Privacy Policy
1. Scope of this policy
This Privacy Policy describes how CT HOLDINGS, LLC ("we," "us," or "our") collects, uses, discloses, and retains information in connection with Lay-It-Down Wholesale (the "Service") — including the Lay-It-Down Wholesale mobile applications, the Lay-It-Down Wholesale web application, our public website at layitdownapp.com and www.layitdownapp.com to the extent it collects information, and our support and founding-access processes.
This policy applies to information about the individuals who use the Service on behalf of their organizations and to the business records the Service maintains for those organizations.
2. A business-only service
Lay-It-Down Wholesale is a private, business-to-business wholesale workflow platform. It is intended solely for business use by:
- Dealer organizations — dealerships that list wholesale units, and their authorized personnel.
- Wholesale buyer organizations — verified wholesale buyers, and their authorized personnel.
The Service is not a public marketplace and is not an auction. There is no public self-service signup and no public buyer directory. Accounts are provisioned and approved by us for verified organizations, and users interact with the Service in a business capacity on behalf of their organization.
3. Who operates the Service and how to contact us
The Service is operated by CT HOLDINGS, LLC, a Louisiana limited liability company doing business as Lay-It-Down Wholesale.
- Email for privacy questions and requests: support@layitdownapp.com
- Mailing address for legal and privacy notices:
Attn: Legal Notices
201 Rue Beauregard, Suite 202
Lafayette, Louisiana 70508
United States
- Support and account requests: see the Support & Account Closure Policy at https://www.layitdownapp.com/account-closure.html
4. Information you provide to us
4.1 Account and organization information
Because there is no public self-service signup, initial account information is typically collected directly from you, from your organization, or during the founding-access onboarding process rather than through an in-app registration form. This information includes:
- Name, business email address, and role or title.
- Organization affiliation — which dealer organization or buyer organization your account belongs to.
- Business contact information you or your organization provide during onboarding or verification.
- Sign-in credentials, which are managed by our authentication provider. We do not store plaintext passwords.
We also maintain organization records: dealer and buyer business names, business locations, business contact information, and verification-related information gathered during onboarding.
4.2 Listing and unit information
Dealers enter wholesale unit information into listings, such as year, make, model, unit type, condition notes, dealer-entered target amounts, and dealer-authorized identifiers (for example, VIN or stock number where the dealer chooses to include them), along with listing status and lifecycle information (for example, open, accepted, or no longer active).
4.3 Unit photos and content
Dealer users upload photos of wholesale units. Photos are stored in access-controlled, non-public storage and are shown only to users authorized for that listing. The Service currently uploads the selected photo file without removing embedded metadata and does not provide a metadata-removal tool. A photo may therefore contain device-created metadata, such as capture date, camera or device details, and location information if the device included it. Users should review photos and remove metadata they do not want to share before uploading. We do not use embedded location metadata as a Service feature.
4.4 Offers and offer history
Buyer users submit offers on listings they were selected for. We collect offer amounts, offer status, and related timestamps. Offers are private: they are visible to the listing dealer's authorized users and to us for support, security, integrity, and record-keeping purposes. Buyers do not see other buyers' offers.
4.5 Listing-specific messages
Dealers and selected buyers exchange messages inside a listing's message thread. Message content is tied to the specific listing and is visible to the thread participants and to us for support, security, integrity, and record-keeping purposes.
4.6 Activity and transaction-status records
The Service keeps records of workflow activity: when a listing is created or closed, which buyers were selected, buyer responses (for example, offer or pass), offer outcomes, deal-outcome status (for example, completed or not completed), and related timestamps. It also records structured feedback organizations submit about deal outcomes — for example, payment-timing feedback about completed deals — which supports review by the organizations involved. These records form the wholesale activity record the Service provides to the organizations involved and support owner and operator visibility into an organization's own activity.
4.7 Support and founding-access inquiries
When you contact us — for support, onboarding, founding-access requests, account changes, issue reports, content reports, or account-closure requests — we collect the contact information you provide and the content of the communication, and we keep records of how the request was handled.
A founding-access request may also include business type and location, expected listing or buying activity, inventory categories, volume ranges, condition and geographic preferences, transportation approach, referral information, preferred follow-up method, and whether you volunteered for a pricing and workflow conversation. These answers help us qualify and route the request, prepare provisional inventory-fit recommendations for human review, and improve founding-launch planning. They do not automatically verify a business, create an account, approve access, or activate a buyer category.
5. Information collected automatically
When you use the Service, we and our infrastructure providers collect a limited amount of technical and operational information in the ordinary course of operating it:
- Device and technical information, which may include device type, operating system and version, app version, browser type (for the web app), IP address, and language or locale.
- Authentication, session, and security information, such as sign-in events, session tokens, and authentication logs.
- First-party operational events, such as sign-in success or failure and listing, selection, offer, message, and status actions, together with related account, organization, record, and timestamp information.
- Operational and diagnostic logs generated by our hosting, database, authentication, and storage providers in the ordinary course of running the Service.
The Service does not use third-party advertising SDKs, third-party analytics or tracking SDKs, or advertising identifiers. The app does not request device-location permission or use device location as a Service feature. As explained in Section 4.3, however, a photo selected by a user may contain location information embedded by the user's device.
6. Information from organizations and administrators
Because access is provisioned at the organization level, we may receive information about you from your organization and its administrators — for example, when your organization requests an account for you, confirms your role, updates your status, or asks us to deactivate your access. Organizations may also provide business contact information about prospective participants — for example, when a dealer asks us to add a wholesale buyer business to its network — which we use for verification, onboarding, and follow-up. We may also generate administrative records about accounts and organizations as part of provisioning, verification, and support.
7. Information you must not submit
The Service is for wholesale unit information only. Users must not upload or enter retail customer personal information or similar sensitive material, whether in photos, listing fields, notes, offers, or messages. Prohibited examples include:
- Customer names and customer contact information.
- Driver's licenses (images or numbers).
- Title documents.
- Finance documents.
- Credit applications.
- Insurance documents.
- Customer paperwork of any kind.
- Banking or payment credentials.
- Any other readable customer personal information, including information visible incidentally in a photo.
This content is prohibited by our Acceptable Use / Photo & Content Policy. If we identify such content or receive a report of it, we may remove or disable it and may take enforcement action. Where practical, we notify the uploading organization so it can correct the practice that produced the upload.
8. How we use information
We use the information described above to:
- Provision, verify, and administer accounts and organizations.
- Operate the private listing workflow: listings, photos, buyer selection, offers, messages, and status tracking.
- Maintain wholesale activity records and provide organizations visibility into their own activity.
- Provide support, onboarding, and founding-access assistance, and respond to inquiries and requests.
- Maintain the security, integrity, and reliability of the Service, including authenticating users, enforcing access controls, preventing fraud and abuse, and investigating suspected violations.
- Enforce our Terms of Service and other policies.
- Comply with legal obligations and respond to lawful requests.
- Communicate with users about the Service, as described in Section 12.
9. How information is shared
9.1 Within the Service
The Service is private by design:
- Listing data and unit photos are visible only to the listing dealer's authorized users, the buyers the dealer selects for that listing, and us.
- Offers are visible to the listing dealer's authorized users and to us. Buyers cannot see other buyers' offers.
- Messages are visible to the participants of that listing's thread and to us.
- Activity records are visible to the organizations involved for their own activity, and to us.
- Dealer organizations can see business-level information about the buyer organizations available to them for listing selection — for example, business name, specialties, and verification status. Individual users are not publicly listed, and buyer organizations are not exposed outside the authenticated, access-controlled Service.
- There is no public buyer directory and no public visibility of listings, offers, or messages.
9.2 Service providers
We use third-party service providers to run the Service, including providers of web hosting and content delivery, database, authentication, file storage, build and release tooling, app distribution, and business email. We authorize these providers to process information as reasonably necessary to provide, secure, support, and administer their services to us, subject to applicable contracts, their governing terms, and law. We do not authorize them to use Service information for their own advertising.
9.3 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of our assets, information we hold may be disclosed to the parties involved in the transaction, under confidentiality protections appropriate to the transaction, and may be transferred as part of it. If a transfer results in a material change to this policy, we will provide notice as described in Section 20.
9.4 Legal, security, and enforcement disclosures
We may disclose information where we believe in good faith that disclosure is necessary to: comply with applicable law, regulation, legal process, or a lawful governmental request; enforce our Terms of Service and other policies, including investigating potential violations; detect, prevent, or address fraud, security, or technical issues; or protect the rights, property, or safety of our users, the public, or CT HOLDINGS, LLC.
9.5 With your organization
Your organization's authorized personnel can see your activity within the Service that belongs to the organization's records — for example, listings, buyer selections, offers, messages, and outcomes tied to your organization's workflow.
10. No sale of personal information; no advertising tracking
- We do not sell personal information, and we have not sold personal information.
- We do not share personal information for cross-context behavioral advertising.
- The Service does not include third-party advertising and does not use third-party advertising tracking technologies.
- First-party security, authentication, and workflow-event records maintained to operate and secure the Service are not advertising tracking.
11. Data security
We use commercially reasonable administrative, technical, and organizational safeguards designed to protect information, including:
- Access-controlled, non-public storage for unit photos.
- Role- and organization-based access rules enforced at the application and database layers.
- Authentication through an established authentication provider, with encrypted connections to the Service.
- Operator-controlled account provisioning, with no public self-service signup.
No system is perfectly secure, and we cannot promise that security incidents will never occur. If a security incident affects personal information, we will investigate and will notify affected users and regulators as required by applicable law, including applicable breach-notification statutes.
12. Communications and marketing choices
- We send business and service communications as needed to operate the Service — for example, provisioning and account messages, workflow and support responses, security notices, and notices about changes to the Service or our policies.
- If we send promotional communications, they will include a clear, functional way to opt out, and we will honor opt-out requests as required by applicable law. Opting out of promotional messages does not stop transactional, account, or security messages that are necessary to operate the Service.
- We do not send SMS marketing and will not do so unless you separately consent to it.
13. Data retention
We retain information only for as long as reasonably necessary to provide, secure, maintain, and improve the Service; administer accounts and business relationships; maintain appropriate listing, offer, communication, and deal records; resolve disputes; enforce agreements; prevent fraud and abuse; and satisfy legal, tax, accounting, regulatory, and legal-hold obligations. Retention varies according to the nature of the information and the reason it is maintained. When information is no longer reasonably needed, we delete, de-identify, or aggregate it, subject to backup cycles, legal holds, security requirements, and lawful retention obligations. After account closure, we remove or de-identify direct personal identifiers that are no longer reasonably needed where reasonably practicable, while retaining organization-level workflow records for the purposes described above.
Data removed from active systems may persist in routine backups until those backups are overwritten in the ordinary course of our infrastructure providers' backup cycles.
14. Account closure and deletion requests
- Access and correction. Users and organizations may contact us to review or correct their account or organization information.
- Account closure. A user, or an authorized representative of the user's organization, may request account closure at any time by emailing support@layitdownapp.com. Closure disables access to the Service.
- Deletion requests. You may request deletion of your personal information by emailing support@layitdownapp.com. We honor deletion requests subject to the retention principles in Section 13 and applicable law. Closing access and deleting every record are different steps: a closed account's historical workflow activity — listings, offers, and messages involving other organizations — is part of those organizations' business records and the Service's activity records, and may be retained under Section 13 even after the account itself is closed.
- Verification. Before acting on closure or deletion requests, we verify that the requester is the account holder or an authorized representative of the organization, to protect against fraudulent requests.
- Process details. The full process, including what to include in a request and what to expect, is described in the Support & Account Closure Policy at https://www.layitdownapp.com/account-closure.html, which includes request instructions.
15. Organization-level records and authorization
Some records belong to an organization rather than to an individual user — for example, the organization's listings, offers, message threads, and activity records. Requests that affect an entire organization (such as deactivating the organization or closing the business relationship) must come from an authorized representative of that organization, and organization records are handled according to our agreements with that organization and the retention principles in Section 13.
16. Legally required retention
Where law requires us to keep certain records — or where records are reasonably necessary for accounting, tax, fraud-prevention, security, dispute, or enforcement purposes, or are subject to a legal hold — we retain them for the required period even if deletion is requested. When we deny a deletion request in part for these reasons, we will tell the requester which categories were retained and why, unless the law prevents us from doing so.
17. U.S. state privacy rights
Depending on where you live, state law may give you rights over personal information — such as the right to know what personal information a business holds about you, to access a copy of it, to correct it, to delete it, and to opt out of certain processing such as sales, sharing for cross-context behavioral advertising, or targeted advertising. As described in Section 10, we do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for third-party targeted advertising.
You may submit a rights request by emailing support@layitdownapp.com. We will verify the request, respond within the time required by applicable law, and will not discriminate against you for exercising your rights. If we decline a request because a particular state law does not apply to us or to the information at issue, we will tell you and will still address the request under this policy where we reasonably can. If applicable law gives you a right to appeal our decision, you may appeal by replying to our response, and we will explain the outcome of the appeal.
18. International users
The Service is operated from the United States and is intended for use by businesses located in the United States. We do not intentionally offer the Service outside the United States. If you access the Service from outside the United States, your information will be processed and stored in the United States, and by using the Service you understand that United States law may differ from the laws of your location.
19. Children and minors
The Service is a business tool for verified dealer and wholesale buyer organizations. It is not directed to children or minors, users must be at least 18 years old, and we do not knowingly collect personal information from anyone under 18. If we learn that information about a person under 18 has been collected through the Service, we will take reasonable steps to delete it, subject to lawful retention needs.
20. Changes to this policy
We may update this policy from time to time. If we make material changes, we will provide notice through the Service or by email to the account contact on file before the changes take effect, and we will update the effective date at the top of this policy. Your continued use of the Service after the updated policy takes effect means the updated policy applies.
21. Contact us
Questions, requests, or complaints about privacy may be directed to:
CT HOLDINGS, LLCAttn: Legal Notices
201 Rue Beauregard, Suite 202
Lafayette, Louisiana 70508
United States
Email: support@layitdownapp.com
Related policies — the Terms of Service, the Acceptable Use / Photo & Content Policy, and the Support & Account Closure Policy — are available at https://www.layitdownapp.com.