Privacy Policy
Last updated: 2026-07-20
This Privacy Policy describes how AllStateDMVs ("we," "us," "our"), operated by TUNDRAA LLC, collects, uses, stores, and discloses information when a dealer or end customer ("you") interacts with our software platform at https://allstatedmvs.com (the "Service").
1. Who we are
AllStateDMVs is a Software-as-a-Service platform that helps automotive dealers process out-of-state vehicle title and registration paperwork and provides finance & insurance (F&I) tooling, including customer credit application intake.
TUNDRAA LLC is the data controller for information collected through the Service.
Contact: info@allstatedmvs.com
2. What we collect
From dealers
- Account information: name, email, dealership name, address, phone
- Subscription billing information processed by Stripe
- Quote, deal, and document records created in the platform
- User activity logs (page views, action timestamps) for product analytics
From end customers (the dealer's customers)
- Identifying information: first name, middle initial, last name, date of birth, driver's license number and state
- Contact information: address, city, state, ZIP, county, phone, email
- Vehicle information: VIN, year, make, model, mileage
- Financial information (when the customer fills out a Credit Application):
- Social Security Number - Employer name, address, phone - Monthly gross income and other income - Housing payment, time at residence - Personal references - Co-applicant information (same categories)
- Trade-in information: prior lien holder, account number, payoff balance
Automatic collection
- IP address, browser type, device information, cookies for authentication
3. Why we collect it
- To process tag and title work the dealer hired us to complete
- To generate state-required documents (title applications, POAs, odometer disclosures, damage disclosures)
- To allow F&I to submit credit applications to lenders the customer is shopping with
- To compute sales tax, registration fees, and processing fees accurately
- For audit trails (who completed a compliance check, when a deal was reassigned, who submitted to which lender)
- For platform analytics — aggregated, never sold
4. Legal basis (GLBA Safeguards Rule)
Because we handle non-public personal information (NPI) of consumers, we are subject to the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 CFR Part 314) as a service provider to financial institutions (the dealers).
We maintain:
- Encryption in transit (TLS 1.2+) and at rest (Firebase Firestore default encryption)
- Access controls: role-based (dealer_owner, sales_manager, finance_manager, tag_title)
- Audit logging of credit application access
- Annual security review (target: Q4 each year)
- Incident response plan (see Section 9)
- Subprocessor due diligence (Firebase / Google Cloud, Stripe, Sendgrid)
5. Who we share it with
- The customer's dealer: customers' credit applications are visible to the assigned F&I manager and the dealer owner within the dealer's organization. Sub-users do not see customers assigned to other F&I personas.
- Service providers: Google Cloud (Firebase Hosting, Firestore, Auth), payment processor (subscription billing only), email delivery (Sendgrid)
- Government / DMV: state-required document data when a deal is submitted to a state DMV or tag agent
- Lenders selected by the dealer: when the dealer submits a credit application to a specific lender. We do not select lenders for the customer.
We do not:
- Sell personal information to advertisers
- Use customer data for marketing or training AI models
- Share data across dealers
6. How long we keep it
- Quote / deal records: 7 years after deal completion (statutory document-retention requirement for dealer records)
- Credit applications: 7 years from the date of submission, then permanently deleted
- Account information: until the dealer cancels and 30 days thereafter
- Audit logs: 1 year
7. Customer rights
Depending on your state of residence, you may have the right to:
- Request a copy of the personal information we hold about you
- Request correction of inaccurate information
- Request deletion (subject to the retention requirements in Section 6)
- Opt out of automatic data collection (some platform features will be unavailable)
To exercise these rights, email info@allstatedmvs.com with your full name, the dealership where you submitted information, and the approximate date.
California residents: Under CCPA/CPRA you have additional rights including the right to know categories of personal information collected, the right to delete, and the right to opt out of "sale" or "sharing" — though we do not sell or share for cross-context behavioral advertising.
8. Children
The Service is not directed to and does not knowingly collect information from anyone under 18.
9. Security incident response
In the event of unauthorized access to personal information:
- We will investigate within 24 hours of discovery
- We will notify affected dealers within 72 hours
- We will notify affected customers as required by state breach-notification laws
- We will notify the Federal Trade Commission as required by GLBA
10. Changes to this policy
We will post material changes at the top of this page with the updated effective date. Continued use of the Service after an update constitutes acceptance.
11. Contact
TUNDRAA LLC Email: info@allstatedmvs.com 9990 Fairfax Blvd, Suite 560, Fairfax, VA 22030