Skip to main content
RooftopOS
Back to RooftopOS

Data Processing Agreement

Last updated: July 2026

Roles

The dealership ("Customer") is the Controller of consumer personal data submitted to RooftopOS through any module. RooftopOS ("Processor") processes the data solely on documented instructions from the Customer to deliver the Service.

Categories of data processed

  • Consumer identifiers (name, address, email, phone)
  • Vehicle data (VIN, condition, photos, ownership documents)
  • Transaction data (offer amount, addendum line items, signatures, timestamps)
  • Communication data (SMS / email content sent through the platform under the dealership's brand)
  • Service data (MPI photos and videos, customer e-approvals — AutoFilm only)

Marketing newsletter data

Newsletter subscribers (the "operator brief" signup in our footer) are stored separately from customer and consumer records, under their own access boundary. Newsletter emails are never sold, never shared with sub-processors beyond our email sender (Resend), and can be deleted independently of any commercial relationship.

Sub-processors

The list below is generated from the sub-processor register maintained in RooftopOS’s codebase, which is kept against the vendors actually in the production request path rather than written by hand. The full table, including data categories and processing regions, is published on the Security page. RooftopOS gives 30 days’ notice before adding a sub-processor.

  • CloudflareHosting, content delivery, TLS termination, DoS protection
  • Supabase (Postgres)Primary database and authentication
  • SentryError monitoring, performance tracing, session replay
  • ResendTransactional and confirmation email
  • SlackInternal notification of a lead, signup or review
  • Cal.comDemo and briefing scheduling

Named in earlier versions of this agreement but not currently provable in RooftopOS's production code path, and therefore not represented as active: Cloudflare R2, Twilio, OpenAI. These are being confirmed or removed.

Security measures

RooftopOS’s current security posture — including what is implemented, what is not, and what has not been independently verified — is published in full on the Security page, including its certification position. One point belongs here because it is commonly assumed: RooftopOS operates no customer-facing audit-logging control — there is no log the Customer can read, query or export for itself — and this agreement therefore makes no commitment to produce, retain, or export an audit trail. The versioned disclosure and consent records the applications write against a deal are Customer data under the categories above, not a control this agreement grants.

Data subject rights

RooftopOS will assist the Customer in responding to consumer requests for access, deletion, correction, or portability under applicable laws (CCPA, state privacy acts). Requests are made by contacting RooftopOS and are carried out by the RooftopOS team. There is no self-service export or deletion control in the Customer-facing product today, and none is represented in this agreement. The timeframes that apply to a request are set in the executed agreement and by applicable law.

Breach notification

RooftopOS will notify the Customer of any confirmed personal-data breach within 72 hours, including known scope, mitigations taken, and recommended Customer next steps.

Cross-border transfers

Persistent storage of Customer and consumer data is in United States regions. The delivery network is global: a connection terminates at the edge location nearest the visitor and is proxied to US origin and storage, so describing the whole system as US-only would be false. International transfer of stored data is not made without prior Customer consent.

Term & deletion

On termination, RooftopOS returns or deletes Customer data on the schedule written into the executed agreement. No return window, retention period, or deletion turnaround is published here, because none has been set for publication. Where the Customer is required to preserve records under federal or state record-keeping rules, the categories and periods are identified in that agreement.

Contact & signature

Email Contact support to receive a signed countersigned copy of this DPA on RooftopOS letterhead for your dealership's compliance file.