Name, email, telephone number, billing and delivery addresses, language and country.
How Spareza uses and protects your data
This policy explains what information we collect when you browse the store, select a vehicle, create an account, place an order or contact our team.
Plain-language promise. We use personal data only for stated business and legal purposes, limit access to people and providers who need it, and do not sell personal data.
Who is responsible for your data
Spareza Oร, operating the Spareza online store, is the controller of personal data described in this policy. The policy covers the website, customer account, garage, checkout, orders, returns, warranty requests and support communication.
Information we may collect
Products, quantities, prices, VAT status, invoices, delivery, returns, warranty history, account settings and business details.
Selected make, model, engine, year, registration details or VIN when you ask for compatibility assistance.
Payment method, amount, reference and status. Card and wallet credentials are entered on the external payment providerโs secure page, not into Spareza checkout.
Messages, order references, photographs, diagnostic details and other information you provide in a request or claim.
IP address, device and browser information, security events, timestamps, requested pages and cookie choices where generated by the website or its security systems.
Content and files you submit
Photographs, workshop reports, invoices, diagnostic files and free-text messages remain your content. You allow Spareza and the relevant service providers to access, copy and use that content only as reasonably necessary to answer the request, verify compatibility, handle a return or warranty claim, prevent abuse and establish or defend legal rights. We do not publish customer submissions or use them for advertising without a separate permission.
We normally receive data directly from you. We may also receive payment status from the payment provider, delivery status from a carrier, and product or fulfilment information from a supplier. Technical and security data is generated when the website or an account is used.
Remove unrelated personal information from photographs and documents. Never send card credentials, passwords, medical information or identity documents unless our team has specifically confirmed that a limited document is legally necessary and provided a secure method.
If you provide another personโs delivery or contact details, you must be entitled to do so and should make sure that person understands that Spareza and the selected carrier will use the information to perform the delivery.
Why we process personal data
Operate the store and fulfil orders
Create and manage the account, remember the selected vehicle, process orders and payments, arrange delivery or pickup, provide invoices, returns, warranty support and customer service.
Meet accounting and regulatory obligations
Keep required transaction records, respond to lawful authority requests, handle consumer claims and comply with tax, accounting, product-safety and other applicable duties.
Protect and improve the business
Prevent fraud and misuse, secure accounts and systems, maintain evidence, resolve disputes, improve catalogue usability and understand service performance, provided these interests are not overridden by your rights.
Use optional technologies or communication
Use optional analytics cookies or send marketing communication only where you have made a separate, freely given choice. Consent can be withdrawn at any time.
Spareza does not currently use customer order data, VIN data or submitted files for unrelated advertising. If a newsletter or other direct marketing service is introduced, it will use a separate subscription choice and every message will include a practical way to unsubscribe.
Where information is required to complete an order or meet a legal obligation, not providing it may prevent us from accepting, delivering or supporting the order.
Who may receive your data
We disclose only the information reasonably required for the relevant service. Recipients may include:
To authorise payment, receive status information, process refunds and prevent fraud.
Including FedEx, DHL or another service selected at checkout, to deliver, notify and track the parcel.
Where necessary to confirm availability, compatibility, prepare an item or fulfil the order. They receive only the data required for that task.
To operate and protect the store, maintain systems, send transactional messages and secure forms.
Accountants, auditors, insurers, legal advisers, courts and public authorities where necessary or legally required.
We do not provide customer or vehicle data to unrelated parties for their independent advertising.
Services outside the EEA
Some service providers may process limited information outside the European Economic Area. Where an adequacy decision does not apply, we require an appropriate transfer mechanism, such as European Commission standard contractual clauses, and assess supplementary safeguards where required.
External payment, carrier or security pages may also process data under their own privacy information. The provider shown during checkout or on the relevant form is the authoritative provider for that transaction.
How long information is kept
When information is no longer needed, it is deleted or anonymised unless further storage is required by law.
Closing an account stops future account use but does not automatically erase transaction records that must be retained for accounting, tax, fraud prevention, product-safety, warranty or legal-claim purposes. Data that is not subject to such a reason will be removed or anonymised under the applicable retention process.
Choices and requests available to you
Ask whether we process your personal data and request a copy together with relevant processing information.
Ask us to correct inaccurate data or complete information that is incomplete.
Ask for deletion where the data is no longer needed or another legal ground applies. This right can be limited by legal retention duties and valid claims.
Ask us to restrict processing in applicable cases or object to processing based on legitimate interests.
Receive eligible data in a structured, commonly used and machine-readable format where the legal conditions apply.
Withdraw consent at any time without affecting processing already carried out lawfully before withdrawal.
We may need to verify your identity before completing a request. We normally respond within one month; the period may be extended where permitted for a complex or numerous request. Rights are not absolute and we will explain any lawful limitation.
A request is normally free of charge. Where a request is manifestly unfounded or excessive, particularly because it is repetitive, the law may allow a reasonable fee or refusal. You may authorise another person to act for you, but we may request evidence of that authority.
What the website stores on your device
Necessary cookies support the requested store functions and cannot be switched off through the consent panel. Optional analytics is disabled unless you choose it.
You can reopen the panel at any time. Browser controls can also delete cookies, but blocking necessary cookies may stop the cart, login, localisation or garage from working correctly.
How information is protected
We use organisational and technical safeguards appropriate to the risk, including access controls, encrypted connections, system maintenance, backups, logging and service-provider controls. No internet service can promise absolute security, but suspected incidents are investigated and notified where legally required.
Payment separation
Card and digital-wallet credentials are entered on the connected payment providerโs secure page and are not stored in Spareza checkout.
Form protection
Google reCAPTCHA may be used on forms to distinguish legitimate requests from automated abuse. It is loaded only where a protected form is present.
Spareza does not make decisions producing legal or similarly significant effects based solely on automated profiling. Automated security signals may flag a request for human review.
The store is intended for customers capable of entering into a purchase contract and is not directed at children. If we learn that a child supplied personal data without a valid legal basis or required authorisation, we will take appropriate steps to remove it.
If a personal-data breach creates a legal notification duty, Spareza will notify the competent supervisory authority and affected individuals in accordance with the applicable risk and timing requirements.
Contact us about personal data
Send a privacy request to sales@spareza.com. Describe the request and the account, order or email address concerned without sending unnecessary identity documents or payment details.
We may update this policy when services, providers or legal requirements change. Material changes will be highlighted where appropriate. The effective date at the top identifies the current version.