01Security & Data Handling

Security & Data Handling

ADRS™ — Auto Dealer Retirement Solutions — is operated by Watchdog IP Holdings LLC in collaboration with 401kWatchdog™ LLC. This page describes, in plain language, what information the platform collects, how it is protected, and how it is shared. It is a summary, not a contract, and runs alongside the Terms & IP notice.

What we collect

The email address you use for verification, one-time passwords (OTP) and the unguessable access token issued to your browser, the dealership queries and form submissions you enter, and limited payment metadata returned by our payment processor. We do not collect government identifiers (SSN/ITIN) or direct payroll data from plan participants; where an Employer Identification Number appears in source filings it is treated as a sensitive employer identifier and gated behind membership.

Payments & card data

We never see or store your card number, CVC, or full card details. All payment-card data is handled by Stripe, a PCI-DSS-compliant processor, on Stripe’s own hosted checkout. We retain only the transaction metadata (for example, customer id and session id) needed to grant and manage your access.

Access credentials

Access is keyed by an unguessable token stored in your browser’s local storage — not a password you retype. One-time verification codes are short-lived (10 minutes). Direct database operations on leads, submissions, and moderated records are restricted to authenticated administrators by role-level controls.

How we protect data

API keys and signing secrets are stored server-side and never exposed to the browser. Entity access is gated by role-based controls, so a visitor can read only the public directory and the data their access grant unlocks. We do not resell, share, or rent personal information to third parties for their own marketing.

Third parties we rely on

Stripe for payments, Google Sheets and Gmail for verified-claim routing, and our hosting platform for application hosting and database storage. Each processor handles your data under its own terms; we share only what is necessary to deliver the feature you requested.

Retention

Lead and submission records are retained for business follow-up and are readable only by administrators. Time- limited access grants expire on their stated term (24 hours for a test pass, 30 days for a single-dealership unlock, the subscription period for paid tiers, and six months for the confirmed-dealer benchmarking grant).

No warranty

The platform is provided “as is.” While we work to keep data accurate and access secure, no system is perfectly secure. Metrics depend on the timeliness and completeness of public filings; where data is insufficient the platform reports a ranking as available rather than producing a synthetic value.

Responsible disclosure

If you believe you have found a security vulnerability, please contact us through the contact page with the details. We ask that you give us a reasonable window to respond before any public disclosure, and we will not pursue good-faith, responsible reports.