Skip to content

🏁 Free shipping on any set of 4 — or any order over $500

Privacy Policy

Last updated: August 20, 2026

What we collect, why we collect it, who receives it, how long we keep it, and the control you have over it. Written from the code that runs this store rather than from a template, so where our practice is imperfect it says so.

Who is responsible for your information

The Auto Rack operates theautorack.com and is responsible for the personal information under our control. We handle it in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Act respecting the protection of personal information in the private sector as amended by Law 25, and other applicable provincial privacy legislation.

Our Privacy Officer is the owner of the business, reachable at contact@theautorack.com with "Privacy" in the subject line, by phone at (289) 991-3884, or by mail at The Auto Rack, 214 Toronto Ave, Oshawa, ON L1H 3C1.

Mailing address only — this is not a retail location. We do not offer in-store pickup and cannot accept walk-in visits or returns dropped off in person.

A note on how this page is written

Policies of this kind are usually taken from a template and then quietly outgrown by the software they describe. This one is written from the code that runs this store. Where our practice falls short of what we would like it to be, we say so here rather than describing an intention as a fact. The retention section is the clearest example.

What we collect when you browse

Our analytics are first-party. Nothing goes to an advertising network, and there are no third-party pixels, session recorders or heatmap tools on this site. We record:

  • pages viewed and the path of each one, including any query string on it
  • searches and fitment lookups: the text you typed and how many results it returned
  • add to cart, checkout steps and completed purchases, including the product names, quantities and prices in your cart and the order value
  • wishlist saves: each product you save is sent to us, even though the list itself lives in your browser
  • discount popup activity: whether it was shown, dismissed or used
  • device type, browser, operating system, and on page views your screen and viewport size, language, time zone, device pixel ratio and whether the device is touch capable
  • approximate location: the country and city our hosting provider derives from your connection
  • how you found us: the referring hostname, the first page of your visit, and any campaign tags on the link you followed
  • a session identifier, ar-sid, described in the next section
  • ar-visited, a marker stored permanently in your browser so that we can count a visit as coming from a new or a returning device across sessions

We do not store your IP address. It is read momentarily to derive an approximate country and city, then discarded. Our abuse counters keep only an irreversible salted hash of it, cleared once the counter lapses.

Analytics begin when a page loads, before you answer the privacy notice, and continue until you opt out. Opting out, or switching on Do Not Track or Global Privacy Control, stops all of it. The Cookies & Tracking page lists every storage key by name.

About the session identifier

ar-sid is a random value created when you arrive and cleared when you close the tab. It is not anonymous, and we will not describe it that way.

The same identifier labels your analytics events, addresses your live chat conversation, keys the abandoned-checkout record that also holds your email address, and is written onto your order record next to your name, phone number and addresses. Browsing recorded during a visit in which you bought something or messaged us can therefore be connected back to you by name.

We treat those records as personal information for every purpose in this policy, including your right to see and delete them. If you would rather that link did not exist, opt out of analytics: with the opt-out in place no session identifier is recorded, and none is attached to your order.

What we collect when you buy

Card details are entered on Stripe’s own hosted checkout. We never receive or store your full card number, CVV or PIN. What does come back to us, and is written to your order record, is:

  • your name, email address and phone number
  • your complete billing address and your complete shipping address, including the recipient name
  • the items ordered with quantities and prices, the subtotal, shipping charge, tax, any discount, and the total
  • any promo code you used
  • the card brand and last four digits, the card expiry month and year, and the wallet type if you paid through Apple Pay or Google Pay
  • the Stripe receipt link for the payment
  • the fraud risk level Stripe assigned to the payment
  • the attribution details described above: session identifier, landing page, referring hostname and campaign tags, unless you have opted out of analytics
  • the payment and fulfilment status of the order, and when each of them changed
  • the carrier and tracking number once your order ships, entered by us rather than received from a carrier system

What we collect when you contact us or use other features

  • Contact form: your name, email address, subject and message. If you later reply to one of our emails, that reply is routed back into the same thread and kept with it, together with our replies and the times we read and answered.
  • Live chat: anything you type, plus a name and email address if you choose to give them. Chat is read and answered by a person on our team. There is no bot and no AI involved, and your messages are not used to train anything.
  • Abandoned checkout: if you enter your email address at checkout and do not finish the order, that address, your session identifier and your full cart are saved so we can send you a reminder. This happens when you enter the address, not when you place the order. Every reminder carries an unsubscribe link, and unsubscribing stops them for good.
  • Newsletter: your email address, where you signed up from, the discount code issued to you, the dates you signed up and confirmed, and a record of the wording you agreed to. No marketing is sent until you click the confirmation link.
  • Unsubscribes: your email address is added to a permanent suppression list so that we do not email you again. Keeping it is the only way to honour the request.
  • Back-in-stock requests: the product you asked about, the label shown for it, and your email address.
  • Return requests: your order number, your email address, the items concerned, the reason you gave, and the status of the request as we work through it.
  • Reviews: the name you type, your rating, title and review text. Reviews are held for moderation and, once approved, are published on the product page under that name, where search engines can index them. Use a first name or initials if you would rather not be identifiable.
  • Order and return lookups: the order number and email address you enter are used to find the order and are not stored as a new record.

Why we use it, and on what basis

PIPEDA requires that we identify the purpose of a collection and obtain your consent for it. Our purposes are:

  • to take, process, ship and support your order, and to handle returns and warranty claims
  • to answer your questions through the contact form, live chat and email
  • to prevent fraud and abuse, secure the site and enforce our Terms
  • to understand how the store is used so we can fix problems, stock the right products and improve the experience
  • to send you commercial email where we are permitted to
  • to meet legal, tax and accounting obligations

For anything needed to complete an order you place, consent is implied by the transaction itself. For analytics and marketing we rely on consent you can withdraw at any time, in the ways set out under "Your rights". Fraud prevention, security and the retention of transaction records rest on the exceptions PIPEDA provides and on legal obligations we cannot contract out of.

We do not use your information to make automated decisions producing legal or similarly significant effects. Stripe assigns a fraud risk level to a payment and we may decline an order in light of it, but a person makes that call.

We do not sell personal information, and we do not share it for third-party advertising or profiling.

Commercial email and CASL

Newsletter signups are double opt-in. We send a confirmation email and add you only after you click the link in it. That click, with the date and the exact wording you were shown, is our record of your express consent under Canada’s Anti-Spam Legislation.

We may also send commercial messages to people who have bought from us, on the basis of the existing business relationship CASL provides for. That basis lapses two years after your last purchase, and unsubscribing ends it immediately.

Abandoned checkout reminders go to the address you entered at checkout and stop as soon as you unsubscribe.

Every commercial message identifies us, gives our mailing address and contact details, and carries a working unsubscribe link that needs no login and no reply. Order confirmations, shipping updates and replies to your own questions are transactional and continue regardless.

Who receives your information

We use a small number of service providers, each bound to process data only to provide their service to us. What each one actually receives:

  • Stripe: your email address and the attribution details for the order, sent when checkout starts. Stripe then collects your name, phone number, shipping and billing address and card details directly on its own page, takes the payment, and screens it for fraud.
  • Resend: the recipient address and the content of every email we send you, including order confirmations, shipping updates, newsletters, abandoned-checkout reminders and replies from our team. Replies you send back to us arrive through the same email path and are stored in your contact thread.
  • Vercel: hosting for the site. Every request you make passes through it, and it supplies the approximate country and city we record.
  • Upstash: the database holding orders, contact threads, chat transcripts, analytics events, newsletter records, back-in-stock requests, return requests and reviews.

Shipping carriers are not connected to this site. No carrier receives anything automatically from it, and no carrier system writes to it: when we ship an order, a person hands the parcel over and types the tracking number back in. The carrier itself is given the delivery name and address needed to complete the delivery, and nothing else.

We may also disclose information where the law requires it, to comply with a valid legal process, to protect our rights or the safety of others, or in connection with a sale or reorganization of the business, in which case it remains subject to this policy.

Where your information is processed, and what that means

Law 25 requires that we tell you when your information is transferred outside Quebec. All four providers above store and process data outside Canada, including in the United States: Stripe, Resend, Vercel and Upstash each operate infrastructure and support from outside the country.

While outside Canada your information is subject to the laws of the jurisdiction holding it, and may be accessible to courts, law enforcement and national security authorities there under laws that differ from Canadian law and that we cannot override.

We have assessed this and are satisfied the information receives adequate protection: all four are established providers with recognized security and confidentiality practices, contractual data protection commitments, and encryption in transit and at rest. If you would rather your information were not handled this way, the practical alternative is to order by phone or email, and we are glad to take an order that way.

How long we keep it

This is the section where we owe you plain speaking. We do not currently run a scheduled, time-based deletion job. Building one is on our list, and until it exists we will not publish a retention period our systems do not actually enforce.

What is true today is that some records are bounded by a fixed volume cap, which drops the oldest entries once the cap is reached, and the rest are kept until you or we delete them. Record by record:

RecordWhat bounds it today
Orders and payment detailsKept indefinitely. We need them for tax and accounting records, which Canadian law requires us to keep for six years, and for returns and warranty claims.
Contact messages and email threadsKept indefinitely.
Live chat transcriptsThe 500 most recent conversations, and the 200 most recent messages within each. Older ones are dropped automatically.
Analytics eventsThe 8,000 most recent events across all visitors. Older ones are dropped automatically. At our traffic that is a matter of weeks, not the hours a phrase like "rolling window" might suggest.
Abandoned checkout recordsThe 2,000 most recent. Older ones are dropped automatically.
Newsletter signups and consent evidenceKept while you are subscribed. The consent record is kept for as long as CASL may require us to prove consent.
Unsubscribe suppression listKept permanently and deliberately. It holds only your email address, and it is the only way to guarantee we never email you again.
Back-in-stock requestsKept indefinitely.
Return requestsKept indefinitely, alongside the order they relate to.
Published reviewsKept until you or we remove them.
Abuse countersA salted hash of the connection, never the address itself, cleared once the counter lapses.

None of this prevents you from asking us to delete your information. Where we are not legally required to keep a record we will erase it on request, and where we are required to keep it we will tell you which record and why.

How we protect it

The site is served entirely over encrypted connections and our providers encrypt data at rest. Card data never reaches our systems. Administrative access is restricted and protected by signed sessions that expire after eight hours, login attempts are rate limited, and public write paths are throttled to resist abuse. Our Security page has the detail.

No system is perfectly secure. If a breach of security safeguards creates a real risk of significant harm we will notify affected individuals and the Office of the Privacy Commissioner of Canada as PIPEDA requires, notify the Commission d’accès à l’information du Québec where Law 25 requires it, and keep a record of the breach.

Your rights, and how to exercise them

You may ask us to:

  • confirm what personal information we hold about you and give you a copy of it
  • correct anything inaccurate or incomplete
  • delete information we are not required to keep
  • stop sending you marketing, or stop collecting analytics about you
  • explain how your information has been used and who it has been disclosed to
  • give you the information you provided in a structured, commonly used electronic format, or send it to another organization for you, which is the portability right Law 25 gives Quebec residents

There is no self-service privacy dashboard on this site, and we would rather tell you that than imply one exists. Email contact@theautorack.com with "Privacy request" in the subject line and a person will handle it by hand. Tell us the email address you used, and the order number if you have one, so we can find every record.

We will acknowledge your request quickly and answer within 30 days, as PIPEDA requires. We may ask you to confirm your identity first, so that a request cannot become a way for someone else to obtain your information. There is no charge.

Withdrawing consent for marketing or analytics takes effect immediately and never affects your ability to browse, order or get support. Withdrawing consent for information we need to complete an order already in progress may mean we cannot complete it, and we will tell you if that is the case.

Children

The store is intended for adults able to enter a binding contract. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.

Concerns and complaints

If you are unhappy with how we have handled your information, please raise it with our Privacy Officer first at contact@theautorack.com. We will investigate and give you a written answer.

If you are still not satisfied you have the right to complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or by phone at 1-800-282-1376. Quebec residents may complain to the Commission d’accès à l’information du Québec at cai.gouv.qc.ca. Residents of Alberta and British Columbia may complain to their provincial Information and Privacy Commissioner.

Coming to us first is not a precondition, and nothing on this page limits your right to go straight to a regulator.

Changes to this policy

We may update this policy as our practices or the law change. The "last updated" date above shows the current version, and material changes will be highlighted on the site. If our retention practice changes, this page changes with it on the same day.