Privacy Policy
Last Updated: February 8th, 2025.
Online-Post.ca is a service provided by Davette (Business Number: 79277 2238, BC PST: PST-1498-6273), a sole proprietorship registered in British Columbia, Canada.
1. Introduction
Davette, operating as Online-Post.ca ("we", "us", or "our"), is committed to protecting your privacy and safeguarding your personal information. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our website and letter mailing services (the "Service").
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and the British Columbia Personal Information Protection Act (PIPA). By using our Service, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy.
2. Information We Collect
We collect the following categories of personal information:
2.1 Information You Provide Directly
- Sender Information: Your name, mailing address, and email address
- Recipient Information: The name and mailing address of your letter recipient(s)
- Letter Content: The text, images, and documents you upload or create for your letters
- Payment Information: Billing address and postal code for tax calculation (credit card details are processed directly by Stripe and not stored on our servers)
- Communications: Messages you send to our customer support team via chat or email
2.2 Information Collected Automatically
- Device and Browser Information: IP address, browser type and version, operating system, device type, and screen resolution
- Usage Data: Pages visited, time spent on pages, click patterns, and navigation paths through our website
- Server Logs: Request timestamps, referring URLs, and error information for troubleshooting and security purposes
- Analytics Data: Aggregated, anonymized website usage statistics
3. How We Use Your Information
We use your personal information for the following purposes:
3.1 Service Delivery
- Processing, printing, and mailing your letters
- Calculating applicable taxes based on your location
- Sending order confirmations and tracking updates
- Providing customer support and responding to inquiries
3.2 Communications
- Sending transactional emails (order confirmations, shipping notifications, receipts)
- Sending marketing communications about new features, promotions, and updates (with your consent)
- Responding to your support requests and inquiries
3.3 Service Improvement and Security
- Analyzing usage patterns to improve our Service
- Detecting, preventing, and addressing technical issues
- Protecting against fraud, abuse, and security threats
- Complying with legal obligations
4. Legal Basis for Processing
Under Canadian privacy law, we process your personal information based on the following legal grounds:
- Consent: You provide consent when you submit an order, subscribe to marketing emails, or use our chat support
- Contractual Necessity: Processing is necessary to fulfill your order and provide the Service
- Legitimate Interests: We have a legitimate interest in improving our Service, ensuring security, and preventing fraud
- Legal Obligations: We may process data to comply with applicable laws, regulations, or court orders
5. Disclosure of Your Information
We may share your personal information with the following categories of third parties:
5.1 Service Providers
We use trusted third-party service providers to help us operate our Service. These providers have access to your personal information only to perform specific tasks on our behalf and are contractually obligated to protect your information and use the data only for the purpose for which it was disclosed.
- Stripe (United States): Payment processing. Stripe processes your payment information directly and is certified as a PCI Level 1 Service Provider.
- Amazon Web Services (AWS) S3 (United States): Secure file storage for your letter documents during processing.
- Railway (United States): Database hosting and backend infrastructure.
- Vercel (United States): Website hosting and content delivery.
- Better Stack (United States): Server logging and error tracking for technical troubleshooting.
- Intercom (United States): Live chat support and help center services.
- Loops (United States): Transactional and marketing email delivery.
- Fathom Analytics (Canada): Privacy-focused, cookieless website analytics.
- Canada Post (Canada): Physical mail delivery services.
5.2 Legal Requirements
We may disclose your personal information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency).
5.3 Business Transfers
If Davette is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information.
6. International Data Transfers
Your personal information may be transferred to and processed in countries outside of Canada, including the United States, where our service providers are located. These countries may have different data protection laws than Canada.
When we transfer your personal information internationally, we take appropriate safeguards to ensure your information remains protected in accordance with this Privacy Policy and applicable law. We use contractual clauses and ensure our service providers maintain adequate security measures.
7. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected:
- Letter Content: Automatically and permanently deleted 30 days after order submission
- Order Records: Retained for 7 years to comply with tax and accounting requirements under Canadian law
- Customer Support Communications: Retained for 2 years after your last interaction
- Server Logs: Retained for 90 days for security and troubleshooting purposes
- Marketing Preferences: Retained until you unsubscribe or request deletion
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/SSL (HTTPS) encryption
- Encryption of sensitive data at rest
- Secure payment processing through PCI-DSS compliant Stripe (credit card data is never stored on our servers)
- Access controls limiting employee access to personal data
- Regular security assessments and monitoring
- Automatic deletion of letter content after 30 days
While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to maintaining industry-standard protections.
9. Cookies and Tracking Technologies
We use the following technologies to collect information about your use of our Service:
9.1 Essential Cookies
These cookies are necessary for the website to function properly. They enable core functionality such as session management and cannot be disabled.
9.2 Analytics (Fathom Analytics)
We use Fathom Analytics, a privacy-focused analytics service that does not use cookies and does not collect personal data. Fathom provides us with aggregated, anonymized statistics about website usage.
9.3 Customer Support (Intercom)
Intercom uses cookies and similar technologies to provide live chat support and track your interactions with our website to provide better support context. This includes pages visited and actions taken on our site. You can manage Intercom cookies through your browser settings.
10. Your Privacy Rights
Under PIPEDA and PIPA, you have the following rights regarding your personal information:
- Right of Access: You may request a copy of the personal information we hold about you
- Right to Correction: You may request that we correct any inaccurate or incomplete personal information
- Right to Deletion: You may request that we delete your personal information, subject to our legal obligations to retain certain records
- Right to Withdraw Consent: You may withdraw your consent to our processing of your personal information at any time (this will not affect the lawfulness of processing before withdrawal)
- Right to Unsubscribe: You may unsubscribe from marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by contacting us
To exercise any of these rights, please contact us using the information provided in Section 14. We will respond to your request within 30 days, as required by law. We may need to verify your identity before processing your request.
11. Marketing Communications
With your consent, we may send you marketing emails about new features, promotions, and updates related to our Service. You can opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link at the bottom of any marketing email
- Contacting us at support@online-post.ca
Please note that even if you opt out of marketing emails, we may still send you transactional emails related to your orders (e.g., order confirmations, shipping notifications, and receipts).
12. Children's Privacy
Our Service is not intended for individuals under the age of 18 or the age of majority in their province or territory of residence. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately, and we will take steps to delete such information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" date at the top of this Privacy Policy
- Post a notice on our website or notify you by email for significant changes
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
- Email: support@online-post.ca
- Live Chat: Available on our website
We will respond to your inquiry within 30 days.
15. Complaints
If you are not satisfied with our response to your privacy concerns, you have the right to file a complaint with the appropriate privacy regulatory authority:
- Office of the Privacy Commissioner of Canada: www.priv.gc.ca
- Office of the Information and Privacy Commissioner for British Columbia: www.oipc.bc.ca