PRIVACY POLICY

This Privacy Policy was last revised on and is effective as of 2/22/2023.

Table of Contents

What Does this Privacy Policy Include?

What Type of Personal Information Do We Collect and How Do We Collect It? How Personal Information Is Used for Business Purposes

What Steps Are Taken to Keep Personal Information Secure? How Can I Access, Correct and Update Personal Information?

Can I Indicate Whether or Not I Want to Receive Promotional Communications? Is Personal Information Collected from Children?

Additional Notice for California Residents Contact for Privacy Questions

How Will I Be Informed About Changes Regarding This Privacy Policy?


This Privacy Policy forms part of your legal agreement with Ace Hardware Corporation, its subsidiaries, and affiliates (collectively, "Ace", "we", "our", or "us"). By downloading, installing, accessing, or using any of the Services (as defined below) or by submitting personal information to us in a manner governed by this Privacy Policy, you agree to the terms of this Privacy Policy, as amended from time to time.

Our Services may contain links to other websites, applications or services operated by others. Please be advised that the practices described in this Privacy Policy do not apply to information gathered through these other websites, applications, or services.

What Does the Privacy Policy Include?

What Steps Are Taken to Keep Personal Information Secure?

We use various security measures to protect personal information that we collect. However, we cannot guarantee that your personal information will be secure from disclosure or misuse, either by accident or by unauthorized access or use.

In order to help protect your personal information, you should keep your account usernames and passwords secure and not provide them to others. If we request that you re-set your username and/or password, please do so promptly. If you become aware of any loss, theft or unauthorized use of a username or password, please contact our Retailer Care Department by phone at (800) 777-6797.

How Can I Access, Correct and Update Personal Information?

You can access, correct, and update certain personal information by accessing your account through the Services, by clicking on the Settings button located on the AceNet home page, under your name. You can also update certain personal information by contacting our Retailer Care Department by phone at (800) 777-6797.

Can I Indicate Whether or Not I Want to Receive Communications?

If you no longer wish to receive notifications when someone replies to a discussion you follow or someone creates a new discussion in a tag you’re following, you can update your information within your account under “Settings” and “Notifications”.

Is Personal Information Collected from Children?

The Services are intended for adults. We do not sell any items ordered through our Services directly to anyone who we know to be under the age of 18, including children under the age of 16. If you are under the age of 18, you should not enroll in the Ace Rewards program or use our Services to submit orders or purchase any items. In addition, we do not collect online any personal information from anyone who we know to be under the age of 13. If you are under the age of 13, you should use our Services only with the

involvement of a parent or guardian and should not submit any personal information of any kind to us.

We do not sell or share personal information about persons who we know to be under the age of 18.

Additional Information for California Residents

The following provides information for California residents, as required under California privacy laws, including the California Consumer Privacy Act ("CCPA"). California privacy laws require that we provide California residents information about how we use their personal information, whether collected online or offline, and this portion of our Privacy Policy is intended to satisfy that requirement.

Under the CCPA, "personal information" is any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular California resident or household. Please note that this definition of personal information applies to only this section of our Privacy Policy.

California Residents’ Rights

California law grants California residents’ certain rights and imposes restrictions on

particular business practices as set forth below.

Notice of Right to Opt-Out of Selling or Sharing: California residents have the right to opt- out of our sale or sharing of their personal information. Opt-out rights can be exercised on our Your Privacy Choices webform on AceHardware.com, by calling the Retailer Care Center at (800) 777-6797. California’s definition of sale is broad and encompasses many

types of data transfers. However, we do not "sell" any retailer data in the traditional

sense for monetary compensation.

Notice of Right to Limit: Notwithstanding the purposes described above, we do not collect, use or disclose Sensitive Personal Information about retailers beyond the purposes authorized by the CCPA. Accordingly, we use and disclose Sensitive Personal Information about residents as reasonably necessary and proportionate: (i) to perform the Services requested by you; (ii) to help ensure security and integrity, including to prevent, detect, and investigate security incidents; (iii) to detect, prevent and respond to malicious, fraudulent, deceptive, or illegal conduct; (iv) to verify or maintain the quality and safety of our Services;

(v) for compliance with our legal obligations; (vi) to our service providers who perform services on our behalf; and (vii) for purposes other than inferring characteristics about you.

Notice at Collection We are required to notify California residents, at or before the point of collection of their personal information, the categories of personal information collected and the purposes for which such personal information is used.

Data Retention

We endeavor not to collect more data than necessary to fulfill our business needs. Categories of personal information collected and disclosed

Generally, we may collect the following categories of personal information (as set forth in the CCPA) about California residents that we collect and have collected in the prior twelve

(12) months, as well as the categories of third parties to whom we may disclose this personal information for a business or commercial purpose. In some cases (such as where required by law), we may ask for consent or give you certain choices prior to collecting or using certain personal information. California’s definition of sale is broad and encompasses many types of data transfers. However, we do not "sell" any retailer data in the traditional sense for monetary compensation.



Categories


Description

Third Party Disclosures for Business or Commercial Purposes

Identifiers (Name, contact info and other identifiers)

Such as a real name, alias, postal address, unique personal identifier, online identifiers, Internet Protocol address, email address, account number and similar identifiers.

  • advisors and agents

  • affiliates and subsidiaries

  • regulators, government entities and law enforcement

  • internet service providers; operating systems and platforms

  • advertising networks; data analytics providers

  • others as required by law

Categories of Personal Information Described in Cal. Civ. Code § 1798.80.

Records containing Personal Information, such as name, signature, photo, contact information, education, financial or payment information.

  • advisors and agents

  • affiliates and subsidiaries

  • regulators, government entities and law enforcement

  • internet service providers; operating systems, and platforms

  • advertising networks; data analytics providers

  • others as required by law

Commercial Information

Including records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

  • advisors and agents

  • affiliates and subsidiaries

  • regulators, government entities and law enforcement

  • internet service providers; operating systems and platforms

  • advertising networks; data analytics providers

  • others as required by law

Internet or Other Electronic Network Activity Information

Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding your interaction with an internet website or application, as well as physical and network access logs and other network activity information related to your use of any Ace device, network or other information resource.

  • advisors and agents

  • affiliates and subsidiaries

  • regulators, government entities and law enforcement

  • internet service providers; operating systems and platforms

  • advertising networks; data analytics providers

  • others as required by law

Geolocation Data

Precise and general location information about a particular individual, vehicle or device.

  • affiliates and subsidiaries

  • regulators, government entities and law enforcement

  • internet service providers; operating systems and platforms

  • advertising networks; data analytics providers

  • others as required by law

Audio, Electronic, Visual, Thermal, or Similar Information.

Audio, electronic, visual, or similar information, such as, photographs, call recordings, and

  • advisors and agents

  • affiliates and subsidiaries

  • regulators, government entities and law enforcement


other audio recording (e.g., recorded webinars).

  • internet service providers; operating systems, and platforms

  • data analytics providers

  • others as required by law

Sensitive Personal Information

Such as financial account and payment information; and precise geolocation information.

  • advisors and agents

  • affiliates and subsidiaries

  • regulators, government entities and law enforcement

  • internet service providers, operating systems, and platforms

  • others as required by law

Categories of Third Parties with Whom We Share, Sell, or Collect Information From

In general, we may collect the personal information identified in the table above from the following categories of sources:



Submitting Requests: Requests to exercise privacy rights may be submitted on our Your Privacy Choices webform or by clicking the "Your Privacy Choices" button on the bottom of AceHardware.com. Additionally, individuals may contact Retailer Care Department at (800)

777-6797. We will respond to verifiable requests received from California residents as required by law.

Verification of Requests: For your protection, we may require you to log into your account to verify your identity or make requests if possible. We will only fulfill requests for personal information upon verifying your identity. In order to process requests to know, delete or correct, we require First Name, Last Name, Zip Code, Email, Phone Number and/or Store Number, and we may ask for additional information such as recent purchases or authenticated interactions with us depending on the nature of the request and the need to prevent fraud and protect security. The information provided in the request will be compared to the data Ace maintains for that Retailer. If the information does not match, we will be unable to process the request.

Authorized Agent Requests: An authorized agent is a person or business who has authorization to request to know what personal information we have about you, to delete the personal information we have about you, to correct the personal information we have about you, or to opt-out of the sale/sharing of personal information on behalf of a California resident. Authorized agents use the same links described above to submit requests.

If you are submitting a request on behalf of another person, we require an authorization, and/or other documentation demonstrating your authority to submit this request. This can be a letter or other documentation signed by the California resident authorizing you to submit this request. Ace reserves the right to contact the Retailer directly to verify their identity and ensure that they have elected an authorized agent.

Right to Non-Discrimination. The CCPA prohibits discrimination against California residents for exercising their rights under the CCPA.

Contact for Privacy Questions

For questions or concerns about the practices described in this Privacy Policy, please contact the Retailer Care Department at (800) 777-6797.

How Will I Be Informed About Changes Regarding This Privacy Policy?

We may change this Privacy Policy from time to time without prior notice. Revised versions of this Privacy Policy will be posted on this page, together with an updated effective date. You should check this page periodically to see if any recent changes to this Privacy Policy have occurred. In some cases, we may post a notice of the revision on the Services and/or send an email or other communication notifying users of the changes. If you have any questions regarding this Privacy Policy, please contact our Retailer Care Department by phone at (800) 777-6797.

I confirm and agree to the terms in the Privacy Policy, Categories of Personal Information, and Notice For International Retailers.