Allparts
Allparts UK Ltd Cookie and Privacy Policy
 
About this policy
 
This is the privacy policy of Allparts UK Ltd.  It applies only to personal data as defined in
General Data Protection Regulation (GDPR) (EU) 2016/679 applicable as of May 25th, 2018 in all member states to harmonize data privacy laws across Europe.
 
The policy tells you
  • who we are,
  • what personal information we collect and how we collect it through our websites,
  • what we use that information for,
  • any third parties with whom we share it,
  • how we keep it secure
  • what options you have to access update or otherwise take control of your personal data that we process
  • if and how we transfer your information outside the European Economic Area (‘EEA’).
 
Please read the policy carefully. By accessing or using this web site you are deemed to agree to the terms of this privacy policy, and if you do not agree with it, then you must not send us any personal information.
 
Note that if you follow a link from this site to another site, this policy will no longer apply. We are not responsible for other sites’ information handling practices. Use of your information by the owner of the linked site will normally be governed by that site’s privacy policy, which we encourage you to read.
 
Further information about the General Data Protection Regulation, privacy and data protection issues can be found on the Information Commissioner’s website at www.ico.org.uk.

Who we are
 
Allparts UK Ltd  is a company registered in England and Wales with company registration number 04954387, dated 05/11/2003.  
 
Our registered office is at:
3 Manor Courtyard,
Hughenden Avenue,
High Wycombe HP13 5RE  

Our normal business address is
Allparts UK Ltd
Unit 2 TRADA Business Campus,
Stocking Lane,
Hughenden Valley,
High Wycombe,
Bucks, HP14 4NB,
United Kingdom
 
.Please see our contact section for more information.
 
If you have any queries about the information we hold on you, please contact our Data Protection Officer, who you may write to at the normal business address above, or by emailing info@allparts.uk.com, raising a helpdesk ticket, or by telephoning on UK : +44(0) 1494 410050.
 
What personal info we collect and how we collect it
 
Allparts UK Ltd uses web based services that need your information in order to
  • take orders, administer product purchase and stock control, deliver goods and to prepare accounts and provide legally required information for tax and accounting purposes
  • to update you as customers or as someone who has signed in to receive selected marketing or technical information
These services are:
  • E-commerce websites
  • Back office administration system - online and paper records
  • Online payment systems
  • Postal and shipping providers
  • Customer support
  • Customer marketing
 
By cookies
 
Cookies are used to ensure the smooth functioning of the website and to aid your experience using it. Cookies are small files which are stored on a user's computer. They are designed to hold a modest amount of data specific to a particular client and website, and can be accessed either by the web server or the client computer. This allows the server to deliver a page tailored to a particular user, or the page itself can contain some script which is aware of the data in the cookie and so is able to carry information from one visit to the website (or related site) to the next.
Cookies are not computer programs, they can't read other information saved on your hard drive, and are not used to recognise you as an individual.
They cannot be used to spread viruses, or get a user's email addresses etc.
 
Our websites uses cookies to provide a smooth and easy experience while visiting the website.  Upon accessing the website for the first time the following message is displayed
We use cookies to provide a great shopping experience.  By continuing to browse you agree to using cookies and to our privacy policy.
You are invited to clearly confirm your agreement and consent by clicking the I accept the use of cookies button.
 
This complies with recent GDPR legislation requirements for websites to obtain explicit consent from users before leaving behind or reading files such as cookies on a user’s computer / device.




Our website, like many others uses Google Analytics in order to monitor the performance of the website and help improve usability.
 
Examples of cookies are included in Appendix 1 below
If you would like to restrict or disable the use of cookies you can control this in your Internet browser.  
 
By your consent
 
When you make a purchase from Allparts UK Ltd , as part of the buying and selling process, we collect the personal information you give us such as your name, address, telephone number(s) and email address and retain a copy of the order and only the information contained within - this is used purely to record the transaction should we need to refer to it at a later date for accountancy, stock control and administration of orders.
 
This is done through the ecommerce websites or by telephone, fax, email or letter.
 
This information is treated as fully confidential.
 
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, by implication you consent to our collecting it and using it for that specific reason only.
 
By registration
If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no.
 
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at info@allparts.uk.com or by post to our normal business address
 
With your permission, we may send you emails about our store, new products and other updates. You can use the opt out option to unsubscribe if you choose
 
Third parties with whom we share your information
 
In general, the third-party providers used by us are trusted and will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us and will have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
 
For all these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers. - see Appendix 2 for a list of links to access their privacy policies
 
In particular, remember that certain providers may be located in or have facilities that are located outside the UK or Europe.  So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
 
Once you leave our store’s website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s Terms of Service.
 
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
 
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.  We will never release your personal details to third parties for mailing or marketing purposes.
 
For a full explanation of our collection and handling of data please see below.

E-commerce websites
Our stores at www.allparts.uk.com and www.allpartsuktrade.com are hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
 
Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
 
We also use apps on or linked to the websites that use personal information to improve our service to you.  These currently comprise:
Now in Stock
Bold Store Locator
Powr - Formbuilder
Google Analytics
Royal Mail Shipping Extensions
Persistent Cart
Hindsight
MailChimp
ZenDesk
SagePay
PayPal
Shiptheory

Back office administration system
We use Brightpearl to handle stock control and order fulfilment linked with online payment systems and shipping management software
SagePay
PayPal
Shiptheory

Online payment systems
When you choose a payment gateway from the checkouts on the websites to complete your purchase, your credit card data is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored within Brightpearl only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted or destroyed if recorded on paper.
 
The payment gateways used via Shopify are
Sagepay
PayPal
 
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.  PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
 
For orders taken over the phone or via email, fax or letter payment is take via Sagepay if credit/debit cards are used orvia an online link to Paypal if that option is chosen
 
Postal and shipping providers
We currently use
  • Royal Mail - information is provided direct and via Shiptheory, a Brightp partner app
  • DPD
  • World Options which enables multiple shipping options using a variety of carriers
These use address and telephone information to facilitate their service to you.
 
Customer support and marketing
We use Brightpearl and Googlemail to send enable email support with relevant emails to you on products, sales orders, backorders and resolution of service problems
 
We use Brightpearl & Mailchimp to send our group emails on product and sales information and on customer service information, news and marketing information.  All marketing emails will have the opportunity to opt out or unsubscribe.
 
We use Zendesk to run our helpdesk system in conjunction with Googlemail.  This functions via e-mail but we may ask for telephone numbers or other contact information to help resolve questions.

How we keep your information secure
 
To protect your personal information, we take appropriate precautions and follow industry best practices to make sure it is not lost, misused, accessed, disclosed, altered or destroyed.
All software has person specific log-ons for staff and software administrators.
 
Your rights and options
 
In compliance with GDPR legislation we offer the Right to Erase, the right of a person to withdraw their consent for data processing if there is there is “no overriding legitimate interest” for ourselves to hold it. Please contact our customer services department with your details and we will advise on how to proceed with your data erasure application.
 
Please note we are only able to allow the full deletion of a customer’s data where there is no transaction history – this being an overriding legitimate interest for retaining the data for the benefit of both the customer and the website owners.
 
You can review the personal data we hold via your personal account logins on Shopify if you have purchased via the websites, or in Brightpearl if you purchased via phone, fax, email or letter
 
Transfers outside Europe
For our primary software
 
Brightpearl states:
We are obliged to satisfy ourselves before transferring your information to a country outside the EEA that it provides adequate protection for your data protection rights. The EEA comprises the EU countries and Norway, Iceland and Liechtenstein. Countries outside the EEA may not give the same level of protection to your information as those within the EEA.
 
Our servers are hosted in the UK, London. No company or personal data is stored outside the EEA.
 
Shopify states:
Where a Data Subject is located in the European Economic Area, that Data Subject’s Personal Data will be processed by Shopify’s Irish affiliate, Shopify International Ltd. As part of providing the Services, this Personal Data may be transferred to other regions, including to Canada and the United States. Such transfers will be completed in compliance with relevant Data Protection Legislation.
 
Information for our other providers can be obtained via the contact details in Appendix 2.
 
Age Restrictions
 
By using our sites, you represent that you are at least the age of majority in your country  of residence, or that you are the age of majority in your country of residence and you have given us your consent to allow any of your minor dependents to use our sites.

Changes to this Privacy Policy
 
We reserve the right to modify this privacy policy at any time.  Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.
 
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.

 
Questions and contact information
 
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Data Protection Officer at info@allparts.uk.com or by mail at:
 
Allparts UK Ltd
Unit 2 TRADA Business Campus,
Stocking Lane,
Hughenden Valley,
High Wycombe,
Bucks, HP14 4NB,
United Kingdom

© Allparts UK Ltd
Effective Date: 25 May 2018
 
----





 
Appendix 1 - Sample list of cookies
 
Here is a list of some of the cookies that we use on the websites. We’ve listed them here so you can choose if you want to opt-out of cookies or not.
  •  _session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
  • _shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
  • _shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
  • cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
  • _secure_session_id, unique token, sessional
  • storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
 
For a full list see:
  • https://www.shopify.com/legal/cookies?utm_source=exacttarget&utm_medium=email&utm_campaign=support&utm_content=gdpr
 
 
Appendix 2
List of software and app providers
So you can investigate further the privacy policies of our software providers if you wish, here are the company names and website addresses.  You can search ‘terms of service’ as well as cookie and privacy policies.:
 
Our main business software:
  • Shopify - Shopify Inc - www.shopify.co.uk
  • Brightpearl - Brightpearl - www.brightpearl.com
 
Supporting apps
  • Now in Stock - mascot software technologies pvt ltd - www.shopapps.in
  • Bold Store Locator - BOLD - www.boldcommerce.com 
  • Powr - Formbuilder - POWr - www.powr.io 
  • Google Analytics - Google Analytics Solutions - www.google.com/analytics 
  • Royal Mail Shipping Extensions - Veeqo - www.78e.co.uk 
  • Persistent Cart - Customer First focus - www.customerfirstfocus.com 
  • Hindsight - Eastside Co - www.eastsideco.com 

    • SagePay - www.sagepay.co.uk/policies/privacy-policy 
    • PayPal - PayPal Inc - www.paypal.com/uk/webapps/mpp/ua/privacy-full
       
      • Shiptheory - https://shiptheory.com/privacy 
      • Royal Mail -  Royal Mail Group Limited - www.royalmail.com/privacy-notice 
      • DPD - DPD Group - http://www.dpd.co.uk/gdpr.pdf 
      • World Options - World Options Ltd - http://uk.worldoptions.com/privacy-policy 

      • MailChimp - part of The Rocket Science Group - https://mailchimp.com/legal/privacy/ 
      • ZenDesk - Zendesk Inc - see help.zendesk.com/hc/en-us/articles/360000586767-Complying-with-GDPR-in-Zendesk-products 
      • Googlemail or gmail - policies.google.com 
        
      --:--