1.About This Policy
This Privacy Policy describes how Barbara Zarzosa ("we", "us", "our") collects, uses, and discloses Personal Information through the website located at thelegacyvault.ca (the "Website").
This Policy applies to the Website only. The Legacy Vault for Canadians desktop application (the "Application") operates entirely on the user's own computer and does not collect or transmit Personal Information. Use of the Application is governed by the End User Licence Agreement, not by this Policy.
By using the Website, you consent to the collection, use, and disclosure of your Personal Information as described in this Policy.
2.Definitions
"Personal Information" means information about an identifiable individual, as defined in the Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy legislation.
"Processor" means a third-party service provider that processes Personal Information on our behalf in accordance with our instructions.
3.Information We Collect
We collect Personal Information from you only in the following circumstances:
When you make a purchase, our payment processor collects your name, email address, billing address, country, and payment card information. We receive a record of your purchase, including your name, email address, billing country, and amount paid. We do not receive or store your full credit card information.
When you contact us by email, we receive your email address, the content of your message, and any other information you choose to include.
When you visit the Website, our hosting provider automatically collects limited technical information, including your IP address, browser type and version, referring URL, the pages you visit, and the date and time of your visit. This information is collected for security purposes and to maintain the Website (for example, detecting attacks and diagnosing errors).
4.Information We Do Not Collect
We do not collect your name, address, or any other personal details unless you voluntarily provide them (e.g., during purchase or in correspondence with us).
We do not collect any data that you enter into the Application. The Application stores all such information locally on your own device and does not transmit it to us or to any third party.
We do not collect cross-site tracking data, marketing identifiers, or advertising profiles.
We do not maintain a mailing list and do not send marketing or promotional emails.
5.How We Use Your Information
We use Personal Information only for the following purposes:
- To complete your purchase — deliver the Application, send your receipt, provide download links, and resolve any issues with your order.
- To respond to your inquiries — when you email us, we use your email address to reply.
- To send essential service notifications — such as critical updates to the Application or important changes to this Policy. We do not use your email address for any other promotional purpose.
- To comply with legal obligations — including Canadian tax and accounting record-keeping requirements.
- For website security and operations — to monitor for and respond to attacks, errors, and abuse.
6.Third-Party Service Providers
We use the following third-party service providers (Processors) to operate the Website. Each is bound by their own privacy policies and is required to handle Personal Information in accordance with applicable privacy law.
Payment Processor: Paddle. Processes all purchase transactions, including credit card information. We do not see or store full card numbers. Their privacy practices are available at paddle.com/legal/privacy.
Hosting Provider: Web Hosting Canada. Stores the Website files and collects standard server logs. Data is stored in Canada.
Fonts: Our Website uses fonts loaded from Google Fonts. When fonts are loaded, your IP address is transmitted to Google solely for the purpose of font delivery. Google's privacy practices are available at policies.google.com/privacy.
We do not use Google Analytics or any other web analytics service on the Website at this time. If we add analytics in the future, we will update this Policy and provide notice on the Website.
7.Where Your Information Is Stored
The Website is hosted in Canada. Server logs and order records are stored on Canadian servers wherever possible.
Some third-party Processors (for example, payment processors) may store or process data outside Canada. Where this occurs, we take reasonable steps to confirm that those Processors provide a comparable standard of protection.
8.Cookies and Similar Technologies
Our Website does not set tracking cookies of its own.
Third-party services embedded on our Website (such as the payment checkout flow) may set cookies when you interact with them. These cookies are governed by the privacy policies of those third parties, not by this Policy.
You may control or disable cookies through your browser settings. Doing so may affect the functionality of the embedded third-party services.
9.Data Retention
Purchase records are retained for a minimum of seven (7) years in accordance with Canadian tax and accounting requirements.
Email correspondence is retained for as long as is reasonably necessary to provide ongoing support and maintain a record of customer service interactions.
Server logs are typically retained for thirty (30) to ninety (90) days.
You may request deletion of your Personal Information at any time (see Section 10), subject to our legal record-keeping obligations.
10.Your Privacy Rights
Under PIPEDA and applicable provincial privacy law, you have the right to:
- Access the Personal Information we hold about you;
- Correct inaccurate or incomplete Personal Information;
- Request deletion of Personal Information that is no longer required for the purposes for which it was collected (subject to our legal retention obligations);
- Withdraw consent to the collection, use, or disclosure of your Personal Information (although this may affect our ability to provide certain services, such as honouring a future refund request);
- File a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or your applicable provincial privacy commissioner.
For residents of Quebec, additional rights under Law 25 apply, including the right to data portability and the right to be informed of automated decisions involving your Personal Information.
For residents of the European Union and United Kingdom, additional rights under the GDPR and UK GDPR apply, including the rights to data portability, restriction of processing, and objection to processing.
For residents of California, certain rights under the CCPA may apply.
To exercise any of these rights, contact us at the address in Section 13.
11.Children's Privacy
The Website and the Application are intended for adults of the age of majority in their jurisdiction. We do not knowingly collect Personal Information from individuals under the age of majority. If you believe we have inadvertently collected such information, contact us and we will delete it.
12.Changes to This Policy
We may update this Policy from time to time. The Effective Date at the top of this Policy will indicate when it was last revised.
Material changes will be announced on the Website. Your continued use of the Website after a change constitutes acceptance of the updated Policy.
13.Contact
Privacy questions, requests, or complaints should be directed to:
We will respond to privacy requests within thirty (30) days, in accordance with PIPEDA timelines.