Dear customer, we want you to have a great experience on our website. To ensure that the website works properly,we store cookies and use comparable techniques. For example, to ensure that your shopping cart remembers which productshave been added. We also keep a record of your interactions. So that we know whether you are logged in, and we keepstatistics to determine what time our store is busy. This way we can tailor our services to this. It helps all of us toensure that we offer a relevant product range and put the right offers in the window for you.
AAG Winparts Privacy Notice
Effective Date: 10/10/2023
Privacy Notice
Winparts as part ofAlliance Automotive Holding Limited and all its subsidiaries ( AAH ) is a wholly owned subsidiary ofGenuine Parts Company ( GPC ),and part of an international company specialized in the distribution and saleof automotive parts and car accessories (AAH will be referred to as we, us, or our throughout thisData Protection Notice ( Notice )unless otherwise specified)).
We place great importanceon the principles of honesty and transparency in operating our businesses andwant to establish and maintain a trusting relationship with you. This Notice isdesigned to help you understand how we respect your personal data by describinghow we collect, use, process, and shareyour personal data when you interact with us, visit our websites ( Sites ), use our mobile applications( Apps ),or participate in any other online services we offer (collectively Services ), and to help you understandand exercise your privacy rights.
Please Note: This Notice does not apply to any of the personal datathat we process on behalf of our enterprise customers or business partners ( Enterprise Customers ) through our commercial relationships with them (such data is our Customers’Data ). The data protectionand other terms applicable to the processingof our Customers’ Data is governed by the contracts between us and ourEnterprise Customers. If you interact with our Enterprise Customers, theirrespective privacy policies govern their collection and use of your personaldata, and any questions or requests youmay have relating to how our Enterprise Customers may collect or use yourpersonal data should be directed to them.
PERSONAL DATA WE COLLECT
The categories of personaldata we collect depend on how you interact with us, our Services, and therequirements of law applicable in aparticular context, including withoutlimitation the EU General Data Protection Regulation 2016/679 ( GDPR ), the United Kingdom GDPR ( UK GDPR )and the United Kingdom Data Protection Act 2018. We collect information that youprovide to us, information we obtain automaticallywhen you use our Services, and information from other sources such asthird-party services and organizations, as described below.
PersonalData You Provide to Us Directly
Wemay collect personal data that you provide to us in a few ways, for example:
- Account Creation. We may collect personaldata when you create an account or register with us through one of our Sites orApps. Information we collect could include personal data such as name, emailaddress, physical address, username, business name (if a business account), mobile phone number, birthdaymonth and day, information about your vehicle, or other data that we mayassociate with you and your account.
- Purchases. We may collect personaldata and details associated with your purchases, including payment information,the location of a retail establishments such as a warehouse or storeif you are picking up an online order, and if applicable and at your election,membership information in organizations thatqualify you for discounts or other privileges. Any payments made via ourServices are processed by third-partypayment processors. We do not directly collect, or store payment cardinformation entered through our Services,but may retain certain account information if you transact using directbanking. Regardless of how you pay, we may receive information associated with your purchase (forexample, if you made a purchase, how much you spent, and information related to payment method, etc.).
- Your Communications with Us. We may collect personal information, such as name,email address, phone number,or mailing address whenyou request information about our Services, register for our newsletter,request customer or technical support, or otherwise communicate with us through email, text, chat, or voice callswith our customer service associates.
- Surveys. We may contact you toparticipate in surveys or other voluntary questionnaires. If you decide toparticipate, we may collect personal data from you in connection with the survey.
- Chat and Other Interactive Features. We and others who use our Services may collect personalinformation that you submit or make availablethrough interactive features such as messaging and chat features, or commentingfunctionalities, forums, blogs, and social media pages. Any information you provide using the public sharing featuresof the Services will be considered public, unless otherwise required by applicable law, and is notsubject to the privacy protections referenced herein.
- Loyalty, Discountor Other Purchasing Programs. We may offer loyalty,discount, or other promotional programsfor interested customers.For example, if you are a frequent purchaser and you enroll in one of ourpromotional programs (any, a Loyalty Program) we may offer discounts, promotional items, orcredit in connection with your purchases or other activities described in theterms applicable to the specificLoyalty Program ( Program Terms ). The personal data you elect to provide when you sign up for anyLoyalty Program will be used to keep track ofyour purchases and administer the Loyalty Program pursuant to its applicableProgram Terms.
- Promotional Activities. If you elect to participate in promotions such as sweepstakes or contests that we may offer from time to time, you will beasked to consent to share your personal data with us so that we can administerthe promotion in accordance with theactivity’s terms and conditions ( Official Rules ). A promotion’s Official Rules will be disclosed at the time and point of entry.
- Conferences, Trade Shows, and Other Events. If you attend or host conferences, trade shows, and other events that we attend or host, we may collectyour contact information and other information about your interests if youconsent to share it with us.
- BusinessDevelopmentand Strategic Partnerships. Wemay collectpersonal datafrom individuals and thirdparties toassess and pursue potential business opportunities.
- Job Applications and Recruiting. If you apply for a job with any of our companies, we may collectinformation that will be used to assess yourskills, qualifications, and interests to determine alignment with careeropportunities with us or our affiliates and to communicate with you regarding the status of your application. If youare offered and you accept a position with one of our organizations, your application data may become partof your worker file. Details about how we handle your personal data as aTeammate is explained in the applicable workerprivacy notice provided to you at the time of your onboarding.
Personal Data Collected Through Technical Means
Weuse technologies that maycollectpersonal data when youuse our Services.
- Device Information. When you use ourServices, we may have access to certain technical information, such as yourInternet protocol (IP) address, user settings, MAC address, cookieidentifiers, mobile carrier, mobile advertising and other unique identifiers,browser or device information, locationinformation (including approximate location derived from IP address), andInternet service provider. We may also collect information regarding your use ofour Services, such as pages that you visit before, during and after using ourServices, information about the links youclick, the types of content you interact with, the frequency and duration ofyour activities, and other information about how you use our Services.
- Cookie Policy (and Other Technologies). With your consent, we, as well as third parties that provide content,advertising, or other functionality on our Services, may use cookies,pixel tags, and othertechnologies (Technologies ) to collect information through your use of our Services.
- Cookies. Cookies are small textfiles placed in device browsers that store preferences and facilitate andenhance your experience.
- Pixel Tags/WebBeacons. A pixel tag (also known as a web beacon) is a piece of code embedded in our Servicesthat collects informationabout engagement on our Services. The use of a pixel tag allows us to record(at your election and with your consent),for example, that a user has visited a particular web page or clicked on aparticular advertisement. We may also includeweb beacons in e-mails to understand whether messages have been opened, actedon, or forwarded.
Categories of Technologies. Our uses of these Technologies fall into the following general categories:
- Strictly Necessary. This includesTechnologies that allow you access to our Services, applications, and tools that are required to identify irregularwebsite behavior, prevent fraudulent activity, improve security, or allow youto make use of functionalities we make available throughour Sites or Services.
- Performance-Related. To the extent you consentto our use of Technologies to assess the performance of our Services, including aspart of our analytics practices to help us understand how individuals use ourServices, we may collect information relatedto the performance of our Site, Apps and aspects of the Services. Some of theperformance-related Technologies we use include Google Analytics and Matamo.You maywish tolearn moreabout Matomo’s services and reviewGoogle Analytics’ Notice to better understand how Google uses your personal data (including for its own purposes, e.g., for profiling or linking it to other data). To learn more abouthow to opt-out of Google Analytics’ use of your information, please click here.
- Functionality-Related. To the extent you have enabledelective Technologies while using our Services, we may use such Technologiesto offer you enhanced functionality when accessing or using our Services.Functionalities on offer may include identifyingyou when you sign into our Services or keeping track of your specifiedpreferences, interests, or past items viewed.
- Targeting-Related. We may use Technologies to deliver content,including ads relevantto your interests, on our Servicesor on third-party digital properties.
- Social Media Platforms. Our Services may contain socialmedia buttons, such as Facebook,Instagram, Twitter, and YouTube, which might include widgetssuch as the “share this�? button or other interactive mini programs. Thesefeatures may collect personal data suchas your IP address, the page you are visiting on our Services, and may set acookie to enable the feature to function properly. Your interactions with these platforms are governedby the privacy policies and terms of the social media companies providing them.
- Verification Providers. We may use third-party providers to mitigateunauthorized logins as a means of protecting our Site and Services.For example, when you fill in certain forms, a service may evaluate variousinformation (e.g., IP address, how long you have been on the Site, mouse movements, etc.) to detect if an activity isfrom an automated program instead of a human. We may retain these data via ourservice providers for security purposes.
Personal Information Collected from Other Sources
We may obtain personal dataabout you from other sources, including through third-party services andorganizations.For example,if you access our Services through a third-party application, such as an appstore, a third-party login service, or a social networking site, we may collect personal data about you from thatthird-party application if you have made such data available via your privacysettings in that application.
HOW WE USE YOUR PERSONAL DATA AND THEIR LEGAL BASIS
We are committed toprocessing your personal data in a fair and authorized manner. We process yourpersonal data for a variety of business purposes, including toprovide our Services, for administrative purposes, and to market our productsand Services. Our processing meets explicit, legitimate, and specific objectives as describedbelow.
Provide Our Services
We use your information toprovide our Services in fulfilment of our contracts with you and atyour request and with your consent, including by:Managing your information and accounts;
- Providing access to certain areas, functionalities, andfeatures of our Services;
- Answering requests for customer or technical support;
- Communicating with you about your account, activities onour Services, your participation in our Loyalty Programs or other promotional offers;
- Communicating with you about other policy changes;
- Processing and completing your transactions, includingorder confirmation, billing, enrollment in our Loyalty Program or other programs and delivering productsor Services, and
- Allowing you to register for events.
Administrative, Business and Legal Purposes
We use your information for variousadministrative purposesin furtherance ofour legitimate interests, as needed to execute a contract between us, or at your initiativeand with your consent including:
- Conducting research and development (including marketingresearch), maintaining network and information security, and preventing fraud;
- Tracking your job application to process yourqualifications for an open role;
- Interacting with you if you contact us as a vendor or onbehalf of another business;
- Detecting security incidents, protecting against malicious,deceptive, fraudulent or illegal activity, and prosecuting those responsible for that activity;
- Measuring interest and engagement in our Services;
- Short-term, transient use, such as contextual customizationof ads; Improving, upgrading, or enhancing our Services;
- Developing new products and services;
- Ensuring internal quality control and safety;
- Authenticating and verifying individual identities,including requests to exercise your rights under this Notice;
- Alerting you about a product safety announcement or recallor correction of an offer, promotion, or advertisement; Debugging to identify and repair errorswith our Services;
- Auditing relating to interactions, transactions, and othercompliance activities; Sharing personal data with third parties as needed to provide the Services;
- Enforcing our agreements and policies;
- Carrying out activities that are required to comply withour legal obligations, and As permitted by law.
Marketingand Advertising our Products and Services
We may use your personaldata in furtherance of our legitimate interests and/or with yourconsent to tailor your experiencewith our Services and to provide you with content and advertisementsas permitted by applicable law. Some of the ways we may market to you include,without limitation, via postal or emailcampaigns, text messages, custom audience advertising, and “interest-based�? or“personalized advertising,�? includingthrough cross-device tracking.
If you have any questionsabout our marketing practices or if you would like to opt out of the use ofyour personal data for marketing purposes, you can learn more about your choices inthe “YOUR PRIVACY CHOICES AND RIGHTS�? section of this Notice or Contact Us.
With Your Consent
Wemay use personal data for other purposes and on such legal basesthatare clearly disclosed to you at the time you provide personal data,and/or with your consent. Other PurposesWe also use your personaldata for other purposes aspermitted byyou or applicable law, and tocreate de-identified, aggregated oranonymized information in our legitimate interest. If we create or receive de-identifiedinformation, we will not attempt to reidentify such information, except to comply with applicable law.
HOW WE DISCLOSE YOUR PERSONAL DATA
We may disclose yourpersonal data to third parties for a variety of business purposes, including toprovide our Services, to protect us or others, or in the event of a majorbusiness transaction such as a merger, sale, or asset transfer, as describedbelow.
Disclosures to Provide our Services
Thecategories of third parties with whom wemay share your personal dataare described below.
- Service Providers. We may share your personal information with our third-party service providers and vendors that assist us with the provision of ourServices. This includes service providers and vendors that provide us with ITsupport, hosting, payment processing, chat and other customer service functions, and relatedservices.
- Business Partners. We may share your personal data with businesspartners to provideyou with a product or service you have requested.We may also share your personal data with business partners with whom wejointly offer products or services.
- Affiliates. We may shareyour personal data with our affiliates, for example with our parentsand subsidiaries for our administrative purposes, ITmanagement, or for them to provide services to you or support and supplementthe Services we provide.
- OtherUsers or ThirdParties You Shareor Interact With. Asdescribed abovein PERSONAL DATA WECOLLECT, ourServices may allow you to share personal data or interact withthird parties (including individuals and third parties who do not use ourServices and
- thepublic).
- Advertising Partners. Through our Services, wemay share your personal data with third-party advertising partners. Thesethird-party advertising partners may set Technologies and othertracking tools on our Services to collect information regarding your activitiesand your device (e.g., your IP address,cookie identifiers, page(s) visited, location, time of day). These advertisingpartners may use this information (andsimilar information collected from other services) for purposes of deliveringpersonalized advertisements to you when you visit digital properties within their networks. This practice iscommonly referred to as “interest-based advertising,�? “cross-contextual behavioral advertising,�? or “personalizedadvertising.�? The categories of data we may share and may have shared for thepurpose of providing cross contextualadvertising and targeted advertising include online identifiers such as IPaddress, marketing id, device identifiersand characteristics; internet or other electronic network activity, such asbrowsing and usage information and, inferences about individual preferences, characteristics, andbehaviors.
We may also share your informationwith third parties as appropriate and as permitted by law. The privacy choicesyou may have about your personal data are determined by applicable law andare described in the “YOUR PRIVACY CHOICES ANDRIGHTS�?Section of this Notice.
Disclosures to Protect Our Company or Others
We may access, preserve,and disclose any information we store associated with you to external parties if we, in goodfaith, believe doing so isrequired or appropriate to: comply with law enforcement or national securityrequests and legal process, such as a court order or subpoena; protectyour, our, or others’ rights, property, or safety; enforce our policies orcontracts; collect amounts owed to us; or assist with an investigation or prosecution ofsuspected or actual illegal activity.
Disclosure in the Event of Merger, Sale, or Other Asset Transfers
If we are involved in amerger, acquisition, financing due diligence, reorganization, bankruptcy,receivership, purchase or sale of assets, or transition of serviceto another provider, your personal data may be transferred as part of such atransaction, as permitted by law and/orcontract.
YOUR PRIVACYCHOICESAND RIGHTS
Your Data Protection Choices and Rights. The privacy choices you may have about your personal data are described below.
- Email Communications. If you receive an unwanted email from us, you may reply to the senderand ask not to be contacted again,or, where applicable,you can use the unsubscribe link found at the bottom of the email to opt out of receiving future emails. Note thatyou will continue to receivetransaction-related emails regarding products or Services you have requested.We may also send you certainnon-promotional communications regarding us and our Services, and you will notbe able to opt out of those communications (e.g., communications regarding our Services or updates to our Terms orthis or other legal Notice(s)).
- Text Messages. If you elected to receive text messages and receive an unwantedtext message from us, you may opt out of receiving future text messages byfollowing the instructions in the text message you received.
- Mobile Devices. If you enable pushnotifications from any App we may offer, we may contact you via pushnotifications. You may opt out from receiving these push notifications bychanging the settings on your mobile device. If you enable location sharing onyour mobile device with our App, we mayalso collect precise location-based information. You may opt out of thiscollection by changing the settings on your mobile device.
- Live Chat. If you visit our Sites oruse our Apps you may request customer service using a live chat feature. Chatsare user-initiated and session-based and you candiscontinue a chat you initiate at any time.
- Phone calls. If you receive anunwanted phone call from us, you may opt out of receiving future phone callsfrom us by following the instructions on the callor by Contacting Us.
- Cookies and Personalized Advertising. You may stop or restrict the placement of certain Technologies on your device or remove them by adjustingyour preferences through the Cookie Banner on the Site you are visiting from,or as your device permits. However, dependingon how you adjust your preferences our Services may not work optimally. Pleasenote that cookie-based opt-outs are not effective on mobile applications. However, you may opt-out of personalizedadvertisements on some mobile applications by following the instructions for Android, iOS, and others. The online advertising industry alsoprovides websites from which you may opt out ofreceiving targeted ads from data partners andother advertising partners that participate in self-regulatory programs. Youcan access these and learn more about targeted advertising and consumer choice andprivacy by visiting theEuropean Digital Advertising Alliance. Please note youmust exercise your preferences in each browser and on each device.
- Loyalty Programs. You can request to have your account deletedand cancel your participation in any LoyaltyProgram by Contacting Usas set forth in this Notice.
- Request to Be Informedand Access Your Personal Data. You have the right to requestthat we disclosecertain information to you about ourcollection, use and disclosure of your personal data. Once we receive andconfirm your verifiable consumer request, we will disclose to you any or all of the following, asrequested by you: the specific pieces of personal data we collected about you;the categories of personal data wecollected about you; the categories of sources from which we collect personaldata about you; the categories ofpersonal data that we have disclosed about you for a business purpose; thecategories of third parties to whom we have disclosed your personal data for a business purpose; and, our business orcommercial purpose for collecting personal data.
- Request Correction/Rectification. You have the right to request that we corrector amend your personal data where it is inaccurate or incomplete. In some cases, we may provideself-service tools that enable you to update your personal data.
- Request to Erase/Delete. You have the right to request that we erase/delete any of your personaldata that we collected from youand retained, subject to certain exceptions. Once wereceive and confirm your verifiable consumer request, we will delete (anddirect our service providers to delete,as applicable) your personal data from our records, unless an exceptionapplies.
- Request Restriction. In some cases, you have the right to request that we restrictour processing of your personaldata. This right enables you to limitour processing of your personal data, so while we may retain your personaldata, we may not process it for certain purposes.
- Right to DataPortability. You have the right to request,under certain conditions, to receive a copy of the personaldata we have retained about you in a form that you can use foryour own purposes or in conjunction with another service provider.
- Right to Object. You have the right to object to certain uses we may make of your personal data.
- Right to Withdraw your Consent to ourprocessing of your personal data. Please note that your withdrawal will only take effect for future processing and will notaffect the lawfulness of processing before the withdrawal.
- Right to Lodge a Complaint with a Supervisory Authority. You have a right not to receive discriminatory treatment by us for the exercise ofany privacy rights conferred by applicable laws and to contact the relevantdata protection authority to lodge a complaint about our data protection practices relative to yourpersonal data.
CONTACTUS
The controller of thepersonal data covered in this Notice is AAH. If you have any questions aboutour privacy practices or this Notice, or to exercise your rights asdetailed in this Notice, we can be reached in the following ways:
Make an online request: clickhere Email: [emailprotected]
Wewillprocess such requests in accordance with applicable laws.
Verification Methods. Once you submit a request, we will verifythat you are the consumerto which the request pertainsby matching theidentifying information provided by you (e.g.,name, email address, account-related information) to the information wemaintain. Depending on the type ofrequest you submit, we will attempt to match either two or three of the datapoints you provided. If we are unableto verify your request with the data points you provided, we may reach out toyou for additional information to verify your request.
Authorized Agent. You can select an“authorized agent�? to submit requests on your behalf. We will require theauthorized agent to have a written authorization confirming thatauthority. We may also require you to verify your own identity directly withus. Once your authorized agent isverified, they may submit a request in the typical way described above.
Appeal. You may have the right toappeal our decision or response to your request. To exercise your right toappeal, you can submit and appeal request using the same method used tosubmit your original request, including by contacting us as described in this Notice.
SECURITY OF YOUR PERSONAL DATA
We take steps to ensurethat your information is treated securely and in accordance with this Noticeincluding devoting appropriate humanand technical resources to ensure an adequatelevel of security including a developed set of policies and rules for thesecurity of our information systems andnetworks. The purpose of these rules is to limit the risks of intrusion orillicit access to informationsystems. Unfortunately, no system is 100% secure,and we cannot ensure or warrant the security of any information you provide tous. To the fullest extent permitted by applicable law, we donot accept liability for unauthorized access, use, disclosure, or loss ofpersonal data. By using our Services or providing personal data to us,you agree that we may communicate with you electronically regarding security,privacy, and administrative issuesrelating to your use of our Services. If we learn of a security incidentaffecting your personal data, we may attempt to notify you electronically byposting a notice on our Services, by mail, or by sending an email to you.
RETENTION OF YOUR PERSONALDATA
We storepersonal data we collect as described in this Notice for as long as you use ourServices, or as necessary to fulfill the purpose(s) for which it was collected,provide our Services, resolve disputes, establish legal defenses, conductaudits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws. Additionally,we endeavor to retain all such personal data in accordance with legal requirements, or based upon other criteria,including, but not limited to, the sensitivity and volume of such data.
CHILDRENSINFORMATION
Our Services are notdirected to, nor intended to be attractive or of interest to persons under 16years of age ( children ) and we donot knowingly collect personal data from children. If youare a parent or guardian and believe your child has uploaded personal data toour site without your consent, pleaseContact Us. If we become aware that a child has provided us withpersonal data in violation of applicable law, we will delete anypersonal data we have collected, unless we have a legal obligation to keep it,and if applicable, terminate the child’s account.
OTHER PROVISIONS
Third-Party Websites/Applications. The Services may containlinks to other websites/applications and other websites/applications may reference or link toour Services. These third-party services are not controlled by us. We encourageour users to read the privacy policies of each website and application with which they interact. We do not endorse,screen, or approve, and are not responsible for, the privacy practices or content of such other websites orapplications. You agree that if you elect to provide personal data tothird-party websites or applicationsencountered on our Sites or through our Services, you do so at your own risk.
INTERNATIONAL DATA TRANSFERS
Some data collected by usmay be transferred, processed, and stored anywhere in the world, including, butnot limited to countries which mayhave data protection laws that are lessprotective than the GDPR and the UK GDPR. We require any importer of yourpersonal data to apply safeguardsrequired by the GDPR and the UK GDPR and take all necessary steps to ensure oursubprocessors have implemented technical and organizational measures necessary to secure yourpersonal data.
If we transfer yourpersonal data from the European Economic Area, Switzerland, and/or the UnitedKingdom to or any country that has not been found to provide an adequatelevel of protection under the GDPR or the UK GDPR applicable data protectionlaws, one of the safeguards we may use to support such transfer is the EU Standard Contractual Clauses ( EU SCCs )and the InternationalData Transfer
Addendum to the EU SCCs.
CHANGES TOOUR NOTICE
We may revise this Noticefrom time to time in our sole discretion. If there are any material changes tothis Notice, we will notify you asrequired by applicable law. You understand andagree that you will be deemed to have accepted the updated Notice if youcontinue to use our Servicesafter the new Notice takeseffect.