Privacy Policy
Last Reviewed: March 6, 2026
Document Reference: ISPO-PP-01 Rev 01
#101-9 Burbidge Street, Coquitlam, B.C. V3K 7B2, Canada
604-472-3800

Table of Contents
1. Introduction
AMPCO Manufacturers Inc. (“Ampco,” “we,” “us,” or “our”) is a precision manufacturer based in Coquitlam, British Columbia, Canada. We produce labels, decals, membrane switches, and printed circuit board assemblies for automotive and industrial customers.
This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you visit our website at ampcomfg.com, interact with our blog, or engage with us through business inquiries, customer orders, or supplier relationships.
We are committed to complying with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia’s Personal Information Protection Act (PIPA), and, where applicable, the European Union’s General Data Protection Regulation (GDPR) and other relevant data protection laws.
Privacy Officer: Ampco has designated a Privacy Officer responsible for our compliance with applicable privacy legislation. If you have questions or concerns about how we handle your personal information, please contact our Privacy Officer using the details in Section 18.
2. Definitions
Term | Definition |
|---|---|
Personal Information / Personal Data | Any information about an identifiable individual, as defined under PIPEDA, BC PIPA, and GDPR. This includes information that can directly or indirectly identify a natural person. |
Processing | Any operation performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, alignment, combination, restriction, erasure, or destruction. |
Data Controller | The entity that determines the purposes and means of processing personal data. For the purposes of this policy, Ampco is the data controller. |
Data Processor | An entity that processes personal data on behalf of the data controller, such as our service providers. |
Data Subject / You | The individual whose personal data is being processed, including website visitors, customers, business contacts, and prospective partners. |
Consent | Any freely given, specific, informed, and unambiguous indication of your wishes by which you agree to the processing of your personal data. |
Service | The website, blog, and related business services provided by Ampco. |
Cookie | A small data file placed on your device by our website to enable functionality and analytics. |
3. Information We Collect
3.1 Information You Provide Directly
We may collect the following personal information when you contact us, submit an inquiry, request a quote, or engage in a business relationship:
- Name (first and last)
- Email address
- Phone number
- Company name and job title
- Mailing address (city, province/state, postal/ZIP code, country)
- Content of your inquiry or message
3.2 Information Collected Automatically
When you visit our website, we automatically collect certain technical data, including:
- IP address
- Browser type and version
- Operating system
- Pages visited, time and date of visit, and time spent on pages
- Referring URL
- Unique device identifiers and other diagnostic data
3.3 Location Data
We may collect approximate location data (such as city or region) derived from your IP address. We do not collect precise GPS location data through our website. If we ever enable precise location services, we will obtain your explicit consent first.
3.4 Business Customer Data
In the course of our B2B operations, we collect business contact information from our customers, suppliers, and partners as necessary to fulfill orders, manage contracts, and maintain our business relationships. This may include names, business email addresses, phone numbers, and shipping/billing addresses associated with purchase orders.
Data Minimization: We limit our collection of personal information to what is necessary and proportionate for the identified purposes. We do not collect personal information indiscriminately, and we regularly review our data collection practices to ensure they remain appropriate.
4. Lawful Basis for Processing
We process your personal information only when we have a valid legal basis to do so. The table below maps each processing activity to its lawful basis under GDPR Article 6 and the corresponding Canadian privacy law authority.
Processing Activity | Lawful Basis (GDPR) | Canadian Authority |
|---|---|---|
Responding to inquiries and quote requests | Implied consent (PIPEDA s. 6.1) | Legitimate interest / Pre-contractual steps (Art. 6(1)(b)) |
Fulfilling customer orders and contracts | Performance of contract (Art. 6(1)(b)) | Consent not required for purposes integral to contract |
Sending marketing communications | Consent (Art. 6(1)(a)) | Express consent (CASL / PIPEDA) |
Website analytics and improvement | Legitimate interest (Art. 6(1)(f)) | Implied consent (PIPEDA s. 6.1) |
Complying with legal obligations | Legal obligation (Art. 6(1)(c)) | Consent not required (PIPEDA s. 7) |
Maintaining website security | Legitimate interest (Art. 6(1)(f)) | Implied consent (PIPEDA s. 6.1) |
Managing supplier and partner relationships | Legitimate interest (Art. 6(1)(f)) | Reasonable purpose (PIPEDA Principle 2) |
Where we rely on legitimate interest, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You may contact us to request details of any such assessment.
5. How We Use Your Information
We use the personal information we collect for the following specific purposes:
- To respond to your inquiries, provide quotes, and facilitate business discussions
- To process and fulfill customer orders, including shipping, invoicing, and quality follow-up
- To communicate with you about changes to our services, products, or policies
- To provide customer support and resolve issues
- To improve our website, products, and services through aggregated analytics
- To monitor and maintain the security and integrity of our website
- To detect, prevent, and address technical issues or fraudulent activity
- To comply with applicable legal, tax, and regulatory obligations
- To send you marketing communications about products and services similar to those you have previously inquired about, where you have provided consent or where permitted by law
We will not use your personal information for purposes materially different from those stated above without first obtaining your consent or providing you with notice as required by law.
6. Consent
6.1 How We Obtain Consent
We obtain consent for the collection, use, and disclosure of your personal information in a manner appropriate to the sensitivity of the information:
- Express consent: For sensitive information or marketing communications, we obtain your explicit, opt-in consent (e.g., checking a consent box, signing a form, or providing written agreement).
- Implied consent: For less sensitive information where the purpose would be obvious to a reasonable person (e.g., providing your email address when sending us an inquiry), your consent may be implied by your actions.
6.2 Withdrawing Consent
You have the right to withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. To withdraw consent:
- For marketing emails: click the “unsubscribe” link in any marketing email
- For other purposes: contact our Privacy Officer at privacy@ampcomfg.com
We will inform you of the implications of withdrawing consent. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Important: In certain circumstances, we may continue to process your information without consent where permitted by law, such as to comply with a legal obligation or to fulfill a contractual commitment.
7. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are guided by the following:
Data Category | Retention Period | Basis |
|---|---|---|
Website analytics data | 26 months | Legitimate interest; industry standard |
Business inquiry records | 3 years after last contact | Legitimate interest in maintaining business relationships |
Customer order and contract records | 7 years after completion | Tax, legal, and regulatory obligations (CRA requirements) |
Marketing consent records | Duration of consent + 3 years | Legal obligation to demonstrate valid consent |
Supplier and partner contact data | Duration of relationship + 3 years | Contractual and legitimate interest |
When personal information is no longer needed, we securely delete or anonymize it in accordance with our Information Security Management System (ISMS) data disposal procedures.
8. International Data Transfers
8.1 Transfers from the EU/EEA
Canada has been recognized by the European Commission as providing an adequate level of data protection for transfers of personal data from the EU/EEA to organizations subject to PIPEDA. Where we engage service providers located in countries without an adequacy decision, we implement appropriate safeguards, including EU Standard Contractual Clauses (SCCs), to ensure your data remains protected.
8.2 Transfers Outside Canada
In accordance with BC PIPA Section 33.1, we notify you that some of your personal information may be disclosed to service providers located outside of Canada for the purposes of providing our services. Before any such transfer, we ensure that:
- The service provider is contractually bound to protect your personal information to a standard comparable to Canadian privacy law
- Appropriate technical and organizational safeguards are in place
- The transfer is necessary for the identified purposes
Currently, Ampco may transfer personal information to service providers in the following countries: Canada (domestic), the United States, and India. If this list changes materially, we will update this policy accordingly.
9. Disclosure of Personal Data
9.1 Business Transactions
If Ampco is involved in a merger, acquisition, or asset sale, your personal data may be transferred to the acquiring entity. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.
9.2 Legal Requirements
We may disclose your personal data when we have a good faith belief that such action is necessary to:
- Comply with a legal obligation, court order, or government request
- Protect and defend the rights or property of Ampco
- Prevent or investigate possible wrongdoing in connection with our services
- Protect the personal safety of our users or the public
9.3 With Your Consent
We may disclose your personal information for purposes not described in this policy only with your express consent.
10. Third-Party Service Providers
We engage third-party companies and individuals to help us provide, maintain, and improve our services. These service providers have access to your personal data only to the extent necessary to perform their designated tasks and are contractually obligated to protect it.
10.1 Categories of Service Providers
Category | Purpose | Data Shared |
|---|---|---|
Web analytics (e.g., Google Analytics) | Analyzing website traffic and usage patterns | Usage data, IP address, device identifiers |
Cloud hosting and infrastructure | Hosting our website and business applications | All data processed through our systems |
IT managed services | Security monitoring, network management | System logs, technical data |
Email and communication tools | Business communications | Contact information, message content |
Shipping and logistics | Order fulfillment | Name, address, order details |
10.2 Data Processing Agreements
We maintain written data processing agreements with all service providers who process personal information on our behalf. These agreements require service providers to process data only on our instructions, implement appropriate security measures, and notify us promptly of any data breaches.
10.3 Google Analytics
We use Google Analytics to analyze website usage. Google Analytics collects data through cookies and similar technologies. Google may use this data to contextualize and personalize advertisements on its own network. You may opt out of Google Analytics by installing the Google Analytics Opt-Out Browser Add-on. For more information, see Google’s Privacy Policy.
11. Data Security
The security of your personal information is important to us. We implement and maintain appropriate administrative, technical, and physical safeguards designed to protect your personal information against unauthorized access, disclosure, alteration, or destruction.
11.1 Our Safeguards Include
- Administrative: Information security policies, employee training, access controls based on the principle of least privilege, and regular security reviews
- Technical: Encryption of data in transit and at rest, multi-factor authentication, network segmentation, continuous monitoring, and vulnerability management
- Physical: Secured facilities with access controls, visitor management, and environmental protections
11.2 Information Classification
All personal information is classified and handled in accordance with Ampco’s Information Classification Policy, which is part of our broader Information Security Management System (ISMS). Data is categorized by sensitivity and handled according to the corresponding protection level.
While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is completely secure. We continuously evaluate and improve our security practices.
12. Breach Notification
In the event of a breach of security safeguards involving personal information under our control, Ampco will follow our Incident Response Plan and comply with all applicable breach notification requirements.
12.1 Canadian Requirements (PIPEDA s. 10.1 & BC PIPA s. 29.1)
- We will assess whether the breach creates a real risk of significant harm to affected individuals
- If significant harm is likely, we will notify the Office of the Privacy Commissioner of Canada (OPC) and/or the BC Office of the Information and Privacy Commissioner (OIPC) as applicable
- We will notify affected individuals as soon as feasible, providing a description of the breach, the types of information involved, and steps they can take to reduce harm
- We maintain a record of every breach of security safeguards, regardless of whether notification thresholds are met
12.2 GDPR Requirements (Art. 33–34)
For breaches involving personal data of EU/EEA data subjects:
- We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to rights and freedoms
- Where the breach is likely to result in a high risk to individuals, we will notify affected data subjects without undue delay
13. Your Privacy Rights
Depending on your location and the applicable law, you have certain rights regarding your personal information. We honour these rights regardless of your location and will respond to legitimate requests within the timeframes required by law.
13.1 Rights Under All Applicable Laws
Right | Description |
|---|---|
Access | You can request a copy of the personal information we hold about you, provided in a structured, commonly used, and machine-readable format. |
Correction | You can request that we correct inaccurate or incomplete personal information. |
Deletion | You can request that we delete your personal information, unless we have a legal obligation to retain it. |
Withdraw Consent | You can withdraw previously given consent to the collection, use, or disclosure of your personal information. |
13.2 Additional Rights Under GDPR (EU/EEA Residents)
If you are a resident of the European Union or European Economic Area, you have the following additional rights:
- Right to Restriction: You can request that we restrict the processing of your personal data in certain circumstances
- Right to Data Portability: You can request to receive your personal data in a structured, machine-readable format and transfer it to another controller
- Right to Object: You can object to processing based on legitimate interest, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds
- Right Not to Be Subject to Automated Decisions: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects
13.3 Canadian Privacy Rights (PIPEDA & BC PIPA)
- You have the right to access your personal information in our custody or control
- You can request correction of inaccurate or incomplete information
- You can withdraw consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions
- You can file a complaint with the Office of the Privacy Commissioner of Canada or the BC Office of the Information and Privacy Commissioner
13.4 How to Exercise Your Rights
To exercise any of these rights, please contact our Privacy Officer using the details in Section 18. We will respond to your request within 30 days. In complex cases, we may extend this by up to two additional months, and we will inform you of any such extension within the initial 30-day period. We may need to verify your identity before processing your request.
14. Children’s Privacy
Our website and services are intended for business use and do not target anyone under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal data from a child without verified parental consent, we will take steps to delete that information promptly.
15. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website. Cookies are small data files placed on your device that help us provide and improve our services.
15.1 Types of Cookies We Use
Cookie Type | Purpose | Duration |
|---|---|---|
Strictly Necessary | Essential for website functionality and security. Cannot be disabled. | Session |
CPerformance / Analytics | Help us understand how visitors use our website through aggregated data. | Up to 26 months |
Preference | Remember your settings and display preferences. | Up to 12 months |
15.2 Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to refuse all cookies, accept only certain cookies, or be notified when a cookie is set. Please note that disabling cookies may affect the functionality of our website.
16. Links to Other Sites
Our website may contain links to third-party websites that are not operated by us. We have no control over the content, privacy policies, or practices of third-party sites. We strongly encourage you to review the privacy policy of every website you visit. A link from our website does not imply endorsement of the linked site.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes:
- We will update the “Effective Date” and “Last Reviewed” dates at the top of this page
- For material changes, we will provide prominent notice on our website and, where feasible, notify you by email
- We will maintain an archive of previous versions upon request
Your continued use of our website after any changes constitutes acceptance of the updated policy.
18. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a complaint about our handling of your personal information, please contact us:
Privacy Officer — AMPCO Manufacturers Inc.
Email: privacy@ampcomfg.com
Phone: 604-472-3800
Mail: #101-9 Burbidge Street, Coquitlam, B.C. V3K 7B2, Canada
If you are not satisfied with our response, you have the right to file a complaint with the applicable regulatory authority:
- Canada (Federal): Office of the Privacy Commissioner of Canada — 1-800-282-1376
- British Columbia: Office of the Information and Privacy Commissioner for BC — 250-387-5629
- EU/EEA Residents: You may contact your local Data Protection Authority
This Privacy Policy is governed by the laws of British Columbia and the federal laws of Canada applicable therein. This document was last reviewed and approved by management on March 6, 2026. Document reference: ISPO-PP-01 Rev 01.
