Comprehensive Privacy Policy
Effective Date: April 2025 | XYZ Supply — xyzsupply.com | CCPA / CPRA / Texas TDPSA
This Comprehensive Privacy Policy applies to XYZ Supply, LLC and supplements our standard Privacy Policy with extended disclosures required under the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the Texas Data Privacy and Security Act (TDPSA), and other applicable privacy laws.
1. Identity of the Data Controller
XYZ Supply, LLC | 2600 Manana Dr, Dallas, TX 75220 | sales@xyzsupply.com | xyzsupply.com
2. Categories of Personal Information Collected
- Identifiers: Name, email address, IP address, account username, business name, contractor license number
- Commercial Information: Products purchased, order history, transaction records, returns history
- Financial Information: Payment method type, billing address, credit application data shared with BlueTape
- Internet Activity: Browsing history on xyzsupply.com, pages viewed, search queries, clickstream data
- Geolocation Data: Approximate location from IP address; delivery address for jobsite orders
- Professional Information: Contractor license, business type, company size, trade specialty
- Communications: Emails, support tickets, and chat transcripts
3. Purposes for Collection
- Fulfilling orders and processing payments
- Managing Pro Accounts and contractor pricing tiers
- Facilitating BlueTape NET payment term applications
- Customer service and account management
- Marketing and promotional communications (with opt-out)
- Website analytics and performance improvement
- Fraud prevention and security
- Compliance with legal and regulatory obligations
4. Cookies and Analytics
Types of Cookies Used
- Strictly Necessary: Session management, authentication, cart persistence
- Performance / Analytics: Google Analytics collects anonymized usage data
- Functional: Preferences, remembered login state
- Targeting / Marketing: Third-party advertising pixels that may track visits across sites
You may opt out of Google Analytics via the Google Analytics Opt-Out browser extension. Manage cookie preferences through your browser settings.
5. Third-Party Services
Shopify Inc. — E-commerce platform and payment infrastructure.
BlueTape — B2B financing for NET 30/60/90 terms. Business credit data shared for underwriting.
Zoho Corporation — CRM and inventory management. Order and account data synchronized.
Google LLC — Google Analytics. Anonymized usage data.
Shipping Carriers (UPS, FedEx, freight carriers) — Delivery name and address only.
6. Sale or Sharing of Personal Information
XYZ Supply does not sell personal information as defined under the CCPA/CPRA. We do not share personal information with third parties for cross-context behavioral advertising beyond what is described in this policy.
7. Your Rights Under CCPA/CPRA and Texas TDPSA
- Right to Know: Request disclosure of categories and specific pieces of personal information we hold about you.
- Right to Delete: Request deletion of personal information, subject to legal exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing: We do not sell data, but you may submit an opt-out request at any time.
- Right to Limit Use of Sensitive Information: Limit how we use sensitive personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
Submit requests to sales@xyzsupply.com with "Privacy Rights Request" in the subject. We respond within 45 days. Identity verification may be required.
8. Opt-Out of Marketing Communications
Opt out of marketing emails via the unsubscribe link in any marketing email or by emailing sales@xyzsupply.com. Transactional emails cannot be opted out of while your account is active.
9. Children's Privacy
XYZ Supply is a B2B service intended exclusively for business use by adults (18+). We do not knowingly collect information from individuals under 18. If discovered, such information will be deleted promptly.
10. International Data Transfers
Our primary operations are in the United States. If you access our services from outside the US, your information may be transferred to and processed in the United States. By using our services, you consent to this transfer.
11. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this policy, with a minimum of 7 years for financial records to comply with tax and legal requirements.
12. Security Measures
We employ TLS encryption for data in transit, access controls, regular security reviews, and PCI-compliant payment processing. XYZ Supply does not store full payment card numbers.
13. Updates to This Policy
Material changes will be communicated via email to account holders or via notice on xyzsupply.com. Continued use constitutes acceptance.
14. Contact and Privacy Requests
Email: sales@xyzsupply.com
Mail: XYZ Supply — Privacy, 2600 Manana Dr, Dallas, TX 75220
Response time: within 45 days for verified requests.