtaining and managing consent in accordance with CASL. CognoSales provides unsubscribe mechanisms in all marketing communications.

10. Cookies

The CognoSales platform uses cookies for authentication (maintaining your logged-in session), user preferences, and internal usage analytics. We do not use cookies for cross-site advertising tracking. You may configure your browser to reject cookies, but this may affect Service functionality.

11. Changes to This Policy

When we make material changes to this Privacy Policy, we will notify Subscribers via email or in-app notification at least 14 days before the changes take effect.

12. Contact

For privacy-related questions, requests, or complaints, contact our Privacy Officer at hello@cognosales.com.

If you are located in Canada and are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.