Privacy Policy
Protection of your personal information
Version 1.0 — March 2026 | Last updated: 2026-03-27
Introduction
[COMPANY_NAME], operating the RepairWorkshop platform (hereinafter "we", "our" or the "Platform"), is committed to protecting the confidentiality and security of its users' personal information in compliance with Quebec's Law 25 on the protection of personal information, the federal Personal Information Protection and Electronic Documents Act (PIPEDA), and applicable provincial legislation (PIPA Alberta, PIPA British Columbia).
This policy applies to our website (repairworkshop.ca), our management application (the "Platform"), and all services we provide.
If you do not agree with the terms of this policy, please do not use our services.
1. Privacy Officer
In accordance with Law 25, we have designated a person responsible for the protection of personal information:
[PRIVACY_OFFICER]
Email: privacy@repairworkshop.ca
Any questions, access requests, correction requests or complaints regarding your personal information may be directed to this person.
2. Personal Information Collected
We collect the following personal information depending on your interaction with our services:
A) When registering on the Platform (workshop owners)
- Full name and first name
- Email address
- Phone number
- Business name
- Business address
- Province and country
- Payment information (processed by Stripe; we do not store your card numbers)
B) When using the Platform
- Operational data from your workshop (customer records, repairs, sales, inventory)
- Activity and access logs (IP address, timestamps)
- Configuration preferences
C) When visiting the website
- Browsing data (cookies, with your consent)
- Information submitted through the contact form (name, email, phone, message)
D) Data processed on behalf of our clients (subcontracting)
As a SaaS provider, we process data that our clients (repair workshops) enter into the Platform about their own customers. This data belongs to the workshop and is processed in our capacity as a subcontractor. Each workshop remains responsible for obtaining consent from their own customers in accordance with applicable laws.
3. Purposes of Collection
We collect and use your personal information solely for the following purposes:
- Providing, maintaining and improving our services
- Managing your account and subscription
- Processing payments through Stripe
- Communicating with you about your account (updates, technical notices, security)
- Ensuring the security and integrity of the Platform
- Complying with our legal and regulatory obligations
- With your explicit consent: sending you marketing communications
4. Consent
In accordance with Law 25, your consent is required before any collection of personal information. This consent is:
- Free: you may refuse without consequence on access to essential services
- Informed: you are informed of the nature of the information collected and its use
- Specific: consent is requested separately for each distinct purpose
- Temporary: you may withdraw your consent at any time
Consent to marketing communications is separate from consent to terms of use.
5. Retention of Information
We retain your personal information for as long as necessary for the purposes for which it was collected:
- Active account data: for the duration of your subscription
- Data after termination: 90 days, after which data is anonymized or deleted according to your preferences
- Billing data: in accordance with Canadian tax requirements (minimum 6 years)
- Security logs: maximum 12 months
The retention period is configurable by each workshop in the Platform settings.
6. Hosting and Data Security
All data is hosted in Canada, at OVH in Beauharnois, Quebec. No data is transferred outside of Canada, except in the following cases:
- Stripe (payment processing): payment data is processed by Stripe Inc., compliant with PCI-DSS standards. Stripe may process data in its centers in the United States and Europe, in accordance with its own privacy policies.
We implement rigorous technical and organizational security measures:
- Communication encryption (HTTPS/TLS)
- Data isolation between workshops (multi-tenant architecture)
- Role-based access controls and secure authentication
- Access and modification logging
- Regular encrypted backups
- OWASP security headers (CSP, HSTS, X-Frame-Options)
7. Disclosure to Third Parties
We do not sell, rent or share your personal information with third parties for commercial purposes.
We may disclose your information in the following cases:
- Stripe: for payment processing
- Technical service providers: hosting (OVH), SSL certificates, only to the extent necessary
- Legal obligations: if required by law, a court order or a competent authority
Before any transfer of information to a subcontractor located outside of Quebec, we conduct a privacy impact assessment in accordance with Law 25.
8. Cookies
Our website uses cookies for:
- Essential cookies: Platform operation (session, authentication, CSRF)
- Analytics cookies: Google Analytics (GA4), only with your explicit consent
You may change your cookie preferences at any time through the consent banner on our site. Analytics cookies are only activated after your explicit consent, in accordance with Law 25.
9. Your Rights
In accordance with Law 25 and PIPEDA, you have the following rights:
- Right of access: obtain confirmation that we hold information about you and access it
- Right of rectification: have inaccurate or incomplete information corrected
- Right to erasure: request the deletion or anonymization of your personal information, subject to our legal obligations
- Right to portability: receive your personal information in a structured, commonly used format (JSON)
- Right to withdraw consent: withdraw your consent at any time
- Right to object: object to the automated processing of your information
To exercise these rights, contact our Privacy Officer at privacy@repairworkshop.ca. We will process your request within 30 days.
10. Privacy Incidents
In accordance with Law 25, any privacy incident presenting a risk of serious harm will be:
- Reported to the Commission d'accès à l'information du Québec (CAI)
- Communicated to the affected individuals as soon as possible
- Recorded in our incident register
11. Minors
Our services are not intended for persons under 14 years of age. We do not knowingly collect personal information from minors under 14 without the consent of a parent or guardian.
12. Changes to This Policy
We reserve the right to modify this policy at any time. In the event of a substantial change, we will notify you by email or by a visible notice on the Platform at least 30 days before the changes take effect.
13. Remedies
If you believe your privacy rights have not been respected, you may:
- Contact us directly at privacy@repairworkshop.ca
- File a complaint with the Commission d'accès à l'information du Québec (CAI): www.cai.gouv.qc.ca
- File a complaint with the Office of the Privacy Commissioner of Canada: www.priv.gc.ca
Effective date: [LAUNCH_DATE]