LEGAL · PRIVACY
Privacy Policy
COMEX Design ("COMEX Design," "we," "us," or "our") respects your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information when you visit our website, create an account, browse our catalog, place an order, or otherwise interact with us. It also explains the rights you may have under applicable United States federal and state privacy laws and how to exercise them.
This Privacy Policy applies only to information collected through our website and our offline interactions with customers in the United States. Our services are intended for residents of the United States who are at least eighteen (18) years of age. By using our website or providing personal information to us, you acknowledge that you have read and understood this Privacy Policy.
A Spanish-language version of this Privacy Policy is provided for the convenience of our customers. In the event of any conflict or inconsistency between the English and Spanish versions, the English version shall control.
Table of Contents
- Who We Are
- Information We Collect
- How We Use Your Information
- Lawful Purposes for Processing
- How We Share and Disclose Information
- Cookies, Local Storage, and Tracking Technologies
- Do Not Track and Global Privacy Control
- Your Rights Under California Law
- Your Rights Under Other State Laws
- How to Exercise Your Rights
- Children's Privacy
- Data Retention
- Information Security
- Users Outside the United States
- Changes to This Privacy Policy
- Contact Us
01.Who We Are
COMEX Design is a retailer of ready-to-install kitchen cabinets, serving customers throughout the United States. For purposes of this Privacy Policy, COMEX Design is the controller of the personal information we collect about you.
You may contact us at any time about this Privacy Policy or your personal information using the contact details provided at the end of this document.
02.Information We Collect
We collect personal information that you provide directly to us, that we obtain automatically when you use our website, and that we receive from third parties such as payment processors, identity providers, and shipping carriers. The categories of personal information we collect include:
Information You Provide
- Identifiers and contact details: full name, email address, telephone number, and billing and shipping addresses.
- Account credentials: username and password. Passwords are stored only in salted, hashed form using bcrypt; we do not retain or have access to your plaintext password.
- Order and transaction information: products ordered, color and finish selections, order history, cart contents, and customer-tier classification (individual, dealer, or VIP dealer).
- Communications: messages you send to us through contact forms, email, telephone, or social channels, including any information you choose to include.
- Tier-eligibility information: business name, resale or tax-exemption documentation, and similar information you submit when applying for dealer or VIP dealer pricing.
Information Collected Automatically
- Device and connection data: IP address, browser type and version, operating system, device identifiers, and approximate location derived from IP address.
- Usage data: pages viewed, links clicked, referring URLs, time spent on pages, and similar interaction data, collected through Vercel Analytics in an aggregated and anonymized form. Vercel Analytics does not use third-party cookies or persistent client-side identifiers.
- Server log data: access logs generated by our hosting infrastructure, including timestamps, request paths, and response status codes, used for security, debugging, and abuse prevention.
- Cookies and local storage: a session cookie maintained by our authentication system (NextAuth) when you sign in, a language-preference value, and a non-personally-identifying anonymous shopping cart stored in your browser's local storage under the key "comex-cart."
Information from Third Parties
- Payment information: when you check out, payment is processed by Stripe, Inc. We do not collect or store full payment-card numbers. Stripe provides us with a tokenized reference, the brand of the card, and the last four digits of the card number for receipts, refunds, and fraud-prevention purposes.
- Shipping and fulfillment data: tracking numbers, delivery confirmations, and exception notices from the carriers we engage to deliver your order.
- Fraud-prevention signals: risk scores and indicators provided by our payment processor and other service providers to help us detect and prevent fraudulent transactions.
03.How We Use Your Information
We use the personal information described above for the following purposes:
- To process, fulfill, ship, and deliver your orders, including communicating with you about order status and exceptions.
- To establish and maintain your account, authenticate you, and enable you to access your order history and saved preferences.
- To determine eligibility for, and apply, the appropriate customer tier (individual, dealer, or VIP dealer) and associated pricing.
- To provide customer support, respond to inquiries, and resolve complaints, returns, and warranty claims.
- To detect, investigate, and prevent fraud, security incidents, and abuse, and to enforce our Terms of Service and other legal rights.
- To comply with legal, tax, accounting, and regulatory obligations, including the retention of transaction records as required by federal and state law.
- To operate, evaluate, debug, and improve our website, products, and services, including measuring performance and aggregate usage trends.
- To send you transactional communications such as order confirmations, shipping notifications, and account-related notices, and, where you have opted in, marketing communications about our products and promotions.
04.Lawful Purposes for Processing
Where state law requires that we identify a lawful purpose for processing personal information, we rely on the following: performance of a contract with you (for example, fulfilling your order); compliance with our legal obligations (for example, tax recordkeeping); our legitimate interests (for example, securing our website, preventing fraud, and improving our services), provided those interests are not overridden by your rights; and your consent, where required by law, which you may withdraw at any time.
07.Do Not Track and Global Privacy Control
Our website does not respond to "Do Not Track" signals because no common industry standard for those signals has been adopted. However, where required by law, we treat a Global Privacy Control ("GPC") signal received through your browser as a valid request to opt out of any sale or sharing of your personal information for cross-context behavioral advertising. Because we do not engage in such sales or sharing, the practical effect of a GPC signal on our processing is limited to confirming our existing practice.
08.Your Rights Under California Law
If you are a California resident, the CCPA gives you the following rights with respect to your personal information:
- The right to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties to whom we have disclosed it.
- The right to request deletion of personal information we have collected from you, subject to legal exceptions (for example, where retention is necessary to complete a transaction, comply with a legal obligation, or detect fraud).
- The right to request correction of inaccurate personal information we maintain about you.
- The right to opt out of the sale or sharing of personal information for cross-context behavioral advertising. As stated above, we do not sell or share personal information for these purposes.
- The right to limit the use and disclosure of any sensitive personal information we collect, to the extent applicable.
- The right not to receive discriminatory treatment for exercising your rights under the CCPA.
Authorized Agents
California residents may designate an authorized agent to submit requests on their behalf. We will require the agent to provide written authorization signed by the consumer, and we may require the consumer to verify their own identity directly with us before fulfilling the request.
09.Your Rights Under Other State Laws
If you are a resident of a state with a comprehensive consumer privacy law — including without limitation Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, Iowa, Tennessee, Indiana, Delaware, New Jersey, New Hampshire, Kentucky, Minnesota, Maryland, and Rhode Island — you may have some or all of the following rights, subject to the conditions and exceptions of the law that applies to you:
- The right to confirm whether we are processing your personal information and to access that information.
- The right to obtain a copy of your personal information in a portable, readily usable format.
- The right to correct inaccurate personal information.
- The right to delete personal information we have collected about you.
- The right to opt out of targeted advertising, the sale of personal information, and certain forms of profiling that produce legal or similarly significant effects.
- The right not to receive discriminatory treatment for exercising your rights.
Appeals
If we decline to take action in response to a rights request, you may appeal that decision by replying to our written response or by contacting us at the privacy email address listed at the end of this Privacy Policy. We will respond to your appeal within the time period required by your state's law and will inform you of any further options, including the ability to contact your state attorney general if you remain dissatisfied with our response.
10.How to Exercise Your Rights
To exercise any of the rights described above, please contact us by email at the address listed at the end of this Privacy Policy, or by mail at our headquarters address. Please include enough information for us to verify your identity and locate your records, such as your full name, the email address associated with your account, and a description of your request.
We will respond to verifiable consumer requests within forty-five (45) days of receipt. Where reasonably necessary, we may extend the response period by an additional forty-five (45) days, in which case we will notify you of the extension and the reason for it. There is no fee to submit a request, although we may charge a reasonable fee or decline to act on requests that are manifestly unfounded, excessive, or repetitive, as permitted by law.
11.Children's Privacy
Our website and services are not directed to children. Consistent with the Children's Online Privacy Protection Act ("COPPA"), we do not knowingly collect personal information from children under the age of thirteen (13). In addition, our services are intended for adults, and we do not knowingly collect personal information from individuals under the age of eighteen (18). If you believe we have collected personal information from a minor, please contact us and we will promptly delete it.
12.Data Retention
We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, including legal, tax, accounting, and reporting obligations. Order and transaction records are typically retained for at least seven (7) years to satisfy applicable Internal Revenue Service and state tax requirements. Account information is retained for as long as your account is active and for a reasonable period thereafter, unless you request deletion. Server logs and security records are retained for shorter operational periods consistent with industry practice. When personal information is no longer needed, we delete or anonymize it in a secure manner.
13.Information Security
We implement and maintain reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These safeguards include encryption of personal information in transit using industry-standard Transport Layer Security (TLS), the storage of account passwords in salted, hashed form, the delegation of payment-card processing to a PCI-DSS-compliant service provider (Stripe), restricted internal access to personal information on a need-to-know basis, and regular review of our security practices.
No method of transmission over the internet or electronic storage is one hundred percent secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for promptly notifying us of any suspected unauthorized access.
14.Users Outside the United States
Our services are intended for residents of the United States, and personal information is collected, stored, and processed in the United States. We do not knowingly market to or accept orders from individuals located outside the United States. If you access our website from another jurisdiction, you do so on your own initiative and are responsible for compliance with local laws.
15.Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will revise the "Last Updated" date at the top of this Privacy Policy and, where appropriate, provide additional notice (such as by email or by posting a prominent notice on our website). Your continued use of our website or services after any update constitutes your acknowledgment of the revised Privacy Policy.
16.Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us using the details provided in the section that follows.
Contact COMEX Design
For privacy-related questions, requests to exercise your rights, or appeals, please reach us using any of the channels below. Please include enough information for us to verify your identity and locate your records.
- Privacy Email
- accounts@comex-design.com
- Telephone
- +1 (713) 924-7388
- Mailing Address
- COMEX Design United States