Privacy Policy

1. Introduction
2. What information do we collect about you?
3. How will we use that information?
4. Overseas transfers
5. Your rights
6. Data privacy and security
7. Location Tracking
8. Disclaimers
9. Accessibilty
10. General
 

1. Introduction

 

Halfords Group PLC ("Halfords") is the UK's leading retailer of car parts, car enhancement, camping and touring equipment and bicycles. As an additional and complementary service, we provide both physical and e-Voucher gift cards to customers.

 

In order to facilitate the creation and delivery of our gift cards, we collect and manage customer data. In doing so, we observe UK data protection legislation, and are committed to protecting and respecting customers’ privacy and rights. Together with Voucher Express (part of Hemingways Marketing Services) who administers this service on our behalf, we act as “Joint Data Controllers” in respect of the information gathered and processed by this website.

 

In order that you are reliably informed about how we operate, we have developed this Privacy Statement. Together with any additional Privacy Notices which you may see as you navigate around this website, this Privacy Statement describes the ways in which we collect, manage, process, store and share information about you as a result of you visiting this site. This Privacy Statement also provides you with information about how you can have control over our use of your data.

 

If you have any comments or queries regarding our use of your data, please contact our Data Protection Officer by email at dataprotectionofficer@halfords.co.uk or by post at Data Protection Officer, Halfords, Icknield Street Drive, Washford West, Redditch B98 0DE.  

 

2. What information do we collect about you?

 

In general terms, we seek to collect information about you so that we can fulfil gift card orders that you may make via this website.

 

The information that we need for these purposes is known as your “personal data”. This includes your name, home address and e-mail address. We collect this in a number of different ways. For example, you may provide this data to us directly when filling in forms on this website, or when corresponding with us by telephone, e-mail or letter.

 

Please be advised that by using this website, we will not be collecting any special categories of data about you (i.e. data about your ethnicity, religion, health etc).

 

Please also be advised that when you visit this website, cookies will be used to collect information about you such as your Internet Protocol (IP) address which connects your computer or mobile device to the internet, and information about your visit such as the pages you viewed or searched for, page response times, download errors etc. We do this so that we can measure our website’s performance and make improvements in the future. Cookies are also used to enhance this website’s functionality and personalisation. You can control this by adjusting your cookies settings as described in section 4 of our Cookies Policy here.

3. How will we use that information?

 

We use the data collected from you for the specific purposes listed in the table below. Please note that this table also explains:

 

 

Data that is collected by cookies is not included in the table below, but is explained in section 3 of our Cookies Policy here.

 

Purpose for processing data

Lawful basis for processing data

Third party organisations with whom data is shared

Data retention period

To fulfil orders for physical or e-Voucher gift cards which you may make via this website: this includes the processing of your order, the arrangement of delivery etc

To meet the requirements of contract law

Customer details will be available to Bliss who helps develop and implement this site. Order information is also saved within the Khaos sales system.

 

This website also supports a postcode finder service provided by PCA which predicts customer address details in order to provide a faster, smoother online experience.

Data relating to physical gift cards is kept for 2 years, whilst data relating to e-Voucher gift cards is kept for 4 years

To process credit / debit card payments

To meet the requirements of contract law

Halfords’ gift card service uses Mastercard, Visa, American Express and all other major credit / debit card companies. In processing credit / debit card information, customer data will also be shared with the Realex Payment Gateway, and Experian for purposes of fraud prevention.

Data relating to physical gift cards is kept for 2 years, whilst data relating to e-Voucher gift cards is kept for 4 years

To communicate with you via email where appropriate in order to update you about your specific order

To meet the requirements of contract law

Data is shared with SendGrid who distributes emails relating to gift cards including for the purpose of order confirmations

Data is retained for 90 days

To provide customer services support by telephone, email or letter: this includes the recording of telephone conversations for monitoring and quality purposes

This is deemed legitimate as it is in customers’ interest that we can access their data in order to resolve any queries, questions, concerns or complaints

Customer services information will be recorded on the Khaos sales system.

 

 

 

Data relating to physical gift cards is kept for 2 years, whilst data relating to e-Voucher gift cards is kept for 4 years

To send you emails about Halfords’ special offers and promotions that are relevant to you, as well as helpful reminders: this includes, for example, emails about offers during peak periods (i.e. New Year, Black Friday etc), abandoned baskets, as well as products or services that you have asked us to tell you about (for further detail, please refer to the Halfords’ Privacy Statement which is available at www.halfords.com/advice/customer-services/policies-regulations?topCategoryId=292503#tab_privacypolicy

Customers will be asked for their consent before we send marketing communications

Customer details will be held in Halfords’ customer database which is managed by Planning-Inc. Emails will be sent by Cheetah Digital

6 years from the end of the final transaction or end of the corresponding warranty period

 

Please be advised that if you store your e-Voucher gift card in an Apple or Samsung electronic wallet, you may be sent notifications about your purchase. If you do not wish to receive these, you will need to change your Apple or Samsung settings.

 

4. Overseas transfers

 

We may transfer to and store the information we collect about you in countries other than the country in which the information was originally collected, including the United States and other destinations outside the European Economic Area (“EEA”), in accordance with applicable law. Those countries may not have the same data protection laws as the country in which you provided the information. When we transfer your information to other countries, we will protect the information as described in this Privacy Statement and comply with applicable legal requirements providing adequate protection for the transfer of information to countries outside the EEA. This includes by entering into the European Commission’s EU Standard Contractual Clauses with the data recipient or ensuring that the data recipient has implemented Binding Corporate Rules. To obtain a copy of the safeguards we have put in place, please contact us as indicated below.

5. Your rights

 

Under the terms of data protection legislation, you have the following rights as a result of using this website:

 

5.1   Right to be informed

This Privacy Statement, together with our Cookies Policy, fulfils our obligation to tell you about the ways in which we use your information as a result of you using this website.

 

5.2   Right to access

You have the right to ask us, in writing, for a copy of any personal data that we hold about you. This is known as a “Subject Access Request”. Except in exceptional circumstances (which we would discuss and agree with you in advance), you can obtain this information at no cost. We will send you a copy of the information within 30 days of your request. To make a Subject Access Request, please write to our Data Protection Officer at Halfords, Icknield Street Drive, Washford West, Redditch B98 0DE. 

 

5.3   Right to rectification

If any of the information that we hold about you is inaccurate, you can contact our Data Protection Officer at dataprotectionofficer@halfords.co.uk. Any corrections that you request will be made as soon as possible, and certainly no later than 30 days following your notification.

 

5.4   Right to be forgotten

You can ask that we erase all personal information that we hold about you. Where it is appropriate that we comply, your request will be fully actioned within 30 days. For further information, please contact our Data Protection Officer at dataprotectionofficer@halfords.co.uk.

 

5.5   Right to object

You have the right to object to the continued use of your data for any purpose listed in section 3 of this Privacy Statement for which the lawful basis of processing is that it has been deemed legitimate. Please contact our Data Protection Officer at dataprotectionofficer@halfords.co.uk.

 

Please note that you can also exercise your right to object to our use of cookies by following the guidance in section 4 of our Cookies Policy here.

 

5.6   Right to restrict processing

If you wish us to restrict the use of your data because (i) you think it is inaccurate but this will take time to validate, (ii) you believe our data processing is unlawful but you do not want your data erased, (iii) you want us to retain your data in order to establish, exercise or defend a legal claim, or (iv) you wish to object to the processing of your data, but we have yet to determine whether this is appropriate, please contact our Data Protection Officer at dataprotectionofficer@halfords.co.uk.

 

5.7   Right to data portability

If you would like us to move, copy or transfer the data that we hold about you to another organisation, please contact our Data Protection Officer at dataprotectionofficer@halfords.co.uk. Please be advised that this only applies to certain data which has been submitted by you electronically for specific purposes only. Our Data Protection Officer can provide further advice.

 

5.8   Rights related to automated decision-making

We do not use automated decision-making processes in relation to any information collected via this website.  

 

6. Data privacy and security

 

Both Halfords and Voucher Express take customer privacy very seriously, and therefore ensure that data protection is a key consideration of all new and existing IT systems. Where any concerns, risks or issues are identified, we conduct relevant impact assessments in order to determine any actions that are necessary to ensure optimum compliance with data protection legislation.

 

We also maintain an active information security work programme which seeks to protect the availability, confidentiality and integrity of all physical and information assets. Specifically, this helps us to:

 

We recognise that the security of data and transactions on this website is of primary importance. We therefore ensure that all connections to secure parts of the website are encrypted and authenticated using strong protocols, key exchanges and ciphers. All collected information is stored on our secure systems on encrypted databases, and credit card numbers are wiped from our computer database following payment and despatch of gift cards.

 

Additionally, Voucher Express employs Verified by Visa / MasterCard Securecode which allows customers to protect their credit cards online by assigning a secret password. If you have joined the scheme, you will be required to provide your password during completion of your order. Voucher Express has no knowledge of, or access to, your password. To maintain secrecy, your password is submitted directly to your card issuer over a secure link, and does not get seen or stored by our system.

 

7. Location Tracking

 

This website does not use geo-location tracking, which shows us where you are in the UK.

 

8. Disclaimers

 

Every effort is made to ensure that the information provided on this website, and in this Privacy Statement, is accurate and up-to-date, but no legal responsibility is accepted for any errors or omissions contained herein.

 

We cannot accept liability for the use made by you of the information on this website or in this Privacy Statement, nor do we warrant that the supply of the information will be uninterrupted. All material accessed or downloaded from this website is obtained at your own risk. It is your responsibility to use appropriate anti-virus software.

 

This Privacy Statement applies solely to the data collected by us, and therefore does not also apply to data collected by third party websites and services that are not under our control. Furthermore, we cannot be held responsible for the Privacy Statements on third party websites, and we advise users to read these carefully before registering any personal data.

 

9. Accessibilty 

 

We are committed to providing a website in which content is accessible to everyone. We therefore update our website regularly in order to make it as adaptable as possible.

 

For example, users can control the text size of each page within their browser. On a PC, holding the “Ctrl” key while pressing the “+” (plus) key will increase text size, and holding the “Ctrl” key while pressing the “-“ (minus) key will decrease the text size.

 

10. General 

 

Questions and comments regarding this Privacy Statement are welcomed, and should be sent to our Data Protection Officer at dataprotectionofficer@halfords.co.uk.

 

You can also contact our Data Protection Officer if you have any concerns or complaints about the ways in which your personal data has been handled as a result of you using this website.

 

Alternatively, you have the right to lodge a complaint with the Information Commissioner’s Office who may be contacted at Wycliffe House, Water Lane, Wilmslow SK9 5AF or https://ico.org.uk.