---
title: "Dealership Website Privacy Demand Letters | What Triggers Them"
description: "Dealers are receiving demand letters over website tracking. What on a dealer site produces the exposure, and what an inventory and disclosure review covers."
canonical: "https://carbidedigital.io/insights/dealership-website-privacy-demand-letters"
published: "2026-09-02"
updated: "2026-09-02"
category: "DEALER WEBSITES"
author: "Carbide Digital"
type: "article"
---

# Dealership website privacy demand letters: what they are actually about.

Dealers across several states have been receiving demand letters concerning website tracking — session recording, chat transcripts, and third-party scripts that pass visitor data to vendors. This page is not legal advice and nothing on it should be treated as any; take the letter itself to your attorney. What it does describe is which parts of a dealership website produce the exposure, because that part is marketing work and it lands on the marketing person's desk. Two things a store can establish without a lawyer, today: what third-party scripts are actually running on the site, and whether the published privacy policy describes them. Most dealerships fail the second, not because the policy says something false but because it was written when the site launched and was never updated as vendors were added to it.

## Key takeaways

- The exposure comes from marketing tooling — session recording, chat, and third-party tracking scripts — which makes the inventory of what your site loads a marketing task.
- The two things you can establish yourself are what is actually running and whether your privacy policy describes it. Most sites fail the second because nobody updated the policy when a vendor was added.
- Take the letter itself to your attorney. We describe the mechanics; the claim is a legal matter and we do not advise on it.

## What is being complained about

The letters generally concern third parties receiving information about a visitor's activity on the dealership's website without the visitor's knowledge. The specific tooling named tends to be the same short list: session recording or replay products that capture what a visitor did on the page, chat products that route conversations through a vendor, and advertising or analytics scripts that pass identifiers to a third party.

What makes dealers a recurring target is not that dealer sites are unusual. It is that dealer sites carry an unusually large number of these scripts, for the reasons set out in [why dealership websites are so slow](https://carbidedigital.io/insights/why-dealership-websites-are-slow) — the layer accumulates and nobody removes anything.

The store is the party that receives the letter, not the vendor whose script it is. That asymmetry is the whole reason this belongs on a marketing agenda rather than being left with the provider.

## The two things you can establish without an attorney

First: what is actually running. Most stores cannot produce a current list of the third-party scripts on their website, which means they cannot answer the first question in the letter. Producing that list is a morning's work with browser developer tools and your tag manager, and it is useful regardless of whether a letter ever arrives.

Second: whether your privacy policy describes what is running. The common failure is not a policy that says something false. It is a policy written when the site launched, never updated as vendors were added, that simply does not mention the categories of tooling now in use. Every store that has added a chat product, a trade tool or a session recorder since the policy was written is in this position by default.

Those two — an accurate inventory and a policy that matches it — are marketing and website work. What to do about a specific letter, what the claim asserts and how to respond to it are legal matters for your attorney, and this page does not address them.

## Why the marketing side of this is worth doing anyway

The inventory and disclosure exercise pays for itself even setting the letters aside. A store that lists every script firing on its site almost always finds vendors it no longer pays, duplicate products doing the same job, and tooling nobody has looked at in a year. Removing those improves page speed, which improves everything the site is asked to do.

It also gives you a real answer to a question dealers increasingly get from customers and occasionally from manufacturers: what happens to information a visitor enters on our website. Being able to answer that specifically is worth having.

And it forces a decision most stores have never made deliberately: which of these tools are we actually using, and for what. That question is the same one that improves the vendor list generally, and it is the question the [marketing consulting](https://carbidedigital.io/marketing-consulting) process starts with.

## What a review of this actually covers

A practical review has four parts and none of them requires a lawyer to begin. Inventory every third-party script on the site, including ones injected by other scripts and ones the platform adds. Map each to a vendor and a purpose, and mark the ones nobody can account for.

Remove what is not in use. Consolidate what is duplicated. Then compare what remains against your published privacy policy and note every category the policy does not describe, so that whoever maintains the policy is working from a real list rather than from memory.

Finally, decide the standing process: who reviews the script list, how often, and who has authority to add one. Most stores have never had this, which is precisely how the layer accumulated in the first place.

## Direct answers

### What are dealership website privacy demand letters about?

Generally, third parties receiving information about a visitor's website activity without their knowledge — most often via session recording, chat products or advertising and analytics scripts. This is a description of the mechanics, not legal advice; take any letter to your attorney.

### Why are car dealers receiving these letters?

Dealer websites carry an unusually large number of third-party scripts, accumulated over years with nothing ever removed. The store receives the letter, not the vendor whose script it is, which is why the script inventory belongs on a marketing agenda.

### Is this a marketing problem or a legal one?

Both, in separate parts. The exposure comes from marketing tooling, so the inventory of what runs on your site and whether your policy describes it is marketing work. The letter itself and how to respond are legal matters for your attorney.

### What should we do first?

Produce a current list of every third-party script running on your site. Most stores cannot, which means they cannot answer the first question the letter asks. It is a morning's work with developer tools and your tag manager.

### Does our privacy policy cover this?

Check rather than assume. The common failure is a policy written when the site launched and never updated as vendors were added, so it does not mention categories of tooling now in use. Any store that has added chat, a trade tool or session recording since then is likely in that position.

### Should we remove session recording from our dealership website?

If nobody has watched a session in six months it is costing page speed for nothing and carrying exposure for nothing. If it is genuinely used, that is a decision to make deliberately with your attorney's input rather than by default.

### Is our website provider responsible for this?

The store receives the letter. Some scripts are the platform's and some are yours, and establishing which is which is part of the inventory. Whether any of that shifts responsibility is a legal question, not one this page answers.

### Does removing scripts help beyond the privacy question?

Substantially. The same inventory almost always finds vendors you no longer pay and duplicate products doing the same job. Removing them improves page speed, which improves everything the site is asked to do.

### Do chat transcripts create exposure?

Chat products route conversations through a vendor, which is one of the categories these letters commonly name. Whether that creates a legal problem in your state is a question for your attorney; whether you know which vendor holds the transcripts is a question you can answer today.

### How often should we review the script list?

Quarterly is sufficient, provided somebody owns it and has authority over what gets added. The absence of that process is exactly how the layer accumulated, so the process matters more than the frequency.

### Can we just add a cookie banner?

A banner is a disclosure mechanism, not an inventory, and it cannot describe scripts nobody has listed. Whether a banner is required or sufficient in your state is a legal question. The inventory has to exist either way.

### Does this affect our advertising vendors?

It affects which pixels you allow and what you disclose about them, which is a conversation to have with each agency. It is also a reasonable moment to ask each one what data their script collects, since most stores have never asked.

## Related services

- [Dealership Website](https://carbidedigital.io/dealership-website)
- [Car Dealer Marketing](https://carbidedigital.io/car-dealer-marketing)
- [Marketing Consulting](https://carbidedigital.io/marketing-consulting)


---

Source: [https://carbidedigital.io/insights/dealership-website-privacy-demand-letters](https://carbidedigital.io/insights/dealership-website-privacy-demand-letters)  
Publisher: Carbide Digital — team@carbidedigital.io  
Editorial standards: https://carbidedigital.io/editorial-standards  
Research methodology: https://carbidedigital.io/research-methodology
