A used car lot runs on paperwork and pictures: every deal jacket, every buyer's order, every finance contract, every vehicle photo from the day it hit the lot to the day it was reconditioned and priced. Most of that lives on one or two Windows computers in the sales office or the F&I room. The backup question every dealer principal needs to answer honestly is whether a specific deal jacket, a customer's full purchase history, or a signed retail installment contract could be pulled up on the day a customer, a lender, or an auditor asks for it.
Everyday Backups provides managed, encrypted cloud backup for Windows computers, with monitoring, restore support, and monthly backup health reporting. Paid plans from $5.99/mo.
A used car dealership's data is a record of every unit bought and sold, every buyer served, and every deal financed. Many of these records exist as a single local file, folder, or scanned image on the office PC in the sales tower or the F&I desk. The categories below represent what a working dealership should be able to recover, from a specific date, when a deal is questioned or a machine fails.
A gap in any one of these categories can become serious in a specific scenario: when a buyer disputes the terms of a deal and the signed buyer's order cannot be located, when a lender requests a document from a submitted finance package, or when years of vehicle photos and reconditioning history disappear after a hard drive failure.
The 3-2-1 rule is a straightforward framework promoted by CISA and widely used in small-business backup guidance. For an independent or used car dealership, here is what it looks like applied to the files that actually matter.
Your working copy on the sales-office PC or DMS server counts as one. A second copy might be a local external drive or a secondary workstation on the dealership network. A third copy, off-site in encrypted cloud storage, is the copy that protects against a local disaster affecting both of the first two copies at the same time.
Keeping backups only on the same type of storage, such as two internal drives in the same machine, does not provide meaningful redundancy against hardware failure or a building event. CISA guidance calls for at least two different storage types, for example a local drive and a separate cloud destination, as distinct and independent layers of protection.
Off-site means physically separated from your dealership. Cloud backup satisfies this requirement when the data is sent to a separate data center rather than just an external drive in the same room. The off-site copy is the one that matters most in the scenarios where everything at the lot is affected: fire, flood, theft, or a ransomware attack that hits every connected device.
CISA specifically recommends maintaining at least one backup copy that is not continuously connected to the network. Ransomware attacks increasingly target connected backup systems as part of the same encryption sweep that hits production files. A cloud-based backup that is not directly mounted on your local network provides a layer that ransomware cannot reach and encrypt alongside your deal jackets and inventory records.
The checklist below reflects CISA small-business backup principles and FTC small-business cybersecurity guidance, applied to the file environment of a working dealership. This is a starting framework for backup decisions, not legal, regulatory, or compliance advice.
For a broader self-assessment of your current backup posture, see the small-business backup checklist. For ransomware-specific preparation, see ransomware restore readiness. If your dealership also operates a service department, the file environment and backup priorities are distinct: see backup for auto repair and service shops for the mechanical/service side of the business.
Two categories of software generate the bulk of a dealership's critical data: the dealer-management or CRM system and the accounting platform. Understanding what your backup does and does not cover for each is essential before you assume you are protected.
Dealer-management platforms used by independent lots, categories that include products such as Frazer, DealerCenter, and Dealertrack (named here only as illustrative examples of the product category, not as an endorsement or claim of compatibility), typically store deal, inventory, and customer data in a specific local database folder or set of data files, whether installed on a local server or a sales-office PC. Some platforms generate scheduled exports or produce backup archives to a designated folder. The key questions to answer for your backup configuration are: where does the DMS store its data files on your Windows machine, are those files included in your backup scope, and are they captured in a consistent state when the application is not actively writing to them.
If your dealership uses a cloud-hosted DMS or CRM where data lives entirely on the vendor's servers rather than your local machine, the local backup question shifts to what you download or save locally from that system: deal jacket PDFs you export, buyer's order printouts, vehicle photos stored to a local or network folder, and any other files saved to Windows machines on the lot. Those locally stored files remain your responsibility to back up independently. The vendor's copy of your data in their cloud does not substitute for your own backup of what lives on your machines.
Some platforms allow you to configure automatic export paths or scheduled backup archives that write to a specific local folder. If your DMS has this capability, configuring it to write exports to a known folder path, and then including that folder in your backup scope, is a practical approach to ensuring the DMS data is covered alongside your other files.
Many independent dealerships use QuickBooks for revenue tracking, floor-plan and unit-cost accounting, payroll, and tax preparation, and buy-here-pay-here operations often layer in-house payment ledgers on top. QuickBooks company files (.QBW) can grow to several gigabytes, are frequently stored on a single office desktop or network share, and are the source of truth for the dealership's complete financial history. Intuit's own documentation recommends maintaining backup copies of QuickBooks data files in a separate location from the original, and specifically notes that backing up only to the same machine is not adequate protection against hardware failure.
Common QuickBooks backup oversights at small dealerships include the company file stored on one machine with no second copy anywhere, the Intuit automatic backup feature saving to a different folder on the same drive as the original, and portable company files (.QBM) treated as complete backups when they are actually compressed snapshots that may not include all supporting files. A complete backup of QuickBooks for a dealership covers the company file itself, the backup copy that QuickBooks may write to its own backup folder, and any exported reports, payroll files, or BHPH payment ledgers that the dealership saves separately.
For a detailed look at QuickBooks backup practices, see QuickBooks backup for small businesses. Intuit's documentation, referenced there, is the authoritative source for QuickBooks-specific backup configuration steps.
The FTC and CISA both publish guidance specifically noting that small businesses, including sales operations with accumulated customer and finance records, are targets of ransomware campaigns. The reason is practical: small businesses often have less IT infrastructure than large corporations, making them easier to compromise, while still holding customer and financial records that create pressure to pay a ransom rather than lose years of deal history.
For a dealership, the factors that make ransomware particularly consequential are: all DMS/CRM data, deal jackets, and inventory records concentrated on a small number of Windows machines, QuickBooks accounting and BHPH payment ledgers covering years of financial records stored locally, vehicle photo libraries and scanned finance documents with no off-site copy, and typically no dedicated IT staff checking backup health on a daily basis.
CISA's #StopRansomware guidance identifies offline and encrypted backup copies as the primary technical recovery mechanism when ransomware has encrypted production files. The critical point is that a backup connected to the same network as the infected machines, or a cloud sync folder that replicates changes in real time, may itself be encrypted before the attack is detected. A backup that is not continuously mounted on your dealership's local network is the copy most likely to survive a ransomware event with usable data intact.
For a complete breakdown of what a ransomware-capable backup posture looks like for a small office or lot environment, see ransomware restore readiness. The guidance there walks through why offline and air-gapped copies matter, what restore testing looks like in practice, and what questions to ask about your current backup setup before an incident occurs.
It is worth noting that ransomware recovery is not just a technology question for a dealership. Even with a good backup in place, a ransomware incident typically means some period of disruption while systems are cleaned and data is restored. The backup does not eliminate that disruption, but it is the difference between recovering from a bad week and potentially losing years of deal history with no path back. A backup you have tested and know works is worth substantially more than one you have never restored from.
Yes, for two distinct reasons. First, even with a cloud-based DMS or CRM, your dealership almost certainly saves files locally to Windows machines: deal jacket PDFs you export, vehicle photos that land in a local or network folder, scanned buyer's orders and title paperwork, QuickBooks accounting files, and customer or lender correspondence. Those locally stored files are not backed up by the DMS vendor. Second, the vendor storing your data is not the same as you having an independent backup of that data that you control and can restore from on your own timeline. The two are separate protection layers, and both matter to a working dealership.
It depends on how your specific DMS stores photo files, and this is a question worth answering precisely rather than assuming. In many configurations, lot photos and reconditioning photos are stored in a local or network folder path that is separate from the DMS database itself. If that folder is not explicitly included in your backup scope, the photos are not protected even if the DMS database is. For a lot that documents detailed before-and-after reconditioning work on every unit, the photo library can represent years of documentation that cannot be recreated after the fact.
No, and the difference matters significantly for ransomware protection. Cloud sync mirrors the current state of your files. If a file is deleted, overwritten, or encrypted by ransomware, that change replicates to the sync destination, often within seconds. Backup, by contrast, retains point-in-time copies with version history so you can restore files as they existed before the damage. For a dealership where ransomware could encrypt all active deal jackets and customer records at once, the version history that backup provides is the difference between recovery and loss. See cloud sync vs. backup for a complete comparison.
CISA guidance recommends maintaining enough backup history to recover from incidents that are not discovered immediately. Ransomware and file corruption are often not noticed for days or even weeks after the event that caused them. A backup window of 24 to 48 hours is almost never sufficient. Thirty days of version history is a practical minimum for a dealership that wants a genuine recovery window. Some dealers choose to retain longer histories for older deal files, particularly for closed sales and finance documents that might be referenced in a dispute months or years later.
A backup job failure should trigger immediate attention, not be deferred to a weekly review. The first step is understanding why it failed: the machine was off during the scheduled backup window, a file was locked by a running application, available disk space ran out, or a network or credential issue prevented upload. Each of those has a different resolution. If backup failures go unnoticed for an extended period, the dealership is operating without coverage, and a hard drive failure or ransomware event during that window would have no recovery path. Backup monitoring that sends an alert on failure is the baseline way to avoid this.
Institutional backup knowledge leaving with one person is one of the more common ways a backup that was once configured and working gradually degrades. The backup may continue running, but no one at the dealership knows what it covers, where the data goes, or how to restore from it. The practical mitigation is to write down the answers to three questions before that person leaves: what is backed up (which machines, which folders), where does the backup data go (which service, which account), and how do you start a restore. Those three answers, stored somewhere accessible to the dealer principal or general manager, are the core of a handoff that preserves the value of the backup investment.
CISA recommends periodic restore testing as a distinct activity from verifying that backup jobs completed. Completing without errors means data was transferred, not that the files are intact and recoverable in the format you need. For a dealership, a quarterly spot-restore is a practical cadence: select a sample of files from different categories (a deal jacket, an inventory photo batch, a QuickBooks backup file) from different backup dates, and confirm you can retrieve and open each one. Doing this quarterly means any scope gap or file-format problem surfaces with several months of lead time before you need the backup in an actual recovery event.
No. A backup is a recovery tool, not a data security or fraud prevention tool. Backing up your files means you can restore a lost or damaged copy of your own records; it does nothing to prevent someone else from misusing customer information, does not detect fraudulent transactions, and does not protect against identity theft. Fraud prevention, data security controls, and customer information safeguards are separate concerns that a backup service does not address. Everyday Backups is a backup and recovery product, not a security or compliance product.
Everyday Backups installs on Windows machines, monitors backup job health, sends alerts when a backup fails or goes overdue, maintains version history so you can recover files from a prior point in time, encrypts data in transit and at rest, and stores backups in off-site cloud infrastructure rather than local media that could be affected by the same event as your primary machines. The service is designed to be configured once and then run automatically in the background, with monitoring and health reporting so you know the backup is working without checking it manually each day. For dealerships with more than one Windows machine, each machine requires its own backup coverage.
Yes, treat it as a distinct file environment. A service department generates repair orders, digital inspection photos, and signed work authorizations that are separate from your sales-side deal jackets, inventory photos, and F&I documents. Both sides need to be mapped and included in your backup scope. If your dealership operates both a sales lot and a service bay, see backup for auto repair and service shops for the service-side file categories and checklist.
Everyday Backups is a backup service, not legal, regulatory, or compliance advice. It does not by itself satisfy any record-retention, privacy, consumer-protection, lending, or other legal requirement applicable to your business. A backup is a data recovery tool; it is not a data security, fraud prevention, or identity theft protection product, and it does not protect customer information from misuse. No compatibility with any specific dealer-management system, CRM, point-of-sale system, accounting platform, or other application is guaranteed or implied; verify backup scope and file coverage with your own IT review. Mention of software categories or products such as Frazer, DealerCenter, or Dealertrack is for illustrative purposes only and does not constitute endorsement of or claimed compatibility with any specific vendor or product. References to CISA, FTC, Intuit, and Microsoft documentation are for informational context only and do not constitute endorsement by those organizations. Consult qualified legal and IT advisors for requirements specific to your business.
Everyday Backups runs on Windows, iPhone, iPad, and Android. Set it once; it backs up automatically, encrypted, off-site. Paid plans from $5.99/mo.
Prefer to talk to a person? Call 850-980-3691
Want a second set of eyes? Schedule your free 15-minute Backup Risk Check with our team