Privacy and cookies

Privacy information should match what the site actually does

This notice describes the current local rebuild. Features that would collect inquiry or appointment data remain disabled until a verified operator, recipient, and retention process are configured.

Information provided directly

When a contact or appointment form is enabled, the form may request a name, email address, request category, relevant page URL, vehicle context, and the message needed to evaluate the inquiry. The active form must identify required fields before submission.

Visitors should not submit passwords, payment card information, vehicle access codes, government identifiers, or unrelated medical or financial information. A general website inquiry does not require those details.

Technical records

A web server ordinarily processes an IP address, request time, requested URL, browser information, response status, and referrer to deliver pages, investigate errors, resist abuse, and maintain security. Access to these records should be restricted to people who need them for operations.

The site does not need to build a profile from a technical log to deliver an article. Logging and security records should be retained only as long as reasonably required for troubleshooting, abuse prevention, and operational accountability.

Analytics and the legacy collection endpoint

The historical site called a shared `/collect/` endpoint with language, local date and time, time zone, and referrer values. The rebuild preserves compatibility as a production-only integration item, but deliberately suppresses the call in the local environment so development traffic is not counted.

Before production enablement, the receiving system, server-side fields, retention period, access controls, IP handling, cookie behavior, and any third parties must be documented. The public notice must then be updated to describe the verified implementation rather than assumptions.

Cookies and local storage

The current local rebuild does not require an advertising cookie or account cookie to read content. Essential security or preference storage may be added only when a feature needs it and the purpose is documented.

Advertising, remarketing, affiliate tracking, and a consent-management platform are not currently configured. They must not be represented as active or compliant until real account values and the applicable consent flow have been implemented and tested.

Use, sharing, and retention

Information should be used to deliver the requested site function, route an enabled inquiry, correct content, respond to a rights request, secure the service, or comply with a valid legal obligation. It should not be sold or reused for unrelated outreach without a clear basis and notice.

Service providers may process limited data when they host the site, deliver messages, protect forms, or provide authorized analytics. A production inventory must identify those providers. Retention should be tied to the request type, security need, and documented operational policy; test submissions must be removed after verification.

Choices, security, and changes

Once a verified contact route is enabled, visitors may use it to ask about a submitted inquiry or request correction or deletion where applicable. Some server records may need to be retained temporarily for security, dispute, or legal reasons.

No internet service can promise absolute security. The rebuild uses data minimization, server-side validation, limited public PHP execution, and restrictive response headers as baseline safeguards. Material changes to collection or sharing require a corresponding update to this notice and its effective date.