The protection of your personal information is an important concern to which we pay special attention.
Depending on the website, product or service you use, we may collect and process, and have collected and processed in the last 12 months, a range of personal information including:• Identifiers: Such as a real name, alias, postal address, telephone number, online identifier, internet protocol address, email address, account name, your signature, or other similar unique personal identifiers.• Commercial Information: Such as transaction and purchase information and history.• Financial Information: Such as your bank account number, credit card number, debit card number or any other financial information.• Technical and Usage Information: Such as login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and information on other technology on the devices using our websites or products; information about how you use our website, products and services, such as browsing history, search history, or other information on interactions with our websites, applications, products and services. For detailed information on the tracking technologies we use on this website, see the Cookies section.• Sensory information: Such as audio, electronic, visual and similar information, such as call and video recordings.• Geolocation Information: Such as device and internet protocol address location.• Inference Information: For example preference profiles drawn from any of the personal information listed above.• Protected Class Information or other Sensitive Information: including classifications protected by law such as: primary language, military/veteran status.• We do not intend to collect personal information of Children: We do not knowingly collect personal information from children under 16. Our website is not intended for children under 16 years of age. If you are under 16, do not use or provide any information on this website or through any of its features. If you believe we might have any information from or about a child under 16, please contact us at email@example.com. What are the sources of personal information we have gathered?
We collect personal information from a variety of sources, including:• From You. You may directly give us personal information when you:o Apply for, purchase, register or use our products and services;o Receive customer support;o Create an account on our website;o Subscribe to our publications;o Request marketing be sent to you;o Enter a competition, promotion or survey;o Correspond with us in person at trade shows, events, or otherwise;o Interact with us as a potential or existing franchisee or as an employee of a franchisee;o Make a claim under a franchisee insurance policy for which we provide claims administration services; o Give us feedback or provide us other information when you contact us; oro When you connect your social media account to your account with us.• From automated technologies or interactions. As you interact with our website or application, we will automatically collect Technical and Usage Information (more fully described in the “What types of personal information do we gather?” section). We collect this data by using cookies, server logs and other similar technologies. For detailed information on the technologies we us on this website, see the Cookies section.• From third parties or publicly available sources. We will receive personal information from various third parties that confirmed they are authorised to share it with us or other public sources, such as:o Original Equipment Manufacturer (OEM)o Consumer reporting agencies, credit reference agencies and publicly available databases;o Auto repair shops and auto dealers who use our products or services;o Our franchisees;o Insurance companies and brokers;o Other Snap-on Group companies that you may interact with through other websites, products, services, or social media pages;o Search information providers; or▪ Marketing list providers and other data aggregators▪ Advertising networks▪ Internet service providers▪ Data Analytics Providers▪ Operating systems and platforms▪ Social networks▪ Data brokers3. How is that personal information used by us?
By visiting our website and/or providing your personal information in order to use our product or services you are accepting and consenting to the practices described in this policy.5. Is my personal information disclosed to third parties?
In the preceding 12 months, we disclosed for our operational business purposes the following categories of Personal Information to the following categories of third parties:
|Categories of Personal Information||Disclosed to Which Categories of Third Parties for Operational Business Purposes|
|Identifiers||Affiliates, Service Providers|
|Commercial Information||Service Providers|
|Financial Information||Service Providers|
|Technical and Usage Information||Affiliates, Service Providers|
|Educational Information||Not collected|
|Professional/Employment Related Information||Not collected|
|Sensory Information||Not collected|
|Geolocation Information||Service Providers|
|Inference Information||Not collected|
|Protected Class Information||Service Providers|
6. How long will my personal information be kept for?
We will endeavor not to keep your personal information in a form that allows you to be identifiedfor any longer than is reasonably necessary for achieving the permitted purposes. This means that information will be destroyed or erased from our systems or anonymised when it has reached the applicable retention period.7. Will my personal information be transferred to other countries?
We are a global company and we may process, store and transfer personal information we collect to a country outside your own, provided that certain conditions as set out in the applicable legislation are complied with.
We are party to an information transfer agreement with the members of the Snap-on Group and we will keep that document up to date with current law. For more information on the safeguards in place, please contact firstname.lastname@example.org. What security measures are in place to protect my personal information?
We endeavor to protect the security of your personal information. We will seek to maintain administrative, technical and physical safeguards to protect against loss, misuse or unauthorised access, disclosure, alteration or destruction of your personal information.
Unfortunately, the transmission of information via the internet is not completely secure. Although we endeavor to protect your personal information, we cannot guarantee the security of your personal information transmitted to us or stored on our systems; any transmission is at your own risk. Once we have received your personal information, we will use procedures and security features to try to prevent unauthorised access. These procedures include physical, electronic, and managerial procedures.9. How do I update or access my personal information?
We ask that you keep your information as up-to-date as possible so you may get the maximum benefit from us.
If you have an account with us then you can access and correct personal information that we keep in your online account by changing your profile on the website or its Access Control system. For other questions related to updating or changing your account information or if any errors in your personal information cannot be corrected by accessing your website account, please send a request to email@example.com. What specific rights do I have in relation to my personal information based on my residency?• European Union and European Economic Area Residents. Depending on the circumstances, the General Data Protection Regulation “GDPR” may provide you the right to:o request access to any personal information we hold about you;o object to the processing of your information for direct-marketing purposes;o ask to have inaccurate information held about you amended or updated;o ask to have your information erased or to restrict processing in certain limited situations;o request the porting of your personal information to another organization in control of your personal information; and/oro object to any decision that significantly affects you being taken solely by a computer or other automated process.o If you are a resident of the European Union or European Economic Area that wishes to make a formal request for information we hold about you, you can contact us, at firstname.lastname@example.org. We will respond to your request consistent with the GDPR. • California Residents: The California Consumer Privacy Act (“CCPA”) provides California residents specific rights regarding their personal information. You have the right to be free from unlawful discrimination for exercising your rights under the CCPA. This section describes your CCPA rights and explains how to exercise those rights. o Access to Specific Information and Data Portability: You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months, including the following: ▪ The categories of personal information we collected about you.▪ The categories of sources for the personal information we collected about you.▪ Our business or commercial purpose for collecting that personal information.▪ The categories of Personal Information about you that we shared or disclosed,and, for each, the categories of third parties with whom we shared or to whom we disclosed such Personal Information.▪ The specific pieces of personal information we collected about you (also called a data portability request).o Deletion Request Rights: You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies. We do not provide these deletion rights for B2B personal information. We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to: ▪ Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform our contract with you.▪ Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.▪ Debug products to identify and repair errors that impair existing intended functionality.▪ Exercise free speech, ensure the right of another consumer to exercise theirfree speech rights, or exercise another right provided for by law.▪ Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).▪ Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.▪ Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.▪ Comply with a legal obligation.▪ Make other internal and lawful uses of that information that are compatible with the context in which you provided it.o Exercising Access, Data Portability, and Deletion Rights.▪ To exercise the rights described above, please submit a verifiable consumer request to us by either: • Calling us toll-free at 844-972-1285; or• Contacting our data protection manager at DataProtectionManager@snapon.com.▪ We will verify and respond to your Request to Know or Request to Deleteconsistent with applicable law, taking into account the type and sensitivity of the Personal Information subject to the request. We may need to request additional Personal Information from you, such as username or account number, in order to verify your identity and protect against fraudulent requests. If you maintain a password-protected account with us, we may verify your identity through our existing authentication practices for your account and require you to re-authenticate yourself before disclosing or deleting your Personal Information. If you make a Request to Delete, we may ask you to confirm your request before we delete your Personal Information.▪ If you are the authorised agent of a consumer, making a Request to Know or a Request to Delete on behalf of the consumer, we will ask you for: • proof of your registration with the California Secretary of State to conduct business in California; and• proof that the consumer has authorised you to make a Request to Know or a Request to Delete on the consumer’s behalf. This must be a permission signed by the consumer. “Signed” means that the permission has either been physically signed or provided electronically in accordance with the Uniform Electronic Transactions Act, Civil Code 1633.7 et seq.▪ If an authorised agent has not provided us with a power of attorney from the consumer pursuant to Probate Code sections 4000-4465, we may also: • require the consumer to provide you with a written permission signed by the consumer to make the request on the consumer’s behalf,• verify the identity of the consumer as we would if the consumer were making the request personally, and• obtain verification from the consumer that they provided the authorised agent permission to make the request.o Other notices for California residents:o California “Do Not Track” Disclosure. We do not track our customers over time and across third party websites to provide targeted advertising and therefore generally do not respond to Do Not Track (DNT) signals.o Pursuant the CCPA, California residents have the right to opt-out of the sale of their personal information.o WE HAVE NOT “SOLD” PERSONAL INFORMATION FOR PURPOSES OF THE CCPA.o If you are a resident of California, under 18, and a registered user of our websites, you may ask us to remove content or information that you have posted by writing to our Data Protection Manager at DataProtectionManager@snapon.com. Please note that your request does not ensure complete or comprehensive removal of the content or information, as, for example, some of your content may have been reposted by another user.• Nevada Residents: Nevada residents may request that website operators not sell consumer’s “Covered Information” as defined by Nevada law. WE HAVE NOT “SOLD” COVERED INFORMATION FOR PURPOSES OF NEVADA LAW. If you are a Nevada resident that would like to make a further inquiry regarding the selling of your Covered Information, please contact DataProtectionManager@snapon.com.11. How do I opt out of being contacted for promotional purposes?
If you are a citizen of the European Union or European Economic Area, you may make a complaint at any time to the applicable supervisory authority for data protection issues. We have appointed a data protection manager who is responsible for addressing any reported data protection issues related to GDPR, and we would like the opportunity to respond to your concerns before you approach a supervisory authority so please feel free to contact the data protection manager at DataProtectionManager@snapon.com.14. Modifications to this Privacy Statement