Legal

Privacy Policy

Your privacy matters. Learn how Auto Buffy Inc. protects your information.

Last updated: January 8, 2026Effective: January 8, 2026

1. Introduction

This Privacy Policy ("Policy") explains how Auto Buffy Inc., doing business as AutoBuffy ("AutoBuffy," "Company," "we," "us," or "our"), collects, uses, discloses, and protects your personal information when you visit our website at autobuffy.com (the "Site"), use our mobile applications, or engage with our services (collectively, the "Services").

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.

This Policy applies to information we collect on this Site, in email, text, and other electronic messages between you and AutoBuffy, and when you interact with our advertising and applications on third-party websites and services.

2. Who We Are

Auto Buffy Inc. is a Maryland corporation operating the consumer retail website autobuffy.com. We specialize in aftermarket automotive parts including suspension components, engine mounts, struts, shocks, and related accessories.

Our principal place of business is located at: 8700 Larkin Rd, Savage, MD 20763, United States.

For any privacy-related inquiries, you may contact our Privacy Team at support@autobuffy.com or by mail at the address above, Attention: Privacy Compliance Officer.

3. Information We Collect

3.1 Information You Provide Directly

  • Account registration information (name, email address, password, phone number)
  • Billing and shipping addresses
  • Payment information (credit card numbers, PayPal account, etc. - processed by secure third-party payment processors)
  • Vehicle information (year, make, model, engine, VIN for fitment verification)
  • Order history and purchase details
  • Customer service communications (emails, chat logs, phone call records)
  • Product reviews and ratings you submit
  • Survey responses and feedback
  • Any other information you voluntarily provide to us

3.2 Information Collected Automatically

  • Device information (IP address, browser type, operating system, device identifiers)
  • Usage data (pages visited, time spent, click patterns, search queries)
  • Location data (derived from IP address or, with your consent, precise GPS location)
  • Referring URLs and exit pages
  • Cookie data and similar tracking technologies (see Section 7)
  • Log files and server data

3.3 Information from Third Parties

  • Payment processors (transaction confirmations, fraud screening results)
  • Shipping carriers (delivery status, address verification)
  • Social media platforms (if you connect your account or interact with our social pages)
  • Analytics providers (aggregated website usage data)
  • Marketing partners (advertising performance data)

4. How We Use Your Information

We use the information we collect for the following purposes:

  • Process and fulfill your orders, including payment processing, shipping, and delivery notifications
  • Create and manage your account, authenticate your identity, and provide customer support
  • Verify vehicle fitment and provide accurate product recommendations
  • Communicate with you about your orders, account, and inquiries
  • Process returns, refunds, exchanges, and warranty claims
  • Send transactional emails (order confirmations, shipping updates, receipts)
  • With your consent, send marketing communications about products, promotions, and company news
  • Improve our website, products, and services through analytics and research
  • Detect, prevent, and address fraud, security threats, and illegal activities
  • Comply with legal obligations and enforce our Terms of Use
  • Personalize your shopping experience and show relevant product recommendations
  • Administer contests, promotions, and surveys

6. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may share your information in the following circumstances:

6.1 Service Providers

We share information with trusted third-party service providers who perform services on our behalf, including:

  • Payment processors (Stripe, PayPal) for secure transaction processing
  • Shipping carriers (FedEx, UPS, USPS) for order delivery
  • Cloud hosting providers (AWS) for data storage and website hosting
  • Email service providers (SendGrid) for transactional and marketing emails
  • Customer service platforms for support ticket management
  • Analytics providers (Google Analytics) for website performance analysis
  • Tax calculation services for sales tax compliance

6.2 Legal Requirements

We may disclose your information when required by law or in response to:

  • Court orders, subpoenas, or legal process
  • Requests from law enforcement or government agencies
  • To protect our rights, property, or safety, or that of our users or the public
  • To investigate potential violations of our Terms of Use

6.3 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity. We will notify you of any such change via email and/or prominent notice on our Site.

7. Cookies and Tracking Technologies

We use cookies, pixel tags, and similar technologies to enhance your experience on our Site.

7.1 Types of Cookies We Use

  • Essential Cookies: Required for basic Site functionality (shopping cart, authentication)
  • Functional Cookies: Remember your preferences (saved vehicles, recently viewed products)
  • Analytics Cookies: Help us understand how visitors use our Site (Google Analytics)
  • Advertising Cookies: Deliver relevant advertisements and measure campaign effectiveness

7.2 Your Cookie Choices

You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, blocking essential cookies may impair Site functionality.

  • Disable cookies in your browser settings
  • Opt out of Google Analytics at tools.google.com/dlpage/gaoptout
  • Use browser extensions that block tracking
  • Adjust your device advertising settings

8. Data Security

We implement industry-standard security measures to protect your personal information:

  • 256-bit SSL/TLS encryption for all data transmission
  • PCI-DSS compliance for payment card data handling
  • Encrypted data storage on secure cloud servers
  • Regular security audits and vulnerability assessments
  • Access controls limiting employee access to personal data
  • Two-factor authentication for administrative accounts
  • Secure password hashing and storage
  • DDoS protection and web application firewalls

While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we commit to promptly notifying affected users in the event of a data breach as required by applicable law.

9. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law.

  • Account information: Retained while your account is active and for 3 years after account closure
  • Order history: Retained for 7 years for tax, accounting, and warranty purposes
  • Customer service records: Retained for 3 years after resolution
  • Marketing preferences: Retained until you unsubscribe or request deletion
  • Website analytics: Aggregated and anonymized after 26 months

After the retention period, we securely delete or anonymize your information. You may request earlier deletion subject to our legal and business obligations (see Section 10).

10. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

10.1 Rights for All Users

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information, subject to certain exceptions
  • Opt-Out: Unsubscribe from marketing communications at any time
  • Account Closure: Close your account and request associated data deletion

10.2 California Residents (CCPA/CPRA)

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected
  • Right to Delete: Request deletion of personal information collected from you
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: We do not sell personal information, so this right does not apply
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights
  • Right to Limit Use of Sensitive Personal Information: Limit use of sensitive data for secondary purposes

10.3 EEA/UK Residents (GDPR)

  • Right of Access: Obtain a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure (Right to be Forgotten): Request deletion under certain circumstances
  • Right to Restriction: Restrict processing of your data in specific situations
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Right to Withdraw Consent: Withdraw consent at any time for consent-based processing

10.4 How to Exercise Your Rights

To exercise any of these rights, please contact us at:

  • Email: support@autobuffy.com
  • Phone: 1-888-477-2530
  • Mail: Auto Buffy Inc., Attn: Privacy Compliance, 8700 Larkin Rd, Savage, MD 20763

We will respond to verifiable requests within 30 days (or 45 days for complex requests, with notice). We may require you to verify your identity before processing your request.

11. Do Not Track Signals

Some web browsers transmit "Do Not Track" (DNT) signals. Because there is no common industry standard for DNT, our Site does not currently respond to DNT signals. However, you can manage your privacy preferences through cookie settings and opt-out mechanisms described in this Policy.

12. Children's Privacy

Our Services are not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 16, we will take immediate steps to delete that information.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@autobuffy.com so we can delete the information.

13. International Data Transfers

Our Services are operated from the United States. If you are located outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located and our central database is operated.

By using our Services, you consent to the transfer of your information to the United States and other countries that may have different data protection laws than your jurisdiction. We take appropriate safeguards to ensure your data remains protected in accordance with this Policy.

For EEA/UK residents, we rely on Standard Contractual Clauses approved by the European Commission for international data transfers.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Policy
  • Post the updated Policy on this page
  • Notify you by email if we have your email address
  • Display a prominent notice on our Site

Your continued use of our Services after any changes constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Contact Our Privacy Team

Email

support@autobuffy.com

Privacy inquiries

Phone

1-888-477-2530

Mon-Fri 8:30AM-5PM ET

Mail

Auto Buffy Inc.
Attn: Privacy Compliance
8700 Larkin Rd
Savage, MD 20763