PRIVACY POLICY
Last updated: 30 September 2026
1. WHO IS RESPONSIBLE
1609372 B.C. LTD is responsible for personal information it handles to operate cart-bc-ltd.com, answer enquiries, manage customer relationships and administer its own business. The owner is Isaiah David Walker. Our address is 3504 32 Street, Vernon, BC V1T 5N3, Canada. Privacy enquiries and requests can be sent to contact@cart-bc-ltd.com, with “Privacy” in the subject line if convenient.
This policy covers visitors, prospective customers, customers and people communicating with us on behalf of a business. It explains our approach to the information needed for one-off digital marketing projects. Applicable privacy law may include British Columbia’s Personal Information Protection Act, Canada’s federal privacy legislation for relevant cross-border commercial activities, and the General Data Protection Regulation where its territorial scope applies.
2. INFORMATION CONCERNED
An enquiry may contain your name, email address, business name, country, service interests, website address and the message you choose to send. When you purchase a project, the information needed may also include billing details, the agreed quotation, payment references, instructions, correspondence and records of delivery. We ask customers to provide only information relevant to their enquiry or project.
Technical information associated with website or payment access may include an IP address, browser and device characteristics, request time, error information and security events. The information involved depends on the function used. Cookies and similar technologies are addressed separately in the Cookie Policy; this policy does not itself constitute permission to activate optional tracking.
Project materials may contain names, business contact details, account identifiers, campaign information or customer-related data. Do not send complete customer databases, sensitive personal information or account credentials merely to request a quotation. Where access to personal information is necessary for a project, its purpose, scope and authorized access must be established before that information is transferred.
3. PURPOSES AND LEGAL GROUNDS
We use relevant enquiry information to respond to questions, discuss requirements and prepare a requested offer. Where GDPR applies, steps requested by an individual before entering a contract, or performance of that individual’s contract, may provide the legal basis. Correspondence with a representative of a corporate customer may instead be based on our legitimate interest in communicating with that customer and managing the business relationship.
Customer and project records are used to organize delivery, communicate about the work, invoice, reconcile payments and handle service issues. Accounting and other legally required records are retained to meet the applicable legal obligation. Information needed to investigate fraud, secure our services or establish and defend legal claims may be processed for those legitimate interests, subject to the required balancing of interests and individual rights.
Where consent is required, including for relevant optional tracking or marketing activity, we seek that consent separately. Reading this policy, sending an enquiry or buying a project is not a blanket consent to unrelated advertising. Withdrawing consent does not invalidate processing already lawfully carried out before withdrawal. We do not require consent for purposes that should properly be explained under another legal basis.
4. STRIPE AND PAYMENTS
Stripe is the payment provider used for project payments. Information entered into a Stripe payment interface is handled through that provider’s payment systems. We receive information necessary to identify the transaction, reconcile the order and deal with payment questions, such as payment status, transaction references and relevant billing information.
Do not send full card numbers or card security codes to our email address. Payment providers and financial institutions may process information for their own fraud prevention, legal and regulatory responsibilities as well as to provide payment services. Stripe explains its practices and the relevant entities in its privacy information at https://stripe.com/privacy. That notice complements, rather than replaces, our responsibility for information we handle ourselves.
5. RECIPIENTS AND ACCESS
Access is limited according to the purpose of the task. Information may need to be handled by people authorized to deliver a project, providers supporting website operation and communications, payment services, or professional advisers dealing with accounting or legal matters. Providers handling information on our instructions must be subject to the protections required by applicable law.
We may disclose relevant information where legally required, in response to a valid request from a competent authority, or where necessary and lawful to protect rights or investigate a security incident. A disclosure is not justified merely because another person asks for customer information. The information shared must be proportionate to the reason for sharing it.
6. INTERNATIONAL PROCESSING
The Company is located in Canada, so information sent to us from France may be processed in Canada. Service providers, including payment providers, may involve processing in other countries. Those countries may have different laws, and information may be subject to lawful requests from their authorities.
Where GDPR transfer rules apply, an international transfer must rely on an available lawful mechanism. Canada’s EU adequacy status is limited to its applicable scope, including relevant commercial organizations subject to PIPEDA; it is not a blanket exemption for every recipient or processing activity in Canada. Where adequacy does not apply, the required safeguards or a legally available exception must be established for the transfer. Contact us for information about a transfer involving your data and any applicable safeguards.
7. RETENTION
Information is kept for as long as necessary for the purpose for which it is handled, taking account of applicable legal requirements. The criteria include whether an enquiry remains active, whether a project is complete, whether accounting or tax records must be retained, and whether an actual or reasonably anticipated dispute requires relevant evidence to be preserved.
An enquiry that does not lead to a purchase does not justify indefinite retention of all information supplied. Customer records must likewise be reviewed against their continuing purpose. Information that is no longer needed should be securely deleted or irreversibly anonymized. Restricted retention for a legal obligation or claim does not authorize continued use for unrelated marketing.
8. YOUR CHOICES AND RIGHTS
Depending on the applicable law, you may request access to personal information, correction of inaccurate information, deletion, restriction, or information about its use and disclosure. GDPR may also provide data portability and a right to object, including an unconditional right to object to processing for direct marketing. Some rights depend on the legal basis, the circumstances and applicable exceptions.
Send your request to contact@cart-bc-ltd.com and explain the information or relationship concerned. We may request proportionate information to verify identity where necessary, but do not routinely send an identity document with your first message. Requests will be handled within the legal deadline. Under GDPR this is normally one month, with a permitted extension where justified and notified as required. A refusal or limitation must have a lawful basis and be explained.
9. SECURITY AND CONFIDENTIALITY
Information must be protected using measures appropriate to its nature and the risks, including access restrictions and careful handling of project materials. No internet transmission or storage method can guarantee absolute security. If you suspect that information sent to us has been accessed improperly, notify us promptly without including passwords or unnecessary sensitive details.
An incident affecting personal information will be assessed under the applicable notification and record-keeping rules. Confidentiality does not prevent a disclosure that is legally required, but such a disclosure must remain limited to its lawful purpose. Customers also play a role by using secure access methods and withdrawing permissions that are no longer needed.
10. CLIENT DATA AND OTHER WEBSITES
When we handle personal information solely on a business customer’s documented instructions, that customer may be the controller and we may act as a processor. The necessary data processing agreement must address the relevant activity; this website policy does not replace it. Individuals with questions about a client’s own collection of their data should contact that client, and we will assist with requests where our role requires it.
Independent websites and platforms have their own privacy practices. Following an external link does not mean that their practices are governed by this policy. Before providing information to another service, review the information supplied by its operator.
11. COMPLAINTS AND UPDATES
You may contact us about a concern without giving up your right to complain to a competent authority. Depending on jurisdiction, this may include the Office of the Information and Privacy Commissioner for British Columbia, the Office of the Privacy Commissioner of Canada, or the CNIL in France. GDPR also permits a complaint to the appropriate supervisory authority, including in your habitual residence, place of work or the place of an alleged infringement.
We may update this policy when our activities or legal requirements change. A new page version does not retrospectively supply missing consent or authorize an incompatible new purpose. Material changes must be communicated and any required consent obtained before the relevant new processing begins. Questions can be addressed to contact@cart-bc-ltd.com.
