GDPR-Related Details in the WPARTS User Privacy Notice
The WPARTS User Privacy Notice (effective October 1, 2025) incorporates principles aligned with the General Data Protection Regulation (GDPR) for users in the European Union (EU) and European Economic Area (EEA). As a U.S.-based company (WPARTS LLC), we comply with GDPR where it applies to our processing of EU/EEA personal data. Below, we outline the key GDPR-relevant sections and details from the policy, focusing on controllers, data processing, legal bases, rights, transfers, and more. This is not legal advice; for full context, refer to the complete notice.
1. Scope and Applicability
(Section 1)
- The policy applies to all users of WPARTS Services, including those in the EU/EEA.
- It covers personal data processing when using the website (wparts.com), apps, and related services.
- Changes to the policy are notified via account dashboard or email, ensuring transparency as required under GDPR.
2. Data Controller (Section 2)
- For EU/EEA residents (based on account address or location): WPARTS LLC acts as the controller under GDPR for data collection and processing.
- As a U.S. entity, we ensure GDPR compliance for EU/EEA data through appropriate safeguards.
3. Personal Data Collected
(Sections 3 and 4)
- Data includes name, email, shipping address, phone, payment info, account credentials, interactions (e.g., searches for car parts, purchase history), device info, IP address, and location data.
- For sellers: Business details, inventory, and shipping preferences.
- Data from third parties: From payment processors, shipping carriers, etc., for verification and fraud prevention.
- This aligns with GDPR's requirements for lawful, fair, and transparent collection, limited to what's necessary.
4. Purposes, Legal Bases, and
Recipients (Section 5)
- Purposes: Providing Services (e.g., buying/selling car parts, payments, shipping), improving the platform, fraud prevention, compliance with laws, marketing (with consent), and analytics.
- Legal Bases (explicitly GDPR-aligned):
- Performance of a contract: E.g., processing orders and deliveries.
- Legitimate interests: E.g., security, fraud detection, personalization.
- Consent: For marketing communications, precise location data, storing financial info, single sign-on, biometric data (for sellers), and other optional services.
- You can withdraw consent anytime (see Section 8).
- Recipients: Data is shared with external providers (e.g., payment processors, shipping carriers), partners (e.g., auto parts suppliers), and third parties for specific services. Sharing is minimized and based on necessity.
- Automated Decision-Making (Section 5.8): Used for fraud detection; no solely automated decisions with significant effects unless contractual, consented, or legally required. You have the right to human review.
- Payment Services (Section 5.7): Data shared with financial institutions, credit agencies, authorities for compliance (e.g., anti-fraud).
- International Data Transfers (Section 6)
- Data may transfer outside the EU/EEA (e.g., to USA), where protections differ.
- Safeguards: Standard Contractual Clauses (SCCs) or other GDPR-approved mechanisms to ensure adequate protection.
- This complies with GDPR Chapter V requirements for cross-border transfers.
- Data Storage and Security (Section 7)
- Retention: As long as needed for Services or legal obligations (e.g., tax/compliance records).
- Security: Industry-standard measures against unauthorized access, loss, or misuse, including encryption and access controls.
- Aligns with GDPR's security and data minimization principles.
- Data Subject Rights (Section 8)
- GDPR rights are fully supported:
- Access: View your data.
- Rectification: Correct inaccuracies.
- Erasure ("right to be forgotten"): Delete data under certain conditions.
- Restriction: Limit processing.
- Objection: Oppose processing based on legitimate interests (e.g., marketing).
- Portability: Receive data in a structured format.
- Withdraw consent: At any time, without affecting prior processing.
- Exercise rights via the Help Center or contact privacy@wparts.com.
- No fee for requests unless excessive; responses within one month (extendable under GDPR).
- Cookies and Similar Technologies (Section 9)
- Used for functionality, analytics, and ads.
- Consent-based where required; manage via browser or cookie tool.
- Complies with GDPR/ePrivacy Directive consent rules.
- Message Filtering (Section 10)
- Automated review of messages for fraud/spam; minimal human access unless needed.
- Based on legitimate interests for platform integrity.
- Regional Disclosures (Section 13)
- Additional EU/EEA-specific rules may apply, such as under GDPR.
- For complaints: Contact the controller or your local data protection authority (e.g., in Germany: Berliner Beauftragte für Datenschutz und Informationsfreiheit).
- Contact and Complaints (Section 14)
- Questions: privacy@wparts.com or Help Center.
- Under GDPR, you can lodge complaints with supervisory authorities if unsatisfied.
If your query relates to a specific aspect (e.g., consent withdrawal process), provide more details for tailored info. For official GDPR guidance, consult the EU's official resources or a legal expert.
Compliance Check and Corrections Summary
- Adaptations Made: Updated company name to WPARTS LLC. Removed references to international affiliates (e.g., EU/Germany, Singapore, Luxembourg entities) as the company is now a single U.S. LLC. Simplified controller section to reflect sole U.S. entity. Retained GDPR elements in the second document but framed them as compliance for EU users by a U.S. company.
- US Law Compliance:
- CCPA/CPRA (California): Expanded Section 8 and 13 in the Privacy Notice to explicitly include CCPA rights (e.g., right to know, delete, opt-out of sale/sharing, limit sensitive data use, non-discrimination). Added mechanisms for requests (email, toll-free number, web form). Confirmed no "sale" or "sharing" occurs, but provided opt-out info. This ensures compliance as the company is in California and may handle CA consumer data.
- General US Laws: No issues with COPPA (no child-directed services), CAN-SPAM (consent for marketing), or FTC guidelines (transparent practices). Automated decision-making disclosures align with fairness requirements. Security measures are industry-standard, complying with FTC expectations.
- No Major Corrections Needed Beyond Adaptations: Original documents were generally compliant but international-focused; adaptations make them U.S.-centric while preserving global applicability. No deceptive practices identified. If serving EU users, GDPR compliance is maintained via safeguards like SCCs. Consult a U.S. attorney for final review.