Privacy Policy
Effective date: September 2, 2026 | Last updated: September 2, 2026 | Version 1.0
1. Who this Policy covers
This Privacy Policy applies to anyone who uses a VaultDrive chat or voice interface — whether you typed in a chat window, sent or received a text message, exchanged email, or spoke with an automated assistant on the phone.
It covers everything VaultDrive operates, including:
- the website chat assistant
- text message (SMS/MMS) conversations
- email conversations
- inbound and outbound phone calls, including call recordings and transcripts
- appointment requests, trade-in intake, and any form or interface we provide
We call all of this the Services.
It explains what we collect, how we use it, how we use it to train artificial intelligence, who we share it with, how long we keep it, and what you can ask us to do about it.
2. Who we are
VaultDrive Enterprises Inc., a corporation incorporated in Canada with its head office in Kelowna, British Columbia, carrying on business as VaultDrive ("VaultDrive", "we", "us", "our").
3510 Spectrum Ct, Kelowna, British Columbia V1V 2Z1, Canada
info@vaultdrive.io
We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's and Alberta's Personal Information Protection Acts, Quebec's private-sector privacy legislation where applicable, and other privacy laws that apply to us.
This Policy forms part of, and should be read with, the VaultDrive Terms of Use.
We are the technology, not the business you're buying from
VaultDrive builds and runs AI communication tools for businesses — automotive dealerships, rental and fleet operators, and similar companies. When you use our chat or voice assistant, you are usually contacting one of those businesses, and it is that business — not VaultDrive — that sells, services, prices and delivers whatever you're asking about.
That business decides what its assistant does and keeps its own records under its own privacy policy. VaultDrive runs the software on its behalf.
Two consequences worth knowing:
- For most of what happens in a conversation, we act on that business's instructions, and it is the organization accountable for the information. Requests to access, correct or delete your information are often best directed to them, and we will help route your request.
- For a defined set of purposes we act on our own behalf and are accountable ourselves — securing and improving the Services, training our AI (Section 6), creating de-identified data, preventing fraud and abuse, meeting our own legal obligations, and defending legal claims. For those, you deal with us directly, and Section 12 sets out your rights.
3. What we collect
Your contact details — name, phone number, email address, city and province.
What you say to us — the full content of your chat messages, text messages and emails; audio recordings of calls; transcripts of those recordings; timestamps and conversation metadata.
What you send us — photographs of your vehicle, documents, screenshots and attachments.
What you're asking about — the vehicle you're interested in, VIN or stock number, budget range you mention, timeline, whether you're paying cash or financing, service concerns you describe, and the questions you ask.
Your trade-in, if you discuss one — year, make, model, VIN, mileage, condition, accident and ownership history, service records, modifications and extras, and photographs.
Technical information — IP address, browser and device type, operating system, the page you were on when you started chatting, referring URL, session and cookie identifiers, and approximate location from your IP address.
Communication records — numbers dialled and received, call times and durations, message delivery status, and your opt-in and opt-out history.
Things we generate about you — AI-written conversation summaries, intent and outcome classifications, sentiment indicators, quality scores, extracted facts and commitments, confidence scores, and lead prioritization signals.
All of this together is your Conversation Data.
Where it comes from
Directly from you; automatically through cookies and our telephony and messaging systems; from the business you contacted, including its customer and inventory records; from lead forms and listing marketplaces that pass your inquiry along; and from the service providers that help us run the Services.
4. Please don't send us sensitive information
Do not provide any of the following through chat, text, email or an automated call:
Social Insurance Number or Social Security Number · date of birth combined with other identifiers · banking, account, credit card or debit card numbers · driver's licence or passport numbers · income, employment or credit history · health information · passwords.
Credit and financing applications should be completed only through a secure application form or in person.
Our systems are built to detect these, interrupt the conversation, redact them from stored transcripts, and keep them out of AI training. Those controls are automated and not perfect. If you send sensitive information anyway you do so at your own risk, and we are not liable for loss arising from your sending it through an unsecured channel.
We also don't want information about your race, ethnicity, religion, political views, sexual orientation, health, or criminal record. If you mention something like that in conversation it may end up in the transcript, and we'll treat it as sensitive — but we don't ask for it, don't use it to make any decision about you, and don't use it to train anything.
5. How we use your information
To respond to you and hold the conversation; to work out which vehicle, appointment, trade-in or service matter you mean; to send you the information, links, photos, videos, vehicle history reports and documents you ask for; to submit appointment requests and trade-in details to the right people; to route and escalate your inquiry to a human; and to follow up with you about your inquiry, subject to the opt-out rights in Section 7.
Also: to keep a record of the interaction, including transcripts and logs, for business, audit and dispute-resolution purposes; to operate, secure, monitor, debug and improve the Services; to train and improve our AI, as described in Section 6; to create and use de-identified data; to detect and prevent fraud, abuse and security incidents; to comply with legal obligations; and to establish or defend legal claims.
6. Artificial intelligence
This is the section most people want to read, so it isn't buried.
6.1 You're talking to AI
The Services use artificial intelligence, including large language models, speech recognition, text-to-speech, and classification and scoring models. When you chat, text or call, you may be interacting with an AI assistant rather than a person. It will tell you it's a virtual assistant if you ask, and you can ask for a human at any time.
6.2 We use your conversations to train AI
You are expressly notified that VaultDrive uses Conversation Data — including chat messages, text messages, emails, call recordings and call transcripts — to develop, train, fine-tune, evaluate, test and improve artificial intelligence and machine learning models, prompts, classifiers, scoring systems and safety controls.
Specifically, we use it to:
- train and fine-tune the models that understand, classify, summarize and respond within conversations;
- build evaluation and test datasets from real conversations, to measure accuracy and safety;
- learn from corrections — when a staff member fixes something the AI got wrong, that correction improves the system;
- tune the assistant's behaviour for the specific business you contacted;
- improve speech recognition, including accents, names and industry terminology; and
- develop new features, models and products, which may be offered to other businesses.
By using the Services, you consent to this. You can opt out at any time under Section 6.7.
Where practical we de-identify, redact, filter or aggregate Conversation Data before training, and we apply the exclusions in Section 6.4. Some training and evaluation still requires realistic conversation content, which can include personal information.
6.3 What we don't do
- We don't sell your personal information, and we don't license or hand your identifiable Conversation Data to other companies to train their AI for their purposes.
- We don't create voiceprints or biometric identifiers. We record and transcribe calls, but we don't turn your voice into a biometric template and we don't use voice recognition to identify or authenticate anyone. If that ever changes, we will ask for separate express consent first.
- We don't use AI to make decisions with legal or similarly significant effects about you. We don't make credit decisions, approve or deny financing, set your price, or determine your trade-in value. People at the business you contacted make those decisions.
- We don't use sensitive categories — race, ethnicity, religion, sexual orientation, health, political opinion, criminal record — for training, scoring, targeting, or any decision about you.
- We don't clone your voice or generate synthetic audio or text impersonating you.
- We don't use your information for advertising or ad targeting.
6.4 What we keep out of training
We filter and redact to exclude: the sensitive categories in Section 4; health information; information from anyone we know or reasonably believe is a minor; Conversation Data from anyone who has opted out; and Conversation Data a client business has contractually excluded.
These controls are automated and imperfect. We describe our practice, not a guarantee.
6.5 De-identified data
De-identified data means data derived from Conversation Data with direct and indirect identifiers removed, obscured or aggregated, so that there is no reasonable expectation it could be used to identify an individual.
We may create, keep, use, disclose, license and commercialize de-identified data for any lawful purpose, indefinitely, including after your dealings with the business end. That includes aggregated benchmarking and performance statistics across multiple businesses, AI training and evaluation, research, analytics, product development, and publishing or licensing aggregate insights.
We will not attempt to re-identify it, we maintain safeguards designed to prevent re-identification, and we contractually prohibit recipients from attempting it.
De-identified data is no longer personal information, so the access, correction, deletion and opt-out rights in Sections 6.7 and 12 don't apply to it.
6.6 Training can't be undone
An important technical limit, stated plainly rather than left for you to assume.
Once information has been used to train or fine-tune a model, the model cannot practicably be "untrained." Deleting your Conversation Data or withdrawing consent removes the source data we can identify and stops all future use of it — but it does not remove patterns a model has already learned, and does not require us to delete, retrain or destroy existing models, model weights, evaluation datasets, or de-identified data already created.
The same is true of aggregated statistics: once data is de-identified or aggregated it is no longer linked to you and can't be located or pulled back out.
Deletion and opt-out requests are honoured going forward. They don't operate retroactively on models already trained.
6.7 How to opt out of AI training
You can opt out at any time, and it won't affect your ability to use the Services or get help with your inquiry.
Email info@vaultdrive.io with the subject line "AI Training Opt-Out", and include the phone number or email address you used so we can find your records.
When you opt out, we stop using your Conversation Data for AI training and remove it from training datasets we can identify. We keep using it for the operational purposes in Section 5 — running the Services, keeping records, security and legal compliance — because those are necessary to provide the Services at all. Section 6.6 applies: opting out doesn't affect models already trained or de-identified data already created.
6.8 AI gets things wrong
AI systems make mistakes. What the Services tell you may be inaccurate, incomplete, out of date or simply wrong. Nothing generated by the Services is a price, quote, appraisal, valuation, confirmed appointment, availability confirmation, credit decision, offer, or professional advice. Confirm anything that matters directly with the business, in writing, before relying on it. Sections 4, 13 and 14 of the Terms of Use govern this.
6.9 Automated processing and human review
We use automated processing to classify conversations, score how urgent or promising an inquiry is, summarize interactions, extract commitments, prioritize follow-up, and route inquiries to the right person. This affects how quickly and by whom you're contacted — not whether you're offered a product, a price, or credit.
Our systems are deliberately built so that AI proposes and a deterministic rules engine decides. Anything that reaches you is executed through defined, logged, reversible operations subject to configured limits and confidence thresholds, and consequential steps require a human to confirm.
You can ask for human review of any automated processing that affects you, and an explanation of the main factors involved. Email info@vaultdrive.io.
6.10 Our AI providers don't train on your data
We use third-party AI and speech providers to run the Services. We contract with them on terms that prohibit them from using your Conversation Data to train their own general-purpose models, and that require them to process it only to provide services to us, under confidentiality and deletion obligations.
The distinction matters: VaultDrive trains on Conversation Data for VaultDrive's Services. Our vendors do not train on it for theirs.
6.11 Trying to manipulate the assistant
Attempts to jailbreak or prompt-inject the assistant, extract its instructions, or make it take unauthorized actions are logged, may be retained separately for security purposes, and may result in your access being suspended.
7. Consent, and how to opt out
How we get consent. Express consent — you click to start a chat after seeing our notice, you give us your phone number, you keep talking after being told the call is recorded. Or implied consent, where the purpose is obvious and you provide the information voluntarily. For sensitive information, and for anything a reasonable person wouldn't expect, we ask for express consent.
Text messages: reply STOP at any time. You'll get one confirmation and nothing further, except messages needed to service something already in progress. Reply HELP for help.
Email: use the unsubscribe link in any message. It takes effect promptly and within 10 business days at the latest, as Canada's Anti-Spam Legislation (CASL) requires.
Calls: tell the assistant you don't want to be called.
Call recording: if you don't consent to being recorded, say so and end the call, then contact the business in person or in writing.
AI training: Section 6.7.
Withdrawing consent generally. You can withdraw consent at any time, subject to legal and contractual limits and on reasonable notice. It may mean we can no longer provide some or all of the Services to you. Some information has to be kept to meet legal, tax, audit, anti-spam recordkeeping and dispute-resolution obligations. Section 6.6 applies to information already used in training.
Opting out of marketing doesn't stop messages about an appointment, repair order or transaction already underway.
8. Who we share it with
The business you contacted, and its staff, affiliated locations and group, which use it under their own privacy practices.
Service providers that help us run the Services — cloud hosting and storage, telephone and SMS carriers, email delivery, speech recognition and text-to-speech, AI model providers, analytics, error monitoring, security, and support tooling. They're bound by contract to use it only to provide services to us, protect it appropriately, and not use it for their own purposes.
Professional advisors, auditors and insurers, under confidentiality.
An acquirer or successor, in a merger, acquisition, financing, reorganization or sale of our business or assets — provided they're bound to handle it consistently with this Policy.
Law enforcement, regulators and courts, where required by law, subpoena, warrant or court order, or where we reasonably believe it's necessary to investigate or prevent fraud, a security incident, harm to someone, or a violation of our Terms of Use.
We may disclose de-identified data without restriction, as described in Section 6.5.
We do not sell your personal information to anyone for their own marketing purposes.
A current list of our categories of service providers is available on request at info@vaultdrive.io.
9. Where your information goes
Your information may be stored and processed in Canada, the United States, and other countries where we or our service providers operate.
Information held outside Canada is subject to the laws of those countries and may be accessible to their courts, law enforcement, regulators and national security authorities under lawful process, without notice to you. By using the Services you consent to this.
You can contact us at info@vaultdrive.io for information about our practices regarding service providers outside Canada, and to reach someone who can answer questions about it.
10. How long we keep it
- Chat, SMS and email content — generally 7 years, or as configured by the business you contacted
- Call recordings — generally 24 months, unless kept longer for a dispute, investigation or legal requirement
- Call transcripts and conversation records — generally 7 years, as a business record
- Consent and opt-out records — at least 3 years after the last message, as anti-spam rules require
- Technical and security logs — generally 12 months
- Anything required for legal, tax or audit purposes — as long as the law requires
- De-identified data — indefinitely
When these periods end we delete or de-identify the information. Backups are cleared on our standard rotation. Section 6.6 applies to anything already used in training. Retention for information we hold on a client business's behalf is set by that business.
11. How we protect it
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the information, including encryption in transit and at rest, access controls and least-privilege permissions, staff authentication, logging and monitoring, vendor security review, and confidentiality obligations and training for our people.
No system is completely secure. We can't guarantee absolute security or promise our systems will never be accessed without authorization.
If a breach happens and we determine it creates a real risk of significant harm, we will report it to the applicable privacy commissioner, notify affected individuals and the relevant business, and keep records of it, as PIPEDA and provincial law require.
12. Your rights
Subject to legal limits and to Sections 6.5 and 6.6, you can:
- access the personal information we hold about you, and find out how it's been used and who it's been shared with
- correct anything inaccurate or incomplete
- withdraw consent, as described in Section 7
- opt out of AI training, under Section 6.7
- ask us to delete information we no longer need for a legitimate or legal purpose
- ask for human review of automated processing that affects you, and an explanation of the main factors (Section 6.9)
- complain to us or to a regulator
To exercise any of these, email info@vaultdrive.io. We may need to verify your identity, and we'll ask for enough detail — the phone number or email you used, and the business you contacted — to find your records. We respond within 30 days, or tell you why we need an extension the law allows. There's no charge for a reasonable request, and we'll tell you in advance if one would involve a fee.
Where we hold information on a client business's behalf, we'll forward your request to them and help them respond, since they're the accountable organization.
We may refuse a request where the law permits or requires — for example if answering would reveal someone else's personal information, breach privilege, compromise an investigation, or if the information is de-identified.
13. Children
The Services aren't directed to children and we don't knowingly collect their personal information. If you believe a child has provided information through the Services, email info@vaultdrive.io and we'll delete it and remove it from training data.
14. Cookies
Our chat widget and web interfaces use cookies, local storage and similar technologies to keep your session going, remember your conversation, secure the Services, prevent abuse, and measure performance. We use strictly necessary cookies for session and security, and analytics cookies to understand how the Services perform. We don't use advertising or cross-site tracking cookies in the chat widget.
The website you're visiting may set its own cookies, including advertising cookies, under its own policy. We don't control that.
You can manage cookies in your browser settings, though disabling them may stop the Services working.
15. If you're outside British Columbia
Quebec. You have additional rights under Law 25, including to be told when a decision is based exclusively on automated processing and to submit observations, to data portability, and to request de-indexation in defined circumstances. As stated in Section 6.3, we don't make decisions about you based exclusively on automated processing that have legal or similarly significant effects.
European Economic Area and United Kingdom. Where the GDPR or UK GDPR applies, our legal bases are performance of a contract, your consent, legal obligations, and our legitimate interests in securing and improving the Services and developing our products, balanced against your rights. You have rights of access, rectification, erasure, restriction, portability and objection, including objection to processing based on legitimate interests. International transfers are made under appropriate safeguards including standard contractual clauses. You may complain to your supervisory authority.
United States. Depending on your state you may have rights to know, access, delete, correct and port your personal information, and to opt out of sale, sharing and targeted advertising. We don't sell or share personal information for cross-context behavioural advertising. Email info@vaultdrive.io to exercise a right. We don't discriminate against anyone who does.
16. Changes to this Policy
We may update this Policy. The current version is always at https://vaultdrive.io/privacy with its effective date and version number, and earlier versions are archived and available on request.
If we materially change how we use personal information — including any material expansion of our AI training practices — we'll give notice before it takes effect and, where the law requires, ask for your consent. For other changes, continuing to use the Services after the effective date means you accept them.
17. Contact us
Privacy Officer
VaultDrive Enterprises Inc.
3510 Spectrum Ct
Kelowna, British Columbia V1V 2Z1, Canada
We'll acknowledge your question or complaint, look into it, and respond in writing. If you're not satisfied, you can complain to:
- Office of the Privacy Commissioner of Canada — priv.gc.ca · 1-800-282-1376
- Information and Privacy Commissioner for British Columbia — oipc.bc.ca · 1-800-663-7867
- Information and Privacy Commissioner of Alberta — oipc.ab.ca · 1-888-878-4044
- Commission d'accès à l'information du Québec — cai.gouv.qc.ca
- or the privacy regulator where you live
For questions about a vehicle, a price, an appointment, a repair or a transaction, contact the business you were dealing with directly.
© 2026 VaultDrive Enterprises Inc. All rights reserved.
