Your privacy is of the utmost importance to Smalley Steel Ring Company and its affiliates ("Smalley" or "We"). Smalley makes every effort to protect all information collected from this website. We respect your privacy and are committed to protecting it through our compliance with this policy. This Privacy Policy describes the types of information we may collect from you or that you may provide when you visit the website www.smalley.com (our “Website”) and our practices for collecting, using, maintaining, protecting, and disclosing that information.
This policy applies to information we collect:
It does not apply to information collected by:
Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Website. This policy may change from time to time. (See Changes to Our Privacy Policy), so please check the policy periodically for updates.
Our Website is not intended for children under 16 years of age. No one under age 16 may provide any personal information to [or on] the Website. We do not knowingly collect personal information from children under 16. If you are under 16, do not use or provide any information on this Website or through any of its features, make any purchases through the Website, use any of the interactive or public comment features of this Website, or provide any information about yourself to us, including your name, address, telephone number, or email address. If we learn we have collected or received personal information from a child under 16 without verification of parental consent, we will immediately delete that information. If you believe we might have any information from or about a child under 16, please contact us at www.smalley.com/contactus.
Please see Notice for Residents of the United States for more information.
We collect several types of information from and about users of our Website, including the following.
Information You Provide Directly to Us.
The information we collect on or through our Website may include:
Information We Collect Through Automatic Data Collection Technologies
As you navigate through and interact with our Website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:
The information we collect automatically may include personal information. It helps us to improve our Website and to deliver a better and more personalized service including by enabling us to:
The technologies we use for this automatic data collection may include:
No Biometric Information
We do not knowingly collect or solicit "biometric identifiers" (as that term and similar terms are defined in applicable laws) or use such information for purposes of identifying an individual. We strongly encourage you to not provide any biometric identifiers to us. If you believe we possess information that could be considered a biometric identifier, please notify us and we will promptly delete such information.
Some content or applications, including advertisements, are served by third parties, including advertisers, ad networks and servers, content providers, and application providers. We use third party service providers and vendors to help provide our services to you. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our Website. The information they collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.
We do not control these third parties’ tracking technologies or how they may be used. Any information collected by third parties is subject to their respective privacy policies. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly. For more information regarding our use of cookies, please see our Cookies Policy.
We use the information that we collect about you or that you provide to us, including any personal information, for the following purposes.
SMS Messages
By providing your mobile number and opting to receive SMS messages from us, you agree that we may send you SMS messages at the phone number you provide to enhance your customer experience (e.g., regarding order status, order tracking, appointment reminders, and account alerts). You may opt out of receiving these SMS messages at any time by replying STOP. Message and data rates may apply.
We may disclose aggregate information about our users, and information that does not identify any individual without restriction. We may disclose personal information that we collect or you provide to us as described in this Privacy Policy to:
We may also disclose your personal information:
For clarity, we do not sell personal information to third parties.
We retain your personal information for as long as necessary to provide our services and fulfill the transactions you have requested, comply with our legal obligations, resolve disputes, enforce our agreements, and fulfill other legitimate and lawful business purposes. In general, we will retain your personal information for as long as necessary for the purposes set out in the Privacy Notice. Because these needs can vary for different data types in the context of different products and services, actual retention periods can vary significantly based on criteria such as user expectations or consent, the sensitivity of the data, the availability of automated controls that enable users to delete data, and our legal and contractual obligations.
We may also retain specific limited information related to your account and any data deletion or other access request you may submit as necessary to document our fulfillment of your requests. In some cases such as by court order, subpoena, or other legal or regulatory obligations, Smalley may be required by law to store your personal information.
We use technical, physical, and administrative safeguards to protect the confidentiality, integrity, and availability of your information. In other words, we use different types of controls and procedures to protect your information from misuse and unauthorized access or disclosure. We employ a range of measures that are commensurate with the dynamic cyber-threat landscape to secure your information, but we also recognize that electronic communications and the processing and storage of data can be inherently insecure and may contain unknown weaknesses. Consequently, while we cannot guarantee absolute security in such a dynamic threat landscape, we are strongly committed to continuously keeping your data as secure as possible. Please keep this in mind when disclosing any information to us via the Internet or other electronic means, including through our Website. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Website.
We strive to provide you with choices regarding the personal information you provide to us. We have created mechanisms to provide you with the following control over your information.
We do not control third parties’ collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. You can opt out of receiving targeted advertisements from members of the Network Advertising Initiative (“NAI”) on the NAI’s website.
Depending on where you reside, you may have additional personal information rights and choices. Please see below for more information.
Depending on the state where you reside, you may have additional rights regarding our use of your personal information. This section intends to provide information required under those laws.
Definitions.
Categories of Personal Information and Purposes for Processing.
The following table shows the categories of Personal Information we may have disclosed for a business purpose in the preceding twelve (12) months.
| Categories of Personal Information | Categories of Third Parties |
|---|---|
| Personal Identifiers Commercial Information Professional/Employment Information |
Shipping Vendors Digital Analytics Services Providers Fraud Prevention Providers Advertising Partners Financial Service Providers |
| Internet or other Electronic Network Activity | Digital Analytics Services Providers Fraud Prevention Providers Advertising Partners |
| Payment Information | Data Storage Providers Financial Service Providers |
We have not sold or shared Personal Information about California consumers in the past twelve (12) months. Relatedly, we do not have knowledge that we sell or share Personal Information of California consumers under 16 years of age. For purposes of the CPRA, a “sale” is the disclosure of Personal Information to a Third Party for monetary or other valuable consideration, and a “share” is the disclosure of Personal Information to a Third Party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration.
Your Rights.
To protect your Personal Information, we may request additional information to verify your identity before we act on your request. To the extent legally required, we will provide the information you request, in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance. We may provide this information to you via email to the email address you have provided with your request. Smalley does not use or disclose Sensitive Personal Information.
Exercising Your Rights.
This GDPR Statement applies to persons in the European Economic Area (“EEA”), including those based in the United Kingdom (“UK”). This GDPR Statement supplements our Privacy Policy, however, where our Privacy Policy conflicts with the GDPR Statement, the GDPR Statement will prevail as to persons located in the EEA.
“Personal Information” in this GDPR Statement means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Smalley Steel Ring Company is the “controller” of your personal information we collect. A “controller” is an entity that determines the purposes for which and the manner in which any personal information is processed. If you would like to contact us please see section Site Operation below.
If the processing of your personal information is subject to the GDPR, including the UK GDPR, you have certain rights regarding your personal information. Your rights include the following:
You are not required to pay any charge for exercising your rights. These rights will be exercisable subject to limitations as provided for by the GDPR/UK GDPR. Any requests to exercise the above-listed rights may be made to datasecurity@smalley.com.
You can also withdraw your consent at any time where we are relying on your consent to process your personal information. Please note that your withdrawal will not affect the lawfulness of any processing carried out before you withdrew your consent.
If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent. For personal information collected about you in the EEA and the UK, we set out below, in a table format, a description of the ways in which we use your personal information and the legal bases we rely on to do so.
We may process your personal information for more than one legal basis depending on the specific purpose for which we are using your personal information. Please contact us at datasecurity@smalley.com if you need details about the specific legal basis we are relying on to process your personal information where more than one ground has been set out in Annex I.
Where we transfer your personal information outside the EEA and the UK to other group companies or service providers, we transfer it subject to the appropriate safeguards as permitted under the GDPR/UK GDPR and the UK GDPR, such as the applicable EU Standard Contractual Clauses or their UK equivalent, to facilitate international transfers of personal information collected in the EEA and the UK. Please contact us if you would like to learn about the specific transfer security mechanism we use.
Further to section on Retention of Your Information above, to determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means and the applicable legal requirements.
This notice for China residents supplements the information contained in our Privacy Policy and applies solely to individuals who reside in China. We adopt this notice to comply with the PRC Personal Information Protection Law (“PIPL”), Regulation on Network Data Security Management and other applicable Chinese laws and regulations on the collection, storage, use, processing, provision, disclosure and deletion of your Personal Information.
List of Personal Information Collected and Processed by us.
For residents in China, we collect and process your Personal Information in accordance with Section of Information Collection and Use. We will obtain your proper consent for processing of your Personal Information in accordance with the applicable PRC laws and regulations. You may also refer to Appendix I for the list of Personal Information collected and processed by us.
We do not routinely collect your Sensitive Personal Information. However, in case we process your Sensitive Personal Information, we will inform you of the necessity and the impact on your personal rights and interests, unless otherwise required by the applicable PRC laws and regulations.
Provision of Personal Information to Third Parties.
For residents in China, we may provide your Personal Information to third parties in accordance with Section of How We Share Your Information above. You may also refer to Appendix I for the list of personal information we provide to third parties.
Cross-border data transfer
For residents in China, we may need to transfer your Personal Information outside of China to our headquarters, overseas affiliates or external parties for administrative management, business development and operation, compliance and other purposes, to the extent permitted by the applicable PRC laws and regulations. We will implement the appropriate mechanisms for cross-border data transfer and conduct the relevant procedures where required by the applicable PRC laws and regulations. We will keep you informed of the relevant information on the cross-border data transfer according to the applicable laws and regulations, including the category of Personal Information involved, the purpose and method of the processing and how to exercise your rights.
Your Rights.
As a data subject in China, you have the rights according to the PIPL and other applicable PRC laws and regulations. We will try our best to support the exercise of your rights according to the law, but please be aware that your exercise of certain rights may affect the services we can offer or be subject to certain constraints. For example, if you withdraw your consent, we may not be able to provide the relevant services for you; if you would like to delete your Personal Information provided to us, but the retention period prescribed by the applicable laws and regulations has not expired, or it is technically difficult to delete the Personal Information, we will cease the processing of the Personal Information, except for the storage and any necessary measure taken for security protection.
If you reside in China and have any inquiries, please contact us at the following address:
Tianjin Smalley
Technology Limited
Address: Room 302, Growth Power Building, intersection of Dongsan Road and Anhe Road, Tianjin Pilot Free Trade Zone (Airport Economic Zone)
Email: china@smalley.com Telephone: +86 22 8895 6811
It is our policy to post any changes we make to our Privacy Policy on this page. The date the Privacy Policy was last revised is at the top of the page. We encourage you to periodically visit our Website and this Privacy Policy to check for any changes.
This site is operated by Smalley Steel Ring Company. If you have any questions regarding this policy, please contact us at:
555 Oakwood Rd. Lake Zurich, IL 60047 Phone: (847) 719-5900
datasecurity@smalley.com
Appendix I List of Personal Information Collected and Processed by Us.
| Type of Personal Information |
Data Element | Purpose of Processing | Scenario of collection | Legal Basis for Processing |
|---|---|---|---|---|
| Identification information | First and last name |
To provide information about our company, products and services in response to queries from our customers and the general public; To create account |
When the user fills in the forms on our website to request information, such as “Contact Us” form; When the user sends an email to us for inquiries |
Performance of a contract Legitimate interests in ensuring the efficient and secure running of our services With your consent where required by applicable law (for example, for any marketing activities) Legal or regulatory obligation |
| Contact information |
Email addresses; Phone numbers; Shipping addresses |
To provide information about our company, products and services in response to queries from our customers and the general public; To create account To complete the delivery |
When the user fills in the forms on our website to request information, such as “Contact Us” form; When the user sends an email to us for inquiries; When the user places an order |
Performance of a contract Legitimate interests in ensuring the efficient and secure running of our services With your consent where required by applicable law (for example, for any marketing activities) Legal or regulatory obligation |
| Job information | Job titles; company name |
To provide information about our company, products and services in response to queries from our customers and the general public; To create account |
When the user fills in the forms on our website to request information, such as “Contact Us” form; When the user sends an email to us for inquiries |
Performance of a contract Legitimate interests in ensuring the efficient and secure running of our services With your consent where required by applicable law Legal or regulatory obligation |
| Internet identification information |
Account number Passwords; IP addresses |
To provide information about our company, products and services in response to queries from our customers and the general public; To create account |
When the user fills in the forms on our website to request information, such as “Contact Us” form |
Performance of a contract Legitimate interests in ensuring the efficient and secure running of our services With your consent where required by applicable law Legal or regulatory obligation |
| Internet records | Log data; Usage data; Communications you provide or submit through our website and resources for access and use of the Website |
To improve our website; To deliver personalized services to users |
When the user navigates through and interacts with our Website |
With your consent where required by applicable law Legitimate interests in ensuring the efficient and secure running of our services Legal or regulatory obligation |
| Personal device information |
Browser Type, Operating System, User Agent |
To improve our website; To deliver personalized services to users |
When the user navigates through and interacts with our Website |
Performance of a contract Legitimate interests in ensuring the efficient and secure running of our services Legal or regulatory obligation |
| Correspondence information |
Email communications |
To provide information about our company, products and services in response to queries from our customers and the general public |
When the user sends an email to us for inquiries |
Performance of a contract Legitimate interests in ensuring the efficient and secure running of our services Legal or regulatory obligation |
| Financial information |
Credit card numbers; Billing addresses |
To carry out transactions; To fulfill orders |
When the user places an order |
Performance of a contract Legitimate interests in ensuring the efficient and secure running of our services With your consent where required by applicable law Legal or regulatory obligation |
Appendix II List of Personal Information We Provide to Third Parties.
| Type of Personal Information Collected |
Business Purpose and Scenario | Method of Provision |
| Personal identifiers (e.g. name, phone number) |
|
Internal data sharing Backend interface transfer |
| Internet Activity (e.g., Apache logs, basic network data, IP Address, device information (e.g., browser type operating agent, and user agent), website usage data (page views, time spent on pages, and paths navigating through the site). |
|
Backend interface transfer |
| Message content (e.g., email correspondence) |
|
Internal data sharing Backend interface transfer |
| Payment Information Credit card number, expiration date, CVV code |
|
Internal data sharing Backend interface transfer |
Connect With Us