DATA PROTECTION CONTACT
San Antonio, Texas 78219
Telephone Number: (833) 258-2058
TYPES OF PERSONAL INFORMATION COLLECTED
Personal Information is defined as any information that can be used to identify a California Resident or household either on its own or when combined with other available information. Personal information does not include information that is: (a) publicly available information from government records, (b) de-identified or aggregated personal information, or (c) certain other information excluded from the scope of CCPA.
Unless specified otherwise, the personal information requested by the XPEL website is required for the website to provide its services.
The following chart enumerates the categories of personal information XPEL collects about California residents in the preceding 12 months.
Category of Personal Information
Collected by XPEL?
1. Identifiers, such as name, contact information, IP address, and other online identifiers.
2. Personal information categories listed in the California Customer Records statute, such as name, address, telephone number, bank account number, credit card number, or debit card number, some of this information may overlap with other categories.
3. Vehicle information including license plate number, car make and model, and vehicle identification (VIN) number
4. Commercial information, such as transaction information and purchase history records of products considered or other purchasing or consuming histories or tendencies.
5. Internet or network activity information, such as browsing history and interactions with our website.
6. Geolocation data, such as device location.
7. Audio, electronic, visual, similar information, such as call and video recordings.
8. Professional or employment-related information.
9. Characteristics of protected classifications under California or federal law, such as sex, age, and marital status.
10. Biometric information, such as fingerprints and voiceprints.
11. Education information subject to the federal Family Educational Rights and Privacy Act, such as student records.
12. Inferences drawn from any of the personal information listed above to create a profile about, for example, an individual’s preferences and characteristics.
EMPLOYEES AND JOB APPLICANTSIn addition to the personal information listed above, XPEL also collects and discloses the following personal information from employees, independent contractors, owners, directors, officers, and job applicants, as well as their emergency contacts, dependents and beneficiaries, for purposes of operating, managing, and maintaining our business, managing our workforce (including recruitment), and administering benefits:
Category of Personal Information
Collected by XPEL?
1. Identifiers, such as Social Security numbers and other government-issued ID numbers.
2. Personal information, as defined in the California customer records law, such as health and health insurance information.
3. Characteristics of protected classifications under California or federal law, such as race, religion, national origin, disability, request for leave, citizenship, and immigration/work authorization status.
4. Professional or employment-related information, such as information relating to references, CV, details of qualifications, human resources data, and data necessary for benefits and related administration services.
5. Education information subject to the federal Family Educational Rights and Privacy Act, such as student records.
Personal Information Collected from Third Parties
XPEL collects most of the personal information directly from you. However, we also collect the following information about you through third-parties:
In addition, in some instances, XPEL collects personal information about you from service providers, advertising networks, and social media platforms.
WHEN XPEL COLLECTS YOUR PERSONAL INFORMATION
XPEL collects your personal information as follows:
- when you voluntarily provide it to us on the website or offline
- when you sign up to receive emails, alerts, or other communications
- when you communicate with us either on the website or offline,
- when you access and browse the XPEL website and
- from third-party sources
HOW WE USE YOUR PERSONAL INFORMATION
XPEL uses your personal information for various business purposes including:
- Providing website functionality and fulfilling your requests. More specifically XPEL uses your information to:
- provide a tailored website experience including allowing you to access your registered account and providing account-related customer service
- respond to requests for dealer information and to schedule installation, service, or repair appointments
- respond to your questions, suggestions, compliments, and/or complaints submitted through XPEL’s online contact forms or otherwise
- fulfill requests submitted through XPEL’s online portals
- complete transactions, verify your information and provide transaction-related customer service
- provide you with administrative information including updated terms, conditions, and policies
- Providing you with our newsletter and/or other marketing materials. More specifically, XPEL uses your personal information to send you marketing-related emails, with information about XPEL’s services, new products, and other news about the company.
- Preparing reports and providing personalized services. More specifically, XPEL uses your information to:
- analyze or predict user preferences to prepare aggregated trend reports on how XPEL’s digital content is used and to improve our services and enhance the functionality of the website
- understand your interests and preferences, so that XPEL can personalize our interactions with you and provide you with information and/or offers tailored to your interests
- understand your preferences so that we can deliver content via the website relevant and interesting to you
- Allowing participation in sweepstakes, contests, or other promotions. More specifically, XPEL uses your information to offer you the opportunity to participate in sweepstakes, contests, or other promotions. Some of these promotions have additional rules containing information about how we will use and disclose your personal information. Please read those additional rules before choosing to participate.
- Accomplishing XPEL’s business purposes. More specifically, XPEL uses your information for:
- data analysis, for example, to improve the efficiency of our website
- audits, to verify that our internal processes function as intended and to address legal, regulatory, or contractual requirements
- fraud and security monitoring purposes, for example, to detect and prevent cyberattacks or attempts to commit identity theft
- developing new products and services
- enhancing, improving, repairing, maintaining, or modifying our current products and services, as well as undertaking quality and safety assurance measures
- identifying usage trends, for example, understanding which parts of our website are of most interest to users
- effectiveness of our promotional campaigns, so that we can adapt our campaigns to the needs and interests of our users; and
- operating and expanding our business activities, for example, understanding which parts of our products and services are of most interest to our users so we can focus our energies on meeting our users’ interests.
- Aggregating and/or anonymizing data. More specifically, XPEL may use aggregated and/or anonymize personal information for its business purposes. In such circumstances, all personal identifiers will be removed from the data prior to its use or disclosure.
XPEL will only use your personal information for the purposes for which it was collected, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose, or as otherwise required by law. If we need to use your personal information for an unrelated purpose, where we are legally permitted, we will notify you promptly and explain the legal basis which allows us to do so.
DISCLOSURE OR SALE OF PERSONAL INFORMATION
In the preceding 12 months, XPEL, for business purposes, disclosed the following categories of personal information to third-parties:
- California Customer Records Personal Information categories (g. name and contact information)
- vehicle information including license plate number, car make and model, and vehicle identification (VIN) number
- Commercial information
- Internet or other electronic network activity (e.g. “cookies” or other tracking tags)
- Geolocation data
- Audio, electronic, visual, similar information
- Professional or employment-related information
- XPEL may disclose personal information for a business purpose to the following categories of third-parties:
- Affiliated or related entities: XPEL shares your personal information with our affiliated or related entities including wholly-owned or third-party dealers, as necessary, to carry out the purposes for which the information was supplied or collected.
- Service providers: XPEL uses third-parties to assist with the running of the website and providing our services including hosting providers, IT providers, software providers, marketing database providers, payment processing providers, and professional services providers (g., accountants, tax advisors, legal counsel, and consultants). To obtain these services, XPEL needs to share your personal information with such third-parties. Our third-party service providers are subject to security and confidentiality obligations and are only permitted to process your personal information for specified purposes and per our direction.
In addition, XPEL may disclose personal information to advertising networks or social media platforms. An updated list of these third-parties with whom your personal information is shared may be requested from XPEL by using the contact information in the Contact Details section above.
In addition, XPEL may disclose information about you in the following circumstances:
- If XPEL sells or buys any business or assets, we may disclose your personal information to the prospective seller or buyer of such business or assets, including to permit the due diligence required to decide whether to proceed with a transaction,
- If all or substantially all of XPEL’s assets are acquired by a third-party, personal information held by XPEL about its customers will be one of the transferred assets,
- If XPEL is under a duty to disclose or share your personal information to comply with any legal or regulatory obligation,
- If necessary, to protect the vital interests of a person,
- To enforce or apply our terms and conditions or to establish, exercise, or defend the rights of XPEL, our employees, customers, or others.
- To third-party sponsors of sweepstakes, contests, and similar promotions, and
- With your consent
- *XPEL does not sell your personal information.
XPEL retains your personal information no longer than is reasonably necessary for the purposes for which it was collected and processed and in accordance with XPEL’s data retention policy, except as required by applicable law or to comply with our legal obligations, resolve disputes, and enforce our agreements.
PROTECTING PERSONAL INFORMATION
In accordance with the CCPA and applicable data protection laws, XPEL has implemented appropriate physical, electronic, and administrative safeguards to protect your personal information from loss, misuse, unauthorized access, disclosure, alteration, destruction, or modification.
These measures are regularly reviewed, evaluated, and updated to proactively identify new or emerging security threats.
Where data processing is carried out on XPEL’s behalf by a third-party, XPEL takes steps to ensure that appropriate security measures are in place to prevent unauthorized disclosure of personal information.
Unless otherwise provided in applicable data protection laws, you have the following rights related to your personal information:
- Right to know. You have the right to request that we disclose the following to you: (1) the specific pieces of personal information we have collected about you; (2) the categories of personal information we have collected about you; (3) the categories of sources from which we have collected your personal information; (4) the categories of personal information we have disclosed for a business purpose; and (5) the categories of third parties to whom we have shared your personal information. You also have the right to request that we disclose the business purpose(s) for collecting or sharing your personal information.
- Right to access. You have the right to access the personal information we hold about. When requested (as described below), we will provide, free of charge, the personal information as required by the CCPA. To the extent possible, the information will be provided in a portable and commonly used format so that it can be transferred to another entity.
- Right to Request Deletion. In certain circumstances, you have the right to request the erasure of your personal information. Upon verifying the validity of your deletion request, we will delete your personal information from our records, and direct any service providers to delete your information, as required by the CCPA.
- Right to Opt-Out of the Sale of Personal Information. XPEL does not sell personal information as defined by the CCPA.
- Right to Non-discrimination. You have the right not to be discriminated against in service or price if you exercise any of your privacy rights.
Please note that the above rights are not absolute, and XPEL may be entitled to refuse or limit the requests, where exceptions under the applicable law apply.
EXERCISING YOUR RIGHTS
You may authorize another person (your “agent”) to submit a request on your behalf. If an authorized agent will be submitting a request for you, please have them send the request to firstname.lastname@example.org and provide the name, email address, contact number and account number, if any for the consumer. Where XPEL has reasonable doubts concerning the identity of the person making the request, we may request additional information necessary to confirm your identity.
This website is not directed at children, and XPEL will not knowingly accept or request personal information from individuals under the age of 16 years. If we learn that we have collected personal information from a child under 16, subject to applicable law, we will either (i) delete this information from our databases, in accordance with our deletion procedures; or (ii) obtain verifiable parental consent, in accordance with the Children's Online Privacy Protection Act.
This website may, from time to time, contain links to and from the websites of our advertisers and affiliates, including social media networks. If you follow a link to any of these websites, please note that these websites have their own data privacy policies, and XPEL does not accept any responsibility or liability for these policies. Please check these policies before you submit any personal information to these websites.
RAISING A COMPLAINT
Effective Date: 08/06/2020
Last Updated: 08 /19/2020