Last updated: 1 May 2026
Applies to bavarianprecisionparts.com
1. Who We Are
Bavarian Precision Parts ("we", "us", "our") is a business based in Alaska, USA. We operate the website bavarianprecisionparts.com.
We are the data controller for personal information collected through our website and services. You can contact our Data Protection contact at privacy@bavarianprecisionparts.com.
2. Data We Collect
Data you provide directly
- Name, email address, phone number and postal address (when you create an account or place an order)
- Payment details — processed securely by our payment provider; we never store raw card numbers
- Your BMW model, chassis number or registration (for fitment queries)
- Messages and attachments sent via our contact form, email or WhatsApp
- Account preferences, wishlist items and saved vehicles
Data collected automatically
- IP address, browser type and device information
- Pages visited, search queries and time spent on site
- Referring website and UTM campaign parameters
- Cookie identifiers (see Section 8)
We do not collect sensitive personal data such as health information, racial or ethnic origin, or political opinions.
3. How We Use Your Data
We use your personal data for the following purposes:
- Order fulfilment — processing payments, dispatching parts, sending tracking information
- Account management — maintaining your order history, wishlist and preferences
- Customer support — responding to enquiries and resolving complaints
- Fitment verification — confirming parts are compatible with your vehicle
- Marketing communications — sending deals, new arrivals and guides (only where you have opted in)
- Site improvement — analysing usage data to improve navigation and product listings
- Legal compliance — retaining records as required by US federal and state tax and consumer law
4. Legal Basis for Processing
We process your data for the following purposes:
- Contract performance — processing your order and providing services you've requested
- Legitimate interests — fraud prevention, site security, improving our service
- Consent — marketing emails and non-essential cookies (you can withdraw at any time)
- Legal obligation — tax records, consumer rights compliance
5. Data Sharing
We do not sell your personal data. We share it only with:
- Delivery partners (UPS, FedEx, USPS) — name and delivery address only
- Payment processors (Stripe, PayPal) — transaction data under their own privacy policies
- Cloud services (AWS hosting, Google Analytics) — subject to appropriate data processing agreements
- Legal authorities — where required by law or to protect our legal rights
All third-party processors are subject to data processing agreements and are required to implement appropriate security measures.
6. Data Retention
- Order records — retained for 7 years for tax and legal compliance
- Account data — retained while your account is active, plus 2 years after closure
- Marketing consent records — retained until you unsubscribe plus 3 years
- Support communications — retained for 3 years
- Analytics data — aggregated and anonymised after 26 months
7. Your Rights
You have the following privacy rights:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data (subject to legal retention requirements)
- Restriction — limit how we process your data in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing for direct marketing at any time
- Withdraw consent — for any processing based on consent (e.g. marketing emails)
To exercise any of these rights, email privacy@bavarianprecisionparts.com. We will respond within 30 days. California residents may have additional rights under the CCPA.
8. Cookies
We use cookies to operate the site and improve your experience. For full details of the cookies we use and how to manage them, see our Cookie Policy.
9. Security
We implement industry-standard security measures including TLS encryption for all data in transit, encrypted storage for sensitive data, access controls limiting data access to authorised staff only, and regular security audits. In the event of a data breach affecting your rights, we will notify you and the ICO within 72 hours as required by law.
10. Changes to This Policy
We may update this policy from time to time. We will notify registered customers of material changes by email at least 14 days before they take effect. Continued use of our website after the effective date constitutes acceptance of the updated policy.