#What is being complained about
The letters generally concern third parties receiving information about a visitor's activity on the dealership's website without the visitor's knowledge. The specific tooling named tends to be the same short list: session recording or replay products that capture what a visitor did on the page, chat products that route conversations through a vendor, and advertising or analytics scripts that pass identifiers to a third party.
What makes dealers a recurring target is not that dealer sites are unusual. It is that dealer sites carry an unusually large number of these scripts, for the reasons set out in why dealership websites are so slow — the layer accumulates and nobody removes anything.
The store is the party that receives the letter, not the vendor whose script it is. That asymmetry is the whole reason this belongs on a marketing agenda rather than being left with the provider.
#The two things you can establish without an attorney
First: what is actually running. Most stores cannot produce a current list of the third-party scripts on their website, which means they cannot answer the first question in the letter. Producing that list is a morning's work with browser developer tools and your tag manager, and it is useful regardless of whether a letter ever arrives.
Second: whether your privacy policy describes what is running. The common failure is not a policy that says something false. It is a policy written when the site launched, never updated as vendors were added, that simply does not mention the categories of tooling now in use. Every store that has added a chat product, a trade tool or a session recorder since the policy was written is in this position by default.
Those two — an accurate inventory and a policy that matches it — are marketing and website work. What to do about a specific letter, what the claim asserts and how to respond to it are legal matters for your attorney, and this page does not address them.
#Why the marketing side of this is worth doing anyway
The inventory and disclosure exercise pays for itself even setting the letters aside. A store that lists every script firing on its site almost always finds vendors it no longer pays, duplicate products doing the same job, and tooling nobody has looked at in a year. Removing those improves page speed, which improves everything the site is asked to do.
It also gives you a real answer to a question dealers increasingly get from customers and occasionally from manufacturers: what happens to information a visitor enters on our website. Being able to answer that specifically is worth having.
And it forces a decision most stores have never made deliberately: which of these tools are we actually using, and for what. That question is the same one that improves the vendor list generally, and it is the question the marketing consulting process starts with.
#What a review of this actually covers
A practical review has four parts and none of them requires a lawyer to begin. Inventory every third-party script on the site, including ones injected by other scripts and ones the platform adds. Map each to a vendor and a purpose, and mark the ones nobody can account for.
Remove what is not in use. Consolidate what is duplicated. Then compare what remains against your published privacy policy and note every category the policy does not describe, so that whoever maintains the policy is working from a real list rather than from memory.
Finally, decide the standing process: who reviews the script list, how often, and who has authority to add one. Most stores have never had this, which is precisely how the layer accumulated in the first place.