Privacy Policy
Effective date: June 3, 2026
Privacy Officer, Ahlnos Inc.: support@vitatide.ca
2.1 Scope
This policy describes how Ahlnos Inc. collects, uses, discloses, and safeguards personal information in the course of operating vitatide.ca, consistent with the Personal Information Protection and Electronic Documents Act (PIPEDA).
2.2 What we collect
- Order data: name, shipping address, billing address, email address, phone number, order history.
- Payment data: Interac e-Transfer reference details and payment-match records needed to process or support an order. Future card or crypto payment data disclosures will be updated before those rails are enabled.
- Account data (if you register): email, password hash, profile preferences.
- Technical data: IP address, user agent, cookie identifiers, pages visited, referring URL.
- Communications: email and support email records.
2.3 What we do not collect
- Date of birth beyond age-verification at checkout.
- Health information.
- Reason for purchase.
- Data about any individual other than the account holder.
2.4 Purposes of collection
- Processing and shipping orders.
- Customer service and support.
- Fraud prevention and security.
- Legal and regulatory compliance (tax, customs, CASL).
- Marketing communications only with your express consent.
- Site analytics (aggregate, non-identifying where possible).
2.5 Consent
Where we rely on consent, it is captured at the point of collection (checkout checkbox for order processing; separate opt-in for marketing emails per CASL). You may withdraw consent for marketing at any time via the unsubscribe link in every marketing email or by emailing support@vitatide.ca. Withdrawal does not affect the lawfulness of processing before withdrawal.
2.6 Disclosure
We disclose personal information only:
- To our payment processor for transaction processing.
- To our shipping carrier for order fulfillment.
- To our email service provider for transactional and (with consent) marketing email.
- To our carrier, insurer, or compliance authority where required to investigate delivery issues, fraud, safety, or legal obligations.
- As required by law (court order, CRA audit, CBSA inquiry, regulator request).
We do not sell personal information to third parties. We do not share personal information with advertisers or data brokers.
2.7 Data residency
Personal information is stored and protected using Canadian-first infrastructure and access controls where practical. Our payment processor and email service provider may be US-based; in that case we ensure they are contractually bound to comparable protection and data is limited to what's necessary.
2.8 Retention
- Order records: 7 years (CRA requirement).
- Account data: until you request deletion; thereafter 2 years for fraud-prevention purposes, then deleted.
- Marketing email logs: 3 years from the last interaction or unsubscribe, then deleted.
- Technical logs: 90 days rolling.
2.9 Safeguards
- Encryption in transit (TLS) and at rest.
- Role-based access control for Ahlnos staff.
- Periodic access review.
- Incident response plan; breaches affecting personal information are reported to the Office of the Privacy Commissioner of Canada and affected individuals in accordance with PIPEDA §10.1.
2.10 Your rights under PIPEDA
You have the right to:
- Know what personal information we hold about you.
- Access and correct that information.
- Withdraw consent for marketing.
- Request deletion (subject to legal retention requirements).
- File a complaint with us or with the Office of the Privacy Commissioner of Canada.
Contact: support@vitatide.ca. We respond within 30 days.
2.11 Cookies and analytics
We use cookies for: session management (required), cart persistence (required), and basic analytics (optional, opt-in via banner). Analytics cookies are set only after you consent via the cookie banner. You can clear cookies in your browser at any time.
2.12 Changes
We may update this policy. Material changes are announced via email to registered users and banner notice on the site 30 days before taking effect.
