1. Introduction
GotMaple Inc. ("GotMaple", "we", "us") operates GotMaple.ca, a 100% Canadian e-commerce marketplace. This Privacy Policy describes how we collect, use, disclose, and protect your personal information in compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act Modernizing Legislative Provisions as Regards the Protection of Personal Information (Law 25).
By using GotMaple.ca, you consent to the practices described in this policy. If you do not agree, please do not use our platform.
2. Information We Collect
- Account information: Name, email address, hashed password, phone number.
- Purchase history: Past orders, items purchased, transaction amounts, return history.
- Browsing data: Pages visited, search terms, items viewed — only with your consent.
- Device information: Browser type, operating system, IP address (anonymised after 24 hours).
- Location (province): Province or territory inferred from shipping address or postal code, used to calculate applicable taxes and surface local sellers.
3. How We Use Your Information
- Order processing: Fulfil your purchases, coordinate shipping with sellers and Canada Post, and manage returns.
- Marketing communications (CASL): Send you offers and news only when you have given express consent, in compliance with Canada's Anti-Spam Legislation (CASL).
- Fraud prevention: Detect and prevent fraudulent activity, account abuse, and unauthorised transactions.
- Platform improvement: Analyse anonymised usage trends to improve features, performance, and user experience.
4. Data Storage
100% Canadian data storage
All GotMaple user data is stored exclusively on servers located in Canada, at the Aptum Technologies data centre in Toronto, Ontario. No data is transferred to the United States or subject to the U.S. CLOUD Act.
We use AES-256 encryption for data at rest and TLS 1.3 for data in transit. Access to personal information is restricted to employees who require it to perform their job functions.
5. Sharing Your Information
We do not sell your personal data — ever.
We share your information only in the following circumstances:
- Canada Post: Your name and shipping address to fulfil order delivery.
- Stripe (payment processing): Payment data required to process transactions securely. Stripe is a globally trusted, PCI-DSS Level 1 compliant payment processor. GotMaple never stores card numbers.
- Sellers (order fulfilment only): Your name, shipping address, and order details are shared with the relevant seller so they can ship your purchase. Sellers do not receive your email address or payment information.
All partners are bound by confidentiality agreements and are required to protect your information in accordance with Canadian privacy laws.
6. Your Rights Under PIPEDA
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Withdrawal of consent: Withdraw your consent to data processing at any time, subject to legal or contractual restrictions.
- Data portability: Receive your data in a structured, machine-readable format.
- Deletion: Request deletion of your personal information, subject to legal retention obligations (see section 11).
To exercise these rights, contact privacy@gotmaple.ca. We will respond within 30 days.
7. Quebec Law 25 (Loi 25)
Under Quebec's Act Modernizing Legislative Provisions as Regards the Protection of Personal Information (Law 25), GotMaple upholds the following additional obligations:
- Privacy Impact Assessments (PIAs): We conduct PIAs before any new project involving personal information.
- Mandatory breach notification: In the event of a confidentiality breach presenting a risk of serious harm, we notify the Commission d'accès à l'information (CAI) and affected individuals within 72 hours.
- Designated Privacy Officer: GotMaple has designated a Privacy Officer reachable at privacy@gotmaple.ca.
- Additional rights for Quebec residents: Data portability, de-indexation (right to be forgotten), and the right to know about automated decisions affecting you.
See our Quebec Privacy (Loi 25) page for full details.
8. CASL Compliance
- Express consent: We send commercial electronic messages only to individuals who have given express consent at registration or through a separate opt-in form.
- Unsubscribe link: Every commercial email contains a functional unsubscribe link. Unsubscribe requests are processed within 10 business days.
- Consent records: We retain consent records for a minimum of 3 years in compliance with CASL requirements.
9. Cookies
We use essential, functional, and analytics cookies. GotMaple does not use any third-party advertising cookies. See our Cookie Policy for the full list and management options.
10. Children's Privacy
The GotMaple platform is not intended for individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with information, please contact privacy@gotmaple.ca and we will promptly delete it.
11. Data Retention
- Active accounts: Data is retained for as long as your account is active.
- Closed accounts: Transaction data is retained for 7 years after account closure in compliance with Canada Revenue Agency (CRA) requirements.
- Marketing data: Marketing consent records are retained for 3 years per CASL. Unsubscribe preferences are retained indefinitely.