StoreBaze
Draft. This Privacy Policy is in draft form pending counsel review. The final version will replace this content before public launch.

Privacy Policy

Last updated: July 1, 2026

Preamble

This Privacy Policy describes how Jonayed Ahmed Riduan, carrying on business as StoreBaze (“StoreBaze”, “we”, “our”, “us”), collects, uses, discloses, and safeguards personal information in connection with:

  • the StoreBaze platform (“Platform”),
  • the StoreBaze website (storebaze.com),
  • communications with prospective and current Merchants.

This policy applies to:

  • Merchants who sign up for or use the Platform.
  • Prospective Merchants who visit storebaze.com or contact us.
  • Staff members added to a Merchant’s account.

This policy does NOT apply to:

  • Customers who shop on a Merchant’s Store. Each Merchant is the controller of its own Customer data. Customers should consult the privacy policy of the Merchant whose Store they are visiting. StoreBaze acts as a processor for that data on behalf of each Merchant.
  • Data collected by third-party services (such as Stripe’s own dashboard for the Merchant’s Stripe Connect account) that operate as separate data controllers.

“Personal information” has the meaning given by Quebec’s Act respecting the protection of personal information in the private sector (“Law 25”) and, where applicable, the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”).

Where this policy uses “Which means” boxes, they translate technical or legal clauses into plain language. If there is a conflict between the formal clause and the “Which means” box, the formal clause governs.

1. Who we are

StoreBaze is an individual sole-proprietorship operated by Jonayed Ahmed Riduan, with its principal place of business at Apt 305, 3400 Avenue Linton, Montreal, Quebec, H3S 1T2, Canada.

Privacy Officer (Person in Charge of the Protection of Personal Information, per Law 25 s. 3.1):

  • Name: Jonayed Ahmed Riduan
  • Title: Owner and Privacy Officer
  • Email: [email protected]
  • Postal address: Apt 305, 3400 Avenue Linton, Montreal, Quebec, H3S 1T2, Canada

All privacy-related requests, questions, or complaints may be directed to the Privacy Officer at the addresses above.

2. Information we collect

2.1 Information you provide directly

  • Account information: name, business name, email address, phone number, password (stored hashed), country and language preference.
  • Store information: store name, subdomain, custom domain (if any), business description, business address, currency and timezone.
  • Billing information: billing address, tax identifier where applicable. Payment card numbers are collected directly by Stripe and are not stored on StoreBaze systems; StoreBaze receives only a Stripe customer identifier and a payment-method reference.
  • Communications: the content of emails, support tickets, or chat conversations you send to us.
  • Staff records: if you add staff to your Merchant account, you provide their name, email, and role.

2.2 Information collected automatically when you use the Platform

  • Session information: login timestamps, session identifiers, IP address, browser user agent, and device type.
  • Server logs: URLs accessed on the merchant dashboard, HTTP status codes, response times, and error traces. Retained for operational and security monitoring.
  • First-party essential cookies: small identifiers stored in your browser that are strictly necessary to keep you signed in and to keep the Platform functioning. See Section 11.

2.3 Information received from third parties

  • Stripe: subscription status, payment attempt outcomes (success, failure, retry), fraud signals, and payout status. See Stripe’s own privacy policy for how Stripe collects data.
  • Resend: email deliverability status (delivered, bounced, complained, opened).
  • Cloudflare: DNS and CDN request metadata; DDoS-mitigation signals.

We do not receive: advertising-network data, cross-site tracking data, social-graph data, or behavioural profiling data from any third party.

3. Why we process personal information (legal bases)

Under Law 25 and PIPEDA, personal information may be collected, used, or disclosed for identified, serious, and legitimate purposes. We rely on the following bases:

BasisApplies toExamples
Performance of a contract with youMerchant account, billing, storefront hostingCreating your account, processing subscription payments, rendering your Store, sending transactional email on your behalf
Compliance with a legal obligationTax records, fraud investigation, court ordersRetaining order data for CRA/Revenu Québec purposes, responding to lawful requests from authorities
Legitimate interest (balanced against your rights)Security, service improvement, prevention of abuseServer logs for intrusion detection, aggregated usage analytics for capacity planning, anti-fraud analysis
ConsentMarketing emails, optional featuresSending you product-update newsletters (opt-in only), enabling optional analytics if we add any in the future

We do not conduct automated decision-making with significant effects on you (Law 25 s. 12.1) without your explicit consent.

4. Sharing & sub-processors

We share personal information with the following categories of recipients:

4.1 Service providers (sub-processors)

We use the following sub-processors to operate the Platform. Each is bound by a written agreement obligating them to process personal information only on our documented instructions and to safeguard it in line with applicable law.

Sub-processorPurposeLocation
Stripe, Inc.Subscription billing, payment processingUnited States (global data centres)
Resend, Inc.Transactional and marketing email deliveryUnited States
Cloudflare, Inc.DNS, CDN, DDoS mitigation, TLS terminationGlobal edge network
MongoDB, Inc. (Atlas)Primary database hostingUnited States (AWS us-east-1)
DigitalOcean, LLCApplication server hostingCanada (Toronto)
GitHub, Inc.Container image registry for deployment artifactsUnited States
DoorDash Technologies, Inc.Delivery integration for Merchants who enable itUnited States and Canada

The list of sub-processors may change from time to time; the current list is available on request and will be updated in this policy.

4.2 Legal, regulatory, and safety recipients

We may disclose personal information without your consent (as permitted by Law 25 s. 18.3 and PIPEDA s. 7(3)) when:

  • required by law, court order, subpoena, or a lawful request from a public authority;
  • necessary to enforce our Terms of Service or Acceptable Use Policy;
  • necessary to detect, prevent, or address fraud, security, or technical issues;
  • necessary to protect the rights, property, or safety of StoreBaze, its Merchants, or the public.

4.3 Successor entities

If the StoreBaze business is transferred, sold, incorporated, or merged (see Terms of Service s. 16.2), personal information may be transferred to the successor entity as part of the transaction, subject to the successor’s continued compliance with this policy or an updated policy with substantially equivalent protections.

4.4 With your consent

For any disclosure not covered above, we ask for your consent first.

We do not sell personal information. We do not share personal information with advertising networks or data brokers.

5. Cross-border transfers (Law 25 s. 17 disclosure)

Some of our sub-processors listed in Section 4.1 process personal information outside Quebec, principally in the United States. In accordance with Law 25 s. 17, before communicating personal information outside Quebec we have conducted an assessment considering:

  • the sensitivity of the information;
  • the purpose of the use;
  • the protection measures (including contractual measures) applicable to the information;
  • the legal framework applicable in the destination jurisdiction.

Based on that assessment, we have determined that the transfers listed in Section 4.1 provide protection equivalent to that afforded under Quebec law, taking into account (a) the contractual protections in each sub-processor agreement, (b) the technical safeguards (encryption in transit and at rest), and (c) the sub-processors’ own public compliance postures.

An internal record of this assessment is maintained by the Privacy Officer and reviewed annually or on material change to sub-processors.

By using the Platform, you acknowledge and agree that your personal information may be processed in the jurisdictions listed in Section 4.1.

6. Retention

We retain personal information only as long as necessary to fulfil the purposes for which it was collected, or as required by law.

Data categoryRetention
Merchant account (active)While the account is active
Merchant account (deactivated)30 days after deactivation (grace period), then permanently deleted (subject to exceptions below)
Order records (post-deactivation)Anonymized in place; records < 7 years old retained until they age out; records 7+ years old deleted (aligns with CRA/RQ)
Payment transaction recordsAs required by Stripe and by anti-money-laundering laws
Event log entriesRetained indefinitely with merchant identifier anonymized
Email log entries90 days from send
Server logs30 days
BackupsRotated out within 30 days of the most recent full-backup cycle
Support and legal correspondence7 years from last contact, then deleted
Marketing subscribers (opt-in newsletter, if launched)Until you unsubscribe, then deleted within 30 days

See Terms of Service s. 6 for the deactivation and Purge process.

7. Your Customers’ data (controller / processor)

When Customers shop on your Store, StoreBaze acts as a processor on your behalf. You (the Merchant) are the controller.

As controller you are responsible for:

  • publishing a Customer-facing privacy policy that complies with the law of the Customer’s jurisdiction;
  • obtaining any consents required for Customer data collection and use;
  • responding to Customer requests to access, correct, or delete their data;
  • notifying Customers of any breach affecting their data, where required by law;
  • complying with Law 25, PIPEDA, GDPR, CCPA, or any other law applicable to your Customers.

As processor StoreBaze:

  • processes Customer data only as directed by you and as necessary to render the Platform;
  • applies the technical and organizational safeguards described in Section 9;
  • notifies you of any security incident affecting your Customer data, without undue delay;
  • assists you in responding to Customer rights requests, on reasonable notice.

A separate Data Processing Addendum is available on request for Merchants who require one (typically Merchants with EU-based Customers or B2B contracts requiring formal Article 28 GDPR terms).

8. Your rights

Subject to conditions and exceptions in Law 25 and PIPEDA, you have the right to:

  • Access — Ask what personal information we hold about you, and receive a copy.
  • Correction — Ask us to correct information that is inaccurate, incomplete, or out of date.
  • Deletion — Ask us to delete personal information we no longer need to retain (subject to legal retention obligations in Section 6).
  • Portability (data portability) — Ask for a copy of personal information you provided to us in a structured, commonly used electronic format (Law 25 s. 27, effective September 2024).
  • Withdraw consent — Where processing is based on consent (e.g., marketing communications), withdraw it at any time.
  • Cease processing — Request that we stop specific processing activities.
  • De-indexing / removal from search — Where legally applicable.
  • Complain — File a complaint with the Quebec Commission d’accès à l’information (cai.gouv.qc.ca) or with the Office of the Privacy Commissioner of Canada (priv.gc.ca), if you are dissatisfied with our response.

How to exercise your rights: email the Privacy Officer at [email protected] from the email address on your account, or write to us at the postal address in Section 1. We will respond within 30 days of receiving a complete request; if we need more time, we will notify you within the initial 30-day period.

We may need to verify your identity before responding. We will not charge a fee for a reasonable first request but may charge a reasonable fee for repeated or manifestly excessive requests, as permitted by law.

9. Security

We apply reasonable technical and organizational measures to safeguard personal information, including:

  • TLS encryption for data in transit (HTTPS across all endpoints, enforced via HSTS on production);
  • password hashing at rest (bcrypt);
  • role-based access control on internal administrative interfaces;
  • server-side session management with short-lived tokens;
  • infrastructure hosted with providers holding independent security certifications (SOC 2 or equivalent) where available;
  • security event logging for detection of anomalous access patterns;
  • limited access to production systems on a need-to-know basis.

No system is 100% secure. In the event of a confidentiality incident that presents a risk of serious injury, we will notify affected persons and the Quebec Commission d’accès à l’information as required by Law 25 s. 3.5, and we will maintain a record of confidentiality incidents as required by Law 25 s. 3.8.

10. Marketing communications

We may send you:

  • Transactional emails (account confirmations, billing notices, dunning notices, security alerts, service announcements affecting your account) — required to operate the Service; you cannot unsubscribe while your account is active.
  • Product-update emails and newsletters — opt-in only. You can unsubscribe at any time via the unsubscribe link in each email or by contacting [email protected].

We comply with Canada’s Anti-Spam Legislation (CASL). We do not sell or purchase email lists.

11. Cookies

The Platform uses only first-party essential cookies that are strictly necessary for the Platform to function. Currently these include:

  • an authenticated-session cookie to keep you signed in;
  • a CSRF-protection cookie to prevent cross-site request forgery;
  • a preference cookie to remember your language and dashboard settings.

We do not use:

  • advertising or marketing cookies;
  • third-party analytics cookies (Google Analytics, Meta Pixel, TikTok Pixel, etc.);
  • cross-site tracking cookies;
  • behavioural profiling cookies.

Because we use only strictly-necessary cookies, no cookie-consent banner is required under Law 25, PIPEDA, or the EU ePrivacy Directive.

If we introduce non-essential cookies in the future, we will update this Section, notify you in advance, and (where required) implement a consent mechanism.

Note about your Merchants’ Stores: if you add analytics, marketing, or advertising code to your own Store (for example, a Facebook Pixel or a Google Tag Manager container), any cookies set by that code are set by you as controller, not by StoreBaze. You are responsible for the corresponding disclosures and consents to your Customers.

12. Children

The Platform is not intended for use by persons under 18. We do not knowingly collect personal information from anyone under 18. If we learn we have collected personal information from a person under 18, we will delete it. If you believe a minor has provided us personal information, contact the Privacy Officer.

13. Changes to this policy

Material changes (including changes to the categories of personal information collected, the purposes of processing, the recipients, or your rights) will be notified to you by email at least 30 days before the change takes effect.

Non-material changes (including clarifications, typographical corrections, and updates to the sub-processor list under Section 4.1) may be made by updating the “Last updated” date at the top of this policy.

The current version of this policy is always available at storebaze.com/privacy.

14. Contact

Privacy Officer (Person in Charge of the Protection of Personal Information):

Jonayed Ahmed Riduan
Owner and Privacy Officer
StoreBaze
Apt 305, 3400 Avenue Linton
Montreal, Quebec, H3S 1T2
Canada
Email: [email protected]

Regulatory authorities:

  • Commission d’accès à l’information du Québeccai.gouv.qc.ca
    Bureau de Québec: 525 boul. René-Lévesque Est, bureau 2.36, Québec (Québec) G1R 5S9
    Bureau de Montréal: 500 boul. René-Lévesque Ouest, bureau 18.200, Montréal (Québec) H2Z 1W7
  • Office of the Privacy Commissioner of Canadapriv.gc.ca
    30 Victoria Street, Gatineau, Quebec, K1A 1H3