DiscoBrakes and CarbonCycles Privacy and Cookie Policy
This policy explains how DiscoBrakes.Com Pte Ltd collects, uses, discloses, transfers, retains and protects personal data when you use DiscoBrakes, CarbonCycles or our related customer-service operations.
It applies when you use either website, place a direct-shop order, contact us, create an account, subscribe to marketing or submit content. Amazon, eBay and other marketplaces also have their own privacy policies for information they collect independently. This policy applies to marketplace information that we receive and process.
Who controls your personal data
Data controller and website operator: DiscoBrakes.Com Pte Ltd, Singapore Unique Entity Number 200716616E.
Privacy contact and complaint route: support27@discobrakes.com.
Use this contact for access, correction, deletion, restriction, objection, portability, consent-withdrawal or privacy-complaint requests.
Personal data we collect and its sources
- Identity, account and contact information, including your name, username, email address, telephone number and delivery or billing address.
- Order and transaction information, including products, prices, taxes, delivery selection, delivery country, customs information, payment identifiers and payment status. We do not receive or store your complete payment-card number when payment is handled directly by PayPal or another payment provider.
- Returns, refunds, warranty claims, import-charge evidence, support messages and other correspondence.
- Newsletter preferences, email delivery and interaction information where tracking is enabled, reviews, forum or blog contributions, survey responses, photographs and other content that you choose to submit.
- Technical and security information, including IP address, browser and device information, cookie or similar identifiers, requested pages, referring page, date and time, session and basket identifiers, approximate country, fraud or abuse signals and consent choices.
- Advertising, social-media or external-media interaction information where you have permitted the relevant service.
- Marketplace order information supplied by Amazon, eBay or another marketplace when we fulfill or support an order placed through that marketplace.
Information may come from you, your device, payment providers, marketplaces, fulfillment partners, carriers, postal or customs services, email providers and security or geolocation services. MaxMind GeoLite data may be used locally to estimate the country associated with an IP address.
Reviews, forum or blog contributions and other content submitted for publication may become publicly visible and may be indexed by search engines. Do not include personal information that you do not want to make public.
Please do not send sensitive personal information unless it is reasonably necessary for us to deal with a particular request or claim.
Why we use personal data
The legal-basis terminology below applies where laws such as the European Union or United Kingdom GDPR require a legal basis. Other countries may use different terminology, but the purposes remain the same.
Total rows: 7
| # | Purpose | Typical legal basis |
|---|---|---|
| 1 | Create and administer accounts; take pre-contract steps; process payments, orders, delivery, returns, refunds and warranties; provide customer service. | Performance of a contract or steps requested before entering into a contract. |
| 2 | Keep tax, customs, accounting, product-safety, recall and regulatory records; respond to legally binding requests. | Legal obligation. Legitimate interests may apply where no specific legal obligation exists. |
| 3 | Prevent fraud and abuse; secure the websites; diagnose faults; protect transactions; investigate incidents; establish, exercise or defend legal claims. | Our legitimate interests in secure and reliable shops, fraud prevention and protecting legal rights, balanced against individual rights. |
| 4 | Maintain and improve website functionality, customer service and shop operations using information that does not require cookie consent. | Our legitimate interests in operating and improving the business, balanced against individual rights. |
| 5 | Display and moderate reviews or content that you ask us to publish; administer surveys and promotions. | Consent where requested, or legitimate interests in operating content features and promoting relevant products, depending on the circumstances. |
| 6 | Send newsletters or other direct marketing. | Consent, unless another lawful direct-marketing basis is expressly identified when information is collected. |
| 7 | Load analytics, advertising, social-media or external-media services. | Consent where required. |
Where we rely on legitimate interests, we consider whether processing is necessary and whether your rights and reasonable expectations outweigh our interests. Where information is required to fulfill an order or legal obligation, failure to provide it may prevent us from accepting or completing the order. Withdrawal of consent does not affect processing that was lawful before withdrawal.
Automated payment and fraud checks
Payment providers and security services may automatically assess payment, fraud or abuse risk. A transaction may be refused, delayed or referred for review as a result.
We do not otherwise use solely automated decision-making that produces legal or similarly significant effects on you. Where applicable law gives you the right to challenge a significant automated decision, contact us to request human review, provide additional information and express your position.
International transfers
We are based in Singapore and use fulfillment or service providers in the United Kingdom, United States, European Union and other countries. Personal data may therefore be processed outside the country where it was collected.
For personal data protected by Singapore law, we take reasonable steps to require an overseas recipient to provide protection comparable to that required by Singapore's Personal Data Protection Act.
Where European Union or United Kingdom international-transfer rules apply, we use the lawful mechanism documented for the relevant recipient and destination. Depending on that documented arrangement, this may be an adequacy decision or regulation, approved standard contractual clauses, the United Kingdom International Data Transfer Agreement or Addendum, a recognized certification or framework, or another mechanism permitted by applicable law. Additional contractual, technical or organizational measures are used where required.
Contact the privacy contact for information about the transfer mechanism documented for a particular recipient or to request a copy of relevant safeguards. Commercially confidential or security-sensitive information may be redacted.
How long personal data is kept
We delete or anonymize personal data when it is no longer reasonably required for the purpose collected, a legal obligation or the establishment, exercise or defense of claims. Retention is determined using these criteria:
- account information is kept while active and afterwards only for a reasonable closure, recovery, fraud-prevention or claims period;
- order, payment, tax and customs records are retained for applicable accounting, tax and regulatory periods;
- returns, warranties, customer-service messages and supporting evidence are retained until resolved and for the relevant claims period;
- product-safety and recall information may be kept while reasonably required to identify affected products and customers;
- security logs are retained for the configured investigation and protection period, and longer where they relate to an incident or claim;
- an active newsletter record is retained until unsubscribe or removal; after unsubscribe, a minimal suppression record may be retained to honor the request;
- public contributions are retained while published and for a reasonable moderation, evidential or backup period after removal; and
- the
bf_cookie_consentcookie lasts 180 days unless choices change, the policy version changes or the cookie is removed sooner.
Newsletters and direct marketing
Submitting a clearly labeled newsletter form authorizes the requested email subscription. A newsletter subscription is not required to buy goods. Mailchimp processes newsletter subscriptions and, where enabled, may record delivery, opening, link-click and unsubscribe events.
Every marketing email provides an unsubscribe method. You may also contact us or use available preference controls to withdraw consent. You may object to direct marketing at any time. Once you object, we will stop using your personal data for that direct marketing.
Account, security, delivery, recall and other service messages relating to an order or account are not marketing.
Your rights
Depending on applicable law and the circumstances, you may have rights to access data and information about its use; correct inaccurate data; request deletion; restrict processing; object to legitimate-interest processing or direct marketing; obtain portable data; withdraw consent; challenge certain significant automated decisions; complain to a regulator; and appeal a refused request where applicable law provides that right.
Where an applicable United States state privacy law applies to us, residents may also have rights to know, correct or delete personal information, opt out of sale, sharing or targeted advertising, use an authorized agent, limit certain uses of sensitive personal information and receive equal treatment when exercising privacy rights.
Singapore law provides access and correction rights and permits withdrawal of consent with reasonable notice. We will explain any likely consequence where processing is needed to continue a requested service.
Submit a request through the privacy contact. We may request information reasonably required to verify identity or an authorized agent. Requests are normally handled without charge, although a reasonable fee or refusal may be permitted for a manifestly unfounded, excessive or repetitive request. Some information cannot be deleted or disclosed where retention is required, disclosure would affect another person's rights, or another legal exception applies.
Security
We use reasonable technical and organizational safeguards appropriate to the information and risk. These may include access controls, transport encryption, monitoring, backups, restricted administrative access and service-provider controls. No internet or storage system can guarantee absolute security.
We assess suspected personal-data breaches and notify regulators and affected individuals where notification is required by applicable law.
Questions and complaints
Contact support27@discobrakes.com. Identify the issue and provide enough information for us to locate the relevant account, order, message or processing activity. Do not send unnecessary identity documents until requested.
We provide this clear electronic complaint route, acknowledge a data-protection complaint within 30 days, investigate it appropriately and without undue delay, keep you reasonably informed where more time is needed, and explain the outcome and any action taken.
We review this policy when services, providers or legal obligations change. Material changes receive a new version and date. Where a new use requires consent, we request consent rather than relying only on a policy update. The related shop contract is in our Terms and Conditions.
