RONA inc. Privacy Statement

Effective Date: 2024-10-28

RONA inc. values and respects your privacy. This Privacy Statement describes how RONA inc. and its subsidiaries, related entities and affiliates collect, use, share, retains, and protects personal information, and of the choices you can make regarding your personal information.

Scope & Accountability

This Privacy Statement applies to personal information collected by the operations of RONA inc. and its subsidiaries, related entities, and affiliates at physical locations in Canada and on their Canadian websites and domains, including, but not limited to, RONA, RONA+ and Dick’s Lumber, as well as www.rona.ca and www.dickslumber.com (collectively, “RONA inc.”).

    This Privacy Statement does not apply to:

    • Your interactions with third parties or their websites that are linked to or accessible from RONA inc. websites or that are operated by unaffiliated parties, even though the website may contain references to RONA inc
    • RONA inc. employment-related records (other than job applicant information)
    • RONA stores operated by independent dealers (including any other activities by or communications from such dealers)

    All employees and those working on behalf of RONA inc. are responsible for following this Privacy Statement. RONA inc. has a Privacy Officer who is responsible for overseeing RONA inc.’s compliance with this Privacy Statement. Please see "How to Contact Us" for information on how to contact RONA inc. Privacy Officer.

      What Information We Collect

      We collect your personal information in order to provide products and services to you, to communicate with you, to enhance our products, services, and operations, and for other operational, legal and compliance purposes. Below are some examples of personal information we collect:

      • Identification information that can be used to identify you, such as your name, alias, address, phone number, or email address. We may also collect online identifiers, such as your IP address, when you browse our websites or use our applications. We may collect government-issued ID for certain types of transactions — but please provide government-issued ID information only if we ask you to.
      • Transactional or commercial information, such as products or services you purchased or considered purchasing. We may also collect your payment card information when you complete a transaction.
      • Online activities information, such as browsing history, search history, and other information when you interact with our websites, applications, and advertisements.
      • Geolocation data, including precise geolocation data if you allow our application to collect it.
      • Audio, electronic, or visual information, such as audio or video recording when you call us or when you come to our stores, but please note that we do not use such recording to identify or authenticate you and may not be able to associate such recordings with you.
      • Demographic information, such as age, gender and family status.
      • Inferences or preferences we learn or infer about you.
      • Other information about you, such as professional or employment-related information, or education information, when you provide us the information in a survey.

      We do not knowingly collect or disclose personal information from youth or children under the age of 14 without parental or guardian consent. If a youth or child under the age of 14 has provided us with personally identifiable information, we ask that a parent or guardian contact us so that the information can be deleted.

        What are the sources of your information

        We collect different types of information about you from a number of sources, including information you provide to us, information we automatically collect, information we obtain from other sources (specified below), and information we derive or infer about you.

          Information You Provide

          You may choose to provide us with information when you interact with us. Examples include:

          • Identification information. You may provide your contact information, such as name, address, and phone number in case we need to reach out to you, such as arranging delivery or pickup. You may also set up your login and access credentials if you become a registered user of our websites. To complete transactions, we may collect your payment information and signatures. You can also provide your contact information, such as email, address, or phone number to receive promotional messages from us. If you apply for a charge account available at RONA stores, we may request additional information such as your date of birth, income, and asset information to evaluate your application. RONA solely makes credit decisions and manages these charge accounts.
          • Transactional or commercial information. You may provide or generate commercial information regarding your RONA inc. purchases, returns, exchanges, warranties, and rebates.
          • Demographic information. You may provide your demographic information, including age, gender, marriage, and family status, such as when you complete a survey from us.
          • Your preferences and inferences. You may let us know your preferences in a survey, contest, promotion or sweepstakes, or other content you submit, such as product reviews.
          • Professional, educational employment-related information. You may also provide other professional, educational, or employment-related information when you respond to our surveys.
          • Other personal information, such as your medical and insurance information, which may be provided in the unlikely event you are injured and/or your property is damaged while at our location or as a result of any services and/or products we have provided to you. In such circumstances, notwithstanding anything to the contrary in this Privacy Statement, we will only use such information for the purpose of assessing and administering your injury or loss and any resulting claim and as otherwise required or permitted by applicable law.

          Information Collected by Automated Means

          We collect information by automated means online and offline in accordance with applicable data protection laws. When you use our websites or mobile applications, RONA inc. and our partners may collect certain information by using Cookies and Other Technologiesa>. If you choose to connect your mobile device to our free in-store Wi-Fi, we may collect your device usage information. When you visit our store or call our customer care hotline, we may collect audio or video information.

            We may collect the following information via automated means:

            • Identification information, such as your IP address, device ID, cookie ID, mobile advertising identifier, or pixel identifier.
            • Online activities, such as browse and search history, interactions with our websites, applications, clickstreams, or other information about your online interactions.
            • Geolocation data, If you activate such function, we may collect certain information about your precise location through our mobile applications when it is in use to help you locate the nearest RONA inc. store or for analytic purposes. RONA inc. may compare the geographic information acquired from commercial sources with the IP address collected when you visit our website to derive a general geographic area in order to provide you with information or promotions relevant to your geographic area.
            • Audio, video, or electronic information, such as audio or video (if we engage in video chats with you) recording of the conversations with you when you contact our customer service centers or other support lines which are used for quality control, training, security and analytic purposes. We may also use video monitoring and other tracking technologies at RONA inc. stores to enhance security, protect against theft and other crimes and to monitor in-store traffic patterns, customer counts and interests, and perform similar analytics. Since video recordings capture all activities occurring within a store, it may not be feasible to associate video recordings with you in the event that you wish to have access to such recordings. Please note that RONA inc. does not use such recording to identify or authenticate you .

            Information We Collect from Other Sources

            • Identification information. . We may collect your contact information from RONA inc. affiliates, acquired businesses, business partners, public sources, or other individuals, such as through “Refer a Friend” programs or if someone purchases a product and asks that it be delivered to you. Please note that if you provide RONA inc. with the personal information of another individual, then you must take all measures, including obtaining the individual's consent, to ensure that you have the lawful right to collect and communicate the information to RONA inc. and for RONA inc. to collect, use, communicate and retain the personal information in accordance with this Privacy Statement.
            • Transactional or commercial information. We may obtain your commercial information, such as your purchase history, from RONA affiliates, acquired businesses, or business partners.
            • Inferences or preference information about you, demographic information, professional or employment-related information, educational background, and geolocation information. We may collect inferences or preference information about you from business partners, such as data analytics or survey vendors. We may use such information to conduct aggregated analyses of our customer composition, and we may collect your interest and preference information to recommend products or services that may interest you. We may also learn about your preferences from public sources, such as information you submit in a public forum (e.g., a customer review).

            Information We Generate or Derive

            • Inferences or preference information about you. We may generate or derive some information about you based on other information we collect. For instance, we may analyze your information and infer your shopping preferences to provide tailored recommendations to you. To the extent allowed under applicable law, we may also conduct analyses based on aggregated, de-identified or anonymized information.

            How we use your information

            We use your personal information for various business or commercial purposes, including fulfilling products and services, communicating with you, supporting and enhancing our business functions, and for other legal, compliance, and security purposes, or as otherwise required or permitted by applicable laws.

              Fulfill Products, Services, and Transactions

              We may use your information to provide products and services to you, such as:

              • Provide and deliver products and services, fulfill your orders and transactions, manage returns and exchanges
              • Process, record and track your purchases, payments, returns, warranties, and rebates
              • Create and manage your account registrations or benefit or reward program enrollment, when you register an account with us
              • Conduct and administer contests, surveys, and sweepstakes
              • Provide you with in-store navigation and mapping services and help you find store locations near you
              • Fulfill benefits associated with your membership or other use of our products and services
              • Identify and verify your identity when needed to provide you with products and services or access to our systems
              • Determine whether to extend commercial credit to you and to manage your commercial credit account if you apply

              Facilitate Customer Communication and Outreach

              We may use your information to facilitate and tailor our outreach to you, such as:

              • Identify and communicate with you through various channels with transactional or promotional information, such as transaction confirmation and reminder, newsletters, coupons, and other messages
              • Evaluate and respond to your requests, inquiries, and applications
              • Administer programs for product reviews and surveys as submitted by you and other customers

              Enhance Our Products, Services, and Operations

              We may use the information we collect listed above to enhance our products, services, and operations:

              • Conduct research and internal analytics, develop new products and services, perform market research and data analytics, and analyze our products, services, websites, and applications
              • Customize your experiences in our stores and online, including customized advertisements and offers
              • Determine and manage the effectiveness of our advertising and marketing
              • Administering our websites and applications, and perform accounting, auditing, billing, reconciliation and collection activities

              Comply with Legal, Compliance, Law Enforcement, and Security Requirements

              We may use your information for legal, compliance, fraud prevention, and security purposes:

              • Comply with and enforce applicable legal requirements, industry standards and our policies and terms, such as our Terms and Conditions of Use
              • Assist law enforcement and respond to regulatory inquiries
              • Detect security/confidentiality incidents, protect against malicious, deceptive, fraudulent or illegal activity and prosecute those responsible for that activity

              Aggregate, Anonymized or De-Identified Data

              • We may use aggregate, anonymized or de-identified data derived from personal information for our internal business purposes where permitted by and in compliance with applicable law.

              How We Share Information

              We may share your personal information with unaffiliated entities (companies outside the RONA inc. family) with your proper implied or express consent, or as otherwise required or permitted by applicable laws. Specifically, we share your personal information to conduct business with service providers and business partners, in accordance with legal data protection requirements.

                Service Providers and Business Partners

                We may disclose your personal information to companies that provide various services to us in areas, such as installation, repair, warranty, order processing and fulfillment, information technology, marketing, customer service, data analytics, research and enhancement, fraud prevention, human resources, background investigations, legal, compliance and risk management. These companies may need access to information about you in order to perform their services and functions.

                  In limited cases, and with your knowledge and/or consent if required by law, we may disclose information about you to a third party who may also use the information for their own specific purposes. For instance, we may provide your information to a supplier in connection with product warranty or safety issues or with a business partner who is jointly providing or promoting a product or service to you. If we jointly provide a product or service to you with a business partner, the product or service will clearly indicate that it is a joint product, typically through the use of our and our partner’s brands and logos used in the promotional and marketing material. In such circumstances our business partner’s ability to collect, use and disclose your personal information will be subject to their own privacy policy.

                    In addition, when you browse our websites, through Cookies and Other Technologies, we may share your online activities, such as cookie ID, device ID, IP addresses and clickstreams with a social media or online advertising vendors to serve tailored commercial information to you. For more information on this, please see the Cookies and Other Technologies and Interest-Based Advertising sections below

                      Legal, Enforcement, Security, and Investigation

                      We may disclose information about you (1) if we believe we are required to do so by law, regulation or legal process, such as a court order or subpoena; (2) as we deem appropriate or necessary in response to requests by government agencies, such as law enforcement authorities or tax authorities; (3) when we believe disclosure is appropriate or necessary to protect the rights, property or safety of RONA inc., our customers or others, including to prevent physical, financial or other harm, injury or loss or to collect debt you owe; or (4) in connection with an investigation of suspected or actual unlawful activity.

                        Sale or Transfer of Business or Assets

                        If all or any portion of our business is acquired (including, without limitation, in the event of a reorganization, dissolution or liquidation), your personal information related to the acquired business may be transferred to the purchaser but only to the extent your personal information is necessary for such transactions in which case RONA inc. will comply with all applicable legal requirements.

                          Corporate Group

                          We may share your information within our corporate group for the purposes contemplated in this Privacy Statement. Where we share your information within our corporate group, we use contractual and other measures to ensure that such information is protected in accordance with this Privacy Statement.

                            RONA’s Independent Dealers

                            We may also provide your personal information to dealers that operate RONA-branded stores for order fulfillment, rebate management, and other purposes to facilitate your transactions.

                              How We Retain and Protect Information

                              RONA inc. retains personal information for as long as it is necessary to process related transactions, maintain appropriate financial and audit records, provide and improve our products and services, protect RONA inc. legitimate business interests, and for as long as may be required by applicable laws.

                                We maintain administrative, technical, and physical safeguards designed and intended to protect personal information against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure, or use, or any other breach in the protection of the information.

                                  RONA inc. uses reasonable safeguards appropriate to the sensitivity and amount of personal information under RONA inc. legal control, to the purposes for which it is used and the format in which it is stored. RONA inc. use a combination of measures – including administrative, physical and technical security and safeguarding measures – to help protect the security of the personal information, including:

                                  • A privacy framework governing the protection of personal information through its lifecycle.
                                  • Internal policies and procedures that define the roles and responsibilities of RONA inc.’s personnel regarding the handling of personal information.
                                  • Technical safeguards, such as encryption, firewalls, passwords and antivirus software, to protect personal information collected, used or stored in electronic format.
                                  • A designated Privacy Officer accountable for RONA inc.’s compliance with applicable privacy laws.
                                  • Employee privacy and data security training.
                                  • Procedures for receiving, investigating and responding to complaints or inquiries regarding RONA inc.’s information handling practices.
                                  • Contractual provisions and other measures to require our service providers with whom we share personal information to maintain adequate privacy protections and standards.

                                  Despite these safeguards, due to inherent uncertainty in the use of the internet and information systems and the potential for unlawful attacks by third parties, we cannot guarantee that the use of our systems, websites, or applications will be completely safe or secure.

                                    RONA inc. may process and store your personal information at a RONA inc. facility or a facility of an affiliate of RONA inc. in Canada, the United States of America, India, or any other country in which it maintains its facilities. In addition, some of RONA inc. service providers, agents, and suppliers are located outside of Canada. Information processed in such countries may be subject to access by law enforcement or other governmental agencies in those countries pursuant to lawful orders or legal process. While your personal information may be subject to the laws of those jurisdictions, RONA inc. policies require that personal information processed or stored outside of Canada or used by service providers, agents, and suppliers outside of Canada are always subject to protections comparable to those required under the applicable laws of Canada and will not be disclosed to third parties except with consent or as set out in this Privacy Statement. If you would like to obtain access to written information about RONA inc. policies and practices with respect to its service providers located outside of Canada or otherwise have any questions regarding these service providers, please contact RONA inc. Privacy Officer at the Contact Us address below.

                                      How to exercise your privacy choices

                                      Give and Withdraw Consent

                                      We obtain your implied or express consent appropriate for the type of personal information being collected, used, or disclosed in accordance with this Privacy Statement. You may withdraw consent for the collection, use, and disclosure of personal information, subject to legal or contractual restrictions, and reasonable notice.

                                        You may withdraw your consent to the collection, use, and disclosure of your personal information. If you request RONA inc. to do so, RONA inc. will take reasonable steps to destroy or delete active personal information that you have provided to us. In some circumstances, the withdrawal of consent to retain, use, or disclose your personal information may impact our capability to provide products or services to you. Please also note, we need to keep certain information when permitted by law to complete the transactions, detect security incidents, prevent fraudulent or illegal activities, identify and repair errors, comply with laws and regulations, and for other solely internal and lawful purposes.

                                          You may withdraw your consent to the use of your personal information for the purpose of sending you our newsletters and the latest offers by e-mail by unsubscribing. Each commercial e-mail will provide you with the opportunity to unsubscribe. You will still receive transactional e-mails when you make a purchase online. In addition, it may take several days for us to register a change of preference across all our systems.

                                            You may make a written request to RONA inc. Privacy Officer at the How to Contact Us address below. When submitting a withdrawal of consent, you will be asked to provide suitable identification or to otherwise identify yourself.

                                              Access and Correct Your Personal Information

                                              We strive to keep accurate information by using technology and management processes and policies. Upon receipt of a written request, RONA inc. will provide individuals with reasonable access to the personal information they provided to RONA inc. as well as the ability to correct the information, if necessary. To protect your privacy and security, RONA inc. will also take reasonable steps to verify your identity before releasing any information to the requesting party and before any corrections will be made. RONA inc. may request appropriate proof of the requested corrections..

                                                If you are a registered user of our websites, you can view or update your registration information by logging into your account. You may also make a written request to RONA inc. Privacy Officer at the How to Contact Us address below.

                                                  Other Important Considerations

                                                  Cookies and Other Technologies

                                                  Cookies refer to small packets of data that websites send to your computer or other internet-connected devices. RONA inc. and our business partners use them for different purposes. These technologies can uniquely identify your browser and log information, such as your device type, system and browser information, IP address, system language, location, and your interactions with the site. Like other websites, we need some essential cookies for our website to function properly. We also use some functional cookies to pre-populate your log-in ID to make it easier for you or to help us remember where you left off when you shopped, so you do not have to restart all over again. We may use browser cookies, flash cookies, and other types of local storage.

                                                    RONA inc. and our business partners also use cookies with other technologies, such as tags, beacons, or pixels. They allow us to count visitors to our webpages, evaluate the effectiveness of our promotional campaigns, or recommend relevant products and services to you when you browse social media or other websites. We think these technologies create meaningful interactions with you and are helpful, but you can let us know that you prefer otherwise by opting-out from these advertising cookies and technologies.

                                                      You may refuse certain cookies and manage your cookie preference by using the privacy settings in your browser’s software. Most browsers let you remove or stop accepting cookies from the website you visit. To do this, follow the instructions on your browser’s settings. If you do not accept cookies, however, you may not be able to use all functionality of our websites, or our websites might not work properly. For more information about cookies, including how to see what cookies have been set on your browser and how to manage and delete them, visit www.allaboutcookies.org.

                                                        Moreover, for Quebec residents, you will be able to provide a consent to our cookies at your entry on our website and you can change your cookies preferences by

                                                          You can find more information and options in the Interest-Based Advertising section.

                                                            Interest-Based Advertising

                                                            In the event that the required consents are obtained pursuant to the law, RONA inc. may collect data about your activities on our websites for use in providing advertising tailored to your individual interests, and we may share your online activities information, such as cookie ID, device ID, IP address and clickstream on our websites with advertising networks administered by third parties. These ad networks track your online activities over time and across websites by collecting information through automated means, and they use this information to show you advertisements that are tailored to your individual interests. The information they collect includes information about your visits to our websites, such as the pages you have viewed. This collection and ad targeting take place both on our websites and on third-party websites that participate in the ad network, such as sites that feature advertisements delivered by the ad network. As a result, you may see certain ads on other websites based on prior activity on our websites, and vice versa.

                                                              The Digital Advertising Alliance of Canada (DAAC) has created guidance for online advertisers and provided a mechanism for such advertisers to comply with users' choices regarding interest-based ads. Visit the DAAC website to learn more about ad networks, including how to opt out of interest-based ads.

                                                                Social Media Widgets

                                                                RONA inc. websites and applications may include social media features (for example, a Facebook "Like" button or sign in with Facebook or Google). These features are connected to third parties and may allow such third parties to collect certain information, such as your IP address and which pages you visit on our websites. These social media features are not operated by RONA inc. Your interactions with these features are governed by the privacy policies of the company providing the features.

                                                                  Links to Other Websites

                                                                  RONA inc. websites and applications may provide links to third-party websites for your convenience and information. For instance, they may link to websites of product suppliers, manufacturers, and service providers. If you access those links, you will leave the RONA inc. website. RONA inc. does not control those sites or their privacy practices, which may differ from RONA inc. practices. RONA inc. does not endorse or make any representations about third-party websites. The personal data you choose to provide to or that is collected by these third parties is not covered by the RONA inc. Privacy Statement. RONA inc. encourages you to review the privacy policy of any company before submitting your personal information to that company.

                                                                    Additional Disclosure to Job Applicants

                                                                    We collect information from you during your job application, including: (1) identification information, such as your name, address, phone number, email, application portal account credentials and government-issued ID (if asked), (2) online activities, such as your interactions with our Career Portal, (3) professional or employment-related information, such as employment status; employment history, references or your résumé, (4) education information, such as your education background, (5) geolocation information, (6) demographic information, personal or family employment affiliation with RONA inc., (7) audio, video or electronic information, when you communicate with us during your application or interview process and (8) other personal information, if it identifies, relates and can be reasonably associated with or linked to you. We use the information for evaluation, background check, communication and analytic purposes.

                                                                      How to Contact Us

                                                                      RONA inc. values your opinions. If you have a privacy inquiry, compliment or complaint, with respect to this Privacy Statement or how we handle your personal information, you may direct your inquiry, compliment or complaint to RONA inc. Privacy Officer at privacy@rona.ca or by submitting a written request to:

                                                                      RONA inc.
                                                                      Attn: RONA inc. Privacy Officer – Legal Department
                                                                      220, chemin du Tremblay
                                                                      Boucherville (Québec) J4B 8H7

                                                                        Changes to this Privacy Statement

                                                                        RONA inc. reserves the right to change this Privacy Statement from time to time to reflect applicable laws or regulations, or changes to our practices or procedures. In such case, RONA inc. will post the revised statement in its entirety on its websites and other applicable websites with an updated revision date. RONA inc. may also notify you, as required by applicable laws, by other means such as sending an e-mail or posting a notice on the home page or in the RONA inc. stores.

                                                                          All changes to this Privacy Statement will be effective when we post the revised Privacy Statement on our Sites. RONA’s collection, use, communication and retention of your personal information will be governed by the version of this Privacy Statement in effect at that time.

                                                                            If you continue using our websites, our products and our services after such revisions are in effect, you accept and agree to the revisions and consent to the collection, use, disclosure and retention of your personal information by RONA inc. as provided in the revised Privacy Statement. It is your responsibility to ensure that you read, understand and accept the latest version of this Privacy Statement. The “Effective Date” of this Privacy Statement (at the top) is the date this Privacy Statement was last revised.