Last updated: 8 September 2026 · Applies to the website at www.cbcwholesale.lol · Published by CBCWholesale LLC
A privacy policy is a written promise about how an organisation handles the personal information that it comes across in the course of its work. This document is that promise for the wholesale cash-and-carry business run through this website and its companion service pages. It has been prepared by the developer responsible for building and operating the site, whose development name is CBCWholesale, acting for and on behalf of the trading entity CBCWholesale LLC.
The policy explains why the Company needs certain details, what those details are used for, how long they are held, who is allowed to see them and what rights a store owner or an individual buyer holds under the applicable data protection law. It also explains the choices that the reader can make.
Reading this policy fully is worthwhile. Every store that opens a trade account, every buyer that phones the desk and every visitor that walks the pages of this site will find an honest account of how their details are treated. If anything in this policy is not clear, the reader should contact the trade and data desk using the contact details set out in this document before supplying any personal information.
The trading entity responsible for the service described in this policy is a limited liability company registered in the United States.
The company details are as follows:
In this policy the words the Company, we, us and our all refer to CBCWholesale LLC unless the context makes clear that a different meaning is intended. Where this policy mentions the developer, it refers to CBCWholesale, the named party that built and operates the technical side of the website. The terms of this website are provided by the Company, and the privacy commitments made in this document are made by the Company to the people whose data it handles.
This policy covers the personal data of a number of distinct groups of people. The first group is the owners and staff of the independent grocers, cafes, delis, convenience stores and similar retail businesses that become trade accounts of the Company. The second group is the individual visitors and buyers who use the website, phone the desk or visit the wholesale floor. The third group is anyone who contacts the Company with a question, a complaint or an enquiry through the contact page, by email or by telephone.
The policy applies to data collected through the public pages of the website, through the contact and account application facilities, through telephone and email correspondence with the trade desk, and through the face to face activity that happens on the wholesale floor itself, such as the checking of an identity document when a trade account is opened.
This policy does not cover the practices of any third party website that can be reached by following a link from this site. Each of those websites has its own privacy notice and its own data controller, and the reader should review that notice before sharing personal information there. The Company does not control those websites and accepts no responsibility for the manner in which they collect or use personal data.
Opening a wholesale account is a business decision, and business decisions rest on trust. A store owner will only hand over details of the store, its trading footprint and its buying patterns if the owner is confident that those details are held safely and used only to serve that store.
The Company has therefore chosen to publish a clear and complete privacy policy that sets out its approach in plain language. This gives every current and prospective account holder a single source of truth that they can rely on, and it gives the Company a discipline of transparency that guides how each new data handling step is designed.
The policy also reflects modern data protection practice. Under the applicable privacy frameworks that regulate business activity in the United States, together with the standards that apply to any organisation that deals with partners elsewhere, a business is expected to be able to show how it collects data, why it collects that data and how it protects the data once gathered. This document is part of that evidence.
The Company collects personal data that a person chooses to share with it. The amount and the type of data naturally varies with the reason for the contact.
When a store applies to open a trade account, the Company gathers the details needed to set up and run that account. These include the store name, the trading or street address of the store, a contact telephone number and a working email address, the name of the store owner or the authorised manager, and the tax or commercial registration details that are needed before a valid trade ticket can be issued. For account holders that wish to pay by an agreed credit arrangement, the Company may collect basic details of the payment route that the store plans to use, recorded without the full card data where a direct bank instruction is agreed.
When an order is placed, whether in person, by telephone or through a standing pack arrangement, the Company records the items ordered, the case volumes, the pickup time and the aisle and cage that carried the load. This order information includes what a buyer purchased but only the minimal personal detail required to link the order to the right account.
When a person uses the contact form on this website, the Company receives the name, the email address and any message text that the person chooses to type. The same applies to emails sent direct to the address shown on the site and to notes left on the trade desk answerphone. Every item supplied in these messages is personal data only to the extent that it identifies the sender.
As with almost every website, the technical servers that deliver this site record a small amount of routine information each time a page is loaded. This includes the internet protocol address of the device making the request, the web browser type and version, the operating system in use, the approximate date and time of the visit, and the pages that were looked at.
This automatic information is log data. It is collected for a narrow set of operational reasons: to keep the site secure, to detect unusual or abusive traffic, to measure how many people use the service and which pages are most helpful to them, and to keep the hosting environment stable. The Company does not use this log data to build a profile of a named individual, does not sell it and does not combine it with the personal records of a trade account unless a security incident makes such a check necessary.
The automatic data is treated as personal data only where it can be tied to a real person. In practice the log files are short lived and are reviewed in aggregate, which keeps the risk to any individual visitor very low. Where the law requires this data to be handled as personal data, the Company applies the same safeguards that protect the rest of the information it holds.
The Company only handles personal data where there is a defensible reason to do so. For the wholesale cash-and-carry service, those reasons fall into a small number of clear categories.
The first reason is the performance of a contract. When a store opens a trade account and places an order, the Company needs the account details and the order details to deliver the goods, to issue a correct register slip, to reconcile the cage at the cash desk and to support any agreed credit arrangement. Without this processing the service could not be delivered.
The second reason is a legal obligation. The Company must keep accurate records for tax and commercial reporting purposes, and it must respond to lawful requests from public authorities where the law compels disclosure. Where such an obligation applies, the Company processes the minimum data needed to comply and no more.
The third reason is the legitimate interest of the Company and of its account holders in running an orderly, secure and safe wholesale operation. This supports activity such as the protection of the floor and its records from fraud, the management of an account query, and the resolution of a dispute. Where the Company relies on its own interest it always checks that its interest is not outweighed by the rights of the individual whose data is involved.
Where data is provided for a purpose that relies on consent, such as any optional contact about future stock lines, the Company obtains clear consent first and records it. Consent can be withdrawn at any time by contacting the desk, and once withdrawn the Company stops the relevant processing without penalising the caller in any way.
The central use of personal data is to run trade accounts well. The Company holds the contact details of an account so that it can confirm a booked pickup window, tell the account that a standing pack is ready, follow up on a damaged case, or explain a change to the opening hours of the wholesale floor.
Account related data is also used to keep the buying experience smooth. Knowing which lines a store buys most often lets the desk prepare a sensible mixed pallet and pull a first cage ahead of a repeat visit. This use is grounded in the account relationship and in the service contract, and it never becomes a basis for selling the data of the store to a competitor or a broker.
Where a store asks to be told about new lines or about available opening windows, the Company uses the email and telephone details it already holds to send that notification. The store can stop these notices at any time with a single reply or a single call to the desk, and it will not be penalised for doing so.
On rare occasions the data supports essential account administration, such as confirming an ownership handover of a store, re-issuing a lost trade ticket or investigating an order that arrived short of the aisle tag total. Each of these tasks needs a precise, limited set of the account details and nothing more.
The Company does not keep personal data for a single day longer than it is needed. A clear retention rule governs every type of record.
Trade account records — the name, address, contact details and order history of a store — are kept for as long as the account is active and for a limited period afterwards to allow the Company to answer a question, to settle a late invoice or to meet its tax and commercial record keeping duties. Once that period has passed, the records are securely deleted or anonymised so that they can no longer be linked to a named person.
Correspondence sent through the contact page or by email is kept only as long as the matter it concerns remains open, and is then removed under the same discipline. Website log files are retained for a short rolling window and are reviewed in aggregate, which keeps the stock of automatic data small.
Any personal data that is no longer needed for the purpose for which it was collected is deleted automatically by the retention policy. This removes the risk of old records lingering on a server where no one can justify keeping them.
Keeping data safe is an operational duty, not a promise made once in writing. The Company applies a set of practical protections to every record it holds.
Access to account records is limited to the small number of staff who need it to do their job — the desk staff who answer a call, the picking team that prepares a cage and the administrator who manages the ledger. Each person is granted only the access their role requires, and access is removed when a role no longer needs it.
Data is protected in transit and at rest. Web traffic to the site is carried over an encrypted connection, email to the desk is handled through secured mail services, and stored records sit on systems that are password protected and monitored. Routine security checks look for signs of unusual access and warn the desk of any anomaly at an early stage.
Written procedures guide the handling of a breach. If personal data is ever exposed in a way that creates a risk to a person, the Company will act quickly to contain the event, to reduce harm and to notify the people affected and the relevant authority where the law requires such notification. No policy can promise that an attack will never happen; this policy promises that the Company is prepared for one.
CBCWholesale LLC is based in the United States, and the day to day operations of the wholesale floor are run from that country. The data described in this policy is therefore held primarily within the United States.
The service may use online tools that route some activity through providers located in other countries, as is common for hosting and messaging infrastructure that operates on a global basis. Where personal data moves outside the country in which a person lives, the Company relies on tools and provisions that the privacy frameworks recognise as offering an adequate level of protection, so that the data continues to benefit from safeguards that match those described in this policy.
A store owner reviewing this section should understand that the primary controller of the data is always the Company, and that the Company remains responsible for the protection of the data wherever the technical infrastructure happens to sit. If the reader has a concern about the handling of data across borders, the desk will answer that concern directly.
The people whose data the Company holds enjoy a set of clearly defined rights. These rights allow a person to stay in control of how their information is handled.
Every account holder and visitor has the right to ask what personal data the Company holds about them and to receive a clear copy of it. This is the right of access. A person may also ask the Company to correct any detail that is inaccurate, to delete data that is no longer needed and to restrict particular processing while a request is checked. Where the law gives a right to data portability, a person may ask to receive their structured data in a machine readable form.
To exercise any of these rights, the person should contact the data desk using the details in the final section of this policy. The Company will respond within the time the law allows, will verify the identity of the caller before releasing personal data so that information does not reach the wrong hands, and will not charge for a reasonable request.
If a person believes that the Company has not handled a request correctly, that person may complain to the Company first, and after that to the supervisory authority with jurisdiction. The Company treats every right as a working promise and welcomes a clear enquiry rather than seeing a confusion go unresolved.
The wholesale cash-and-carry service sells stock to independent retail businesses. Its offer is not aimed at children, and the Company does not run any activity that is designed to collect information from a child or to attract a child to browse its purchasing pages.
This website does not include games, contests, reward features or other interactive content that would engage a child. A child is not asked for personal data anywhere on the site, and the contact facilities are directed to the owners and staff of retail businesses.
Because the service is business to business in character, the Company would not normally come into contact with the personal data of a child at all. If, in spite of this design, the Company ever became aware that it held personal data relating to a child without a proper lawful basis, it would delete that data promptly and close the route by which it had arrived. Any visitor who believes that a child has shared personal data with this site can alert the desk and the matter will be handled without delay.
The pages of this site may, from time to time, carry a link to an external source, such as a map of the trading address, a trade body concerned with the wholesale sector, or a page produced by a partner that offers a service relevant to the account holder.
Every click on one of these links takes the reader onto a site that the Company does not operate. Once the reader leaves this site, the rules of the destination site apply, including its own privacy notice, its own cookie choices and its own handling of automatic data.
The Company provides such links for the convenience of the visitor and does not pass any personal data to the destination when the link is followed unless the visitor chooses to share data on that other site itself. The reader should review the privacy notice of each external site before offering personal information there, as that notice is the only document that governs how that other organisation behaves.
The Company keeps this policy under review so that it stays true to the way the business actually works and to the way the law develops. From time to time a change may be needed.
When the policy is updated, the date at the top of this page is amended to show when the current version took effect. A material change, meaning one that alters the way personal data is used in a way that a reasonable person would want to know, will be flagged on the site and will be explained to active account holders by a short notice from the trade desk before the change takes effect where that is practical.
Continuing to use the website or an open trade account after a change has taken effect is taken as acceptance of the revised policy. A visitor who does not wish to accept a revised policy should stop using the site and should close the account if one is held. The desk will always provide the current policy text on request.
Every question about this policy, about the personal data of an account or about a request to exercise a right should be sent to the data desk of the Company. The desk will give the enquiry its full attention and will reply in plain language.
Contact can be made by email to memo@cbcwholesale.lol or by telephone to +17794633468. Written correspondence may be sent to the Company at its trading address at 7533 S Center View Ct, West Jordan - 84084-5526, United States (US). The desk is available during the business hours shown on the contact page of this site.
The Company thanks every store and visitor that reads this policy. A clear notice of how data is treated is part of the trust on which the wholesale floor is built. If anything in this page remains unclear, asking the desk is always the right first step.