You are here

Privacy Notice

1. Introduction

Established in 1957, McConechy’s Tyre Service Limited (“McConechy’s”) is one of the country’s best-known suppliers of tyres and high quality automotive products. In 2019, McConechy’s became a subsidiary of the Halfords Group.

As an essential part of our business, we collect and manage customer data. In doing so, we observe all relevant data protection legislation, and are committed to protecting and respecting customers’ privacy and rights. Specifically, Halfords acts as “Data Controller” in respect of the information gathered and processed by this website or when customers visit one of our centres.

In order that you are reliably informed about how we collect, process, store and share your information, we have developed this Privacy Statement. This Statement also advises how you can have control over our use of your data.

If you have any comments or queries regarding our use of your data, please contact our Data Protection Officer by email at dataprotectionofficer@halfords.co.uk or by post at Data Protection Officer, Halfords Group plc, Icknield Street Drive, Washford West, Redditch B98 0DE.

2. What information do we collect about you?

In general terms, we collect information about you so that we can:

  • fulfil orders or bookings that you may make via this website;
  • provide services at our centres;
  • deliver high-levels of customer care and support; and
  • communicate with you effectively whether this is about your service, or so that you don't miss out on great promotions, offers and helpful reminders.

Collecting information from you

The information that we collect from our customers is known as “personal data”. This includes customers’ names, home addresses and e-mail addresses. We collect this in a number of different ways. For example, customers may provide this data to us directly when filling in forms on this website, or when corresponding with us by telephone, e-mail or letter.

We also take customers’ credit card details: however, we do not save this information on any of our systems. Equally, we do not collect any special category data about our customers (i.e. information about their ethnicity, religion, health etc).

Please also be advised that when you visit this website, cookies will be used to collect information about you such as your Internet Protocol (IP) address which connects your computer or mobile device to the internet. We do this so that we can measure our website’s performance and make improvements in the future. Cookies are also used to enhance this website’s functionality and personalisation, which includes sharing data with third party organisations (as described in our Cookies Policy here). You can control this by adjusting your cookies settings.

Information sourced from third parties

In order to best support our customers, we also collect data from HaynesPro. This includes limited information about customers’ vehicles so that we can identify the make, model and age of their car using their Vehicle Registration Number, and where appropriate, validate orders for car parts prior to engaging a technician. Additionally, we use this information to provide customers with the most up-to-date and relevant messages regarding their car’s safety, maintenance and upkeep.

3. How will we use that information?

We use the data collected from you for the specific purposes listed in the table below. Please note that this table also explains:

  • the lawful basis for processing your data, linked to each processing purpose;
  • in what circumstances your personal data will be shared with a third-party organisation; and
  • for how long we keep customer data.

Data that is collected by cookies is not included in the table below, but is explained in section 3 of our Cookies Policy here.

Purpose for processing data

Lawful basis for processing data

Third party organisations with whom data is shared

Data retention period

Data processing related to a purchase

To fulfil purchases and orders which you may make via this website

To meet the requirements of contract law

Customer data will be available to the following:

  • Levy McCallum who administers this website on our behalf;

  • DataTechnical (Glasgow) who supports our IT infrastructure;

  • HaynesPro where a Vehicle Registration Number is provided; and

  • Planning-Incwho manages our customer database.

Orders are saved in our SAP sales system, which is supported by BCX, as well as TCS, our IT partners.

Data may also be shared with relevant suppliers and manufacturers: however as we use many different providers, it is not possible to list them all here

6 years following the customer’s last transaction

To fulfil purchases and orders which you may make in a centre

To meet the requirements of contract law

Customer data will be available to the following:

  • Viqtor Davies who supports our PACE till system;

  • Cam Systems who supports our Cameo till system and who maintains our data warehouse;

  • HaynesPro where a Vehicle Registration Number is provided;

  • the Driver and Vehicle Standards Agency where MOT data is captured; and

  • Planning-Inc who manages our customer database.

Orders are saved in our SAP sales system, which is supported by BCX, as well as TCS, our IT partners.

Data may also be shared with relevant suppliers and manufacturers: however as we use many different providers, it is not possible to list them all here

6 years following the customer’s last transaction

To fulfil purchases and orders which are forwarded to us by partner organisations

To meet the requirements of contract law

We work with a number of third party organisations such as Asda, Black Circle and RAC, who ask us to fit new tyres on customers’ vehicles, whether by appointment at one of our fast-fit centres, or at the roadside. In these circumstances, we act as a separate and independent Data Controller to those organisations, and therefore process, manage and store customer data as described within this Privacy Statement

6 years following the customer’s last transaction

To process customer requests for finance (please note that this includes processing for the purposes of fraud prevention)

Customers will be asked to provide informed consent before their data is processed for the purposes of applying for finance

Depending on the finance package chosen, data will be captured by:

  • Klarna Bank AB who is authorised and regulated by the Swedish Financial Supervisory Authority, with limited supervision by the Financial Conduct Authority and Prudential Regulation Authority in the UK; or

  • Payment Assist who is authorised and regulated by the Financial Conduct Authority

6 years following expiry of the finance agreement

To process credit / debit card payments, and communicate with you if there are any issues

To meet the requirements of contract law

Data will be shared with Worldpay. In processing this data, customer details will also be automatically checked for fraud prevention purposes

We do not record credit / debit card information: however, anonymised token data is retained for 6 years following the transaction

To update you as necessary about your specific order or purchase, for example to remind you about a pre-booked service

To meet the requirements of contract law

Email communications will be supported by Cheetah Digital

6 years following the customer’s last transaction. Data used by Cheetah Digital will be retained for 19 months

After-sales data processing

To communicate with you via email, SMS text or telephone in respect of a product recall or other safety information about a purchase which you have made from us

This is deemed legitimate as it is in customers’ interest to be alerted about safety issues which may affect them. Depending upon the nature of the alert, this may also help protect people’s vital interests

Customer data will be held in PACE which is managed by Viqtor Davis or Cameo which is managed by Cam Systems. Information will also be held in our customer database which is managed on our behalf by Planning-Inc


Emails will be sent by Cheetah Digital

6 years following the customer’s last transaction. Data used by Cheetah Digital will be retained for 19 months

To contact you via telephone, email or text in relation to repairs which are essential and/or time-sensitive following an MOT or Service (i.e. an MOT fail or advisory notice)

This is deemed legitimate as it is in customers’ interest to be reminded about repairs that are necessary and/or advised for either legal or safety reasons

Customer data will be held in our marketing database that is managed on our behalf by Planning-Inc. Emails will be sent by Cheetah Digital

6 years following the customer’s last transaction. Data used by Cheetah Digital will be retained for 19 months

To contact you via email or text in order to reminder you about the need for an annual MOT or Service

This is deemed legitimate as it is in customers’ interest to be reminded about their MOT or Service

Customer details will be held in our customer database which is managed on our behalf by Planning-Inc. Emails or texts will be sent by Cheetah Digital

6 years following the customer’s last transaction. Data used by Cheetah Digital will be retained for 19 months

To send you emails asking you to complete a survey based on your experience of our service

This is deemed legitimate, as it enables customers to provide feedback and resolve queries in as non-intrusive a manner as possible

Customer details will be held in our customer database which is managed on our behalf by Planning-Inc. Emails will be sent by Cheetah Digital


Please note that customers’ data will only be shared with our market research partner (ABA) if they actively choose to complete the survey

6 years following the customer’s last transaction. Data used by Cheetah Digital will be retained for 19 months. Customer survey responses will be kept by ABA for 5 years

To send you emails asking you to complete a product review

This is deemed legitimate, as it enables customers to complete reviews that inform the wider public about a product’s usefulness and value




Customer details will be held in our customer database which is managed on our behalf by Planning-Inc. Emails will be sent by Cheetah Digital


Please note that customers’ data will only be shared with our partners (Trustpilot) if they choose to submit a review

6 years following the customer’s last transaction. Data used by Cheetah Digital will be retained for 19 months

Data processing for marketing

To send emails with news, special offers, promotions and other messages that are relevant to you: this includes emails about abandoned baskets, as well as reminders about services that you have asked us to tell you about. This may require us to profile you as described in section 5.8 below

Customers will be asked for their consent before we send marketing communications

Customer details will be held in our customer database which is managed on our behalf by Planning-Inc. Emails will be sent by Cheetah Digital, and may include personalised messages facilitated by Moveable Ink

6 years following the customer’s last transaction. Data used by Cheetah Digital will be retained for 19 months

To use customer data (primarily email addresses) to deliver advertising across various social media and other online platforms (e.g. Google, Facebook)

Even though it is in customers’ interest to receive communications for which they have given their consent, no personal data is shared in these circumstances

Anonymised data only will be shared with various advertising partners

6 years following the customer’s last transaction

Other data processing

To process competition entries and inform winners

Customers give consent when they submit competition entries: this is separate to consent for marketing purposes





Details will be held in our customer database which is managed on our behalf by Planning-Inc (NB where a competition is run by a third party, for example a newspaper or radio station, any subsequent data sharing with us will be made clear within the competition terms & conditions)

6 years following the customer’s last transaction

To match data that we hold in order to acquire improved insight about our customers both individually and at aggregate level: this requires us to profile you as described more fully in section 5.8 below

This is deemed legitimate as it is in customers’ interest that we understand their preferences and buying behaviours so that the information we provide, is tailored to them

Customer details will be held in our customer database which is managed on our behalf by Planning-Inc. Additionally, we will use Google Analytics to improve our performance and impact

6 years following the customer’s last transaction

4. Overseas Transfers

Customer data is retained within the European Economic Area (“EEA”) with the exception of where it is processed on our behalf by the following third party organisations for the purposes described in section 3 above:

Organisation name

Purpose for the transfer

Areas where the data is processed

BCX

Provides technical support to our SAP sales system

South Africa

Cheetah Digital

Provides out-of-hours technical support

Costa Rica, Malaysia, India

Moveable Ink

Facilitates personalisation of marketing emails

USA

TCS

Provides IT support across Halfords

India

In these instances, we ensure that the relevant third parties observe appropriate technical and organisational security measures in order to protect the data against unauthorised access, disclosure, alteration or destruction. In doing so, we are assured that these third parties operate equivalent data protection and security practices as organisations based within the EEA.

5. Your rights

Under the terms of data protection legislation, you have the following rights as a result of using this website:

5.1 Right to be informed

This Privacy Statement, together with our Cookies Policy, fulfils our obligation to tell you about the ways in which we use your information as a result of you using this website.

5.2 Right to access

You have the right to ask us, in writing, for a copy of any personal data that we hold about you. This is known as a “Subject Access Request”. Except in exceptional circumstances (which we would discuss and agree with you in advance), you can obtain this information at no cost. We will send you a copy of the information within 30 days of your request.

To make a Subject Access Request, please write to our Data Protection Officer at Halfords Group plc, Icknield Street Drive, Washford West, Redditch B98 0DE.

5.3 Right to rectification

If any of the information that we hold about you is inaccurate, you can contact our Data Protection Officer at dataprotectionofficer@halfords.co.uk. Any corrections that you request will be made as soon as possible, and certainly no later than 30 days following your notification.

5.4 Right to be forgotten

You can ask that we erase all personal information that we hold about you. Where it is appropriate that we comply, your request will be fully actioned within 30 days. For further information, please contact our Data Protection Officer at dataprotectionofficer@halfords.co.uk.

5.5 Right to object

You have the right to object to:

  • the continued use of your data for any purpose listed in section 3 of this Privacy Statement for which consent is identified as the lawful basis of processing (i.e. you have the right to withdraw your consent at any time); or
  • the continued use of your data for any purpose listed in section 3 of this Privacy Statement for which the lawful basis of processing is that it has been deemed legitimate.

To exercise this right, contact our Data Protection Officer at dataprotectionofficer@halfords.co.uk.

Please note that you can also exercise your right to object to our use of cookies by following the guidance in section 4 of our Cookies Policy here.

5.6 Right to restrict processing

If you wish us to restrict the use of your data because (i) you think it is inaccurate but this will take time to validate, (ii) you believe our data processing is unlawful but you do not want your data erased, (iii) you want us to retain your data in order to establish, exercise or defend a legal claim, or (iv) you wish to object to the processing of your data, but we have yet to determine whether this is appropriate, please contact our Data Protection Officer at dataprotectionofficer@halfords.co.uk.

5.7 Right to data portability

If you would like us to move, copy or transfer the data that we hold about you to another organisation, please contact our Data Protection Officer at dataprotectionofficer@halfords.co.uk.

Please be advised that this only applies to certain data which has been submitted by you electronically for specific purposes only. Our Data Protection Officer can provide further advice.

5.8 Rights related to automated decision-making

In order that we can understand your interests and preferences - and deliver communications that will be most of interest to you, where you have consented to receive these - we employ profiling techniques (which include automated decision-making) based upon the information that you have provided to us, as well as your purchasing history and engagement with us. We do not believe that these processes have any potential to significantly or negatively affect you i.e. they will not lead to any form of discrimination against you or impact your legal rights.

Examples of how we use profiling are as follows:

  • if you have provided us with your vehicle registration number, we are more likely to send you reminders about MOTs and other related products and services; and
  • if you do not engage or interact with special offer emails that we send you (even though you will have consented to receive these), we are likely to send you fewer emails than customers who are more actively involved with us.

Where we hold a customer’s details, we will also seek to ensure that, as far as possible, we maintain a single composite record of their interactions with us, which may require us to match their different activities. Where customers have indicated that they do not want us to us their data for receiving communications (other than those deemed legitimate), we will use this information purely for anonymised internal analytics and reporting, for example, looking at sales trends which does not identify individual customers.

If you do not want us to undertake profiling or matching, you may either:

  • object to the processing of your data (see section 5.5 of this Privacy Statement above); or
  • request that we erase all personal data about you (see section 5.4 of this Privacy Statement above).

6. Data privacy and security

At McConechy’s, we maintain a comprehensive data management work programme, which includes processes for ensuring that data protection is a key consideration of all new and existing IT systems that hold customers’ personal data. Where any concerns, risks or issues are identified, we conduct relevant impact assessments in order to determine any actions that are necessary to ensure optimum privacy.

We also maintain an active information security work programme which seeks to protect the availability, confidentiality and integrity of all physical and information assets. Specifically, this helps us to:

  • protect against potential breaches of confidentiality;
  • ensure all IT facilities are protected against damage, loss or misuse;
  • increase awareness and understanding of the requirements of information security, and the responsibility of our colleagues to protect the confidentiality and integrity of the information that they handle; and
    ensure the optimum security of this website.

We recognise that the security of data and transactions on this website is of primary importance. We therefore ensure that all connections to secure parts of the website (such as when you login) are encrypted and authenticated using strong protocols, key exchanges and ciphers.

7. Card payment security

Halfords is proud to have been awarded the Payment Card Industry Data Security Standard (PCI-DSS), which recognises the robust processes that we apply when handling card transactions from the major card schemes. This independent certification gives our customers assurance that our transactional systems protect your data with appropriate levels of security.

8. Disclaimers

Every effort is made to ensure that the information provided on this website, and in this Privacy Statement, is accurate and up-to-date, but no legal responsibility is accepted for any errors or omissions contained herein.

We cannot accept liability for the use made by you of the information on this website or in this Privacy Statement, nor do we warrant that the supply of the information will be uninterrupted. All material accessed or downloaded from this website is obtained at your own risk. It is your responsibility to use appropriate anti-virus software.

This Privacy Statement applies solely to the data collected by us, and therefore does not also apply to data collected by third party websites and services that are not under our control. Furthermore, we cannot be held responsible for the Privacy Statements on third party websites, and we advise users to read these carefully before registering any personal data.

9. Accessibility

We are committed to providing a website in which content is accessible to everyone. We therefore update our website regularly in order to make it as adaptable as possible.

For example, users can control the text size of each page within their browser. On a PC, holding the “Ctrl” key while pressing the “+” (plus) key will increase text size, and holding the “Ctrl” key while pressing the “-“ (minus) key will decrease the text size.

10. General

Questions and comments regarding this Privacy Statement are welcomed, and should be sent to our Data Protection Officer at dataprotectionofficer@halfords.co.uk.

You can also contact our Data Protection Officer if you have any concerns or complaints about the ways in which your personal data has been handled as a result of you using this website.

Alternatively, you have the right to lodge a complaint with the Information Commissioner’s Office (“ICO”) who may be contacted at Wycliffe House, Water Lane, Wilmslow SK9 5AF or https://ico.org.uk (for details on how your data will be managed by the ICO, please refer to https://ico.org.uk/global/privacy-notice/