Privacy policy

Towmax Privacy Policy


Last reviewed and updated: 03/25/2026 | Effective date: 03/25/2026



Who are we and what is the scope of this Privacy Policy?


To enable you to use our e-commerce shop operated on the Shopify platform and to enjoy our products, Towmax, LLC (“we”, “us”, “our” or “Towmax”) processes certain personal information. This Privacy Policy describes our personal information processing operations and outlines your rights related to your personal data.

This Privacy Policy covers websites operated under our domain (towmaxgear.com), including our Shopify-hosted e-commerce store and all related activities, such as order fulfillment, delivery arrangement, customer support, and email marketing operations.

If you wish to learn more about which cookies and similar technologies we use, please see the Your Privacy Choices section at the end of this policy.



What personal information do we process and for which purposes?


Provision of Core Services


It is necessary for Towmax to process your personal information to fulfill our contractual obligations to you and provide our e-commerce services. This includes processing your:

  • Contact information: full name, email address, delivery/billing address details, and phone number (collected solely for order delivery and shipping verification purposes)
  • Order and payment information: payment method details, product selection, order date, shipping method, order history, and transaction confirmations
  • Account information: username, password, profile details, and preferences you provide when creating an account on our Shopify store
  • Customer support information: all email communications you send to us, including inquiries, feedback, complaints, and warranty claims

We process this information to:

  1. Execute purchase agreements, including order processing, dispatch, delivery tracking, and payment processing
  2. Respond to your email inquiries, manage your account, and provide timely customer service via email
  3. Manage product returns, process complaints, warranty claims, and dispute resolution via email
  4. Send you non-promotional service communications exclusively via email, including technical or security-related updates, order status alerts, fraud warnings, account notifications, and changes to our terms or policies
  5. Provide any additional services requested by you, with all related communications delivered via email

Marketing Operations


We also process your information (including email address, order history, and browsing behavior) for legitimate marketing purposes, with your consent where required by applicable law. All marketing communications will be delivered to you exclusively via email. To personalize marketing emails, we may also process your purchase history, browsing behavior on our Shopify store, and interests as indicated by cookies and other tracking technologies.

Our email marketing operations may include:

  • Sending newsletters, cart abandonment reminders, product updates, personalized recommendations, promotional offers, and other marketing communications to your registered email address
  • Administering contests, sweepstakes, or surveys via email, and providing associated discounts, benefits, or rewards
  • Delivering targeted promotional content recommendations via email, based on your purchase history and website behavior

If you wish to object to our use of your personal information for email marketing operations, you may do so at any time: by using the one-click unsubscribe link included in all marketing emails, or by sending an opt-out request to us at support@towmaxgear.com. You may also update your marketing preferences in your user profile (where applicable).

To enhance your experience and deliver tailored email communications and promotions, we may create a customer profile and assign you to a relevant customer segment. This profile is based on:

  • The personal information defined above (including your name, contact details, and billing/shipping information)
  • Your purchase history and order behavior
  • Your device and network information
  • Your actions on our Shopify store (unless you have declined cookies and other trackers)
  • Your interaction with our marketing emails
  • Any additional information you voluntarily provide to us via email (e.g., birthday for birthday discounts)

Blog & User-Generated Content


We may operate a blog on our website, which enables you to interact with our content and other readers by submitting comments, or subscribing to email notifications for new comments or blog articles. If you choose to leave a comment, the personal data processed includes your name or chosen username (pseudonym) that is publicly available on the website, as well as your email address and IP address, which are processed in a non-public manner for security and spam prevention purposes. All notification communications related to your comments or subscriptions will be delivered exclusively via email.

Other Legitimate Purposes


We may also use the categories of personal information mentioned above, as well as information collected by our essential cookies, for the following purposes:

  • Maintenance of the security and integrity of our Shopify store, website, and services, including preventing data breaches, unauthorized access, and cyberattacks
  • Fraud prevention and detection, including anti-money laundering and identity verification checks
  • Research and development of our website, products, and services, using summarized, pseudonymized or anonymized data
  • Compliance with applicable laws, regulations, court orders, or legal process
  • Establishment, exercise or defense of legal claims
  • All communications related to the above purposes will be delivered exclusively via email



From where do we get your personal information?


In general, we process personal information that is:

  1. Directly provided by you to us via email or our Shopify store (e.g., when creating an account, placing an order, signing up for email marketing communications, or contacting customer support)
  2. Derived from your use of our services (e.g., browsing behavior on our Shopify store, interaction with our marketing emails, order history)
  3. Collected via cookies and similar tracking technologies, in accordance with our Cookie Consent Mechanism

Disclosure of Personal Information


We will only disclose your personal information in the following limited circumstances:

  • If we are obliged by law, regulation, or court order to disclose your personal information
  • If we need to disclose information to establish, exercise or defend legal claims, including to law enforcement authorities, regulatory bodies, or other relevant third parties
  • We will notify you of any such disclosure via email where permitted by law.

We do not sell your personal information to any third parties for monetary consideration.



Where is your personal information processed?


Towmax is a U.S. company, and our primary data processing operations are conducted in the United States. All data processing activities are carried out in compliance with applicable U.S. federal and state data protection laws.



How is your personal information protected?


Towmax has implemented comprehensive technical and organizational security measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These measures are reviewed and updated regularly to ensure they comply with industry standards and applicable laws, to safeguard the confidentiality and security of your personal data.



When will we delete your information?


Your personal information is only stored for as long as it is necessary for the purposes defined in this Privacy Policy. The specific retention period depends on the type of information and the purpose for which it is processed:

  • We retain order and transaction information for the duration of any applicable warranty period, and as required by tax, accounting, and other legal obligations (typically 3-7 years, depending on applicable law)
  • We retain your email address for marketing purposes until you opt out of receiving marketing communications from us, or until the information is no longer necessary for our marketing purposes
  • We retain account information until you request deletion of your account, or after a prolonged period of inactivity (we may disable inactive accounts after 24 months of inactivity)
  • We retain customer support email communications for as long as necessary to resolve your inquiry, and for a subsequent period to comply with legal obligations and for quality assurance purposes

We may still retain certain personal information to comply with our legal obligations, resolve disputes, and enforce our agreements, even after you request deletion of your account or information. We will notify you via email of any retention of your information where required by law.



Your Privacy Choices & Cookie Policy


Cookie Consent


We use cookies and similar tracking technologies (e.g., pixels, web beacons) on our Shopify store to enhance your user experience, analyze website performance, and deliver personalized email marketing content. Cookies are small text files placed on your device browser that store your preferences and enable core website functionality.

We classify cookies into the following categories:

  1. Essential Cookies: Required for the core functionality of our website, including cart management, checkout, and account login. You cannot opt out of these cookies, as they are necessary for the website to operate.
  2. Performance & Analytics Cookies: Help us understand how visitors interact with our website, by collecting and reporting information anonymously.
  3. Marketing & Targeting Cookies: Used to inform personalized email marketing content, based on your browsing behavior and interests.

At your first visit to our website, you will be presented with a Cookie Consent Mechanism, where you can choose to accept or reject non-essential cookies. You can also update your cookie preferences at any time via the Cookie Settings link on our website.

Do Not Track Signals


Do Not Track (“DNT”) is a web browser setting that adds a signal to the browser's header, informing websites about your DNT preferences. At this time, we do not respond to automated DNT browser signals, but we enable all website visitors to opt out of non-essential cookies and tracking mechanisms via our Cookie Consent Mechanism, and to opt out of marketing email communications via the methods outlined in this policy.

Email Marketing Opt-Out


You have the right to opt out of receiving marketing emails from us at any time. To exercise this right, simply click the unsubscribe link included in every marketing email we send, or send an opt-out request to support@towmaxgear.com. We will process your opt-out request within 10 business days, and will not send you marketing emails after your request is confirmed.

Please note that even if you opt out of marketing emails, we will still send you non-promotional service emails related to your orders, account, or any ongoing customer support inquiries.



How can you contact us?


If you have further questions about our information processing practices, or wish to exercise your privacy rights, you can submit your request exclusively via email at:

support@towmaxgear.com

You can also reach us via mail at:

Towmax, LLC

Attn: Data Protection Team

[Insert Your Physical Business Address Here]

Note: A valid physical business address is required for full Shopify store compliance



Supplemental Privacy Notices for U.S. State Residents


The clauses below apply exclusively to residents of the respective U.S. states, as defined by applicable state privacy laws. All communications related to privacy rights requests will be delivered exclusively via email.

Supplemental California Privacy Notice (CCPA)


This Supplemental California Privacy Notice only applies to natural persons who reside in California, even when temporarily outside of the state, as defined by the California Consumer Privacy Act of 2018 (“CCPA”), as amended by the California Privacy Rights Act (CPRA).

Categories of Personal Information We Collect


We collect the following categories of personal information from California residents:

  1. Identifiers (name, email address, phone number, mailing address, IP address, account username)
  2. Personal information categories listed in Cal. Civ. Code § 1798.80(e) (payment information, signature, government identifiers)
  3. Commercial information (order history, purchase records, product preferences, transaction data)
  4. Internet or other electronic network activity (browsing behavior on our website, interaction with our marketing emails, device information)
  5. Inferences drawn from other personal information to create a customer profile about you

We collect this information directly from you via our Shopify store or email, from your use of our services, and via cookies and similar tracking technologies. We do not sell personal information of minors under 16 years of age.

Business Purposes for Processing


We collect and use your personal information for the business and commercial purposes outlined in this Privacy Policy, including providing our services, processing orders, customer support via email, email marketing, fraud prevention, security, and compliance with legal obligations.

Your Rights Under the CCPA


California residents have the following rights with regard to their personal information:

  1. Right to Know and Access: You have the right to request confirmation that we process your personal information, and to request access to a copy of the specific pieces of personal information we hold about you.
  2. Right to Data Portability: You have the right to request that we transfer your personal information to you in a commonly used, machine-readable format, or to another designated entity, where technically feasible.
  3. Right to Correct: You have the right to rectify any inaccurate or incomplete personal information we hold about you.
  4. Right to Delete: You have the right to request that we delete your personal information, subject to limited exceptions where we are required to retain the information to comply with legal obligations, fulfill a contract, or exercise our legal rights.
  5. Right to Opt-Out: You have the right to opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising purposes.
  6. Right to Limit Use of Sensitive Personal Information: We do not process sensitive personal information (as defined by the CCPA) for purposes beyond those permitted by law.
  7. Right to Non-Discrimination: You have the right to exercise your rights under the CCPA without receiving discriminatory treatment from us. We will not charge you a different price for our products, deny you services, or provide a different level of service, for exercising your privacy rights.

Financial Incentives


Towmax may offer you financial incentives, such as discounts on your order, free shipping, or other benefits, in exchange for your personal information (e.g., when you subscribe to our email newsletter). The value of these incentives is reasonably calculated based on the estimated value of your information to us, in compliance with the CCPA. You may opt in to these programs at any time, and opt out by unsubscribing from the relevant email communications.

How to Exercise Your Rights


To exercise your rights under the CCPA, please send an email to support@towmaxgear.com with the subject line "CCPA Privacy Rights Request". We will process your request in accordance with applicable law, and will verify your identity by confirming the email address associated with your account. You may also designate an authorized agent to act on your behalf, by providing written authorization signed by you, and verifying both your and the agent’s identity via email.

Supplemental Virginia Privacy Notice (VCDPA)


This Supplemental Virginia Privacy Notice only applies to consumers who are residents of the Commonwealth of Virginia, acting only in an individual or household context, in accordance with the Virginia Consumer Data Protection Act (“VCDPA”).

Your Rights Under the VCDPA


Virginia residents have the following rights with regard to their personal data:

  1. Right to Know and Access: You have the right to request confirmation that we process your personal data, and to request access to your personal data.
  2. Right to Correct: You have the right to rectify any inaccurate or incomplete personal data we hold about you.
  3. Right to Delete: You have the right to request that we delete your personal data, subject to limited exceptions under the VCDPA.
  4. Right to Opt-Out: You have the right to opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell your personal data for monetary consideration, or carry out profiling that produces legal or similarly significant effects.
  5. Right to Data Portability: You have the right to obtain your personal data in a portable and readily usable format that allows you to transmit the data to another entity without hindrance.
  6. Right to Non-Discrimination: You have the right to exercise your rights under the VCDPA without discriminatory treatment from us.
  7. Right to Appeal: If we refuse to act upon your request, you have the right to appeal our decision. You may submit an appeal by emailing support@towmaxgear.com within 60 days of our refusal notice.

How to Exercise Your Rights


To exercise your rights under the VCDPA, please send an email to support@towmaxgear.com with the subject line "VCDPA Privacy Rights Request". We will process your request in accordance with applicable law, and will verify your identity before acting on your request.

Supplemental Colorado Privacy Notice (CPA)


This Supplemental Colorado Privacy Notice only applies to consumers who are residents of Colorado, acting only in an individual or household context, in accordance with the Colorado Privacy Act (“CPA”).

Your Rights Under the CPA


Colorado residents have the following rights with regard to their personal data:

  1. Right to Access: You have the right to request access to the personal data we process about you.
  2. Right to Correction: You have the right to rectify any inaccurate or incomplete personal data we hold about you.
  3. Right to Deletion: You have the right to request that we delete your personal data, subject to limited exceptions under the CPA.
  4. Right to Opt-Out: You have the right to opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell your personal data for monetary consideration, or carry out profiling that produces legal or similarly significant effects.
  5. Right to Data Portability: You have the right to obtain your personal data in a portable and readily usable format that allows you to transmit the data to another entity without hindrance.
  6. Right to Non-Discrimination: You have the right to exercise your rights under the CPA without discriminatory treatment from us.
  7. Right to Appeal: If we refuse to act upon your request, you have the right to appeal our decision. You may submit an appeal by emailing support@towmaxgear.com within 60 days of our refusal notice.

How to Exercise Your Rights


To exercise your rights under the CPA, please send an email to support@towmaxgear.com with the subject line "CPA Privacy Rights Request". We will process your request in accordance with applicable law, and will verify your identity before acting on your request.

Supplemental Connecticut Privacy Notice (CTDPA)


This Supplemental Connecticut Privacy Notice only applies to Connecticut residents who are not acting in an employment or commercial context, in accordance with the Connecticut Act Concerning Personal Data Privacy and Online Monitoring (“CTDPA”).

Your Rights Under the CTDPA


Connecticut residents have the following rights with regard to their personal data:

  1. Right to Be Informed and Access: You have the right to request confirmation that we process your personal data, and to access the same.
  2. Right to Correct: You have the right to rectify any inaccurate or incomplete personal data we hold about you.
  3. Right to Deletion: You have the right to request that we delete your personal data, subject to limited exceptions under the CTDPA.
  4. Right to Opt-Out: You have the right to opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell your personal data for monetary consideration, or carry out profiling that produces legal or similarly significant effects.
  5. Right to Data Portability: You have the right to obtain your personal data in a portable and readily usable format that allows you to transmit the data to another entity without hindrance.
  6. Right to Non-Discrimination: You have the right to exercise your rights under the CTDPA without discriminatory treatment from us.
  7. Right to Appeal: If we refuse to act upon your request, you have the right to appeal our decision. You may submit an appeal by emailing support@towmaxgear.com within 60 days of our refusal notice.

How to Exercise Your Rights


To exercise your rights under the CTDPA, please send an email to support@towmaxgear.com with the subject line "CTDPA Privacy Rights Request". We will process your request in accordance with applicable law, and will verify your identity before acting on your request.