Legal
Privacy Policy
How Polymer Nation collects, uses, and protects information — your privacy choices, our opt-in tracking model, and how to exercise your rights.
Polymer Nation — Privacy Policy
Last updated: August 11, 2026
Polymer Nation Chemical Company, LLC ("Polymer Nation," "we," "us," "our," or "the Company") is an American manufacturer of high-performance industrial epoxy, polyaspartic, polyurea, and urethane floor and wall coating systems. This is our marketing and inquiry website (the "Site"). This plain-English summary is provided for convenience only; it is not a substitute for the full Privacy Policy below, which controls in all cases. Where this summary and the detailed sections differ, the detailed sections govern.
You control tracking, and what is already running before you choose depends on where you are. In eighteen states — California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — analytics cookies may already be running when you arrive, and the banner is your notice and your off switch. In nineteen states — that same list together with Maryland — targeted advertising and the technologies that may count as a "sale" or "share" of personal information may already be running when you arrive. Maryland is where those answers part company: targeted advertising may already be running there, while analytics stays off until you switch it on. Everywhere else — every other U.S. state, the District of Columbia, the U.S. territories, every visitor outside the United States, and every visit where we cannot resolve your location — nothing non-essential loads or records, and analytics and advertising stay off until you affirmatively turn them on. Identity resolution is never switched on automatically. You can change or withdraw your choices at any time via the "Cookie settings" link in our footer, and we honor the Global Privacy Control (GPC) browser signal, and a Do Not Track (DNT) signal, as a binding opt-out for every visitor, applied automatically without any further action by you.
When you contact us, we collect what you give us: name, email, optional phone, company, message, and inquiry details. We also collect limited technical data automatically (such as IP address, approximate location, device/browser data, pages viewed, referrer, timestamps, and marketing-attribution identifiers like UTM parameters, gclid, and fbclid).
Our consent system applies the rule of the state we resolve you to, automatically, and we reserve the rights described in Section 4.5 to the fullest extent the law allows. This Site is intended for adults 18 and older and is not directed to children. Please do not send us sensitive information (such as government IDs, health information, or financial-account numbers) through the Site.
1. Scope, Who We Are, and Acceptance
1.1 Identity of the Controller / Business
This Privacy Policy ("Policy") describes how Polymer Nation Chemical Company, LLC collects, uses, discloses, retains, secures, and otherwise processes personal information (also called "personal data") in connection with this Site and any web pages, forms, or features that link to or reference this Policy. For purposes of the EU and UK General Data Protection Regulation ("GDPR" / "UK GDPR"), the Company acts as the "controller" of the personal data processed through the Site. For purposes of U.S. state privacy laws, the Company acts as a "business" (or equivalent "controller").
The Company is Polymer Nation Chemical Company, LLC, doing business as "Polymer Nation," with its principal place of business at 405 Oakwood Ave, Waukegan, IL 60085. Where this Policy refers to our governing jurisdiction, it means the State of Illinois; where it refers to our address, it means the address above. To exercise any right, withdraw consent, or contact us about privacy, please call us at (847) 774-5038 or use the contact form on our /contact page, and we will provide any further routing needed to handle your request.
1.2 Scope and What This Policy Does Not Cover
This Policy applies to personal information we collect: (a) through forms and interactive features on the Site (including our contact / inquiry form); and (b) automatically through your use of the Site (including cookies and similar technologies).
This Policy does NOT apply to: (a) information collected on any website, platform, or service operated by a third party, even where linked from the Site; (b) information you provide through channels other than the Site, which may be governed by separate notices or agreements; or (c) data we process in the course of performing services for a customer under a separate contract, which is governed by that contract.
1.3 Acceptance of This Policy
By accessing or using the Site, you acknowledge that you have read and understood this Policy. Where we rely on consent, that consent is requested, recorded, and honored as described in Section 4, and what is already switched on before you make a choice depends on the state we resolve you to. Your use of the Site is also subject to our Terms & Conditions.
1.4 Eligibility — Adults Only
The Site is intended for, and directed solely to, users who are 18 years of age or older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. See the Children's Privacy section.
2. Categories of Personal Information We Collect
We collect only the categories of information described in this Policy; we do not engage in collection practices beyond those disclosed here.
2.1 Information You Provide to Us (Inquiry Form)
When you choose to contact us or submit an inquiry through our contact form, you may provide, and we collect:
- Name — your full name or the name you choose to give us;
- Email address — the address at which you wish to be contacted;
- Phone number (optional) — provided only if you choose to give it;
- Company / organization — the business or organization you represent;
- Message — the free-text content of your inquiry; and
- Inquiry details — any further information you choose to include about your needs, project, or timeline.
We use a third-party provider, Resend, to transmit and deliver the contents of these submissions to us. As a result, the information you submit through the form is processed by Resend solely for the purpose of delivering your message to us (see Section 5).
2.2 Information We Collect Automatically
When you access or interact with the Site, certain information may be collected automatically through your browser, device, our infrastructure, and (subject to the consent model in Section 4) cookies and similar technologies. This may include:
- IP address (which may be used to derive an approximate, non-precise location, such as city or region, and to determine which state's privacy rule applies to you; we do not collect precise GPS geolocation);
- Device and browser data, such as device type, operating system, browser type and version, language settings, and screen or viewport characteristics;
- Usage data, such as the pages and content you view, the date and time of your visits (timestamps), the duration and sequence of page views, and interactions with Site features;
- Referrer information, such as the website or source from which you navigated to the Site; and
- Marketing-attribution identifiers, including UTM parameters (e.g., utm_source, utm_medium, utm_campaign), gclid (Google click identifier), and fbclid (Meta/Facebook click identifier), which may be stored in your browser (for example, in cookies or local storage) to attribute and measure marketing performance.
Strictly necessary processing (for example, basic server logs needed for security, fraud prevention, and the technical delivery of the Site) may occur whatever your cookie choices, as permitted by law. Whether any non-essential automatic collection happens before you make a choice depends on the state we resolve you to: in the states named in Section 4, some non-essential categories may already be running when you arrive; everywhere else, nothing non-essential is collected or recorded until you affirmatively turn it on.
2.3 Categories of Sources
We collect personal information from: (a) you directly; (b) automatically from your device and browser through cookies and similar technologies; (c) our hosting, analytics, advertising, and email service providers; and (d) where that category is available to you and you have turned it on, identity-resolution and business-data enrichment providers.
2.4 Sensitive Personal Information and "Do Not Send Us Sensitive Information"
We do not seek to collect "sensitive personal information" (as defined under the California Privacy Rights Act and analogous state laws) or "special category data" (as defined under the GDPR and UK GDPR), and we do not use personal information to infer characteristics about you. Please do NOT send us, through the form or otherwise, any sensitive personal information — including government identifiers (e.g., Social Security, driver's-license, or passport numbers), financial-account or payment-card numbers, account credentials, health or medical information, biometric or genetic data, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, sex life or sexual orientation, immigration status, or information about minors. If you nonetheless choose to submit such information, you do so voluntarily and at your own risk, and you consent to our processing it solely as necessary to respond to your inquiry and to its deletion in the ordinary course.
3. How and Why We Use Information (Purposes and Legal Bases)
We use personal information for the purposes set out below. Where the GDPR or UK GDPR applies, the legal basis we rely on is indicated in brackets: [Consent], [Legitimate Interests], [Contract] (performance of a contract or steps prior to a contract at your request), or [Legal Obligation].
- To respond to your inquiries and communicate with you — to receive, review, and respond to messages submitted through the contact / inquiry form. [Contract / Legitimate Interests]
- To evaluate and pursue potential business relationships — to assess fit, prepare estimates and proposals, schedule work, and manage business-development activities. [Legitimate Interests / Contract]
- To operate, maintain, secure, and improve the Site — including ensuring technical functionality, availability, integrity, and security; preventing and detecting fraud, abuse, and unauthorized access; and diagnosing technical problems. [Legitimate Interests / Legal Obligation]
- To determine which privacy rule applies to you — to resolve your approximate location from your IP address so that the correct state's consent model, and any universal opt-out signal you send, can be applied. [Legal Obligation / Legitimate Interests]
- To measure and understand Site usage (analytics) — to understand how visitors find and use the Site and to improve content and design. [Consent]
- For marketing, advertising, and attribution — to measure marketing performance using attribution identifiers (UTM, gclid, fbclid), to deliver and measure advertising (including retargeting), and to build and use custom and lookalike audiences. [Consent]
- For identity resolution and enrichment — where that category is available to you and you have turned it on, to match a visit to an organization and to append third-party business firmographic data. [Consent]
- To send commercial or marketing communications — where permitted, subject to your right to opt out at any time. We do not send autodialed, prerecorded, or SMS/text marketing unless you have separately and specifically opted in (see the BIPA/VPPA/CAN-SPAM/TCPA section). [Consent / Legitimate Interests]
- To comply with legal obligations and enforce our rights — to comply with applicable laws and legal process; to establish, exercise, or defend legal claims; and to enforce our Terms & Conditions. [Legal Obligation / Legitimate Interests]
- For corporate transactions — to evaluate, negotiate, or complete a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, subject to the safeguards in Section 5. [Legitimate Interests]
3.1 Legitimate-Interests Balancing
Where we rely on legitimate interests, we have conducted a balancing assessment: (a) our interests include operating and securing the Site, responding to and developing business relationships, and measuring our marketing; (b) the processing is necessary for those interests and we use the least-intrusive practical means, including by applying each state's own consent rule to non-essential tracking and by honoring GPC and DNT universally; (c) we considered the impact on you and concluded that the strictly-necessary and security processing involves limited data and aligns with your reasonable expectations; and (d) we provide safeguards including transparency, per-category controls, data minimization, retention limits, and an unconditional right to object. We do not rely on legitimate interests for advertising or other non-essential tracking; those categories are governed by the state-by-state consent model in Section 4. You may request more information about our balancing assessment using the contact details below.
3.2 Automated Decision-Making and Profiling (Pointer)
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, including profiling, without meaningful human involvement. To the extent our advertising and audience-building involve profiling or automated decision-making technology, our full disclosures — including under the EU AI Act, the new California CPPA regulations, and state AI laws — are in the "Automated Decision-Making, Profiling, and Artificial Intelligence" section below.
7. GDPR and UK GDPR (EEA, United Kingdom, and Switzerland)
This Section applies if you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, and supplements the rest of this Policy. The controller is Polymer Nation Chemical Company, LLC, contactable at (847) 774-5038 or via the contact form on our /contact page.
7.1 Legal Bases
We process personal data only where we have a lawful basis under Article 6: Consent (Art. 6(1)(a)) for non-essential cookies and all non-essential tracking, including Google Analytics and the Meta Pixel; Performance of a contract / pre-contractual steps (Art. 6(1)(b)) to respond to your inquiry and prepare estimates and proposals; Legitimate interests (Art. 6(1)(f)) to operate, secure, and improve the Site, maintain server logs and security, respond to business inquiries, and pursue reasonable business-development interests, subject to the balancing in Section 3.1; and Legal obligation (Art. 6(1)(c)) to comply with applicable law. We do not rely on legitimate interests for advertising tracking, which requires consent. Visitors we resolve to a location outside the United States receive our strictest settings: nothing non-essential runs until you turn it on, and identity resolution is not offered at all.
7.2 Your Rights as a Data Subject
Subject to applicable law, you have the right to:
- Access your personal data and obtain a copy;
- Rectification of inaccurate or incomplete data;
- Erasure ("right to be forgotten");
- Restriction of processing;
- Data portability — to receive your data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible;
- Object to processing based on legitimate interests, and at any time and absolutely to object to processing for direct-marketing purposes (including related profiling);
- Withdraw consent at any time; and
- Not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects.
To exercise these rights, call us at (847) 774-5038 or use the contact form on our /contact page. We will respond within the timeframes required by law (generally one month under the GDPR/UK GDPR, extendable for complex requests).
7.3 International Data Transfers
We are based in the United States, and our service providers may process personal data in the United States and other countries that may not provide the same level of data protection as your jurisdiction. Where we transfer personal data out of the EEA, UK, or Switzerland, we implement appropriate safeguards, which may include the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs, the Swiss addendum, reliance on adequacy decisions where applicable, and supplementary technical and organizational measures. You may request information about these safeguards by contacting us.
7.4 EU/UK Representative and Data Protection Officer
Where required, our EU Representative (Art. 27 GDPR) and UK Representative (Art. 27 UK GDPR), and any appointed Data Protection Officer, are identified through the contact details we maintain for that purpose; until any such representative or officer is designated and published, you may direct all data-protection inquiries to (847) 774-5038 or the contact form on our /contact page, and we will route them appropriately.
7.5 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority — in the EU, in the Member State of your habitual residence, place of work, or place of the alleged infringement; in the UK, with the Information Commissioner's Office (ICO) at ico.org.uk; and in Switzerland, with the Federal Data Protection and Information Commissioner (FDPIC). We would appreciate the opportunity to address your concerns first, so please consider contacting us before approaching a supervisory authority.
8. California Privacy Rights — CCPA / CPRA
This Section applies to California residents and supplements the rest of this Policy, as required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA").
8.1 Notice at Collection
At or before the point of collection, we collect the categories of personal information described in Section 2 and summarized in Section 6, for the purposes described in Section 3, retained as described in the Data Retention section. We treat certain categories as "sold" or "shared" for cross-context behavioral advertising. For California residents, targeted advertising may already be running when you arrive, and you can stop it at any time through the banner, the footer "Do Not Sell or Share My Personal Information" link, or Global Privacy Control. We do not use or disclose sensitive personal information for purposes beyond those permitted under the CCPA, and we do not "sell" or "share" sensitive personal information.
8.2 Your CCPA Rights
- Know / Access — request the categories and specific pieces of personal information we have collected, the categories of sources, the business or commercial purposes, and the categories of third parties to whom we disclose it;
- Delete — request deletion of personal information we collected from you, subject to legal exceptions;
- Correct — request correction of inaccurate personal information;
- Opt Out of Sale / Sharing — direct us not to "sell" or "share" your personal information for cross-context behavioral advertising;
- Limit Use of Sensitive Personal Information — direct us to limit use of sensitive PI to permitted purposes (we do not use sensitive PI beyond permitted purposes); and
- Non-Discrimination — not receive discriminatory treatment for exercising your rights.
8.3 How to Exercise Your Rights; Opt-Out and Limit Mechanisms
You may exercise these rights by: (a) using the "Do Not Sell or Share My Personal Information" and "Cookie settings" links in our footer to opt out of the Analytics and Marketing categories; (b) enabling Global Privacy Control (GPC), which we honor as a valid opt-out of sale/sharing and targeted advertising and reflect as honored; or (c) calling us at (847) 774-5038 or using the contact form on our /contact page.
8.4 Verification, Authorized Agents, and Non-Discrimination
We will take reasonable steps to verify your identity before responding to a know, delete, or correct request, which may involve matching information you provide against information we hold. You may use an authorized agent to submit a request; we may require proof of written authorization and may require you to verify your identity directly with us. We will not discriminate against you for exercising any CCPA right, and we do not offer financial incentives in exchange for personal information.
8.5 ADMT, Risk Assessments, and Cybersecurity Audits (CPPA Regulations)
To the extent any advertising or analytics profiling constitutes "automated decisionmaking technology" (ADMT) or "extensive profiling" under the California Privacy Protection Agency's regulations, we conduct the risk assessments those regulations require, provide a pre-use notice describing the technology's purpose, and offer the rights to opt out of, and to access information about, such ADMT where the regulations apply. Because our profiling is limited to marketing audiences, is governed by the state-by-state model in Section 4, and is not used to make decisions that produce legal or similarly significant effects about you, the most burdensome ADMT triggers are not engaged. We also maintain reasonable cybersecurity measures and, where required, the cybersecurity-audit and risk-assessment documentation contemplated by those regulations.
8.6 "Shine the Light" (Cal. Civ. Code § 1798.83)
California residents may request information about our disclosure of personal information to third parties for those third parties' own direct-marketing purposes. We do not disclose personal information to third parties for their own direct-marketing purposes. You may direct Shine the Light inquiries to (847) 774-5038 or the contact form on our /contact page.
9. Texas Data Privacy and Security Act (TDPSA)
If you are a Texas resident, you have the rights to: confirm whether we process your personal data and access it; correct inaccuracies; delete personal data; obtain a portable copy; and opt out of (i) the sale of personal data, (ii) targeted advertising, and (iii) profiling in furtherance of decisions producing legal or similarly significant effects. We provide these opt-outs via the cookie banner, the footer opt-out and "Cookie settings" links, and recognition of Global Privacy Control as a universal opt-out mechanism. Texas-specific notice: in Texas, targeted advertising may already be running when you arrive, and we may disclose your personal data to advertising partners, which may constitute a sale of personal data and processing for targeted advertising. You may appeal a denial of your request as described in the Requests and Appeals section.
10. Other U.S. State Privacy Laws (Comprehensive State Roster)
If you are a resident of a U.S. state with a comprehensive consumer-privacy law, you have, to the extent and as provided by your state's law, the rights described below. As of 2026 these laws include, with their effective dates: California (CCPA, Jan 1, 2020; as amended by CPRA, Jan 1, 2023); Virginia (VCDPA, Jan 1, 2023); Colorado (CPA, Jul 1, 2023); Connecticut (CTDPA, Jul 1, 2023); Utah (UCPA, Dec 31, 2023); Texas (TDPSA, Jul 1, 2024); Oregon (OCPA, Jul 1, 2024); Florida (Digital Bill of Rights, Jul 1, 2024, which generally applies only to very large controllers); Montana (Consumer Data Privacy Act, Oct 1, 2024); Delaware (DPDPA, Jan 1, 2025); Iowa (ICDPA, Jan 1, 2025); Nebraska (DPA, Jan 1, 2025); New Hampshire (Jan 1, 2025); New Jersey (Jan 15, 2025); Tennessee (TIPA, Jul 1, 2025); Minnesota (MCDPA, Jul 31, 2025); Maryland (MODPA, Oct 1, 2025); Indiana (Jan 1, 2026); Kentucky (Jan 1, 2026); and Rhode Island (Jan 1, 2026).
Subject to your state's law, you may have the rights to:
- Confirm and access the personal data we process about you;
- Correct inaccuracies;
- Delete personal data;
- Obtain a portable copy of personal data you provided to us;
- Opt out of (i) the sale of personal data, (ii) targeted advertising, and (iii) profiling in furtherance of decisions that produce legal or similarly significant effects; and
- Where applicable, opt in before any processing of sensitive data (we do not knowingly process sensitive data).
10.1 State-Specific Heightened Duties
Several of these laws impose heightened duties, and where a state's law is stricter than our baseline our consent system applies that state's rule for you automatically. In particular: Maryland's MODPA imposes a strict data-minimization mandate and an outright prohibition on the sale of sensitive data (with no consent cure) and bans selling minors' data or targeting under-18s with advertising; Minnesota's MCDPA gives consumers the right to question the result of profiling, to be informed of the reason and how to achieve a different outcome, to review and correct the data used in profiling and have it re-evaluated, and to obtain a list of the specific third parties to whom their data was disclosed; and New Jersey prohibits the sale of sensitive personal information outright, so we offer no sensitive-data processing and no identity-resolution switch to New Jersey visitors at all. We do not sell sensitive data anywhere, do not target advertising to known minors, and honor profiling-related rights as described here and in the AI/profiling section.
10.2 Universal Opt-Out and Advertising
We recognize Global Privacy Control (GPC) as a universal opt-out mechanism for sale, sharing, and targeted advertising, and we honor it for every visitor rather than only where a statute compels it (see Section 4.4). Whether targeted advertising is running before you choose depends on the state we resolve you to, as set out in Section 4; where it is running, the banner, the footer links, and a GPC or DNT signal each switch it off. If you reside in the state in which we are principally located (Illinois) and that state provides comprehensive privacy rights, you may exercise them as described above. Right-to-appeal procedures are described in the Requests and Appeals section.
11. Consumer Health Data (Washington My Health My Data Act, Nevada SB370, and Similar Laws)
Some states regulate "consumer health data" outside their comprehensive privacy laws — most notably Washington's My Health My Data Act (MHMDA), Nevada's SB370, and Connecticut's health-data amendments. "Consumer health data" is defined broadly to mean information linked or reasonably linkable to a consumer that identifies their past, present, or future physical or mental health status, including health-related inferences and precise location information that could reasonably indicate an attempt to acquire health services or supplies.
We do not knowingly collect, process, infer, or sell consumer health data through this Site. We do not operate a health-care service and do not request health information (see Section 2.4). We will not collect or sell consumer health data without first obtaining your separate, affirmative opt-in consent or a valid authorization, as the applicable law requires. We do not use geofencing around any health-care facility to identify, track, collect data from, or send notifications to consumers, consistent with MHMDA's prohibition. As a further safeguard, we never run identity resolution or enrichment on our /resources, /products, /faq, or /tech-tips pages, which are the pages that carry safety-data-sheet and protective-equipment content. We honor rights to access and delete consumer health data and to withdraw consent. The MHMDA provides a private right of action through Washington's Consumer Protection Act. If our practices ever change such that we collect consumer health data, we will publish a separate, distinctly linked Consumer Health Data Privacy Policy as those laws require; if you have questions about consumer health data, contact us at (847) 774-5038 or via our /contact page.
12. Canada — PIPEDA and Quebec Law 25
This Section applies if you access the Site from Canada and supplements the rest of this Policy.
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), we rely on meaningful consent for the collection, use, and disclosure of personal information, and we limit collection to what is necessary for the purposes identified in this Policy. Under Quebec's Law 25 (the Act respecting the protection of personal information in the private sector), which can apply to the handling of a Quebec resident's personal information regardless of where the business is located: we designate a Privacy Officer responsible for our compliance (by default, the Company's chief executive, reachable via the contact details below); we obtain clear, free, and informed consent, sought separately and for specific purposes, before activating any tracking or profiling technology, which remains off by default for every visitor we resolve to a location outside the United States; we disclose when we use technology that profiles or locates you; we honor rights of access, rectification, de-indexing, portability, and withdrawal of consent; we conduct a transfer assessment before disclosing personal information outside Quebec (including to the United States); and we maintain governance, including privacy-impact assessments, for higher-risk processing. To exercise Quebec or PIPEDA rights, or to reach our Privacy Officer, contact us at (847) 774-5038 or via our /contact page.
13. Electronic Communications Consent — CIPA, Wiretap, Session Replay, and Pixel Technologies
Some U.S. states require the consent of all parties to record or intercept certain electronic communications, and some plaintiffs have applied wiretap, pen-register, trap-and-trace, and session-replay theories to website analytics and tracking technologies. To the extent the California Invasion of Privacy Act (CIPA), including its pen-register and trap-and-trace provisions, the California Comprehensive Computer Data Access and Fraud Act (CDAFA), or any analogous state wiretap or all-party-consent law (including those of states such as Florida, Pennsylvania, Illinois, and Massachusetts) applies to analytics, performance measurement, session activity, or communications on or through the Site, the following applies.
In the states listed in Section 4.1, analytics tags may fire before you make a choice; everywhere else, no pixel, tag, analytics script, or session-replay technology fires until you turn the relevant category on. We do not deploy session-replay technology that records keystrokes or the contents of fields as you type, and we do not capture financial-account entry. By using the Site with a category switched on — whether because you switched it on or because you left your state's setting in place after being given notice and an off switch — you expressly consent to the collection, recording, monitoring, processing, replay, and analysis of your interactions with the Site, including page activity, clicks, navigation, session and performance data, IP address, device and communication identifiers, any dialing, routing, addressing, or signaling information, and the contents of electronic communications you transmit to us through the Site, by us and by our analytics and advertising service providers acting on our behalf and as our agents (and not as independent eavesdroppers), for the purposes described in this Policy. This constitutes your prior, express, all-party consent to any such collection, recording, or interception, and your authorization for the use of any device-, communication-, or signaling-identifying process. Strictly necessary and security-related logging is processed whatever your choices, as permitted by law. The legal status of pen-register, trap-and-trace, and session-replay theories under CIPA and similar statutes remains unsettled; nothing here is an admission that any such technology is used or that any such law applies. If you do not consent, switch the categories off, enable GPC, or refrain from using the Site.
14. Defensive Statutory Coverage — BIPA, VPPA, CAN-SPAM, and TCPA
14.1 Biometric Information (BIPA and Similar Laws)
We do not collect, capture, purchase, receive, store, use, or disclose biometric identifiers or biometric information (such as fingerprints, voiceprints, retina/iris scans, faceprints, or scans of hand or face geometry) as defined under the Illinois Biometric Information Privacy Act (BIPA) or analogous laws (e.g., Texas CUBI, Washington's biometric statute). We do not use facial recognition, camera input, or similar biometric technologies on the Site. Please do not submit biometric data to us.
14.2 Video Privacy (VPPA)
We do not knowingly operate as a "video tape service provider" or knowingly collect or disclose "personally identifiable information" relating to your request for or obtaining of specific video materials in a manner governed by the Video Privacy Protection Act (VPPA). To the extent any audiovisual content is presented on the Site, the advertising technologies described in Section 4 operate on pages containing such content on the same state-by-state basis set out there, and we do not knowingly disclose your video-viewing information in a manner prohibited by the VPPA. Where applicable, your use of the Site with the Marketing category switched on constitutes your informed, written consent to such disclosure for the limited purposes described in this Policy; you do not consent to any disclosure beyond what this Policy describes.
14.3 Commercial Email (CAN-SPAM)
If we send you commercial email, we will comply with the CAN-SPAM Act and applicable law, including by using accurate header and subject-line information, identifying the message as an advertisement where required, including a valid physical postal address (our principal place of business at 405 Oakwood Ave, Waukegan, IL 60085), and providing a clear and conspicuous unsubscribe mechanism. We will honor opt-out requests promptly (generally within 10 business days). You may opt out at any time using the unsubscribe link in the email or by calling (847) 774-5038 or using the contact form on our /contact page. Transactional or relationship messages (such as responses to your inquiry) are not subject to opt-out.
14.4 Telephone and Text Communications (TCPA)
We do not send automated telemarketing calls or marketing text (SMS/MMS) messages, and we do not use an automatic telephone dialing system or a prerecorded or artificial voice for marketing, unless you have separately and expressly opted in. Providing your phone number on our contact form authorizes us to contact you about your inquiry only; it does not enroll you in any automated or marketing text or call program. Consistent with the Telephone Consumer Protection Act (TCPA) and related rules, any marketing calls or texts would require your prior express written consent, which is not a condition of any service, and you may revoke consent at any time. Message and data rates may apply to any texts you exchange with us.
15. Automated Decision-Making, Profiling, and Artificial Intelligence
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, including profiling, without meaningful human involvement. Where the advertising category is on for you, we (and our service providers) may engage in profiling for marketing and audience purposes (for example, inferring business interest and building audiences). This profiling does not produce legal or similarly significant effects about you, and it is governed by the state-by-state model in Section 4.
We do not deploy high-risk or "consequential" automated decision systems on this Site. To the extent frameworks such as the EU AI Act (including its Article 50 transparency duties), the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), or the Colorado AI Act apply, we do not use artificial intelligence to make consequential decisions about visitors, to unlawfully discriminate, or to manipulate or harm. If we ever deploy a chatbot, AI assistant, or AI-generated content, we will disclose its artificial nature and, where required, mark AI-generated content in a machine-readable way. You have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects (to the extent any such profiling were to occur) and to opt out of profiling for targeted advertising, by switching off the relevant cookie categories, enabling GPC, or using the "Cookie settings" link. Minnesota residents additionally have the profiling-specific rights described in Section 10.1, and EEA/UK data subjects have the rights described in Section 7.2.
16. Submitting and Verifying Requests; Appeals
16.1 How to Submit a Request
To exercise any privacy right under any applicable law, submit a request by calling (847) 774-5038 or using the contact form on our /contact page, or use the footer opt-out and "Cookie settings" links for opt-out and consent changes.
16.2 Verification
To protect your privacy and security, we will take reasonable steps to verify your identity before fulfilling a substantive request (such as access, deletion, correction, or know). Verification may require you to confirm information we already maintain about you (for example, the contact details you used to reach us). We will not use information collected for verification for any unrelated purpose, and we may decline a request where we cannot reasonably verify identity, as permitted by law.
16.3 Timing and Authorized Agents
We will respond within the timeframes required by applicable law (generally 45 days under U.S. state laws, with permitted extensions; generally one month under the GDPR/UK GDPR). You may use an authorized agent where the law permits, subject to proof of authorization and, where required, your own verification.
16.4 Right to Appeal
If we decline to act on your request, you may appeal by contacting us at (847) 774-5038 or via the contact form on our /contact page, indicating that your request is a "Privacy Appeal." We will respond to your appeal within the period required by applicable law (generally 45–60 days). If your appeal is denied, you may, depending on your state, contact your state Attorney General or relevant regulator (for example, the California Privacy Protection Agency or your state's Attorney General) to submit a complaint.
17. Data Retention Schedule
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements, and to establish, exercise, or defend legal claims. We do not retain personal information indefinitely. Our general retention guidelines are:
- Contact / inquiry submissions (name, email, phone, company, message, inquiry details): for the duration of our communications and any resulting relationship, plus a reasonable period thereafter for business-development and recordkeeping (generally up to 24–36 months after last contact), unless a longer period is required by law or you request deletion sooner.
- Email delivery logs (via Resend): for the limited period our provider retains transactional logs, then deleted or anonymized.
- Analytics data (Google Analytics, where enabled): per the configured retention settings of the analytics tool (typically 14 months or less for Google Analytics), in aggregate or pseudonymized form.
- Cookie / consent records: for the period necessary to evidence your consent choices — including the categories you selected and the location we resolved you to — and as required by law.
- Advertising data (where enabled): for the period determined by the relevant provider and our needs, and only while the category remains on for you; deleted or suppressed when you switch it off or send a universal opt-out signal.
- Identity-resolution and enrichment records (where enabled): only while you have that category switched on, and deleted or suppressed when you switch it off or send a universal opt-out signal.
- Security and server logs: for a limited period necessary for security, fraud prevention, and reliability.
When personal information is no longer needed, we will delete, de-identify, or anonymize it, or securely isolate it from further processing, in accordance with our retention practices and applicable law.
18. Security and Breach Notification
18.1 Security
We implement technical and organizational measures designed to protect personal information against unauthorized or unlawful access, use, alteration, disclosure, loss, or destruction. These measures are designed to include encryption of data in transit, access controls aligned with least-privilege principles, use of reputable infrastructure and processors, logging and monitoring, and limiting the collection of personal information to what is necessary. No method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the security of any device and connection you use to access the Site and for not transmitting sensitive information to us (see Section 2.4).
18.2 Breach Notification
In the event of a personal-data breach that triggers notification obligations under applicable law, we are committed to: (a) assessing the breach without undue delay; (b) notifying the relevant supervisory authority and/or other regulators within the timeframes required by law (for example, where feasible and where the breach is likely to result in a risk to individuals, consistent with the GDPR/UK GDPR's framework); and (c) notifying affected individuals where required by applicable law (including U.S. state breach-notification statutes), describing the nature of the breach and the steps we are taking. We will cooperate with authorities as required.
19. Children's Privacy (COPPA; 18+)
The Site is intended for users who are 18 years of age or older, and is not directed to children. We do not knowingly collect, use, sell, or share personal information from anyone under 18, and we do not knowingly apply targeted-advertising technology to anyone we know or have reason to believe is a minor. Our consent system resolves your state, not your age, so this commitment is enforced by our own practice rather than by an automated age check. Consistent with the Children's Online Privacy Protection Act (COPPA), including the FTC's 2025 amendments to the COPPA Rule, we do not knowingly collect personal information from children under 13; we recognize that the amended Rule expands "personal information" to include biometric and certain government-issued identifiers, requires separate verifiable parental consent for non-integral third-party disclosures, and requires a written information-security program and a written data-retention policy with no indefinite retention of children's data.
We state eligibility here and in our Terms rather than presenting an age-gate modal. If you are under 18, please do not use the Site or submit any information to us. If you are a parent or guardian and believe a child under 18 may have provided us personal information, contact us at (847) 774-5038 or via the contact form on our /contact page, and we will take reasonable steps to delete it.
20. Accessibility Statement (ADA / WCAG / EAA)
Polymer Nation Chemical Company, LLC is committed to digital accessibility and to making the Site usable by the widest possible audience, including people with disabilities. We work to improve accessibility with reference to the Web Content Accessibility Guidelines (WCAG) and consistent with the principles of the Americans with Disabilities Act (ADA) and applicable accessibility laws. Where the European Accessibility Act (Directive (EU) 2019/882) applies to services offered to consumers in the European Union, we work toward the WCAG 2.1 AA benchmark (via EN 301 549). Accessibility is an ongoing effort, and some portions of the Site — including interactive, animated, or three-dimensional content — may not yet fully conform. A dedicated Accessibility Statement is also available on the Site.
If you encounter any accessibility barrier, or need assistance or an alternative means of access, please contact us at (847) 774-5038 or via the contact form on our /contact page, describing the issue and the page involved. We welcome your feedback and will make reasonable efforts to address accessibility concerns and to provide the information or functionality you need through an alternative method where feasible.
21. Third-Party Links, Changes to This Policy, and Contact
21.1 Third-Party Links and Services
The Site may contain links to, or integrations with, third-party websites, platforms, or services (including those of Vercel, Resend, Supabase, and — where enabled — Google and Meta) that we do not own or control. This Policy does not apply to those third parties, and we are not responsible for their content, privacy practices, or security. We encourage you to review the privacy policies of any third party before providing your information to it.
21.2 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will revise the "Last updated" date above and, where required by law, provide additional notice (such as a notice on the Site). Changes are effective when posted unless otherwise stated. Your continued use of the Site after the effective date of any change constitutes your acceptance of the updated Policy, to the extent permitted by law. We encourage you to review this Policy periodically.
21.3 Contact Us
If you have questions, requests, or concerns about this Privacy Policy or our data practices — including to exercise any privacy right, withdraw consent, or submit a complaint or appeal — please contact us by phone at (847) 774-5038 or through the contact form on our /contact page. Our mailing address is 405 Oakwood Ave, Waukegan, IL 60085. For data-protection inquiries under the GDPR/UK GDPR, you may also contact our EU/UK representative once designated (see Section 7.4), and you retain the right to lodge a complaint with your supervisory authority (see Section 7.5).
This Privacy Policy is provided for general informational purposes and does not constitute legal advice. Polymer Nation Chemical Company, LLC reserves all rights, defenses, and protections available under applicable law.
Questions?
Need clarification on our privacy practices?
Reach the Polymer Nation team and we'll help with any privacy, terms, or accessibility question.
