🏁 Free shipping on any set of 4 — or any order over $500

Security

Last updated: July 27, 2026

How we protect your payment and personal information, what we ask of you, and how to report a security concern.

Payment security

All payments are processed by Stripe, a PCI DSS Level 1 certified provider — the highest level of payment security certification.

Your card details are entered on Stripe’s own encrypted checkout and are never transmitted to or stored on our systems. We never see, handle or retain your full card number, CVV or PIN. We receive only the outcome of the payment and limited non-sensitive details such as the card brand and last four digits.

We will never ask you to send card details by email, chat or phone. If you receive such a request claiming to be from us, do not respond — forward it to contact@theautorack.com.

Encryption

The entire site is served over HTTPS with TLS encryption, so traffic between your browser and our servers is encrypted in transit. Data held by our infrastructure providers is encrypted at rest.

Security headers, including strict transport security and content protections, are enforced across the site.

Access controls

Administrative access is restricted to authorized personnel and protected by a password plus signed, expiring session tokens. Administrative sessions time out automatically, and login attempts are rate-limited to resist brute-force attacks.

Access to customer data is limited to what is needed to run the store — fulfilling orders, handling returns and providing support.

Service providers

We use established providers for payment processing, hosting, data storage and email delivery. Each is bound to process data only to provide their service to us. We do not sell customer data, and we do not use third-party advertising trackers on this site.

What we ask of you

  • use a strong, unique password on any account you hold with a payment provider or email service used for your order
  • keep your order confirmation emails private — they contain your order number
  • be alert to phishing: check the sender address, and remember we will never request payment details or passwords by email
  • contact us at contact@theautorack.com if you see activity on an order that you do not recognize

Incident response

We monitor for unusual activity and maintain a process to investigate and contain incidents. In the event of a breach of security safeguards involving personal information that creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required under PIPEDA, and maintain records of the breach.

Responsible disclosure

If you believe you have found a security vulnerability in theautorack.com, please report it privately to contact@theautorack.com with enough detail to reproduce it. We will acknowledge your report and work to resolve confirmed issues promptly.

Please give us a reasonable opportunity to fix an issue before disclosing it publicly, and while testing do not access, modify or delete data belonging to others, degrade our service, run denial-of-service or automated scanning at scale, or use social engineering against our staff or customers.

We appreciate good-faith reports made under these conditions and will not pursue action against researchers who follow them.

No absolute guarantee

We take security seriously and use commercially reasonable safeguards. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. Our responsibilities and limits are set out in our Terms of Service and Privacy Policy.