Privacy Policy
Last updated: July 27, 2026
Regio Systems, LLC, d/b/a Regio Title (“Regio Systems,” “we,” “us,” or “our”) is a New Jersey limited liability company that operates a business-to-business titling and registration service for licensed motor-vehicle dealers in the United States. Regio Systems is regulated as a “financial institution” under the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, 16 CFR Part 314, in its capacity as a third-party service provider to dealerships that arrange consumer financing. Our principal place of business is in New Jersey, and we do not currently process personal information outside of the United States.
Scope of this Privacy Policy
This Privacy Policy describes how we collect, use, share, retain, and protect personal information in connection with our dealer-facing titling and registration services, including our dealer and administrative dashboards, this website, and any related service or communication that links to this Privacy Policy.
This Privacy Policy does not apply to the privacy practices of dealers, financial institutions, lenders, insurers, state departments of motor vehicles, or any other third party with whom a consumer separately transacts; to data processing performed by a dealer’s own systems before information is transmitted to us; or to data processing performed by a state department of motor vehicles after we submit a title or registration application on the dealer’s behalf.
Whose information we receive
Our services are delivered to dealers, not directly to end consumers. The personal information we receive concerns three categories of people: consumers — the end purchasers, lessees, or transferees of motor vehicles for whom a dealer engages us to obtain title and registration; dealer signers and dashboard users — individuals associated with our dealer customers who sign service agreements, authorize ACH debits, or access our dashboards; and website visitors — individuals who visit regiotitle.com for general information about our service.
Information we collect
About consumers, received from dealers. When a dealer submits a deal to us for titling and registration, the dealer transmits information including: name, address, and date of birth; driver’s license number; Social Security number where a destination state requires it for a title application; vehicle, purchase, and financing details; lienholder and insurance information; and scanned copies of identification and deal documents, including any power of attorney authorizing the dealer or Regio Systems to act on the consumer’s behalf. We receive this information from the dealer, not directly from the consumer; the dealer is responsible for providing its own GLBA privacy notice and any state-required disclosures to the consumer.
About dealer signers and dashboard users. When onboarding a dealership, we collect the dealership’s business identity (legal name, trade name, states of licensure, address, federal EIN); the authorized signer’s name, title, business email, and business phone; identifying information for additional dashboard users the dealership creates; authentication data for dashboard accounts; and the dealership’s business bank account, connected and verified through a third-party bank-account verification service at onboarding. We retain only a tokenized payment-method reference plus the bank name and last four digits — not the full account or routing number.
From website visitors. Visitors to regiotitle.com are not required to provide personal information to view the site. The site uses cookies necessary for operation and security, and a third-party analytics and lead-management service that sets its own cookies to track page views, returning visits, and form interactions. This service does not receive consumer nonpublic personal information; it processes only website visitor behavior and any contact information voluntarily submitted through the site’s forms. The site does not deploy third-party advertising trackers or behavioral advertising pixels. Server logs capture standard request metadata (IP address, requested URL, user agent, timestamp) for operational and security purposes.
What we don’t collect. We do not collect biometric identifiers such as fingerprints or facial-geometry data. We do not track consumers across third-party sites or collect precise geolocation. Our services are not directed to children — consumers in transactions we handle are motor-vehicle purchasers or lessees, who must be at least the age of contractual capacity in their state.
How we use information
We use the information we receive only for the purposes for which the dealer engages us: preparing, completing, and submitting title and registration applications; computing applicable taxes and fees; performing automated and human-review quality checks on uploaded documents; communicating with the dealer about a deal’s status; communicating with the destination state’s titling authority as required to complete a transaction; maintaining audit records of access to sensitive information; billing the dealership and remitting state fees and taxes; detecting and responding to security incidents or suspected fraud; and complying with our own legal and regulatory obligations. We do not use consumer information for marketing to consumers, for behavioral advertising, or for sale or rental to any third party.
How we share information
We share information only as needed to provide our services and as required by law:
- With state titling authorities — departments of motor vehicles, county clerks, and equivalent authorities, to submit and complete a transaction.
- With the dealer — the dealer that submitted a deal can view the information, documents, quote, and status of that deal through the dealer dashboard.
- With sub-processors — service providers that support our operations under contractual confidentiality and data-protection obligations, as identified in our Sub-Processor Schedule.
- With financial institutions, lienholders, and insurers — as necessary to verify lien status, request lien releases, or complete a title transfer, sharing only what’s necessary for that specific communication.
- In legal or regulatory contexts — to comply with legal process, cooperate with law enforcement, respond to a regulatory inquiry, or protect the rights, property, or safety of Regio Systems, our dealers, our dealers’ customers, or the public.
We do not sell personal information, do not share it with third parties for their own marketing purposes, do not engage in cross-context behavioral advertising, and do not share it with data brokers.
How we protect information
We maintain a written Information Security Program designed to meet the elements of the GLBA Safeguards Rule (16 CFR 314.4), described fully in our Information Security Policy. At a high level: all public-facing endpoints use HTTPS/TLS encryption in transit; data is encrypted at rest, with uploaded documents additionally encrypted at the application layer; both dashboards and our production infrastructure require multi-factor authentication; every access to sensitive information is audit-logged; we run continuous vulnerability management with severity-based remediation timelines; we maintain nightly encrypted backups and a documented disaster-recovery plan; and we maintain a documented incident-response plan covering detection, containment, eradication, notification, and post-incident review. No security program can guarantee perfect protection against every threat; our program is designed to provide safeguards appropriate to the sensitivity of the information we process.
Retention and disposal
We retain personal information only as long as necessary for the purposes for which it was collected, except where a longer period is required or permitted by law. Completed deal records and uploaded documents are retained for 5 years from completion, after which document files are deleted and personal-information fields are anonymized. Quote-only records that never became deals are retained for 1 year on the same basis. Full detail is available in our data retention and disposal policy.
Your privacy rights
Because we receive consumer information from dealers rather than directly from consumers, requests to access, correct, or delete information should typically be directed to the dealer that submitted the deal, who can coordinate with us. Where a consumer contacts us directly, subject to identity verification, you may have the right — depending on your state of residence — to know what information we hold about you and where it came from, correct inaccurate information, delete information (subject to legal and recordkeeping exceptions), receive a portable copy of information you provided, opt out of any sale or sharing for behavioral advertising (we do not engage in this), and be free from retaliation for exercising these rights. These rights are recognized under laws including the California Consumer Privacy Act (as amended by the CPRA), and comparable laws in Virginia, Colorado, Connecticut, and Utah; we honor verified requests from residents of any U.S. state. To submit a request, contact us using the details below with the dealership name, approximate transaction date, and vehicle identification number, so we can locate your information. We typically respond within 45 days. Where permitted, you may designate an authorized agent to submit a request on your behalf.
GLBA: the dealer’s role and ours
Where we receive consumer nonpublic personal information in the course of providing services to a dealer that arranges consumer financing, we act as a “service provider” to that dealer under the GLBA Safeguards Rule and Privacy Rule. The dealer is the “financial institution” with the direct consumer relationship and is responsible for providing its own initial and annual GLBA privacy notices. We use the information we receive only for the purpose for which the dealer disclosed it, and for the limited additional purposes permitted by the GLBA Privacy Rule, without further notice to the consumer.
Cookies and similar technologies
Our dealer and administrative dashboards use session cookies necessary for authentication and security; these are not used for cross-site tracking. This website uses cookies necessary for operation and security, along with cookies set by a third-party analytics and lead-management service to track page views, returning visits, and form interactions, as described above; it does not deploy third-party advertising trackers or behavioral advertising pixels. We do not respond to “Do Not Track” browser signals, as no industry consensus exists on the meaning of that signal in our context.
International data transfers
Our services are operated in the United States, and personal information we process is stored and processed on infrastructure located in the United States. We do not currently offer our services to dealers or consumers outside the United States.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be reflected on this page.
Contact us
If you have questions about this Privacy Policy or our handling of information, contact us at support@regiotitle.com.