Privacy Policy

American Digital Marketing — Helm by American Digital Marine

Effective August 27, 2026

Last updated: August 27, 2026

American Digital Marketing (“ADM,” “we,” “us”) respects your privacy. This Privacy Policy describes how we collect, use, and share information when you use Helm by American Digital Marine (the “Service”), including staff applications and the customer portal.

1. Information We Collect

We collect information you provide directly, information generated through your use of the Service, information from your Organization’s administrators, and information needed to send documents or messages you or your Organization initiate.

  • Account information: name, email address, password (stored by our authentication provider), and profile details you or your Organization provide.
  • Organization and membership data: dealership, brokerage, or service-yard affiliation, role assignments, and access permissions.
  • Customer, vessel, and operations data: contact names, emails, phone numbers, addresses, boat names and identifiers (including HIN where stored), service requests, estimates, work orders, invoices, parts activity, F&I deal-jacket fields, and related notes.
  • Identity and deal documents: files your Organization uploads (for example driver’s licenses or received PDFs) and signed document archives returned from DocuSign.
  • Communications data: email contents we send or log as transactional mail; SMS destination numbers and message metadata for one-time passcodes and operational notices; DocuSign envelope identifiers, signer name and email, and signature status.
  • Inventory and listing data: vessel specifications, pricing, media, syndication fields, import/export payloads, and related operational records.
  • Security and authentication data: multi-factor or one-time codes, trusted-device tokens, recovery-code hashes, and session metadata.
  • Usage and technical data: log files, IP address, browser type, device identifiers, pages viewed, and error diagnostics.

2. How We Use Information

We use information to:

  • provide, operate, and maintain the Service (inventory, sales, F&I, service, parts, invoicing, and the customer portal);
  • authenticate users, verify phone numbers or accounts (including one-time SMS or email codes), and enforce access controls;
  • send, track, and archive documents for electronic signature via DocuSign when an Organization initiates a send;
  • send transactional email and SMS (verification codes and operational notices such as an estimate or document being ready);
  • import, export, and syndicate listing data at your or your Organization’s direction;
  • encrypt, store, and retrieve personal information as described in Section 5;
  • secure accounts, detect abuse, and troubleshoot issues;
  • comply with law and respond to lawful requests; and
  • improve the Service and communicate about updates, security, or support.

3. How We Share Information

We do not sell your personal information. We share information only as described below.

  • Service providers that host infrastructure, process authentication, send email, send SMS, provide electronic signature, or otherwise help us operate the Service. These currently include (as applicable) Supabase, our cloud host (including Vercel), our email vendor, Twilio (SMS), and DocuSign (e-sign and related webhooks). Providers may access information only to perform services for us or for your Organization and subject to their terms and contractual obligations.
  • Third-party systems you or your Organization connect to or export data to (for example BoatWizard, Boats Group, accounting or payment platforms), when that transfer is initiated.
  • Within your Organization, according to role-based permissions configured by administrators.
  • When required by law, legal process, or to protect the rights, safety, and security of ADM, users, or others.
  • In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.

4. SMS

If you provide a mobile number and consent (or your Organization does so in connection with a job or account), we may send transactional SMS through Twilio: typically one-time verification codes and similar operational messages. Message frequency varies. Message and data rates may apply. Reply STOP to opt out of that SMS program; reply HELP for help. Consent to receive SMS is not a condition of purchase. We do not use these numbers for third-party marketing and we do not sell mobile numbers.

Carriers and Twilio receive the destination number and message content required to deliver the SMS.

5. Encryption of personal information (PII)

Personal information we treat as PII is encrypted before it is stored. We use AES-256-GCM (application-level encryption) with keys derived from a server-held secret. Ciphertext—not plaintext names, emails, phone numbers, addresses, or equivalent identifiers—is what we write to our database for those fields. F&I uploads and signed DocuSign PDF archives we retain are encrypted with the same family of keys before they are written to private object storage.

Encryption keys are not stored in the database alongside the ciphertext. Data in transit between your browser and the Service is protected with TLS. Passwords are stored by our authentication provider using that provider’s hashing, not as recoverable PII ciphertext.

To allow authorized search (for example looking up an account by email or phone) we may store one-way keyed indexes (HMACs) that are not reversible to the original value without the key. Some operational, listing, catalog, and diagnostic records are not classified as PII and are not encrypted with this application-level cipher. Third parties such as DocuSign and Twilio receive plaintext as needed to deliver their service (a signer must see the document; a carrier must see the destination number).

No method of transmission or storage is completely secure. You are responsible for maintaining the confidentiality of your credentials.

6. Data Retention

We retain information for as long as an account is active, as needed to provide the Service, and as required to meet legal, accounting, or operational obligations. Listing, deal, service, signature, and audit records may be retained according to your Organization’s business needs and applicable law. You may request deletion of certain account data subject to limitations described in Section 8.

7. Security

We use administrative, technical, and organizational measures designed to protect information, including encrypted transport, application-level encryption of designated PII at rest, access controls, and authentication safeguards. Role-based permissions inside an Organization determine which staff can view decrypted personal information.

8. Your Choices and Rights

Depending on your location, you may have rights to access, correct, delete, or restrict certain processing of your personal information, or to object to processing and receive a portable copy of information you provided.

To exercise these rights, contact us at support@americandigitalmarketing.com. We may need to verify your identity and coordinate with your Organization administrator where account access is managed at the org level.

Residents of certain U.S. states may have additional privacy rights under applicable state law. We will honor valid requests in accordance with those laws. SMS opt-out is described in Section 4.

9. Cookies and Similar Technologies

The Service uses cookies and similar technologies to maintain sessions, remember security preferences (such as trusted devices), and support core functionality. You can control cookies through your browser settings, but disabling them may limit your ability to use the Service.

10. Children

The Service is intended for business users and adult customers of those businesses. It is not directed to individuals under 18. We do not knowingly collect personal information from children.

11. International Users

If you access the Service from outside the United States, you understand that information may be processed and stored in the United States and other countries where we or our service providers operate, which may have different data-protection laws than your jurisdiction.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy with an updated effective date. Material changes may require additional notice where required by law.

13. Contact

Questions about this Privacy Policy or our privacy practices: support@americandigitalmarketing.com.