USE OF COOKIES
The Online Store uses cookies. A cookie is a small text file that the web browser automatically saves to the device used by the customer. Cookies are used to collect information about how the customer uses the Online Store, with the aim of providing the customer with a better user experience.
The Online Store uses the following types of cookies:
- Session cookies, which are intended to enable the use of the Online Store;
- Persistent cookies, which are intended to remember the customer's choices in the Online Store;
- First and/or third-party cookies, which are intended to display relevant advertisements and offers to the customer;
- Third-party analytical cookies, which are intended to optimize marketing communications.
The customer can delete and/or block cookies stored on their device by changing the corresponding settings in their web browser. If cookies are not used, the Online Store may not function as intended and/or some functionalities may not be available to the customer.
In addition to the use of analytical cookies, the Online Store uses pixels (pixel tags, web beacons) to monitor the usage of the seller's website. In doing so, personal identification data is not processed.
PROCESSING OF PERSONAL DATA
Data Controller
The responsible data controller for the Online Store AutoExtra’s personal data is Autoextra OÜ (registration code 12090540), located at Värvi 5, Tallinn, email: shop@autoextra.ee.
Types of Personal Data Processed
- Name, phone number, and email address;
- Delivery address of the goods;
- Bank account number;
- Cost of goods and services and payment-related data (purchase history);
- Customer support data.
Purposes of Processing Personal Data
- Personal data is used to manage customer orders and to deliver goods.
- Purchase history data (purchase date, goods, quantity, customer data) is used to create an overview of purchased goods and services and to analyze customer preferences.
- Bank account numbers are used to refund payments to the customer.
- Personal data such as email, phone number, and customer name are processed to resolve issues related to the provision of goods and services (customer support).
- The Online Store’s user IP address or other network identifiers are processed to provide the Online Store as an information society service and to compile web usage statistics.
Legal Basis
- The processing of personal data is carried out for the purpose of fulfilling the contract concluded with the customer.
- The processing of personal data is carried out to comply with a legal obligation (e.g., accounting and resolving consumer disputes).
Recipients of Personal Data
Personal data is transmitted to the Online Store’s customer support for managing purchases and purchase history and for resolving customer issues.
- Name, phone number, and email address are transmitted to the transportation service provider chosen by the customer. If a courier is involved in delivering the goods, the customer’s address is also transmitted in addition to contact information.
- Accounting is handled by a service provider; personal data is transmitted to the service provider for performing accounting operations.
- Personal data may be transmitted to information technology service providers if necessary to ensure the functionality or data hosting of the Online Store.
Security and Access to Data
Personal data is stored on ShopRoller.com servers located in the territory of an EU Member State or a country associated with the European Economic Area. Data may be transmitted to countries whose data protection level has been assessed as adequate by the European Commission and to U.S. companies participating in the Privacy Shield framework.
Access to personal data is granted to the Online Store’s employees who need to access the data to resolve technical issues related to the use of the Online Store and to provide customer support services.
The Online Store implements appropriate physical, organizational, and IT security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized access, and disclosure.
Transmission of personal data to authorized processors (e.g., transportation service providers and data hosting) is carried out under contracts concluded between the Online Store and the authorized processors. Authorized processors are obliged to ensure appropriate protective measures when processing personal data.
Access and Correction of Personal Data
Customers can view and correct their personal data in their user profile on the Online Store. If a purchase was made without a user account, personal data can be accessed through customer support.
Withdrawal of Consent
If the processing of personal data is based on the customer’s consent, the customer has the right to withdraw their consent by notifying customer support via email.
Retention
- Upon closing the Online Store’s customer account, personal data is deleted unless such data needs to be retained for accounting purposes or for resolving consumer disputes.
- If a purchase was made on the Online Store without a customer account, the purchase history is retained for three years.
- In cases of disputes related to payments and consumer complaints, personal data is retained until the claim is fulfilled or until the expiration of the statute of limitations.
- Personal data necessary for accounting purposes is retained for seven years.
Deletion
To delete personal data, please contact customer support via email. Deletion requests will be responded to within no more than one month, specifying the period for data deletion.
Transfer
Requests for the transfer of personal data submitted via email will be responded to within no more than one month. Customer support will verify the identity and inform about the personal data that is subject to transfer.
Direct Marketing Communications
The email address and phone number are used to send direct marketing communications if the customer has given corresponding consent. If the customer does not wish to receive direct marketing communications, they must select the appropriate link in the email footer or contact customer support.
If personal data is processed for direct marketing purposes (profiling), the customer has the right to object at any time to both the original and subsequent processing of their personal data, including profiling related to direct marketing, by notifying customer support via email (the relevant information must be provided clearly and separately from any other information).
DISPUTE RESOLUTION
Disputes related to the processing of personal data are resolved through customer support via shop@autoextra.ee. The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).
For any further questions or concerns regarding this Privacy Policy, please contact us at shop@autoextra.ee.