Your data

AAG Winparts Privacy Notice

Effective Date: 10/10/2023

Privacy Notice

Winparts as part of Alliance Automotive Holding Limited and all its subsidiaries (“AAHâ€?) is a wholly owned subsidiary of Genuine Parts Company (“GPCâ€?), and part of an international company specialized in the distribution and sale of automotive parts and car accessories (AAH will be referred to as “we,â€? “us,â€? or “ourâ€? throughout this Data Protection Notice (“Noticeâ€?) unless otherwise specified)).

We place great importance on the principles of honesty and transparency in operating our businesses and want to establish and maintain a trusting relationship with you. This Notice is designed to help you understand how we respect your personal data by describing how we collect, use, process, and share your personal data when you interact with us, visit our websites (“Sitesâ€?), use our mobile applications (“Appsâ€?), or participate in any other online services we offer (collectively “Servicesâ€?), and to help you understand and exercise your privacy rights.

Please Note: This Notice does not apply to any of the personal data that we process on behalf of our enterprise customers or business partners (“Enterprise Customersâ€?) through our commercial relationships with them (such data is our “Customers’ Dataâ€?). The data protection and other terms applicable to the processing of our Customers’ Data is governed by the contracts between us and our Enterprise Customers. If you interact with our Enterprise Customers, their respective privacy policies govern their collection and use of your personal data, and any questions or requests you may have relating to how our Enterprise Customers may collect or use your personal data should be directed to them.

PERSONAL DATA WE COLLECT

The categories of personal data we collect depend on how you interact with us, our Services, and the requirements of law applicable in a particular context, including without limitation the EU General Data Protection Regulation 2016/679 (“GDPRâ€?), the United Kingdom GDPR (“UK GDPRâ€?) and the United Kingdom Data Protection Act 2018. We collect information that you provide to us, information we obtain automatically when you use our Services, and information from other sources such as third-party services and organizations, as described below.

Personal Data You Provide to Us Directly

We may collect personal data that you provide to us in a few ways, for example:

  •  Account Creation. We may collect personal data when you create an account or register with us through one of our Sites or Apps. Information we collect could include personal data such as name, email address, physical address, username, business name (if a business account), mobile phone number, birthday month and day, information about your vehicle, or other data that we may associate with you and your account.
  •  Purchases. We may collect personal data and details associated with your purchases, including payment information, the location of a retail establishments such as a warehouse or store if you are picking up an online order, and if applicable and at your election, membership information in organizations that qualify you for discounts or other privileges. Any payments made via our Services are processed by third-party payment processors. We do not directly collect, or store payment card information entered through our Services, but may retain certain account information if you transact using direct banking. Regardless of how you pay, we may receive information associated with your purchase (for example, if you made a purchase, how much you spent, and information related to payment method, etc.).
  •  Your Communications with Us. We may collect personal information, such as name, email address, phone number, or mailing address when you request information about our Services, register for our newsletter, request customer or technical support, or otherwise communicate with us through email, text, chat, or voice calls with our customer service associates.
  •  Surveys. We may contact you to participate in surveys or other voluntary questionnaires. If you decide to participate, we may collect personal data from you in connection with the survey.
  •  Chat and Other Interactive Features. We and others who use our Services may collect personal information that you submit or make available through interactive features such as messaging and chat features, or commenting functionalities, forums, blogs, and social media pages. Any information you provide using the public sharing features of the Services will be considered “public,â€? unless otherwise required by applicable law, and is not subject to the privacy protections referenced herein.
  •  Loyalty, Discount or Other Purchasing Programs. We may offer loyalty, discount, or other promotional programs for interested customers. For example, if you are a frequent purchaser and you enroll in one of our promotional programs (any, a “Loyalty Programâ€?) we may offer discounts, promotional items, or credit in connection with your purchases or other activities described in the terms applicable to the specific Loyalty Program (“Program Termsâ€?). The personal data you elect to provide when you sign up for any Loyalty Program will be used to keep track of your purchases and administer the Loyalty Program pursuant to its applicable Program Terms.
  •  Promotional Activities. If you elect to participate in promotions such as sweepstakes or contests that we may offer from time to time, you will be asked to consent to share your personal data with us so that we can administer the promotion in accordance with theactivity’s terms and conditions (“Official Rulesâ€?). A promotion’s Official Rules will be disclosed at the time and point of entry.
  • Conferences, Trade Shows, and Other Events. If you attend or host conferences, trade shows, and other events that we attend or host, we may collect your contact information and other information about your interests if you consent to share it with us.
  • Business Development and Strategic Partnerships. We may collect personal data from individuals and third parties to assess and pursue potential business opportunities.
  • Job Applications and Recruiting. If you apply for a job with any of our companies, we may collect information that will be used to assess your skills, qualifications, and interests to determine alignment with career opportunities with us or our affiliates and to communicate with you regarding the status of your application. If you are offered and you accept a position with one of our organizations, your application data may become part of your worker file. Details about how we handle your personal data as a Teammate is explained in the applicable worker privacy notice provided to you at the time of your onboarding.

Personal Data Collected Through Technical Means

We use technologies that may collect personal data when you use our Services.

  •  Device Information. When you use our Services, we may have access to certain technical information, such as your Internet protocol (IP) address, user settings, MAC address, cookie identifiers, mobile carrier, mobile advertising and other unique identifiers, browser or device information, location information (including approximate location derived from IP address), and Internet service provider. We may also collect information regarding your use of our Services, such as pages that you visit before, during and after using our Services, information about the links you click, the types of content you interact with, the frequency and duration of your activities, and other information about how you use our Services.
  •  Cookie Policy (and Other Technologies). With your consent, we, as well as third parties that provide content, advertising, or other functionality on our Services, may use cookies, pixel tags, and other technologies (“Technologiesâ€?) to collect information through your use of our Services.
  •  Cookies. Cookies are small text files placed in device browsers that store preferences and facilitate and enhance your experience.
  •  Pixel Tags/Web Beacons. A pixel tag (also known as a web beacon) is a piece of code embedded in our Services that collects information about engagement on our Services. The use of a pixel tag allows us to record (at your election and with your consent), for example, that a user has visited a particular web page or clicked on a particular advertisement. We may also include web beacons in e-mails to understand whether messages have been opened, acted on, or forwarded.

Categories of Technologies. Our uses of these Technologies fall into the following general categories:

  •  Strictly Necessary. This includes Technologies that allow you access to our Services, applications, and tools that are required to identify irregular website behavior, prevent fraudulent activity, improve security, or allow you to make use of functionalities we make available through our Sites or Services.
  •  Performance-Related. To the extent you consent to our use of Technologies to assess the performance of our Services, including as part of our analytics practices to help us understand how individuals use our Services, we may collect information related to the performance of our Site, Apps and aspects of the Services. Some of the performance-related Technologies we use include Google Analytics and Matamo. You may wish to learn more about Matomo’s services and review Google Analytics’ Notice to better understand how Google uses your personal data (including for its own purposes, e.g., for profiling or linking it to other data). To learn more about how to opt-out of Google Analytics’ use of your information, please click here.
  •  Functionality-Related. To the extent you have enabled elective Technologies while using our Services, we may use such Technologies to offer you enhanced functionality when accessing or using our Services. Functionalities on offer may include identifying you when you sign into our Services or keeping track of your specified preferences, interests, or past items viewed.
  • Targeting-Related. We may use Technologies to deliver content, including ads relevant to your interests, on our Services or on third-party digital properties.
  • Social Media Platforms. Our Services may contain social media buttons, such as Facebook, Instagram, Twitter, and YouTube, which might include widgets such as the “share thisâ€? button or other interactive mini programs. These features may collect personal data such as your IP address, the page you are visiting on our Services, and may set a cookie to enable the feature to function properly. Your interactions with these platforms are governed by the privacy policies and terms of the social media companies providing them.
  • Verification Providers. We may use third-party providers to mitigate unauthorized logins as a means of protecting our Site and Services. For example, when you fill in certain forms, a service may evaluate various information (e.g., IP address, how long you have been on the Site, mouse movements, etc.) to detect if an activity is from an automated program instead of a human. We may retain these data via our service providers for security purposes.

Personal Information Collected from Other Sources

We may obtain personal data about you from other sources, including through third-party services and organizations. For example, if you access our Services through a third-party application, such as an app store, a third-party login service, or a social networking site, we may collect personal data about you from that third-party application if you have made such data available via your privacy settings in that application.

HOW WE USE YOUR PERSONAL DATA AND THEIR LEGAL BASIS

We are committed to processing your personal data in a fair and authorized manner. We process your personal data for a variety of business purposes, including to provide our Services, for administrative purposes, and to market our products and Services. Our processing meets explicit, legitimate, and specific objectives as described below.

Provide Our Services

We use your information to provide our Services in fulfilment of our contracts with you and at your request and with your consent, including by:  Managing your information and accounts;

  •  Providing access to certain areas, functionalities, and features of our Services;
  •  Answering requests for customer or technical support;
  •  Communicating with you about your account, activities on our Services, your participation in our Loyalty Programs or other promotional offers;
  •  Communicating with you about other policy changes;
  •  Processing and completing your transactions, including order confirmation, billing, enrollment in our Loyalty Program or other programs and delivering products or Services, and
  •  Allowing you to register for events.

Administrative, Business and Legal Purposes

We use your information for various administrative purposesin furtherance of our legitimate interests, as needed to execute a contract between us, or at your initiative and with your consent including:

  •  Conducting research and development (including marketing research), maintaining network and information security, and preventing fraud;
  •  Tracking your job application to process your qualifications for an open role;
  •  Interacting with you if you contact us as a vendor or on behalf of another business;
  •  Detecting security incidents, protecting against malicious, deceptive, fraudulent or illegal activity, and prosecuting those responsible for that activity;
  •  Measuring interest and engagement in our Services;
  •  Short-term, transient use, such as contextual customization of ads;  Improving, upgrading, or enhancing our Services;
  •  Developing new products and services;
  •  Ensuring internal quality control and safety;
  •  Authenticating and verifying individual identities, including requests to exercise your rights under this Notice;
  •  Alerting you about a product safety announcement or recall or correction of an offer, promotion, or advertisement;  Debugging to identify and repair errors with our Services;
  •  Auditing relating to interactions, transactions, and other compliance activities;  Sharing personal data with third parties as needed to provide the Services;
  •  Enforcing our agreements and policies;
  •  Carrying out activities that are required to comply with our legal obligations, and  As permitted by law.

Marketing and Advertising our Products and Services

We may use your personal data in furtherance of our legitimate interests and/or with your consent to tailor your experience with our Services and to provide you with content and advertisements as permitted by applicable law. Some of the ways we may market to you include, without limitation, via postal or email campaigns, text messages, custom audience advertising, and “interest-basedâ€? or “personalized advertising,â€? including through cross-device tracking.

If you have any questions about our marketing practices or if you would like to opt out of the use of your personal data for marketing purposes, you can learn more about your choices in the “YOUR PRIVACY CHOICES AND RIGHTSâ€? section of this Notice or Contact Us.

With Your Consent

We may use personal data for other purposes and on such legal bases that are clearly disclosed to you at the time you provide personal data, and/or with your consent. Other Purposes We also use your personal data for other purposes aspermitted by you or applicable law, and to create de-identified, aggregated or anonymized information in our legitimate interest. If we create or receive de-identified information, we will not attempt to reidentify such information, except to comply with applicable law.

HOW WE DISCLOSE YOUR PERSONAL DATA

We may disclose your personal data to third parties for a variety of business purposes, including to provide our Services, to protect us or others, or in the event of a major business transaction such as a merger, sale, or asset transfer, as described below.

Disclosures to Provide our Services

The categories of third parties with whom we may share your personal data are described below.

  •  Service Providers. We may share your personal information with our third-party service providers and vendors that assist us with the provision of our Services. This includes service providers and vendors that provide us with IT support, hosting, payment processing, chat and other customer service functions, and related services.
  •  Business Partners. We may share your personal data with business partners to provide you with a product or service you have requested. We may also share your personal data with business partners with whom we jointly offer products or services.
  •  Affiliates. We may share your personal data with our affiliates, for example with our parents and subsidiaries for our administrative purposes, IT management, or for them to provide services to you or support and supplement the Services we provide.
  •  Other Users or Third Parties You Share or Interact With. As described above in PERSONAL DATA WE COLLECT, our Services may allow you to share personal data or interact with third parties (including individuals and third parties who do not use our Services and
  • the public).
  •  Advertising Partners. Through our Services, we may share your personal data with third-party advertising partners. These third-party advertising partners may set Technologies and other tracking tools on our Services to collect information regarding your activities and your device (e.g., your IP address, cookie identifiers, page(s) visited, location, time of day). These advertising partners may use this information (and similar information collected from other services) for purposes of delivering personalized advertisements to you when you visit digital properties within their networks. This practice is commonly referred to as “interest-based advertising,â€? “cross-contextual behavioral advertising,â€? or “personalized advertising.â€? The categories of data we may share and may have shared for the purpose of providing cross contextual advertising and targeted advertising include online identifiers such as IP address, marketing id, device identifiers and characteristics; internet or other electronic network activity, such as browsing and usage information and, inferences about individual preferences, characteristics, and behaviors.

We may also share your information with third parties as appropriate and as permitted by law. The privacy choices you may have about your personal data are determined by applicable law and are described in the “YOUR PRIVACY CHOICES AND RIGHTSâ€? Section of this Notice.

Disclosures to Protect Our Company or Others

We may access, preserve, and disclose any information we store associated with you to external parties if we, in good faith, believe doing so is required or appropriate to: comply with law enforcement or national security requests and legal process, such as a court order or subpoena; protect your, our, or others’ rights, property, or safety; enforce our policies or contracts; collect amounts owed to us; or assist with an investigation or prosecution of suspected or actual illegal activity.

Disclosure in the Event of Merger, Sale, or Other Asset Transfers

If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, purchase or sale of assets, or transition of service to another provider, your personal data may be transferred as part of such a transaction, as permitted by law and/or contract.

YOUR PRIVACY CHOICES AND RIGHTS

Your Data Protection Choices and Rights. The privacy choices you may have about your personal data are described below.

  •  Email Communications. If you receive an unwanted email from us, you may reply to the sender and ask not to be contacted again, or, where applicable, you can use the unsubscribe link found at the bottom of the email to opt out of receiving future emails. Note that you will continue to receive transaction-related emails regarding products or Services you have requested. We may also send you certain non-promotional communications regarding us and our Services, and you will not be able to opt out of those communications (e.g., communications regarding our Services or updates to our Terms or this or other legal Notice(s)).
  •  Text Messages. If you elected to receive text messages and receive an unwanted text message from us, you may opt out of receiving future text messages by following the instructions in the text message you received.
  •  Mobile Devices. If you enable push notifications from any App we may offer, we may contact you via push notifications. You may opt out from receiving these push notifications by changing the settings on your mobile device. If you enable location sharing on your mobile device with our App, we may also collect precise location-based information. You may opt out of this collection by changing the settings on your mobile device.
  •  Live Chat. If you visit our Sites or use our Apps you may request customer service using a live chat feature. Chats are user-initiated and session-based and you can discontinue a chat you initiate at any time.
  •  Phone calls. If you receive an unwanted phone call from us, you may opt out of receiving future phone calls from us by following the instructions on the call or by Contacting Us.
  •  Cookies and Personalized Advertising. You may stop or restrict the placement of certain Technologies on your device or remove them by adjusting your preferences through the Cookie Banner on the Site you are visiting from, or as your device permits. However, depending on how you adjust your preferences our Services may not work optimally. Please note that cookie-based opt-outs are not effective on mobile applications. However, you may opt-out of personalized advertisements on some mobile applications by following the instructions for Android, iOS, and others. The online advertising industry also provides websites from which you may opt out of receiving targeted ads from data partners and other advertising partners that participate in self-regulatory programs. You can access these and learn more about targeted advertising and consumer choice and privacy by visiting the European Digital Advertising Alliance. Please note you must exercise your preferences in each browser and on each device.
  •  Loyalty Programs. You can request to have your account deleted and cancel your participation in any Loyalty Program by Contacting Us as set forth in this Notice.
  •  Request to Be Informed and Access Your Personal Data. You have the right to request that we disclose certain information to you about our collection, use and disclosure of your personal data. Once we receive and confirm your verifiable consumer request, we will disclose to you any or all of the following, as requested by you: the specific pieces of personal data we collected about you; the categories of personal data we collected about you; the categories of sources from which we collect personal data about you; the categories of personal data that we have disclosed about you for a business purpose; the categories of third parties to whom we have disclosed your personal data for a business purpose; and, our business or commercial purpose for collecting personal data.
  •  Request Correction/Rectification. You have the right to request that we correct or amend your personal data where it is inaccurate or incomplete. In some cases, we may provide self-service tools that enable you to update your personal data.
  •  Request to Erase/Delete. You have the right to request that we erase/delete any of your personal data that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete, as applicable) your personal data from our records, unless an exception applies.
  •  Request Restriction. In some cases, you have the right to request that we restrict our processing of your personal data. This right enables you to limit our processing of your personal data, so while we may retain your personal data, we may not process it for certain purposes.
  •  Right to Data Portability. You have the right to request, under certain conditions, to receive a copy of the personal data we have retained about you in a form that you can use for your own purposes or in conjunction with another service provider.
  •  Right to Object. You have the right to object to certain uses we may make of your personal data.
  •  Right to Withdraw your Consent to our processing of your personal data. Please note that your withdrawal will only take effect for future processing and will not affect the lawfulness of processing before the withdrawal.
  •  Right to Lodge a Complaint with a Supervisory Authority. You have a right not to receive discriminatory treatment by us for the exercise of any privacy rights conferred by applicable laws and to contact the relevant data protection authority to lodge a complaint about our data protection practices relative to your personal data.

CONTACT US

The controller of the personal data covered in this Notice is AAH. If you have any questions about our privacy practices or this Notice, or to exercise your rights as detailed in this Notice, we can be reached in the following ways:

Make an online request: click here  Email: [email protected]

We will process such requests in accordance with applicable laws.

  Verification Methods. Once you submit a request, we will verify that you are the consumer to which the request pertains by matching the identifying information provided by you (e.g., name, email address, account-related information) to the information we maintain. Depending on the type of request you submit, we will attempt to match either two or three of the data points you provided. If we are unable to verify your request with the data points you provided, we may reach out to you for additional information to verify your request.

  Authorized Agent. You can select an “authorized agentâ€? to submit requests on your behalf. We will require the authorized agent to have a written authorization confirming that authority. We may also require you to verify your own identity directly with us. Once your authorized agent is verified, they may submit a request in the typical way described above.

  Appeal. You may have the right to appeal our decision or response to your request. To exercise your right to appeal, you can submit and appeal request using the same method used to submit your original request, including by contacting us as described in this Notice.

SECURITY OF YOUR PERSONAL DATA

We take steps to ensure that your information is treated securely and in accordance with this Notice including devoting appropriate human and technical resources to ensure an adequate level of security including a developed set of policies and rules for the security of our information systems and networks. The purpose of these rules is to limit the risks of intrusion or illicit access to informationsystems. Unfortunately, no system is 100% secure, and we cannot ensure or warrant the security of any information you provide to us. To the fullest extent permitted by applicable law, we do not accept liability for unauthorized access, use, disclosure, or loss of personal data. By using our Services or providing personal data to us, you agree that we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use of our Services. If we learn of a security incident affecting your personal data, we may attempt to notify you electronically by posting a notice on our Services, by mail, or by sending an email to you.

RETENTION OF YOUR PERSONAL DATA

We store personal data we collect as described in this Notice for as long as you use our Services, or as necessary to fulfill the purpose(s) for which it was collected, provide our Services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws. Additionally, we endeavor to retain all such personal data in accordance with legal requirements, or based upon other criteria, including, but not limited to, the sensitivity and volume of such data.

CHILDRENS INFORMATION

Our Services are not directed to, nor intended to be attractive or of interest to persons under 16 years of age (“childrenâ€?) and we do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has uploaded personal data to our site without your consent, please Contact Us. If we become aware that a child has provided us with personal data in violation of applicable law, we will delete any personal data we have collected, unless we have a legal obligation to keep it, and if applicable, terminate the child’s account.

OTHER PROVISIONS

Third-Party Websites/Applications. The Services may contain links to other websites/applications and other websites/applications may reference or link to our Services. These third-party services are not controlled by us. We encourage our users to read the privacy policies of each website and application with which they interact. We do not endorse, screen, or approve, and are not responsible for, the privacy practices or content of such other websites or applications. You agree that if you elect to provide personal data to third-party websites or applications encountered on our Sites or through our Services, you do so at your own risk.

INTERNATIONAL DATA TRANSFERS

Some data collected by us may be transferred, processed, and stored anywhere in the world, including, but not limited to countries which may have data protection laws that are less protective than the GDPR and the UK GDPR. We require any importer of your personal data to apply safeguards required by the GDPR and the UK GDPR and take all necessary steps to ensure our subprocessors have implemented technical and organizational measures necessary to secure your personal data.

If we transfer your personal data from the European Economic Area, Switzerland, and/or the United Kingdom to or any country that has not been found to provide an adequate level of protection under the GDPR or the UK GDPR applicable data protection laws, one of the safeguards we may use to support such transfer is the EU Standard Contractual Clauses (“EU SCCsâ€?) and the International Data Transfer

Addendum to the EU SCCs.

CHANGES TO OUR NOTICE

We may revise this Notice from time to time in our sole discretion. If there are any material changes to this Notice, we will notify you as required by applicable law. You understand and agree that you will be deemed to have accepted the updated Notice if you continue to use our Services after the new Notice takes effect.