1. Overview and scope
This Privacy Policy explains how REACH Supply collects, uses, discloses, retains, transfers, and protects personal information when you use ReachSupplyCo.com, create an account, place an order, apply for a Trade Account, submit a compatibility, return, or warranty request, contact support, receive marketing, or otherwise interact with the U.S. store.
This Privacy Policy applies to information handled by REACH Supply through the website and related customer-service and business processes. It does not replace the privacy notices of payment processors, carriers, suppliers, or third-party services that process information under their own terms.
2. Accountability and privacy contact
REACH Supply is responsible for personal information under its control and designates a Privacy Officer to coordinate privacy practices, requests, complaints, service-provider oversight, retention, and incident response.
Privacy questions may be sent to [email protected]. Submit only the information reasonably needed to identify the account, transaction, or request.
3. Information we collect
Depending on how you interact with the store, we may collect the following categories:
- Identifiers and contact details: name, business name, email, telephone number, billing address, shipping address, account username, customer number, and online identifiers.
- Order and commercial information: products, quantities, prices, discounts, taxes, status, shipping, tracking, returns, refunds, warranty claims, invoices, quotes, and purchasing history.
- Payment-related information: payment-method type, billing details, authorization status, transaction status, and limited identifiers supplied by payment providers. We generally do not store complete payment-card numbers.
- Account information: protected credentials, saved addresses, preferences, order history, user roles, saved lists, approvals, purchase limits, and settings.
- Trade Account information: legal and operating business details, contacts, business type, purchasing needs, EIN or tax information, resale or exemption documentation, verification results, pricing group, and account communications.
- Support and product-fit information: equipment brand, model and serial number, existing part number, photographs, videos, installation details, technical findings, correspondence, and claim evidence. Uploaded files may incidentally contain other personal information, so submit only what is relevant.
- Internet, device, and usage information: IP address, browser, device, operating system, referring page, pages viewed, approximate location derived from IP, cookie identifiers, and interactions with the website or emails.
- Marketing and preference information: subscription choices, consent records, campaign interactions, advertising preferences, and unsubscribe status.
- Fraud, security, and compliance information: signals, risk scores, authentication records, logs, and other information used to prevent unauthorized transactions, account abuse, chargebacks, and security incidents.
- Inferences: inferences created from purchasing, browsing, account, or support activity to improve service, identify fraud risk, or present relevant products where permitted.
- Sensitive personal information: precise account credentials, payment information handled by processors, government or tax identifiers submitted for business verification, and the contents of private communications. We request that customers avoid submitting Social Security numbers or unrelated identification.
4. Sources of information
We collect information directly from you through checkout, accounts, forms, emails, calls, support requests, Trade Account applications, and uploaded files.
We collect some information automatically through essential cookies, server logs, security tools, and, where enabled subject to applicable choices, analytics or advertising technologies.
Information may also come from payment processors, carriers, suppliers, fulfillment partners, fraud-prevention providers, business registries, public business sources, advertising and analytics providers, and other parties involved in a transaction or account review.
5. How information is used
We may use personal information to:
- create, secure, and administer customer and Trade Accounts;
- verify identity, business information, addresses, payments, tax documentation, and eligibility;
- authorize and capture payments and process orders, shipments, refunds, returns, warranties, and disputes;
- identify products and assess compatibility using information supplied by the customer;
- communicate about orders, accounts, security, recalls, policies, and support;
- operate, secure, troubleshoot, personalize, and improve the website and services;
- measure website and campaign performance and understand customer journeys;
- provide marketing or targeted advertising where permitted and subject to applicable choices;
- prevent fraud, misuse, unauthorized access, and security incidents;
- meet tax, accounting, recordkeeping, regulatory, and legal obligations; and
- establish, exercise, or defend legal claims and enforce agreements.
We will not use personal information for a materially different purpose without any notice, consent, or other process required by applicable law.
6. Consent and permissions
We obtain consent where required, including for certain marketing, cookies, advertising technologies, or sensitive-information processing. Consent may be withdrawn subject to legal, contractual, security, and operational restrictions.
Some processing is necessary to provide requested products or services, protect accounts and transactions, comply with law, or pursue legitimate business purposes recognized by applicable law. Withdrawing an optional permission does not stop necessary transactional, account, recall, security, warranty, or support communications.
8. Suppliers and direct fulfillment
Many orders may be fulfilled directly by authorized suppliers, distributors, manufacturers, warehouses, or logistics partners. We may provide the information required to confirm, pack, ship, deliver, track, recall, return, or administer warranty service for an order.
This information may include the recipient name, company, shipping address, telephone number, email where required for delivery, products ordered, quantities, order references, and claim details. We do not provide complete payment-card details to fulfillment partners.
9. Payments, fraud screening, and automated tools
Payment providers displayed at checkout collect and process payment information under their own privacy notices and security standards. REACH Supply generally receives payment status, billing details, method type, and limited identifiers rather than the complete card number.
REACH Supply and its providers may use automated tools to assess payment, order, account, device, location, and behavioral signals for fraud and security risk. An order may be declined, delayed, limited, canceled, or referred for human review.
Where applicable law provides a right to information, review, or appeal concerning a qualifying automated decision, we will provide the required process.
11. Sale, sharing, targeted advertising, and Global Privacy Control
REACH Supply does not sell personal information for money. Certain disclosures involving advertising, analytics, cookies, or similar technologies may be treated as a “sale,” “sharing,” or targeted advertising under some U.S. state privacy laws even when no money changes hands.
Where applicable, customers may opt out through a “Your Privacy Choices,” “Do Not Sell or Share My Personal Information,” cookie-preference, or similar control made available on the website.
Where legally required and technically supported, REACH Supply will treat a recognized Global Privacy Control signal as an opt-out request for the browser or device sending the signal. A signal may not apply to information associated with a separate account unless the law requires or the user also submits an account-level request.
12. Marketing communications
Commercial emails are sent in accordance with applicable law. Marketing messages should accurately identify the sender, use non-deceptive subject lines, include required contact information, and provide a functioning unsubscribe method.
Unsubscribe requests are processed as required by law. Customers may still receive transactional, account, security, recall, warranty, or support messages after opting out of marketing.
The Federal Trade Commission provides CAN-SPAM compliance guidance.
13. Processing in other jurisdictions
Service providers, suppliers, fulfillment partners, and technology systems may process or store information in the United States or other countries. Information processed in another jurisdiction may be subject to that jurisdiction’s laws and lawful-access requirements.
REACH Supply uses contractual, technical, organizational, and other safeguards appropriate to the information and service.
14. Retention and disposal
We retain information only as long as reasonably necessary for the purposes described in this Privacy Policy and for order fulfillment, warranty, fraud prevention, tax, accounting, legal, dispute, security, and recordkeeping requirements.
Retention varies by information type, sensitivity, purpose, account status, and legal obligation. When information is no longer required, it is deleted, destroyed, or deidentified using measures appropriate to the information. Protected backups may retain information until the normal backup cycle removes it.
15. Security and privacy incidents
REACH Supply uses administrative, technical, and physical safeguards appropriate to the nature and sensitivity of the information, including access controls, encrypted connections, account protections, monitoring, backups, and service-provider controls. No system or transmission method is completely secure.
We maintain procedures to contain, assess, document, and respond to suspected privacy and security incidents. Where required, REACH Supply will notify affected individuals, regulators, consumer-reporting agencies, or other parties in accordance with applicable breach-notification laws.
The Federal Trade Commission provides data-breach response guidance for businesses.
16. U.S. state privacy rights
Depending on your state of residence, the nature of the information, and whether a particular law applies to REACH Supply, you may have rights to:
- confirm whether personal information is processed and request access;
- request correction of inaccurate personal information;
- request deletion, subject to legal exceptions;
- receive certain information in a portable format;
- obtain information about categories, sources, purposes, and recipients;
- opt out of sale, sharing, targeted advertising, or qualifying profiling;
- limit certain uses or disclosures of sensitive personal information where applicable;
- withdraw consent where processing depends on consent;
- appeal a denied request where applicable; and
- receive equal service and pricing without unlawful discrimination for exercising privacy rights.
Rights are subject to verification, scope, exceptions, frequency limits, and applicability thresholds. We may deny or limit a request where permitted by law and will explain available appeal or complaint options where required.
Authorized agents may submit requests where permitted, but we may require proof of authority and may verify the consumer directly.
17. California notice at collection
For California residents, the categories of personal information collected during the preceding 12 months may include identifiers; customer records; commercial information; internet or other electronic-network activity; geolocation derived from IP; audio, electronic, visual, or similar information submitted in support files; professional or employment-related information supplied for Trade Accounts; inferences; and sensitive personal information such as account credentials, payment information handled by processors, and government or tax identifiers used for business verification.
These categories are collected and used for the business and commercial purposes described in Sections 4 and 5 and may be disclosed to the categories of recipients described in Sections 7 and 8.
REACH Supply does not sell personal information for money. Advertising or analytics disclosures may be treated as sale or sharing under California law depending on the technology enabled. California consumers may have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive non-discriminatory treatment, subject to applicability and exceptions.
The California Department of Justice describes CCPA consumer rights and explains recognized opt-out mechanisms, including Global Privacy Control.
18. Children and minors
The store is intended for adults and business customers and is not directed to children under 13. We do not knowingly collect personal information online from a child under 13 without the notice and verifiable parental consent required by the Children’s Online Privacy Protection Act and its implementing rule.
If you believe a child has provided personal information, contact the Privacy Officer so the situation can be reviewed and appropriate action taken.
19. Changes to this policy
We may update this Privacy Policy to reflect changes in services, providers, technology, practices, or law. The revised page will show its effective and reviewed dates.
Material changes will receive any additional notice, consent, or choice required by applicable law.
20. Contact, privacy requests, and appeals
Questions about this Privacy Policy and requests to access, correct, delete, opt out, limit, appeal, or exercise another applicable privacy right may be submitted to:
Include your name, contact information, state of residence, a description of the request, and relevant account or order information. Do not email passwords, Social Security numbers, government identification images, or complete payment-card numbers.
We may verify identity, account ownership, state residency, and authorized-agent status before completing a request. If an applicable law gives you a right to appeal a denial, submit the appeal using the same contact method and identify it as a “Privacy Request Appeal.”
You may also contact the attorney general or privacy regulator with jurisdiction over your concern.
