// LEGAL
Privacy Policy
Overview
ESP Safety, operating under ESP Safety Equipment & Tools ("we," "us," or "our"), is committed to protecting the privacy of our customers, site visitors, and business partners. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit esprimesafety.com or make a purchase from us.
We supply professional-grade tools, hardware, construction equipment, safety gear, and industrial supplies to contractors, construction firms, fabrication shops, and government entities across the United States. The nature of our business means we handle both consumer and business-to-business (B2B) data, and we take both equally seriously.
By accessing our website or placing an order, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of our services.
Information We Collect
We collect information in the following ways:
Information You Provide Directly
- Full name, company name, job title
- Billing and shipping address
- Email address and phone number
- Payment information (processed securely via Shopify Payments — we do not store raw card data)
- Order history, product preferences, and special requests
- Messages submitted via our contact form
- Account credentials if you create a customer account
Information Collected Automatically
- IP address and approximate geographic location
- Browser type, operating system, and device identifiers
- Pages visited, time on site, referral URLs, and click paths
- Session data and shopping cart contents
- Cookies and similar tracking technologies (see Section 05)
Information from Third Parties
- Fraud prevention and identity verification services
- Shipping carriers (UPS, FedEx, USPS) for delivery status
- Analytics providers such as Google Analytics
- Marketing platforms including email service providers
How We Use Your Information
We use the information we collect for the following legitimate business purposes:
- Order fulfillment — processing transactions, arranging shipping, and sending order confirmations and tracking updates
- Customer support — responding to inquiries, resolving disputes, and providing technical assistance on equipment
- Account management — creating and maintaining your customer account and purchase history
- Marketing communications — sending promotional emails, product announcements, and special offers (you may opt out at any time)
- Site improvement — analyzing usage patterns to improve navigation, product listings, and checkout experience
- Fraud prevention — detecting and preventing unauthorized transactions and abuse
- Legal compliance — meeting our obligations under applicable federal and state laws
- B2B relationship management — managing wholesale accounts, bulk order quotes, and government procurement requests
We do not sell your personal information to third parties for their own marketing purposes.
Sharing of Information
We may share your information with trusted third parties only as necessary to operate our business:
- Shopify Inc. — our e-commerce platform provider, which hosts our store and processes payments under their own privacy policy
- Payment processors — Shopify Payments, Stripe, and similar PCI-DSS compliant processors
- Shipping & logistics partners — UPS, FedEx, USPS, and third-party logistics (3PL) providers for order fulfillment
- Email marketing platforms — such as Klaviyo or Shopify Email, used to send transactional and promotional communications
- Analytics services — Google Analytics and similar tools for site performance measurement
- Legal authorities — when required by law, court order, or to protect the rights and safety of our company or others
All third-party service providers are contractually required to handle your data securely and only for the purposes we specify.
Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law:
- Order records — retained for a minimum of 7 years for tax and accounting compliance
- Customer accounts — retained while your account is active; deleted within 90 days of a verified deletion request
- Marketing data — retained until you unsubscribe or request deletion
- Analytics data — aggregated and anonymized after 26 months
- Contact form submissions — retained for up to 2 years
Security
We implement industry-standard security measures to protect your information:
- SSL/TLS encryption for all data transmitted between your browser and our servers
- PCI-DSS compliant payment processing — we never store raw credit card numbers
- Two-factor authentication (2FA) on all administrative accounts
- Regular security audits and vulnerability assessments
- Access controls limiting employee access to personal data on a need-to-know basis
While we take every reasonable precaution, no method of transmission over the internet is 100% secure. In the event of a data breach that affects your rights, we will notify you as required by applicable law.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
California Residents (CCPA / CPRA)
- Right to know what personal information we collect and how it is used
- Right to delete your personal information
- Right to opt out of the sale or sharing of personal information
- Right to correct inaccurate personal information
- Right to non-discrimination for exercising your privacy rights
All Users (General Rights)
- Access and review the personal data we hold about you
- Request correction of inaccurate data
- Opt out of marketing emails via the unsubscribe link in any email
- Request data portability in a machine-readable format
To exercise any of these rights, contact us at info@esprimesafety.com. We will respond within 45 days.
Third-Party Links
Our website may contain links to third-party websites, manufacturer pages, or partner portals. These sites operate under their own privacy policies, and we are not responsible for their practices. We encourage you to review the privacy policy of any third-party site you visit.
Children's Privacy
Our website and services are intended for business and professional use by individuals aged 18 and older. We do not knowingly collect personal information from children under the age of 13. If we become aware that a child under 13 has provided us with personal information, we will delete it promptly. If you believe we have inadvertently collected such information, please contact us immediately.
Policy Changes
We reserve the right to update this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:
- Update the "Effective Date" at the top of this page
- Post a notice on our website homepage for 30 days
- Send an email notification to registered customers for significant changes
Your continued use of our website after any changes constitutes your acceptance of the updated policy.
Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us: