Privacy Policy
Last updated: March 2025
This policy complies with the Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5) and, where applicable, Quebec's Act respecting the protection of personal information in the private sector (Act 25 / Bill 64, in force since September 2023).
1. Privacy Officer
Brume Studio — [full address, Canada]
Privacy Officer: [First Last]
Email: contact@brume-store.com
2. Personal Information Collected
We collect the following personal information:
- Account: email address (magic link sign-in).
- Order: name, shipping and billing address, email, order amount and details.
- Payment: processed by Stripe — we never store card numbers.
- Navigation: IP address, browser type, pages visited (Vercel server logs).
3. Purposes and Legal Bases
- Processing and tracking your orders — contract performance
- Sending transactional emails (confirmation, shipping) — contract performance
- Managing your customer account — contract performance
- Newsletter (with your consent) — explicit consent
- Fraud prevention and security — legitimate interest
- Legal and accounting obligations — legal obligation
4. Service Providers & Disclosure
Your information may be shared with the following providers, strictly within the scope of their services:
- Stripe — secure payment processing (United States)
- Supabase — database hosting (United States)
- Vercel — website hosting (United States)
- Resend — transactional email delivery (United States)
These providers are located outside Canada. Before transferring your information to them, we ensure they provide an adequate level of protection consistent with PIPEDA requirements.
5. Retention Periods
- Account data: until deletion + 3 years
- Order data: 7 years (Canadian tax obligations)
- Newsletter data: until consent is withdrawn
- Navigation logs: maximum 12 months
6. Your Rights
Under PIPEDA and Quebec's Act 25, you have the following rights:
- Right of access to your personal information
- Right to correction of inaccurate information
- Right to erasure (Act 25)
- Right to data portability (Act 25, since September 2023)
- Right to withdraw consent
- Right to file a complaint with a supervisory authority
To exercise your rights, contact us at contact@brume-store.com. You may also file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, for Quebec residents, with the Commission d'accès à l'information (CAI) (cai.gouv.qc.ca).
7. Privacy Incidents
In accordance with PIPEDA and Act 25, any privacy incident posing a risk of serious harm will be reported to the relevant authority and affected individuals within the timeframes prescribed by law. We maintain a privacy incident register as required.
8. Cookies
This site uses only strictly necessary cookies:
- Supabase session cookie (authentication)
- Cart local storage (localStorage, never sent to our servers)
No advertising, profiling, or third-party analytics cookies are placed.
9. Security
We implement appropriate technical and organisational security measures: TLS encryption, role-based access control, and Row Level Security on our database.
10. Policy Updates
This policy may be updated. The last revision date is shown at the top of this page. We will notify you by email of any material changes.