Privacy Policy

    Last updated: August 23, 2026

    PrimeLot Technologies LLC is committed to protecting privacy, security, and the responsible handling of personal data. This Privacy Policy explains how we collect, use, retain, protect, and disclose personal data when people visit our websites, use our web or mobile applications, or use our software-as-a-service products.

    This policy applies to PrimeLot Technologies LLC and to the products, applications, and related services operated by the company, including:

    1. Who is responsible for your data

    For personal data that PrimeLot Technologies LLC processes for its own purposes, PrimeLot Technologies LLC is the data controller. Our legal address is 407 Lincoln Rd Ste 708, Miami Beach, FL 33139, United States.

    For privacy questions, requests, or concerns, contact info@primelottechnologies.com. Where a service-specific notice identifies another controller or representative, that notice will apply to the relevant processing.

    2. Our role for business customer data

    PrimeLot may act as a controller or as a processor. We are generally a controller for account registration, administration, subscriptions, billing, support, security, communications, and legal compliance.

    When a business customer uses V-CarShop, NominaRed, SITEM ERP, RadiaSuite, or another PrimeLot service to enter or manage information about its employees, customers, suppliers, candidates, vehicles, contacts, or other people, that customer normally decides why the data is processed. In that situation, the customer is generally the controller and PrimeLot processes the data on the customer's documented instructions.

    Business customers are responsible for having a lawful basis to provide that information and for giving affected people any notices required by law. PrimeLot will provide reasonable assistance under the applicable agreement.

    3. Personal data we may process

    The data we process depends on the product, account, and features used. It may include the following categories:

    • Account and identity data, such as name, email address, telephone number, company, role, language, username, internal identifiers, and authentication information.
    • Professional and business data supplied to configure or use a service.
    • Subscription and billing data, such as billing address, tax information, plan, amounts, currency, customer or transaction identifiers, and subscription status.
    • Information entered into a PrimeLot application, which may include records about employees, customers, suppliers, vehicles, contacts, operations, documents, payroll, invoices, or other business activity.
    • Technical and usage data, such as IP address, access time, browser, device and operating system, application version, session information, access logs, error reports, diagnostic information, and security events.
    • Files, photographs, and documents selected or uploaded by a user for a requested feature.
    • Notification information, such as a device or delivery token needed to send a notification the user or customer has enabled.
    • Information included in support or commercial communications, including contact details, message contents, attachments, and relevant technical information.

    4. Mobile permissions and device access

    Our mobile applications request device permissions only when a requested feature reasonably needs them. Depending on the application, this may include camera, photos, files, notifications, or other operating-system resources.

    We request permission before accessing protected device information when the operating system or applicable law requires it. Refusing a permission should not prevent use of features that do not depend on that permission.

    We access only the content selected by the user or needed to provide the requested feature. We do not use a granted permission for a materially different purpose from the one communicated to the user.

    5. Why we use data and our legal bases

    We use personal data only for appropriate and disclosed purposes. Depending on the context, our legal basis may be performance of a contract or pre-contractual steps, compliance with a legal obligation, our legitimate interests, or the user's consent.

    • To create and administer accounts, authenticate access, configure services, provide features, and respond to support requests.
    • To manage subscriptions, payments, invoices, accounting, tax, and other administrative obligations. Payment card data is handled by payment providers such as Stripe; PrimeLot does not intentionally store full card numbers on its systems.
    • To protect users, accounts, services, and systems; prevent fraud, abuse, unauthorized access, attacks, and activity that violates our terms; and investigate incidents.
    • To send operational communications about accounts, security, service changes, incidents, billing, or requested features.
    • To send commercial communications only where permitted by law. Where consent is the basis, it can be withdrawn at any time.
    • To understand product usage, diagnose errors, improve features, and optimize the experience. Non-essential analytics or device identifiers are used only with consent where applicable law requires it.

    6. Artificial intelligence and automated processing

    Some PrimeLot applications may offer AI-assisted features that a user actively requests. We send only information reasonably needed to provide that feature to the technology provider involved.

    PrimeLot does not use personal data processed for a business customer to train general-purpose third-party AI models unless the customer has authorized that use and there is an appropriate legal basis and notice. AI providers must be subject to suitable privacy, confidentiality, security, and purpose-limitation obligations.

    AI-generated results are support tools and should be reviewed by a person where the result matters. PrimeLot does not make decisions producing legal or similarly significant effects about a person solely through automated processing unless the law permits it and the required safeguards are provided.

    7. Service providers and disclosures

    PrimeLot does not sell personal data. We may disclose information to service providers that help us operate the services, only to the extent reasonably necessary for their assigned function and subject to appropriate confidentiality and data-protection obligations.

    Provider categories may include hosting and infrastructure, databases and storage, email and communications, payment processing, customer support, security, error monitoring, analytics, notifications, and AI technology. Stripe currently processes certain payment and subscription transactions.

    Apple, Google, and other platform operators may collect information independently when people use their stores, operating systems, or platform services. Their own privacy policies also apply to that processing.

    8. International transfers

    PrimeLot is established in the United States, and some providers may process data outside the European Economic Area. When a transfer is subject to applicable data-transfer rules, we use a legally recognized mechanism, which may include an adequacy decision, a recognized adequacy framework, Standard Contractual Clauses, or another permitted mechanism.

    Where appropriate, we apply supplementary measures designed to protect transferred data. Business customers may request additional information about transfers made on their behalf under the applicable agreement.

    People in the EEA may contact PrimeLot at info@primelottechnologies.com about processing and rights. If a service requires a separate representative or contact under applicable law, the relevant service notice will provide those details.

    9. Retention

    We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing the service, handling disputes, preventing fraud, protecting security, and meeting legal or accounting obligations.

    Account data is generally retained while the account is active and for any additional period needed for these purposes. Technical and security logs are kept for a reasonable period related to diagnosis, abuse prevention, and incident response. Backups may retain temporary copies until they are rotated under the applicable backup cycle.

    When the applicable retention period ends, we delete the data or anonymize it so that it can no longer reasonably identify a person.

    10. Account and data deletion

    People may request deletion of their account and associated personal data. If an application allows account creation, the deletion request can be started from that application's account or settings area, using the option provided there.

    A complete deletion request can also be sent to info@primelottechnologies.com. We may request information reasonably needed to verify the requester and prevent unauthorized deletion.

    We delete or anonymize data that we are not legally required to keep. We may retain limited information when necessary for legal obligations, security, fraud prevention, dispute resolution, or proof of completed transactions. Data controlled by a business customer should normally be requested from that customer; PrimeLot will assist the customer as required by the applicable agreement.

    11. Privacy rights

    Depending on where a person lives and the law that applies, they may have rights to access, correct, delete, restrict, object to, or receive a portable copy of their personal data, withdraw consent, and request review of certain solely automated decisions.

    Requests can be sent to info@primelottechnologies.com. Please provide enough information to locate the relevant account or records. We may ask for additional information when reasonably necessary to verify identity. Withdrawing consent does not affect processing that was lawful before withdrawal.

    People in the EEA may also complain to their competent data-protection authority. In Spain, this includes the Agencia Española de Protección de Datos (AEPD).

    12. Security and incidents

    We use technical and organizational measures designed to protect the confidentiality, integrity, availability, and resilience of our systems and personal data. These measures may include authentication, access controls, security logging, encrypted communications using current transport-security protocols, and controls intended to prevent unauthorized access.

    Security measures are reviewed and adapted to the nature of the data, identified risks, and technological development. No internet-connected system can guarantee zero risk.

    If a personal-data incident occurs, PrimeLot assesses it and provides notices to customers, authorities, or affected people when required by applicable law or contract. When we act as a processor, we notify the relevant customer controller according to the applicable agreement.

    13. Cookies, SDKs, and similar technologies

    Our websites and applications may use cookies, local storage, technical tokens, SDKs, or similar technologies. Strictly necessary technologies may be used for authentication, security, session management, and requested functionality.

    Non-essential analytics, personalization, advertising, or similar technologies are used only with consent where applicable law requires it. Information about technologies used by a particular product may also appear in that product's privacy notice or consent controls.

    14. App Store and Google Play disclosures

    For applications distributed through the Apple App Store, PrimeLot keeps App Store Connect privacy declarations consistent with the data practices and SDKs of the distributed version. Required iOS permissions, consent, and App Tracking Transparency controls are used when applicable.

    For applications distributed through Google Play, PrimeLot keeps the Data Safety information consistent with the data collected, shared, or processed by the application and its SDKs. Where an application creates accounts, users can start deletion from the application settings and contact PrimeLot through the email process described above.

    15. Children

    PrimeLot's business services are not directed to children. We do not knowingly collect personal data from children where the service is not intended for them. If we learn that such data was collected without the authorization required by applicable law, we will take reasonable steps to delete it.

    16. Changes to this policy

    We may update this policy to reflect legal, technical, organizational, or service changes. The date at the beginning identifies the latest update. When a change is material and applicable law requires additional notice, we will provide notice through an appropriate channel.

    Cookies and technology preferences

    You can choose which technologies this website may use. Your choice is stored locally so we can remember it and can be changed at any time using the button below or the Privacy preferences link in the footer.

    Strictly necessary
    The local storage entry that remembers your privacy choice, plus any security, session, or requested functionality required by a product. These technologies do not require optional consent.
    Analytics and other non-essential
    Analytics and optional third-party enhancements, including web fonts on this public site. They remain disabled until you opt in.

    17. Contact

    For privacy questions, data-rights requests, or account and information deletion requests, contact:

    Company
    PrimeLot Technologies LLC
    Legal address
    407 Lincoln Rd Ste 708, Miami Beach, FL 33139
    Country
    United States

    For data that PrimeLot processes on behalf of a business customer, the person concerned should normally contact that customer as the controller.

    Request Account Deletion