Home ULTRA SDK & API Sample Reports Competition About Careers Press Insights Contact
Trust & Security

How we protect your data.

CarDr handles vehicle diagnostic data, dealership information, and business records for auctions, dealers, fleets, and lenders. Here's how we approach protecting it.

Encryption in Transit

Traffic to and from cardr.com and the CarDr client dashboard is encrypted using HTTPS/TLS. Diagnostic data transmitted from a CarDr ULTRA device to our cloud platform is likewise sent over encrypted connections.

Account Access & Verification

Business accounts — dealerships, auctions, fleets, and other partners — are verified before device activation, consistent with the terms described on our Order page. Access to the CarDr client dashboard is tied to individual user accounts, and dashboard visibility into scan history and reports is scoped to the business account that operates the devices in question.

Vehicle & Diagnostic Data

VINs, diagnostic trouble codes, and related scan data captured by a CarDr ULTRA device are collected on behalf of, and for the benefit of, the business account operating that device. That data is used to generate the reports and dashboard views available to that account, and is not shared outside CarDr except as described in our Privacy Policy.

Payment Information

CarDr does not collect credit card or other payment information through cardr.com. Order requests submitted through our website are handled by our sales team, who complete payment directly with the customer through channels outside the website.

Form Submissions

Contact, order, and career applications submitted through our website forms are processed by a third-party form-delivery provider and routed directly to CarDr's email. We do not store form submissions in a public-facing database on cardr.com.

Third-Party Service Providers

We work with a limited number of third-party providers to operate our website and Services, including form processing and, where applicable, integration partners such as AutoAp for open recall data. These providers are given access only to the information needed to perform their function.

Data Retention

We retain information consistent with the retention practices described in our Privacy Policy — generally, for as long as necessary to provide the Services, meet legal obligations, and support the business account under which data was collected.

Reporting a Security Concern

If you believe you've found a security vulnerability affecting CarDr's website, platform, or devices, please contact us at info@cardr.com. We take reports seriously and will work to investigate and address legitimate concerns promptly.

Questions

For security or data-handling questions as part of a vendor review or procurement process, contact us at info@cardr.com or (800) 932-1120.

This page describes CarDr's general approach to data handling and security and is provided for informational purposes. It does not constitute a warranty or a legally binding representation of specific technical controls. For contractual security commitments, please contact our sales team.