On This Page

(1) Scope

Rock Paper Coffee (“we,” “us,” “our”) explains in this Privacy Policy how we collect, use, disclose, and protect personal information when you visit our website, create an account, sign up for emails, or buy products from our online store.

This Privacy Policy applies to our website and online store, and to customer communications related to orders and support. This Policy does not apply to third-party websites or services that we link to.

(2) Information We Collect

We collect personal information that you provide to us, and information collected automatically when you use our site.

Information you provide

  • Contact details: name, email address, phone number
  • Order and account details: shipping address, billing address, order history, account login details (if you create an account)
  • Customer support: messages you send us, and details needed to resolve an issue (order number, product, photos if you choose to share them)
  • Newsletter signups: email address and any preferences you choose to provide

Information collected automatically

  • Device and usage data: IP address, browser type, device type, pages viewed, and actions on our site
  • Approximate location: inferred from IP address (city/region level)
  • Cookies and similar technologies: described below

Payment information
We do not store full payment card numbers. Payments are processed through third-party payment processors.

(3) How We Use Information

We use personal information for purposes a reasonable person would consider appropriate in the circumstances, including:

  • To provide products and services: process orders, ship purchases, send order confirmations and delivery updates
  • To provide support: respond to requests, troubleshoot issues, handle returns or quality concerns
  • To operate and improve our site: monitor performance, fix bugs, improve usability and shopping experience
  • To protect against fraud and security issues: detect suspicious activity, secure accounts and transactions
  • To communicate with you: send service messages (order updates, policy updates, support replies)
  • To send marketing (only where permitted): newsletters, early access, and offers, and you can opt out anytime

Under PIPEDA, organizations are expected to be transparent about these practices and to obtain meaningful consent where required. (Office of the Privacy Commissioner)

(4) Cookies and Similar Technologies

We use cookies and similar technologies to help our site function, understand how visitors use our site, and improve performance.

Depending on your settings and your device/browser, cookies may be used for:

  • Essential site functions (cart, checkout flow, security)
  • Analytics (understanding site traffic and what content is useful)
  • Marketing (showing relevant ads and measuring performance, where enabled)

Your choices

  • You can control cookies through your browser settings and, if available on our site, through our cookie banner or preference tools.
  • Disabling some cookies may affect site functionality.

(5) Sharing and Service Providers

We share personal information only as needed to run our business and provide our services, including with service providers that help us with:

  • Payment processing
  • Shipping and delivery
  • Website hosting and infrastructure
  • Email delivery (order emails and newsletters)
  • Analytics and advertising (if enabled)

Service providers are authorized to use personal information only to perform services for us, and we expect appropriate safeguards and confidentiality.

(6) Marketing Preferences

If you sign up for marketing emails, you can unsubscribe at any time using the link in our emails. Unsubscribing stops marketing emails, but we may still send non-marketing messages like order confirmations, shipping updates, or support replies.

(7) Retention {#retention}

We keep personal information only for as long as necessary for the purposes described in this Policy, and as required by law.

  • Order and transaction records may be retained to meet legal, tax, and accounting requirements.
  • Support records may be retained to handle ongoing issues, product quality follow-ups, or to improve customer service.
  • Marketing email information is kept until you unsubscribe (or until we no longer need it).

(8) Security and Breach Response

We use reasonable administrative, technical, and physical safeguards designed to protect personal information against loss, theft, unauthorized access, disclosure, copying, use, or modification.

If there is a breach of security safeguards involving personal information, we will take steps to reduce the risk of harm and follow applicable legal requirements, including notification and reporting obligations where required. PIPEDA’s breach framework includes requirements about what a report and notification should contain, and record-keeping obligations (including maintaining records of breaches for 24 months after determining a breach occurred). (Department of Justice Canada)

(9) Access and Correction

You may request access to the personal information we hold about you and request corrections if it is inaccurate, subject to legal exceptions.

To make a request, contact us using the details in the “Contact Us” section below. We may need to verify your identity before responding.

PIPEDA includes access rights and openness expectations as part of its fair information principles. (Department of Justice Canada)

(10) Cross-Border Processing

Some of our service providers may process or store information outside of Canada. When personal information is processed outside Canada, it may be subject to the laws of that jurisdiction.

We remain responsible for personal information we transfer to service providers for processing and we expect appropriate safeguards. (Department of Justice Canada)

(11) Third-Party Links

Our website may link to third-party sites. Their privacy practices are governed by their own policies. We are not responsible for third-party privacy practices.

(12) Children

Our website is not intended for children, and we do not knowingly collect personal information from children.

(13) Updates

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of the page.

(14) Contact Us

For questions, requests, or concerns about privacy, contact us at:
info@rockpapercoffee.com