LotRoster

LotRoster

Privacy & Data Handling

This page gives a high-level description of information used to operate LotRoster. Deployment-specific notices, agreements, organizational policies and applicable law remain controlling where they apply.

Scope

LotRoster is a restricted dealership operations application rather than a public consumer registration service. This public overview does not replace any privacy notice, consent record, employment policy, contractual requirement or statutory right that applies to a particular deployment or user.

Information used by the service

Depending on the features enabled for an authorized user, the service may process account identifiers and role information, authentication and session data, dealership vehicle and inventory records, operational workflow records, and technical or security logs needed to operate and protect the application.

Device permissions

Features that use device capabilities such as the camera require browser or operating-system permission. Permission is controlled by the user and device. LotRoster does not make public operational data available merely because a public information page can be viewed without signing in.

Access and handling

Operational access is restricted to authenticated users and further limited by assigned application role. Data handling and retention are subject to the policies and legal requirements applicable to the deployment and the organization using it.

Google Calendar integration

LotRoster offers an optional Google Calendar sync feature that an authorized user may connect from their own account settings. LotRoster's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Access. A user must explicitly connect Google Calendar through a Google sign-in and consent screen that they control. LotRoster requests only the minimum Google Calendar scope needed to create, update, and delete calendar events (it does not request access to Gmail, Drive, Contacts, or any other Google product).

Use. Data obtained through this connection (a Google account identifier used to label the connection, and calendar event details such as title, start time, end time, and all-day status) is used solely to push the user's own LotRoster calendar events into their connected Google Calendar. It is never used for advertising, never sold, and never used to train generalized artificial intelligence or machine learning models, whether generalized or product-specific.

Storage and security. The OAuth refresh token issued by Google is encrypted at rest in a dedicated secrets vault, never stored in a plain database column, and never returned to any client application, including the LotRoster web app itself. Only an internal, non-public server process may decrypt it, solely to obtain a short-lived access token immediately before a sync operation.

Sharing and disclosure. Data obtained through this connection is not shared with any third party other than Google itself (as the calendar destination) and is not disclosed for any purpose unrelated to providing the calendar sync feature to the connecting user.

Retention and deletion. A user may disconnect Google Calendar sync at any time from their account settings. Disconnecting immediately and permanently deletes the stored refresh token from the secrets vault, after which LotRoster can no longer access that user's Google Calendar until they reconnect and grant consent again. LotRoster never reads a user's existing Google Calendar events back into LotRoster, and deleting an event in Google Calendar never deletes or modifies the corresponding LotRoster record.

Questions

Authorized users should raise privacy or data-handling questions through their LotRoster administrator or the organization's established privacy or management contact.