Privacy policy
Last updated: May 28, 2026
Effective date: January 2026
Last updated: April 2026
Legal entity: FREESTORM LTD
Registered address: Unit 3, Churchfield, Exchange Business Park, T23V027, Cork, Ireland
Contact email:
Contact phone: +353 21 2066 112
VAT number: IE9656359L
Related policies:
Cookie Policy
Terms & Conditions
Returns & Refunds
Warranty
Contact Us
Introduction
This Privacy Policy explains how FREESTORM LTD (“FREESTORM”, “we”, “us”, “our”) collects, uses, stores, shares and protects personal data when you use our website, create an account, buy automotive parts from us, request compatibility or fitment checks, submit units for testing, diagnostics, repair, coding or related workshop services, or otherwise interact with us.
This Privacy Policy applies to personal data processed in connection with:
- visitors to our website;
- customers purchasing new, refurbished or remanufactured automotive parts;
- customers requesting testing, diagnostics, repair, coding, exchange supply or related workshop services;
- customers submitting warranty, return, refund or complaint requests; and
- individuals contacting us by website forms, email, telephone, customer portal or other communication channels.
This Privacy Policy applies to both private individuals and business customers, although certain data we process may differ depending on whether you are acting in a personal or business capacity.
Who We Are
FREESTORM LTD is the controller of the personal data described in this Privacy Policy.
Our details are as follows:
Legal name: FREESTORM LTD
Company registration number: 439795
Registered address: Unit 3, Churchfield, Exchange Business Park, T23V027, Cork, Ireland
Trading / workshop address: Unit 3, Churchfield, Exchange Business Park, T23V027, Cork, Ireland
Privacy contact email:
General contact email:
Telephone: +353 21 2066 112
VAT number: IE9656359L
If you have any questions about this Privacy Policy or about how we handle personal data, you can contact us using the details above.
If we appoint a dedicated data protection officer or separate privacy contact in future, we will update this Privacy Policy accordingly.
Scope of This Policy
This Privacy Policy applies to personal data processed by us in connection with:
- browsing and using our website;
- creating and using an online account or customer portal;
- placing orders for automotive parts and related products;
- payments, invoicing and order administration;
- shipping, delivery and collection arrangements;
- returns, refunds and cancellations;
- warranty claims and after-sales support;
- repair, testing, diagnostics, coding and related service requests;
- compatibility / fitment checks and vehicle-related enquiries;
- customer support and complaint handling;
- fraud prevention, abuse prevention and website/account security;
- marketing communications, where permitted by law;
- cookies, analytics and preference management.
This Privacy Policy applies whether you interact with us through our website, by email, by telephone, in person, through your customer account, or through other approved communication channels.
This Privacy Policy does not apply to third-party websites, platforms or services that may be linked from our website or used in connection with our services, except to the extent expressly stated by us.
What Personal Data We Collect
The types of personal data we collect depend on how you interact with us, the products or services you request, and whether you are acting as a private individual or on behalf of a business.
Identity and Contact Data
We may collect:
- first name and surname;
- company name, where applicable;
- billing address;
- shipping or collection address;
- email address;
- telephone number;
- other contact details you choose to provide.
Account Data
Where account registration or customer portal access is available, we may collect and process:
- account login details;
- password hash and account security credentials;
- customer ID or account reference number;
- saved order history;
- saved addresses;
- account preferences;
- saved vehicle or garage-related details, where those features are available.
Vehicle and Technical Request Data
Because our business involves compatibility checks, diagnostics and repair services, we may collect vehicle-related and technical request data, including:
- vehicle make;
- vehicle model;
- vehicle year;
- engine type;
- VIN / chassis number;
- registration-related vehicle details provided by you;
- OEM numbers or part numbers;
- compatibility or fitment request details;
- fault codes or diagnostic codes;
- photos, videos or other technical evidence uploaded by you;
- repair request descriptions and related notes;
- installed part details;
- module/ECU reference details;
- bleeding/coding/calibration-related details, where provided.
Order and Transaction Data
We may collect and process data relating to your orders and transactions, including:
- ordered items;
- product category or service type, including new, refurbished, remanufactured, repair, exchange or coder-rental transactions;
- prices;
- VAT details;
- payment status;
- invoice information;
- order history;
- refund, return and cancellation records;
- warranty claim records;
- core return records;
- core deposit / surcharge records; and
- coder rental and deposit administration records.
Repair and Workshop Service Data
Where you request testing, diagnostics, repair, coding or related workshop services, we may collect:
- booking details;
- requested service type;
- workshop or intake details;
- communications relating to the service;
- diagnostic findings;
- repair notes;
- repair outcome;
- estimated completion dates;
- service history with us.
Communications Data
We may collect personal data contained in communications with us, including:
- emails;
- contact form submissions;
- phone call notes;
- customer portal messages;
- chat messages, where available;
- complaint details;
- warranty, refund or support correspondence.
Technical and Usage Data
When you use our website or account portal, we may collect certain technical and usage data, such as:
- IP address;
- browser type and version;
- operating system;
- device type;
- language settings;
- referring URL;
- pages viewed;
- timestamps;
- session activity;
- security and server logs.
Marketing and Preference Data
Where relevant and legally permitted, we may collect:
- newsletter subscription status;
- country and language preferences;
- marketing preferences;
- consent records;
- campaign attribution or interaction data.
Cookies and Similar Technologies
We may collect information through cookies and similar technologies, including:
- strictly necessary cookie data;
- preferences cookie data;
- analytics cookie data;
- marketing cookie data, where used;
- cookie consent choices and settings.
Further details are available in our Cookie Policy.
Anti-Fraud and Legal / Compliance Data
To protect our business, customers and website, and to comply with legal obligations, we may collect and process:
- billing and tax records;
- fraud screening indicators;
- transaction verification signals;
- abuse prevention logs;
- suspicious activity records;
- chargeback-related records.
CCTV Data
When you visit our premises, we may collect CCTV footage for security, health and safety, fraud prevention and incident investigation purposes.
How We Collect Personal Data
We collect personal data from a number of sources depending on how you interact with us, the services you request, and the features you use.
Directly from You
We collect personal data directly from you when you:
- place an order for products or services;
- create an account or use the customer portal;
- request a compatibility or fitment check;
- request a repair quote, workshop booking, testing, diagnostics, coding or related service;
- submit a return, refund, warranty or complaint request;
- contact us by email, phone, website form, portal message or other communication channel;
- upload photos, videos, fault codes or other technical evidence;
- subscribe to marketing communications;
- provide vehicle details, part numbers, VIN or related technical information.
Automatically
When you use our website or customer portal, we may collect certain data automatically through technical means, including:
- cookies and similar technologies;
- website analytics tools, where enabled in accordance with your consent settings;
- server, security and access logs;
- fraud prevention and abuse prevention systems;
- device and browser information generated during website use.
From Third Parties
Where relevant and legally permitted, we may also receive personal data from third parties, including:
- payment service providers and banks;
- courier, shipping and logistics providers;
- ecommerce or account platform providers;
- fraud prevention and security service providers;
- credit-reference agencies, where relevant for business account or trade-credit applications;
- professional advisers such as accountants, insurers, legal advisers or tax advisers;
- marketplaces or sales platforms, where you place orders through those channels;
- public or commercial verification sources, where used to verify business, VAT or anti-fraud information.
We will only process personal data received from third parties where we have an appropriate legal basis for doing so.
Why We Use Personal Data
We use personal data for the following purposes.
To Provide and Manage Your Account
We use personal data to:
- create and manage your account;
- authenticate logins and maintain account security;
- provide access to order history, saved details and account functions;
- enable customer portal features.
To Process and Deliver Orders
We use personal data to:
- accept, confirm and process orders;
- collect and verify payment;
- issue invoices and related documents;
- arrange dispatch, delivery or collection;
- manage cancellations, returns, refunds and exchange processes;
- administer warranty and after-sales support;
- administer exchange transactions, core returns, core deposits / surcharges, and coder-rental deposits;
- verify return conditions and process release, refund or retention of deposits where applicable.
To Verify Fitment and Part Compatibility
We use vehicle and technical request data to:
- assess whether a part may fit or function in a particular vehicle;
- process VIN-, OEM- or part-number-based compatibility checks;
- reduce incorrect orders, failed installations and unnecessary returns;
- provide support relating to fitment, coding or installation issues.
To Provide Repair, Diagnostic and Workshop Services
We use personal data and technical information to:
- assess service requests;
- prepare quotations;
- schedule testing, diagnostics, repair, refurbishment, remanufacturing, coding or related workshop services;
- communicate about inspection results, faults, approvals, delays or completion;
- document and complete repair work;
- manage service history, after-sales support and warranty follow-up.
- maintain technical and service records for warranty review, after-sales support and dispute resolution;
To Provide Customer Support
We use personal data to:
- answer enquiries;
- respond to technical questions;
- investigate complaints;
- manage warranty claims;
- resolve order, service or account issues.
To Protect the Website, Accounts and Business
We use personal data to:
- detect and prevent fraud;
- prevent misuse of the website or account portal;
- protect customer accounts and business systems;
- monitor suspicious transactions or behaviour;
- maintain logs and records for website, account and transaction security;
- investigate incidents, disputes, abuse or chargebacks.
To Comply with Legal and Regulatory Obligations
We use personal data where necessary to comply with legal obligations, including obligations relating to:
- accounting and tax;
- invoicing and financial record-keeping;
- consumer rights;
- product safety and warranty compliance;
- legal claims, dispute handling and regulatory requests;
- anti-fraud, anti-abuse and law enforcement cooperation where required.
To Improve Our Services, Website and Operations
We use personal data to:
- analyse website and account usage;
- improve product pages, compatibility workflows and repair processes;
- improve customer support and service quality;
- review and improve site performance, search, filtering and user experience;
- improve internal operations, fraud prevention and process efficiency.
To Send Marketing Communications
Where permitted by law, we may use personal data to:
- send newsletters;
- send product and service updates;
- send country- or language-relevant offers;
- send reminders relating to incomplete orders, abandoned requests or service follow-ups, where legally permitted;
- maintain records of marketing preferences, consent and unsubscribe choices.
To Manage Cookies and Consent Preferences
We use personal data and technical identifiers to:
- remember cookie and consent choices;
- maintain website settings and preferences;
- operate consent tools and related records;
- enable analytics or other non-essential tools only where consent has been given, where required.
Legal Bases for Processing
We process personal data only where we have a lawful basis to do so under applicable data protection law.
Depending on the context, we rely on one or more of the following legal bases:
- performance of a contract;
- steps taken at your request before entering into a contract;
- compliance with a legal obligation;
- legitimate interests;
- consent, where required.
The table below summarises the main legal bases we rely on.
Where we rely on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Where we rely on legitimate interests, we do so only where those interests are not overridden by your rights and freedoms.
Legitimate Interests
We process certain personal data on the basis of our legitimate interests, provided that those interests are not overridden by your rights and freedoms.
Our legitimate interests may include:
- protecting our website, systems, customer accounts and business operations;
- detecting, preventing and investigating fraud, abuse, suspicious transactions and unauthorised access;
- maintaining internal records and business administration;
- supporting customer service quality and complaint handling;
- improving our product compatibility, fitment and repair service workflows;
- improving website performance, usability and service delivery;
- protecting our legal rights and defending claims;
- operating CCTV for premises security, safety and incident investigation.
Where we rely on legitimate interests, we take into account the nature of the data, the context in which it is processed, and the reasonable expectations of the individuals concerned.
When You Must Provide Data
In some cases, providing personal data is necessary for us to enter into or perform a contract, comply with legal obligations, or assess whether we can provide the product or service you request.
For example:
- billing and payment data may be required to complete a purchase;
- a delivery or collection address may be required to dispatch products;
- account login details are required if you wish to use account or portal features;
- vehicle details, VIN, OEM numbers or other technical data may be required to assess fitment or compatibility;
- diagnostic information, fault descriptions, photos or other technical evidence may be required to assess a repair, testing or service request;
- invoice and tax-related data may be required to comply with accounting, VAT and legal obligations.
- certain unit or vehicle details may be required before we can assess whether an ABS/EPS unit is suitable, repairable or compatible;
- certain technical evidence may be required before we can quote or diagnose a repair;
- if you do not provide sufficient vehicle or unit information, we may be unable to confirm fitment or proceed with the requested service.
If you do not provide personal data that is required for these purposes, we may be unable to:
- process your order;
- deliver the requested goods;
- verify compatibility;
- assess or provide the requested repair or diagnostic service;
- respond fully to a warranty, refund or complaint request;
- provide access to account-related services.
Where the provision of data is optional, we will make that clear where reasonably possible.
Who We Share Personal Data With
We do not sell personal data. We share personal data only where necessary for the purposes described in this Privacy Policy, where required by law, or where otherwise lawfully permitted.
Depending on the circumstances, we may share personal data with the following categories of recipients:
Payment and Financial Service Providers
- payment processors;
- banks;
- card payment providers;
- fraud screening and payment verification providers.
Shipping and Logistics Providers
- couriers;
- postal operators;
- shipping and delivery partners;
- customs or logistics intermediaries, where relevant.
Technology and Hosting Providers
- website hosting providers;
- cloud service providers;
- ecommerce platform providers;
- account portal providers;
- IT support, maintenance and security providers;
- backup and infrastructure providers.
Communication and CRM Providers
- email service providers;
- customer support systems;
- CRM or communications tools;
- messaging or contact management services, where used.
Analytics and Website Service Providers
- analytics providers;
- website performance and security tools;
- cookie consent or preference management providers.
Professional Advisers and Business Support Providers
- accountants;
- insurers;
- legal advisers;
- tax advisers;
- auditors or similar professional service providers.
Fraud Prevention, Security and Compliance Providers
- fraud prevention vendors;
- identity, business or transaction verification providers;
- credit-reference agencies, where relevant to business credit or trade account applications;
- providers supporting abuse prevention and site security.
Regulators and Public Authorities
We may disclose personal data where required by law or where lawfully requested by:
- Revenue Commissioners;
- courts or tribunals;
- law enforcement authorities;
- regulators;
- supervisory authorities;
- other public bodies with lawful authority.
Other Parties Connected with Legal Claims or Business Protection
We may share personal data where reasonably necessary to establish, exercise or defend legal claims, investigate disputes, respond to chargebacks, or protect our legal rights and business operations.
We require service providers processing personal data on our behalf to act only on our instructions, to maintain appropriate confidentiality and security, and to comply with applicable data protection law.
International Transfers
Some of the service providers we use may process personal data outside the European Economic Area (“EEA”), or may provide support or infrastructure that involves international data transfers.
Where personal data is transferred outside the EEA, we will take steps to ensure that the transfer is protected by an appropriate lawful safeguard, including where applicable:
- an adequacy decision issued by the European Commission;
- the European Commission’s Standard Contractual Clauses;
- other lawful transfer mechanisms recognised under applicable data protection law.
Where required, we also assess whether supplementary contractual, technical or organisational safeguards are appropriate.
You may contact us if you would like further information about the safeguards used in connection with international transfers of personal data.
Data Retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
The exact retention period depends on the type of data, the reason it was collected, the services involved, and any legal, tax, accounting, warranty or dispute-related obligations.
Account Data
We retain account data while your account remains active and for a reasonable period after account closure or inactivity, unless longer retention is required:
- to comply with legal obligations;
- to maintain records of transactions;
- to protect against fraud or abuse;
- to establish, exercise or defend legal claims.
Order, Invoice and Payment Data
We retain order, invoice and payment-related data for as long as necessary to:
- perform the contract;
- administer refunds, returns and warranties;
- comply with accounting, tax and audit obligations;
- maintain records required by law.
Repair, Diagnostic and Workshop Service Records
We retain repair, diagnostic, booking and workshop-related records for as long as reasonably necessary for:
- service administration;
- warranty and after-sales support;
- complaint handling;
- technical follow-up;
- dispute resolution;
- legal and regulatory compliance.
Compatibility, VIN and Fitment Request Data
We retain compatibility and fitment request data, including VIN and related technical information, only for as long as reasonably necessary to:
- assess the request;
- support related orders, returns, warranty or complaints;
- manage legitimate after-sales and dispute-resolution needs.
We do not retain compatibility or VIN data indefinitely unless there is an ongoing legal, contractual, safety or dispute-related reason to do so.
Support and Communications Data
We retain emails, complaint records, support requests, phone call notes and similar communications for as long as reasonably necessary to:
- manage customer service;
- handle complaints and warranty requests;
- maintain business records;
- protect our legal rights and respond to disputes.
Marketing Data
We retain marketing preferences, consent records and related marketing data until:
- you withdraw consent;
- you unsubscribe;
- you object to direct marketing; or
- the data is otherwise no longer needed for lawful marketing purposes.
We may retain limited suppression-list information where necessary to ensure that marketing opt-out requests are respected.
Technical Logs and Security Data
We retain website, account and security logs for limited periods appropriate to:
- fraud prevention;
- abuse prevention;
- troubleshooting;
- security investigation;
- internal auditing and system integrity.
CCTV Data
We retain CCTV footage for 30 days unless a longer retention period is necessary for incident investigation, legal proceedings, insurance handling, fraud prevention or compliance purposes.
Retention Criteria
Where it is not possible to specify an exact retention period, we determine retention by considering:
- the nature and sensitivity of the personal data;
- the purpose for which it was collected;
- whether there is an ongoing contractual relationship;
- applicable limitation periods;
- accounting, tax and legal obligations;
- product safety, warranty and dispute-handling requirements;
- the need to establish, exercise or defend legal claims.
Your Rights Under GDPR
Subject to applicable law and the circumstances of the processing, you may have the following rights in relation to your personal data:
Right of Access
You may request confirmation of whether we process your personal data and, where we do, request access to that data and related information.
Right to Rectification
You may request that we correct inaccurate personal data or complete incomplete personal data.
Right to Erasure
You may request that we delete your personal data in certain circumstances, for example where the data is no longer necessary for the purpose for which it was collected, subject to any legal or legitimate basis for retaining it.
Right to Restriction of Processing
You may request that we restrict the processing of your personal data in certain circumstances.
Right to Data Portability
Where applicable, you may request a copy of certain personal data in a structured, commonly used and machine-readable format, and may request that it be transmitted to another controller where technically feasible.
Right to Object
You may object to our processing of your personal data where we rely on legitimate interests, including processing for direct marketing purposes.
Right to Withdraw Consent
Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Rights Related to Automated Decision-Making
We do not carry out automated decision-making that produces legal or similarly significant effects on individuals without meaningful human involvement. We may use limited automated tools or rules-based systems for fraud detection, payment-risk review, account security, product suggestions, website analytics and service optimisation.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, including in the EU/EEA country where you live, work, or where the alleged infringement occurred.
For users in Ireland, the relevant authority is the Data Protection Commission.
How to Exercise Your Rights
If you wish to exercise any of your data protection rights, please contact us using the privacy contact details set out in this Privacy Policy.
Privacy contact email: [email protected]
When submitting a request, please provide enough information for us to understand your request and identify the relevant records.
To protect personal data and prevent unauthorised disclosure, we may ask you for information reasonably necessary to verify your identity before responding to your request.
We will normally respond to valid requests within one month of receipt. Where legally permitted, that period may be extended by up to a further two months where the request is complex or where we have received multiple requests, in which case we will inform you accordingly.
In certain circumstances, we may refuse a request or charge a reasonable fee where the request is manifestly unfounded, excessive, repetitive or otherwise permitted to be handled in that way under applicable law.
Right to Object to Direct Marketing
You have the right to object at any time to the processing of your personal data for direct marketing purposes.
If you no longer wish to receive marketing communications from us, you may:
- click the unsubscribe link in any marketing email;
- change your preferences, where account settings allow;
- contact us directly and request to be removed from marketing communications.
If you object to direct marketing or unsubscribe, we will stop sending you marketing communications, but this will not affect service-related communications that are necessary for:
- orders;
- payments;
- deliveries;
- returns;
- warranty claims;
- repair or diagnostic services;
- account security;
- important legal or contractual notices.
We may retain limited suppression-list information where necessary to ensure that your opt-out preference is respected.
Cookies and Tracking Technologies
We use cookies and similar technologies on our website for functional, security, analytics and, where applicable, marketing purposes.
These technologies may include browser cookies, local storage, pixels, tags, scripts and similar tools.
Types of Cookies and Technologies We May Use
We may use the following categories of cookies and similar technologies:
- Strictly necessary cookies – required for the operation of the website, checkout, account login, fraud prevention, basket functions and other essential services;
- Preference cookies – used to remember choices such as language, region or settings;
- Analytics cookies – used to understand how visitors use the website and to improve performance, navigation and content;
- Marketing cookies – used, where applicable, to measure campaigns, support relevant communications or improve marketing effectiveness.
Consent for Non-Essential Cookies
Where required by law, non-essential cookies and similar technologies will only be used if you provide consent.
Strictly necessary cookies do not require consent where they are genuinely necessary to provide the website or a service you request.
Cookie Controls
You can manage your cookie choices through:
- our cookie banner or consent manager;
- your browser settings;
- other preference tools made available on the website.
Please note that disabling certain cookies may affect website functionality or your user experience.
More Information
Further details about the cookies and similar technologies we use, including categories, purposes and controls, are set out in our Cookie Policy.
Automated Decision-Making and Profiling
We do not carry out automated decision-making that produces legal or similarly significant effects on individuals.
However, we may use limited automated tools or rules-based systems for purposes such as:
- fraud detection;
- transaction monitoring;
- account or website security;
- basic product recommendations;
- website analytics;
- service optimisation;
- routing support or service requests.
These tools are used to support our operations and improve security, efficiency and customer experience. They are not intended to replace meaningful human review where a decision could have a significant impact on an individual.
If this position changes in future, we will update this Privacy Policy accordingly.
Children’s Privacy
Our website, products and services are not directed to children.
We do not knowingly collect personal data from children for consumer-facing purposes without an appropriate legal basis.
If you believe that a child has provided personal data to us without appropriate authorisation or legal basis, please contact us and we will review the matter and take appropriate steps where necessary.
Where consent-based processing involving children may arise under applicable law, additional safeguards may apply.
Third-Party Links and External Services
Our website or services may include links to, or integrations with, third-party websites, platforms or services, including for example:
- payment gateways;
- courier or delivery tracking tools;
- map services;
- manufacturer or product reference materials;
- external service or software providers;
- linked resources or embedded tools.
These third-party services operate under their own privacy notices, terms and practices.
We are not responsible for the privacy practices of third-party websites or services that are not operated by us. We encourage you to review the privacy policies of any third-party websites or services you use where relevant.
Complaints to a Supervisory Authority
If you believe that your personal data has been processed in a way that does not comply with applicable data protection law, you have the right to lodge a complaint with a supervisory authority.
You may do so in the EU/EEA country where:
- you live;
- you work; or
- the alleged infringement took place.
For users in Ireland, the relevant supervisory authority is the Data Protection Commission.
We would, however, appreciate the opportunity to address your concerns first, and we encourage you to contact us in the first instance where appropriate.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes in applicable law or regulatory guidance;
- changes to our website, services or business operations;
- changes to the types of personal data we process;
- changes to our service providers or processing arrangements;
- security, compliance or transparency improvements.
The updated version of this Privacy Policy will be posted on this page, and the Effective date and Last updated date at the top of the Policy will be updated accordingly.
Where required by law, or where changes are material, we may also provide additional notice by email, website notice, account notification or other appropriate means.