Privacy Policy
Draft — not yet in force. This document has been drafted but not reviewed by a lawyer, and it still contains unfilled details. It does not describe a final position until that review is complete and this notice is removed.
Last updated: TODO: [FILL: effective date — the day this goes live, not the day it was drafted]
Who this policy is from
This policy describes how TODO: [FILL: registered legal entity name — must match the Stripe account character for character], a sole proprietorship carrying on business in Ontario, Canada, trading as Eternafuse ("Eternafuse", "we", "us"), handles personal information.
We are the organisation accountable for the personal information described here. Our handling of it is governed by Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
This policy covers this website and our dealings with prospective and current clients. It does not cover what our clients do with their own customers' data in systems we have built and handed over — in those systems the client is the one accountable, and their own privacy policy applies.
Our contact details are at the end.
1. What we collect
When you use the contact form. The form asks for:
- your name — required
- your email address — required
- what you are doing by hand right now, in your own words — required
- your business name — optional
- your phone number — optional
We do not ask for anything else. The form carries one hidden field that stays empty for a person and only an automated submitter fills in; if anything appears in it, the submission is discarded and nothing is stored. It collects nothing about you.
Please do not put sensitive information — financial details, health information, government identifiers — into the message field. We do not need it.
When you become a client. During an engagement we collect what the work requires: business details, account and access information, billing details, and correspondence. We ask for the least that will do the job.
Automatically, when you visit. Our hosting provider keeps standard server logs — IP address, request time, page requested, browser user agent — as part of serving and securing the site. We do not use them to build a profile of you. TODO: [FILL: confirm the hosting provider's log retention period once the Vercel project exists, and state it here]
We do not collect payment card details on this site. See section 4.
2. Why we collect it, and your consent
We use the information above to:
- reply to your enquiry and arrange a call;
- quote for, deliver, support, and invoice work;
- keep records we are required to keep, including for tax purposes;
- keep the site running and secure.
Submitting the contact form is your consent to us using what you sent to reply to you. We will not use it for anything else without asking.
We do not sell personal information, and we do not share it for advertising.
Marketing. We do not send marketing email. We reply to what you sent us, and we may follow up about that specific enquiry. You will not be added to a list, and we will not send you anything you did not ask for.
3. Where it goes
A contact form submission is stored in a database we run on Supabase, a hosted database platform. TODO: [FILL: name the Supabase region once the project exists. If it is not a Canadian region, say plainly that submissions are stored outside Canada — see section 6]
A submission is sent to our own server first, which checks it and then writes it to that database. It is not sent to the browser of anyone else and it is not posted to any third party from your browser.
No other service processes your submission today. We intend to switch on our own notification workflow (n8n) so that an enquiry is not missed; when we do, it will receive the same fields you sent, notify us, and pass them nowhere else — and this policy will say so before it is switched on, not after.
We use these service providers, and only for the purposes above:
- Supabase — stores contact form submissions. Located in TODO: [FILL: region].
- Vercel — serves this website and keeps the server logs described in section 1. Located in TODO: [FILL: region].
- Stripe — processes payments for our clients. See section 4. Located in the United States and elsewhere.
- TODO: [FILL: email provider, once the business email exists] — carries email between us and you. Located in TODO: [FILL: region].
Service providers may only use the information to provide their service to us. They may not use it for their own purposes.
We may also disclose personal information where the law requires it, or where it is necessary to establish or defend a legal claim.
4. Payments
We never see or store your card details. Card payments made through systems we build are processed by Stripe, Inc. and its affiliates ("Stripe"). Card numbers go directly to Stripe and are handled under Stripe's own security standards. They do not reach our servers.
Where we set up payments for a business, we operate a Stripe Connect platform account and the business accepts payments through its own connected Stripe account. In that arrangement:
- the business's own onboarding information — identity documents, business details, bank details — is collected by Stripe under the Stripe Connected Account Agreement between that business and Stripe;
- we can see limited account and transaction information for accounts connected to our platform, so that we can set up, verify, and support the integration;
- we cannot see full card numbers, and we cannot move the business's funds.
Stripe's handling of personal information is governed by Stripe's own privacy policy at stripe.com/privacy. Stripe operates internationally, so information handled by Stripe is processed outside Canada.
5. How long we keep it
- Contact form submissions that do not become an engagement: 24 months, then deleted.
- Client records: for the length of the engagement, and afterwards for six years — the period Canadian tax law requires business records to be kept.
- Server logs: TODO: [FILL: hosting provider's retention period]
We delete or anonymise personal information when we no longer need it for the purpose it was collected for and no legal obligation requires us to keep it.
6. Information handled outside Canada
Some of our service providers store or process information outside Canada, including in the United States. While it is there it is subject to the laws of that country, and may be accessible to courts and law enforcement there under those laws.
We also work with businesses in Saint Lucia and elsewhere in the Caribbean, so information may be sent to and from those countries in the ordinary course of an engagement.
We use providers that offer a comparable level of protection to what is required in Canada, and we bind them contractually to use the information only for the service they provide to us.
7. Cookies and analytics
This site sets no cookies and uses no analytics. It stores nothing in your browser — no cookies, no local storage, no session storage — and there is no consent banner because there is nothing to consent to.
We do not use advertising cookies or third-party tracking pixels.
If we add analytics later, this section will say what it is, what it collects, and how to opt out, before it is switched on.
8. Your rights
Under PIPEDA you may:
- ask what we hold about you, and get a copy of it;
- ask us to correct it if it is wrong or incomplete;
- ask us to delete it, where we are not required to keep it;
- withdraw your consent to our using it, subject to legal and contractual limits — for instance, we cannot keep working on an engagement without the information the work requires.
Write to the contact address below and we will respond within 30 days. We may need to confirm your identity first. We do not charge for a request unless it is unusually costly to fulfil, in which case we will tell you the cost before doing the work.
If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
9. Security
We protect personal information with safeguards appropriate to its sensitivity:
- the site is served over HTTPS, so submissions are encrypted in transit;
- the database is access-controlled, and stored data is encrypted at rest by the provider;
- access is limited to the people who need it — in practice, one person;
- accounts we control use multi-factor authentication where the provider supports it.
No system is perfectly secure. If a breach occurs that creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner as PIPEDA requires.
10. Children
This site is for businesses and is not directed at children. We do not knowingly collect personal information from anyone under the age of majority in their province or country. If you believe we have, tell us and we will delete it.
11. Changes to this policy
We may update this policy. When we do, we will change the date at the top. If a change materially affects how we handle information we already hold, we will take reasonable steps to tell the people affected before it takes effect.
12. Contact
Questions, access requests, and complaints about privacy go to:
- Accountable person: Joshua Joseph
- Legal entity: TODO: [FILL: registered legal entity name]
- Address: TODO: [FILL: business address — must match the Stripe account]
- Email: TODO: [FILL: privacy contact email — the business email is fine for a business this size]
- Phone: 647-546-0089