1A Auto Privacy Policy
1A Auto, Inc.
Privacy Policy
This Privacy Policy (the “Policy”) explains how 1A Auto, Inc. (“1A Auto,” “we,” “our,” or “us”) collects, uses, maintains, and discloses information from individuals who register for and/or use this website (the “Website”).
We take reasonable steps to protect user privacy in accordance with this Policy and applicable U.S. state and federal laws, including but not limited to:
- The California Consumer Privacy Act (CCPA)/California Privacy Rights Act (CPRA)
- The Virginia Consumer Data Protection Act (VCDPA)
- The Colorado Privacy Act (CPA)
- The Utah Consumer Privacy Act (UCPA)
- Other relevant state data protection laws
While we implement industry-standard security measures to safeguard your information, no system is entirely secure. By using the Website, you acknowledge and accept the inherent risks of online data transmission, including the possibility of unauthorized access, disclosure, alteration, or destruction despite our security efforts.
For the purposes of this Policy, “user” or “you” refers to any individual accessing or using the Website. This Policy is incorporated into our Terms of Use, and forms part of the agreement governing your use of our services.
BY ACCESSING OR USING THE WEBSITE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTAND, AND AGREE TO BE BOUND BY THIS PRIVACY POLICY AND OUR TERMS OF USE. IF YOU DO NOT AGREE TO THESE TERMS, DO NOT USE THE WEBSITE.
Notice at Collection
In accordance with the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), we provide the following Notice at Collection describing the categories of personal information we collect, the business or commercial purposes for which each category is collected, the categories of third parties with whom each category is disclosed, and whether any category is sold or shared.
| Category of Personal Information | Examples | Business/Commercial Purpose | Disclosed To | Sold or Shared? |
|---|---|---|---|---|
| Identifiers | Name, email address, mailing address, phone number, username, IP address | Account creation, order fulfillment, customer support, fraud prevention, marketing communications | Third-party payment processor, shipping carriers, Google Analytics, email marketing platform | No |
| Payment & Financial Information | Credit card number, expiration date, billing address | Payment processing, billing, fraud prevention | A PCI-DSS compliant third-party payment processor. 1A Auto does not receive, store, or access full payment card details. | No |
| Commercial Information | Products purchased, order history, returns | Order fulfillment, customer support, service improvement | Shipping carriers, customer support contractors | No |
| Internet or Network Activity | Pages visited, links clicked, browser type, device ID, device model, email open events | Website analytics, performance optimization, marketing effectiveness, fraud detection, system logging and security monitoring | Google Analytics; cloud infrastructure provider (log storage and hosting) | No |
| Geolocation Data | IP-derived approximate location | Fraud prevention, localized content delivery | Google Analytics | No |
| Vehicle Information | Year, make, model (provided at registration or purchase) | Order fulfillment, product compatibility, service improvement | Contractors providing website and catalog services | No |
| Inferences | Product recommendations derived from aggregate (non-personalized) order history | Website functionality, service improvement | None — recommendations are generated internally from aggregate data and are not tied to any individual customer | No |
| Sensitive Personal Information (SPI) | IP-derived geolocation | Fraud prevention and localized content delivery | Google Analytics | No |
Sensitive Personal Information: We collect limited sensitive personal information as described above. We do not use or disclose sensitive personal information for purposes beyond what is necessary to perform the services you request. To limit our use of your sensitive personal information, please contact us at compliance@1aauto.com.
Connected Accounts:
To access certain sections of the Website, including the online store, you may choose to register using your login credentials from a third-party service such as Facebook, Google, or another social media account (a “Connected Account”). By using a Connected Account, we may access and collect personal information such as your name and email address, as permitted by your privacy settings on that platform.
Third-Party Data Usage: The data we receive from Connected Accounts is subject to both this Privacy Policy and the privacy policies of the respective third-party providers. We do not have control over, nor assume responsibility for, the privacy practices of third-party platforms. Users should review and manage their privacy settings directly on those platforms.
User Data:
"User Data" refers to all data—excluding Personal Information—that users provide in relation to their use of the Website. As described in our Terms of Use, we may store and analyze User Data and may correlate it with third-party data sources to enhance Website functionality, improve user experience, and detect fraudulent activities.
Web Tracking Information and Cookies:
We, along with third-party service providers (“Contractors”), use various tracking technologies, including cookies, pixel tags, and clear GIFs, to enhance Website performance and collect usage-related data (“Web Tracking Information”).
Web Tracking Information may include:
- Website interactions (e.g., pages visited, links clicked)
- Type of browser used
- Device model, device ID, and unique identifiers
- Internet Protocol (IP) address
- Whether you opened email communications from us
Some Web Tracking Information may be unique to individual users, but we do not correlate such data with Personal Information unless required for Website functionality, fraud prevention, or security purposes.
Cookies:
A cookie is a small text file stored on your device when you visit our website. Cookies help us:
- Improve navigation speed and provide personalized content
- Remember user preferences and login details
- Monitor the effectiveness of marketing campaigns
- Analyze aggregate usage patterns and visitor statistics
User Control Over Cookies: You can manage your cookie preferences through your browser settings. Disabling cookies may affect certain Website functionalities. Additionally, where required by law (e.g., under the CCPA, CPRA, and GDPR), we provide users with options to opt out of certain tracking mechanisms and manage cookie consent preferences through our website.
For more details about how we use cookies and similar tracking technologies, please refer to our Cookie Policy.
Compliance and Third-Party Tracking Disclosures:
In compliance with data privacy laws, we disclose the use of tracking technologies to users and, where applicable, obtain consent. If required under applicable laws (e.g., CCPA “Do Not Sell or Share My Personal Information” requirements), we provide users with mechanisms to control how their data is shared with third parties for advertising or analytics purposes.
How Do We Use the Information We Collect?
Personal Information and User Data: We will use and store your Personal Information and User Data to provide, maintain, and improve the Website, as well as to analyze and enhance its operation. We may also use your Personal Information and User Data for internal operational and administrative purposes, including customer support, fraud prevention, and compliance with our policies.
If you purchase products from our website, we may use any Personal Information and User Data you provide to fulfill your order and for one-time and recurring billing purposes according to the terms pertaining to such order. If we (or our payment processor) have trouble processing an order, such information may be used to contact you. Payment card information is transmitted in encrypted format and is used only to process payments through our third-party payment processor. We do not store or have access to your full payment card details, which are securely managed by our payment processor to authorize, clear, and reverse charges as needed.
Web Tracking Information: We use Web Tracking Information to administer the Website, understand its performance, store user preferences, and develop statistical insights into how visitors interact with the Website. This information helps us identify popular features, optimize functionality, personalize your experience, and measure the overall effectiveness of our services.
Aggregate and De-Identified Information: We may generate statistical, aggregated, and/or de-identified data from Personal Information and User Data for analytical and commercial purposes. Such data does not duplicate or reveal any personally identifiable information. Instead, it is used to analyze our customer base, improve our services, and develop new offerings. This data may also be shared with third parties in an aggregated or anonymized form that does not identify any individual user.
Customer Reviews: We may use and display customer reviews, testimonials, or social media comments (collectively, "Reviews") regarding the Website, our products, or services. Reviews may contain personally identifiable information, such as your name or social media handle. Prior to using a Review or displaying your name alongside it, we will seek your consent via email, fax, PDF, or mail. Reviews may be posted on our website, used in marketing materials, or repurposed in other formats consistent with the consent received. By submitting a Review, you grant us a non-exclusive, royalty-free license to use and display it in accordance with applicable laws.
Legal Compliance and Protection: Notwithstanding the above, we may store and use Personal Information and User Data to the extent required by applicable law, regulation, or legal process. This includes responding to court orders, subpoenas, or other lawful requests from authorities. Additionally, we may retain and use Personal Information as necessary to enforce our agreements (including this Privacy Policy and our Terms of Use), resolve disputes, prevent fraud, or protect our legal rights, property, and safety, as well as the rights, property, and safety of third parties.
Promotional Communications: If you register and provide your email address, we may send you administrative and promotional emails, including newsletters, special offers, and updates about our services. You can opt out of promotional communications by following the unsubscribe instructions included in such emails. However, we may still send you non-promotional communications related to your account, transactions, or legal notices.
Account Closure: If any of your account information appears to be incorrect, you may contact us to request updates or corrections. If you choose to close your account, we will delete any Personal Information associated with it, except where retention is required by law, for dispute resolution, or for legitimate business interests. However, any non-personally identifiable information that you provided may not be deleted, as it may be part of aggregated or anonymized datasets used for analytical and operational purposes.
What Information Do We Disclose to Third Parties?
Personal Information and User Data: We will not disclose your Personal Information or User Data to any third parties except as follows:
(i) To Third-Party Contractors: We may share your Personal Information and User Data with third-party contractors engaged to provide services on our behalf ("Contractors"), such as analyzing data and Website usage, hosting and operating the Website, soliciting customer reviews, providing marketing, payment processing, customer service, shipping products, and providing technical support. We enter into agreements with all Contractors that require them to use the Personal Information they receive solely for the purpose of performing services on our behalf, with appropriate security and confidentiality obligations.
(ii) When We Have Your Consent: We will disclose your Personal Information when you provide explicit consent for such sharing.
Web Tracking Information: We may disclose Web Tracking Information to Contractors to analyze the Website's performance, monitor user behavior, and improve functionality. Such data is used in an aggregated and de-identified manner whenever possible.
Google Analytics and Third-Party Data Collection: We use Google Analytics and similar third-party analytics services to analyze Website usage and improve user experience. These services collect and process data about your interactions with our Website, including your IP address, device information, browser type, pages visited, and time spent on the Website. This information is collected through cookies and similar tracking technologies.
You can manage or disable cookies through your browser settings. You may also opt out of Google Analytics tracking by installing the Google Analytics Opt-Out Browser Add-on available at https://tools.google.com/dlpage/gaoptout.
Additionally, we may allow third-party service providers to collect data on our behalf for purposes such as advertising, analytics, and Website functionality. These third parties may use cookies, web beacons, and other tracking technologies to collect data about your online activities across different websites over time.
Your Rights & Opt-Out Choices: California Residents (CCPA/CPRA): You have the right to request details on how your data is collected, used, and shared. You may also request that we do not sell or share your Personal Information. To submit a do-not-sell or data deletion request, please use our Do Not Sell or Share My Personal Information form, or email us at compliance@1aauto.com.
Other U.S. Residents (VCDPA/CPA/UCPA/Oklahoma SB 546): You may opt out of targeted advertising and data collection by adjusting your preferences in your browser settings or contacting us.
Right to Correct: Regardless of your state of residence, you have the right to request that we correct inaccurate personal information we maintain about you. To submit a correction request, email compliance@1aauto.com or use our Contact Us form and select "Privacy Request/Data Deletion Request" from the subject drop-down menu.
Global Privacy Control (GPC): We are in the process of implementing support for the Global Privacy Control (GPC) signal, a browser-based universal opt-out mechanism required under the CCPA/CPRA and the Colorado Privacy Act. Until GPC recognition is fully implemented, you may submit an opt-out request manually by emailing compliance@1aauto.com or using our Contact Us form and selecting "Privacy Request/Data Deletion Request" from the subject drop-down menu.
Data Retention: We retain analytics data for a period necessary to fulfill its intended purpose, after which it is deleted or anonymized.
Aggregate and De-Identified Information: We may disclose aggregated and/or de-identified data that does not contain Personal Information or User Data to any third parties, such as Contractors, potential customers, business partners, marketers, and funding sources, in order to describe our business operations, conduct market research, and enhance our services.
Network Operators: Use of the Website may involve third-party telecommunications providers. Such providers operate independently and are not our Contractors. Any information collected by a telecommunications provider in connection with your use of the Website is outside the scope of this Privacy Policy. We encourage you to review their privacy policies to understand their data handling practices.
Additional Disclosures: We reserve the right to disclose any information we collect in connection with the Website, including Personal Information and User Data, under the following circumstances:
(a) Business Transactions: If we undergo a merger, acquisition, asset sale, or similar corporate transaction, we may transfer your information to a successor entity, ensuring that reasonable safeguards remain in place to protect your data.
(b) Legal Requirements: We may disclose Personal Information to law enforcement, regulatory authorities, or judicial bodies as required by law or if, in our reasonable discretion, such disclosure is necessary to enforce our legal rights, comply with legal obligations, or protect third parties from harm.
Privacy Settings and Opt-Out Options
If you would like your name and email address permanently removed from our database, please email us. We will promptly delete your contact details from active databases; however, records of past transactions, Website usage, and data retained in system backups will be maintained per our business and legal obligations.
If you wish to opt out of promotional emails (without permanently removing your data), you may do so by following the "unsubscribe" link in any marketing email or by contacting customer service via email or phone at (888) 844-3393. Note that administrative emails related to transactions, account security, or legal notices cannot be opted out of while you remain registered.
If you wish to exercise additional privacy rights, such as restricting the processing of your data or objecting to direct marketing, please contact us through the designated compliance email.
How to Exercise Your Privacy Rights
Submitting a Request: You may submit a verifiable consumer request to exercise any of your privacy rights by:
- Email: compliance@1aauto.com
- Online: Via our Contact Us form — select "Privacy Request/Data Deletion Request" from the subject drop-down menu
To protect your personal information, we are required to verify your identity before processing any request. We cannot fulfill a request if we are unable to verify your identity.
Identity Verification: To verify your identity, we will confirm that the email address provided in your request matches one on file with us. We will only use this information for the purpose of verifying your identity and will not retain it for any other purpose.
Please note that identity verification applies to privacy data requests only. We may apply different verification procedures for other types of account or customer service inquiries.
Response Timeframe: We will respond to your request within 45 days of receipt. If we require additional time due to the complexity or volume of requests, we may extend this period by an additional 45 days. We will notify you of any such extension within the initial 45-day period, along with the reason for the extension.
Appeal Process: If we decline to take action on your request, we will inform you of our decision and the reason for it within the applicable response period. If you wish to appeal our decision, you may do so by emailing compliance@1aauto.com with the subject line "Privacy Request Appeal." We will respond to your appeal within 60 days of receipt. If your appeal is denied, you may contact the Attorney General of your state to submit a complaint.
Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights. This means we will not:
- Deny you goods or services
- Charge you different prices or rates
- Provide you a different level or quality of goods or services
- Suggest that you will receive a different price, rate, or quality of goods or services
Authorized Agents: If you are a California resident, you may designate an authorized agent to submit a request on your behalf. To do so, the authorized agent must provide either a signed written authorization from you or a valid power of attorney. We may still require you to verify your own identity directly with us in order to protect against unauthorized requests.
General
Security: We implement a layered set of technical and organizational security controls to protect the confidentiality, integrity, and availability of your Personal Information, including:
- Encryption in transit: All data transmitted between your browser and our website is encrypted using TLS (Transport Layer Security).
- Access controls: Access to systems containing Personal Information is restricted on a least-privilege basis, with role-based access controls and multi-factor authentication required for administrative access.
- Vendor security requirements: Third-party contractors who process Personal Information on our behalf are contractually required to maintain appropriate security standards and to notify us promptly in the event of a security incident affecting our users' data. Where available, we review vendors' third-party security certifications or audit reports (such as SOC 2 Type II or ISO 27001) as part of our vendor onboarding process.
- Payment security: Payment card data is never stored or accessed by 1A Auto. All payment processing is handled by a PCI-DSS Level 1 compliant third-party processor.
Despite these controls, no method of transmission over the Internet is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your Personal Information, we will notify you as required by applicable law.
Third-Party Links: Our website may contain links to external websites. 1A Auto is not responsible for the privacy practices or content of these third-party sites. Users should review the privacy policies of each website they visit. This Privacy Policy applies only to information collected by our website.
Policy Amendments: 1A Auto reserves the right to modify or update this Privacy Policy at any time. If we make material changes to how we collect, use, or share Personal Information, we will notify you by email or through a prominent notice on our website. Your continued use of the website after such changes constitute your acceptance of the updated policy. Any Personal Information collected prior to modifications will be handled in accordance with the version of the Privacy Policy in effect at the time of collection, unless you provide consent otherwise.
Children’s Privacy: 1A Auto does not knowingly collect or maintain Personal Information from individuals under 13 years of age, and our website is not intended for persons under 16. If you are under 16, please do not use the Website. If we learn that we have collected Personal Information from a child under 13 without verifiable parental consent, we will take steps to delete such information. If you become aware of such a case, please contact us immediately to request removal.
Transparency in Coverage: To comply with applicable transparency requirements, you may access machine-readable files at: https://hpitpa.com/transparency-in-coverage-machine-readable-files/.
International Visitors: This Website is intended for use by residents of the United States. We do not market, offer products or services to, or intentionally target residents of the European Union (EU), the United Kingdom (UK), or other jurisdictions outside the United States.
If you access this Website from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States in accordance with this Privacy Policy. Data protection laws in the United States may differ from those in your country of residence.
We do not knowingly collect Personal Information from individuals located in the EU or UK. If we become aware that we have received Personal Information from an individual located in the EU or UK in a manner inconsistent with this Policy, we will take reasonable steps to delete such information.
All operations of 1A Auto are conducted within the United States and are subject to applicable U.S. federal and state laws.
Effective Date: January 1st, 2026
Last Revised: March 27th, 2026