Global Privacy Policy
Last Updated: July 11, 2026
PIPEDA • GDPR • CCPA Compliant
This Global Privacy Policy describes how we collect, use, disclose, and safeguard personal information when you visit or purchase products from our website originating in Canada. We target global compliance standards, matching obligations for users across Canada, the United States, the European Union, the United Kingdom, and internationally.
🔒 Cookie-Free Notice
Our website respects your privacy by operational design. We do not use tracking cookies, analytics cookies, advertising cookies, or persistent local storage tracking mechanisms of any kind. Your browsing activity remains entirely private.
1. Accountability and Scope
We are responsible for personal information under our control. We have designated a Privacy Officer to oversee compliance with international data privacy regulations, handle access requests, and respond to data inquiries. This policy applies to all global users purchasing our products or visiting our web infrastructure.
2. Lawful Bases and Consent
We only collect and process personal information when we have a valid legal justification. Depending on your jurisdiction, this includes:
- Performance of a Contract: Necessary processing to fulfill transactions, process payments, and ship products you purchase.
- Consent: Express opt-in consent where required by law (e.g., subscribing to direct marketing lists). You may withdraw consent at any time.
- Legitimate Interests: To detect fraud, defend legal rights, and ensure data security.
3. Information We Collect
We collect only the minimum necessary information to facilitate transactions and run operations. We do not use automatic tracking or cookies to profile you.
a. Information You Provide Voluntarily
- Contact Information: Name, email address, physical shipping address, billing address, and phone number provided during checkout or contact forms.
- Transaction Data: Details of the items purchased. Please note: All payment transactions are processed securely by our Merchant of Record, Paddle (paddle.com). Paddle handles checkout, billing, invoicing, and global tax compliance on our behalf. We never store, see, or transmit your raw financial account or credit card numbers on our servers.
b. Technical Log Data
- Server Logs: Like almost all web servers, our systems automatically log basic server requests (IP address, browser type, referring URL, and timestamp). This data is strictly used for security auditing, fraud prevention, and performance diagnostics, and is regularly purged. For software download activity, we derive and retain aggregate country-level and OS platform information from server logs at the time of download; no IP addresses or raw browser strings are stored in download records.
4. How We Use Your Information
Your information is used strictly to fulfill your orders and support transactions, including to:
- Process, verify, invoice, and deliver your international or domestic orders.
- Respond to your direct customer support or technical inquiries.
- Maintain security infrastructure, guard against fraud, and comply with international tax laws (e.g., local VAT/GST reporting).
5. Data Transfer and Disclosure
We do not sell, rent, trade, or share your data for behavioral marketing or advertising. Data is shared only with partners essential to business fulfillment:
- Third-Party Processors: Our Merchant of Record, Paddle, handles all payment processing, invoicing, and global tax remittance. Paddle's checkout script is loaded on product pages and may process your IP address and browser information as part of fraud prevention and compliance. Paddle is contractually and legally bound to handle your data in accordance with GDPR, CCPA, and applicable privacy law. You can review Paddle's privacy policy at paddle.com/legal/privacy.
- Fulfillment & Delivery Partners: Any services required to deliver digital goods or support transactions are contractually bound to handle data securely.
- International Data Transfers: Because our operations originate in Canada, your information will be transferred to and stored on servers located in Canada (and potentially the United States via cloud infrastructure hosting partners). Canada's privacy laws are recognized by the European Commission as offering an adequate level of data protection (an "Adequacy Decision").
6. Data Retention and Security
We keep personal information only for as long as needed to fulfill transactions or meet legal tax, commercial, and financial record-keeping mandates. We use rigorous administrative and technical security measures — including TLS/SSL encryption for all traffic — to guard your data.
- Contact form submissions (name, email, message): retained for up to 12 months after your inquiry is resolved, unless a longer period is required for legal purposes.
- Purchase and license records (email, transaction ID, license key): retained as required by applicable tax and accounting laws, typically 5–10 years depending on jurisdiction.
- Server log data (IP address, browser type, timestamp): regularly purged; retained no longer than 90 days unless required for active security or fraud investigation.
7. Children's Privacy
We do not knowingly target or collect data from children under the age of 16 (or 13 depending on local jurisdiction requirements, including US COPPA). If we learn we have inadvertently collected data from a child under these limits, we will purge it immediately.
8. Regional Rights and Disclosures
A. For Residents of Canada (PIPEDA & Provincial Laws)
You have the right to request access to and correction of the personal information we hold about you. Contact our Privacy Officer to file a request. We resolve valid requests within thirty (30) days. You may also contact the Office of the Privacy Commissioner of Canada (OPC).
B. For Residents of the European Economic Area (EEA) and United Kingdom (GDPR / UK GDPR)
Under the GDPR, you possess extended rights regarding your data, including:
- Right to Erasure ("Right to be Forgotten"): Request full deletion of your transaction data, subject to legal financial retention limits.
- Right to Portability & Restriction: Request structured transfer of your data or a pause in processing.
- Right to Lodge a Complaint: File a direct grievance with your local European Data Protection Authority.
C. For Residents of the United States (California CCPA/CPRA & State Laws)
We do not "sell" or "share" personal information to third parties, nor do we track users via cookies for cross-context behavioral advertising. You possess the right to know what data we collect, request correction or deletion, and do so without facing discrimination. If you are a California resident, you may submit an authorized agent request to exercise these privileges.
9. Contact Information
To exercise your international data rights or to submit questions, please reach out via our Contact page. We will respond within 30 days.