Privacy Policy

Last updated: September 9, 2025

saskdesicandy.com (“the Site”) is owned and operated by SaskDesi Candy Shop (“we,” “our,” “us”), which is the controller of your personal information.

This Privacy Policy explains in detail how we collect, use, store, and safeguard your personal data when you interact with our website, purchase products, or engage with our services. By using our Site, you consent to the practices described here.

We are committed to maintaining the highest standards of privacy, transparency, and data security.

1. Information We Collect

We collect different categories of information depending on how you use our Site:

1.1 Information You Provide Directly

When you create an account, place an order, subscribe to our newsletter, or contact us, we may collect:

  • Full name (first and last)

  • Billing and shipping address

  • Email address

  • Phone number

  • Payment details (processed securely by third-party providers; we do not store full card details)

  • Account login details (username, password)

  • Any messages or inquiries you send us

1.2 Automatically Collected Information (“Device Information”)

When you browse our Site, we automatically collect:

  • IP address

  • Browser type and version

  • Operating system

  • Time zone settings

  • Referring website or search engine

  • Pages you visit and time spent on them

  • Products you view or add to cart

  • Date and time of access

  • Cookies and tracking technologies (see Section 7)

1.3 Order Information

When you make a purchase, we collect:

  • Order history and transaction details

  • Shipping and delivery information

  • Communication related to your order

1.4 Marketing & Communication Information

  • Newsletter subscriptions

  • Preferences regarding promotions, offers, and updates

1.5 Special Categories (if applicable)

We do not intentionally collect sensitive personal data such as health, religious beliefs, or biometric information.

2. How We Use Your Data

We process personal data only when there is a lawful basis, such as contractual necessity, legitimate business interests, consent, or legal obligation.

Your data may be used for:

  • Processing and fulfilling orders

  • Managing your account

  • Providing customer support and responding to inquiries

  • Sending order confirmations, shipping updates, and receipts

  • Detecting and preventing fraudulent activity

  • Analyzing website traffic and improving site performance

  • Personalizing shopping experiences (product recommendations, tailored offers)

  • Marketing communications (if you opt in)

  • Complying with applicable laws and regulations

3. Legal Bases for Processing (GDPR Compliance)

For users in the European Economic Area (EEA), we rely on the following lawful bases:

  • Contractual necessity – processing your data to complete an order

  • Legitimate interests – improving services, preventing fraud

  • Consent – for marketing emails or cookie preferences

  • Legal obligation – complying with tax and accounting laws

4. Data Retention

We keep personal information only as long as necessary:

  • Account details: retained while your account is active

  • Order information: retained for 7 years to comply with tax and legal requirements

  • Marketing data: retained until you unsubscribe

  • Customer support communications: retained for up to 2 years

After these periods, your data will be securely deleted or anonymized.

5. Sharing of Personal Data

We never sell your personal data. However, we may share information with trusted third parties, including:

  • Payment processors (e.g., Stripe, PayPal, credit card companies)

  • Shipping and logistics providers (for order delivery)

  • IT and website hosting providers (to operate our Site securely)

  • Analytics providers (e.g., Google Analytics)

  • Marketing service providers (if you consent to promotional emails)

  • Legal authorities (if required by law or to prevent fraud)

Each partner only receives the minimum data required for their role and must comply with strict confidentiality obligations.

6. International Data Transfers

Your data may be transferred and stored outside your country of residence, including in Canada and the United States. We take steps to ensure that international transfers comply with applicable data protection laws, including standard contractual clauses where required.

7. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your browsing experience. Cookies may be:

  • Essential cookies – required for website functionality

  • Performance cookies – to understand website usage and traffic patterns

  • Functional cookies – to remember preferences and improve personalization

  • Advertising cookies – to deliver relevant promotions (only if consented)

You can disable cookies in your browser settings, though this may affect website performance.

8. Marketing Communications

If you subscribe to our newsletter or promotions, we may use your data to send:

  • Special offers

  • Product updates

  • Loyalty rewards

You can unsubscribe at any time by clicking the “unsubscribe” link in our emails or contacting us directly.

9. Your Rights

Depending on your location, you may have rights under data protection laws, including:

  • Right to access your data

  • Right to correct inaccuracies

  • Right to request deletion (“right to be forgotten”)

  • Right to restrict or object to processing

  • Right to data portability (transfer of your data)

  • Right to withdraw consent at any time

  • Right to lodge a complaint with your local Data Protection Authority

To exercise your rights, contact us at order@saskdesicandy.com.

10. Children’s Privacy

Our website is not intended for children under 13 years old (or under 16 in the EU). We do not knowingly collect personal data from children. If we discover such data has been provided, we will delete it immediately.

11. Data Security

We implement strong security measures, including:

  • Secure servers and encrypted connections (SSL)

  • Firewalls and intrusion detection systems

  • Regular security audits

  • Limited access to personal data (authorized staff only)

While we take every precaution, no system is 100% secure. By using our Site, you acknowledge this risk.

12. Third-Party Links

Our Site may contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their policies before sharing personal data.

13. Legal Disclosure

We may disclose personal data if:

  • Required by law, subpoena, or government request

  • Necessary to protect the rights and safety of our customers or the public

  • To investigate suspected fraud, security breaches, or violations of our Terms of Service

14. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last Updated” date. Significant updates may also be communicated by email or website notice.

15. Contact Information

For questions, requests, or complaints about this Privacy Policy, contact us at:

📧 Email: order@saskdesicandy.com
📍 Location: Regina, Saskatchewan, Canada