PRIVACY POLICY
Type of website:
E-commerce
Effective date:
8th day of January, 2026
​
www.studiosoulful.ca (the "Site") is owned and operated by Studio Soulful & Co. Inc. Studio Soulful & Co. Inc. can be contacted at:
info@studiosoulful.ca
​
When you conduct a transaction on our website, as part of the process, we collect personal information you give us, such as your name, address and email address. Your personal information will be used for the specific reasons stated above only.
​
​
Purpose
The purpose of this privacy policy (this "Privacy Policy") is to inform users of our Site of the following:
-
The personal data we will collect;
-
Use of collected data;
-
Who has access to the data collected;
-
The rights of Site users; and
-
The Site's cookie policy.
This Privacy Policy applies in addition to the terms and conditions of our Site.
PIPEDA Compliance
Studio Soulful Inc. is committed to complying with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law. We are also committed to compliance with applicable Ontario consumer protection legislation.
Under PIPEDA, individuals have the right to access their personal information held by us, to challenge its accuracy, and to withdraw consent for its use, subject to legal and contractual restrictions.
​
GDPR
For users in the European Union, we comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.
​
We have not appointed a Data Protection Officer because we do not fall within the categories of controllers or processors required to appoint one under Article 37 of the GDPR.
​
Consent
By using our Site, users consent to the conditions set out in this Privacy Policy.
​
When the legal basis for our processing of your personal data is your consent, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing which we completed before you withdrew your consent unlawful.
​
Users may withdraw their consent at any time by clicking the "unsubscribe" link at the bottom of any marketing or promotional email or by adjusting their browser or website settings. Withdrawal of consent will be processed as soon as reasonably practicable. Certain data is exempt from withdrawal requests, including transaction and financial records retained in compliance with Canadian tax and regulatory obligations.
​
Legal Basis for Processing
​
Under PIPEDA (Canadian Users)
We collect and process personal data in accordance with PIPEDA. Under PIPEDA, consent is the primary basis for processing personal data. We rely on the following bases:
-
Express consent: for marketing communications and non-essential data processing;
-
Implied consent: for processing necessary to fulfill a transaction or service requested by the user; and
-
Legal obligation: for data we are required to retain under Canadian law, including tax and financial records maintained in accordance with Canada Revenue Agency requirements.
Under GDPR (EU/UK Users)
We collect and process personal data of users in the EU only when we have a legal basis under Article 6 of the GDPR. We rely on the following legal bases:
-
Users have provided their consent to the processing of their data for one or more specific purposes;
-
Processing of user personal data is necessary for us or a third party to pursue a legitimate interest. Our legitimate interest is not overridden by the interests or fundamental rights and freedoms of users. Our legitimate interests are: We process certain personal data based on our legitimate interest in operating a secure and reliable ecommerce platform, including the prevention and detection of fraudulent transactions, the protection of customer accounts from unauthorized access, and the improvement of our website and services through analytics; and
-
Processing of user personal data is necessary for us to take, at the request of a user, steps before entering a contract or for the performance of a contract to which a user is a party. If a user does not provide the personal data necessary to perform a contract the consequences are as follows: If a user does not provide the required personal data, we will be unable to process their order, complete payment, or arrange delivery of their purchase.
​
​
Personal Data We Collect
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.
Data Collected Automatically
When you visit and use our Site, we may automatically collect and store the following information:
-
IP address;
-
Clicked links;
-
Technical details; and
-
Session metrics.
Data Collected in a Non-Automatic Way
We may also collect the following data when you perform certain functions on our Site:
-
First and last name;
-
Email address;
-
Shipping and billing address;
-
Payment information; and
-
Auto fill data.
This data may be collected using the following methods: when you conduct a transaction on our website, we collect personal information you provide, such as your name, address, and email address.
How We Use Personal Data
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.
​
Data collected automatically is used for the following purposes: Operating and improving our website, analyzing traffic and user behaviour, ensuring website security, and detecting fraudulent activity.
Data collected when the user performs certain functions is used for the following purposes: Processing and fulfilling orders, arranging payment and delivery, managing customer accounts, and sending order confirmations and marketing communications where consent has been provided.
Who We Share Personal Data With
Employees
We may disclose user data to any member of our organization who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.
​
Third Parties
We may share user data with the following third parties: Google Analytics.
We may share the following user data with third parties: Links clicked while using the site.
We may share user data with third parties for the following purposes:
-
To create aggregated statistical data and other aggregated and/or inferred non-personal information, which we or our business partners may use to provide and improve our respective services;
-
To comply with any applicable laws and regulations;
-
To be able to contact our visitors and users with general or personalized service-related notices and promotional messages;
-
To provide our users with ongoing customer assistance and technical support; and
-
To provide and operate the services.
Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.
Other Disclosures
We will not sell or share your data with other third parties, except in the following cases:
-
If the law requires it;
-
If it is required for any legal proceeding;
-
To prove or protect our legal rights; and
-
To buyers or potential buyers of this company in the event that we seek to sell the company.
If you follow hyperlinks from our Site to another site, please note that we are not responsible for and have no control over their privacy policies and practices.
How Long We Store Personal Data
User data is retained for as long as necessary to fulfill the purposes outlined in this Privacy Policy. Transaction and financial records are retained for a minimum of seven years in accordance with Canada Revenue Agency requirements. Marketing data is retained until consent is withdrawn. You will be notified if your data is retained beyond this period.
How We Protect Your Personal Data
Our website is hosted on Wix, which employs industry-standard security measures to protect user data. All data transmitted between users and our website is encrypted using HTTPS and SSL/TLS 1.2 or above. Data stored at rest is protected using AES-256 encryption, the industry standard for data storage. Payment information is safeguarded in compliance with PCI DSS Level 1 certification, the highest standard in payment card security. Wix's platform is built on a security-by-design approach, incorporating continuous monitoring, threat modelling, and regular security assessments to protect against vulnerabilities.
While we take all reasonable precautions to ensure that user data is secure and users are protected, there is always a risk of harm. The Internet as a whole can be insecure at times, and therefore, we are unable to guarantee the security of user data beyond what is reasonably practical.
International Data Transfers
We transfer user personal data to the following countries: United States.
When we transfer user personal data we will protect that data as described in this Privacy Policy and comply with applicable legal requirements for transferring personal data internationally.
If you are located in the United Kingdom or the European Union, we will only transfer your personal data if:
-
The country your personal data is being transferred to has been deemed to have adequate data protection by the European Commission or, if you are in the United Kingdom, by the United Kingdom adequacy regulations; or
-
We have implemented appropriate safeguards in respect of the transfer. For example, the recipient is a party to binding corporate rules, or we have entered into standard EU or United Kingdom data protection contractual clauses with the recipient.
Your Rights as a User
Under PIPEDA (Canadian Users)
As a Canadian user, you have the following rights under PIPEDA:
-
Right to be informed of what personal data we collect and how it is used;
-
Right to access your personal data held by us;
-
Right to challenge the accuracy and completeness of your personal data and have it amended;
-
Right to withdraw consent, subject to legal and contractual restrictions; and
-
Right to file a complaint with the Office of the Privacy Commissioner of Canada.
Under GDPR (EU/UK Users)
Under the GDPR, you have the following rights:
-
Right to be informed;
-
Right of access;
-
Right to rectification;
-
Right to erasure;
-
Right to restrict processing;
-
Right to data portability; and
-
Right to object.
Children
We do not knowingly collect or use personal data from children under 13 years of age. If we learn that we have collected personal data from a child under 13 years of age, we will delete it as soon as possible. If a child under 13 years of age has provided us with personal data their parent or guardian may contact our privacy officer.
​
How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under PIPEDA or the GDPR, please contact our privacy officer here:
Privacy Officer
Studio Soulful Inc.
How to Opt-Out of Data Collection, Use or Disclosure
In addition to the method(s) described in the How to Access, Modify, Delete, or Challenge the Data Collected section, we provide the following specific opt-out methods for the forms of collection, use, or disclosure of your personal data:
-
You can opt out of the use of your personal data for marketing emails by clicking "unsubscribe" at the bottom of any marketing email or updating your email preferences under "Your Account".
Cookie Policy
A cookie is a small file stored on a user's hard drive by a website. Its purpose is to collect data relating to the user's browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience.
​
We use the following types of cookies on our Site:
-
Functional cookies: Functional cookies are used to remember the selections you make on our Site so that your selections are saved for your next visits;
-
Analytical cookies: Analytical cookies allow us to improve the design and functionality of our Site by collecting data on how you access our Site, for example data on the content you access, how long you stay on our Site, etc;
-
Targeting cookies: Targeting cookies collect data on how you use the Site and your preferences. This allows us to personalize the information you see on our Site for you; and
-
Third-Party Cookies: Third-party cookies are set by websites other than ours. We use third-party cookies for analytics purposes to track website traffic and user behaviour, and for marketing purposes to deliver relevant advertisements.
Modifications
This Privacy Policy may be amended from time to time to maintain compliance with applicable laws and to reflect any changes to our data collection process. When we amend this Privacy Policy, we will update the "Effective Date" at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.
Complaints
If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue.
Canadian users may lodge a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.