Privacy policy

This Privacy Policy explains how the merchant operating hesterandcook.shop under the Hester & Cook trade name collects, uses, discloses, retains, and protects personal information. It also explains choices and rights. The Privacy Officer may be contacted at info@hesterandcook.shop. This policy is designed for a Shopify-powered Canadian online store and must be kept aligned with the store's actual apps, settings, and business practices.

1. Scope and Roles

This policy applies when an individual visits the website, creates an account, makes or attempts a purchase, joins a mailing list, submits a form or review, communicates with support, participates in a promotion, or otherwise interacts with the store. It does not govern a third party's independent website or service, even when linked from the store.

For personal information used to operate the store and customer relationship, the merchant is responsible for deciding why and how the information is handled. Shopify provides the commerce platform and may process information for the merchant or for Shopify's own stated purposes, depending on the feature. Payment providers, carriers, app providers, analytics vendors, advertising partners, and other suppliers have their own roles and legal duties.

2. Canadian Privacy Framework

Depending on the merchant's location, customer, and information flow, the Personal Information Protection and Electronic Documents Act may apply, as may substantially similar private-sector privacy laws in Quebec, British Columbia, or Alberta and other sector-specific or provincial rules. Interprovincial or international information flows may also engage federal requirements.

Our approach follows core principles of accountability, identified and reasonable purposes, meaningful consent, limited collection, limited use and retention, accuracy, safeguards, openness, individual access, and a process to challenge compliance. Where a more specific applicable law gives an individual greater protection, we apply that requirement.

3. Accountability and Privacy Officer

The merchant is accountable for personal information under its control, including information transferred to a service provider for processing. The Privacy Officer coordinates questions, access or correction requests, complaints, incident response, retention practices, and review of service-provider arrangements. The public contact for the Privacy Officer is info@hesterandcook.shop.

The merchant should maintain a privacy management program proportionate to the sensitivity and volume of information it handles. That program includes documented purposes, access controls, service-provider review, staff instructions, retention and destruction practices, incident response, complaint handling, and periodic checks that this published policy matches the technologies and actual practices in use.

4. Information You Provide

We may collect identifiers and contact details such as name, billing and delivery address, email address, telephone number, account username, and communication preferences. We collect order information such as products viewed or purchased, quantities, price, discount, tax, delivery option, returns, support history, gift message, and transaction status.

When a customer contacts us, we collect the content of the message and attachments supplied, which may include photographs, video, model or serial numbers, proof of purchase, packaging, delivery labels, and information needed to diagnose or resolve an issue. A customer should avoid sending unnecessary sensitive information and should obscure unrelated payment or identity details.

5. Payment and Transaction Information

Payments are generally processed by Shopify Payments or another payment provider selected at checkout. The store normally receives transaction status, amount, currency, payment method type, billing verification results, risk signals, and limited account details such as the last digits or token, but does not need to receive or store a complete card number or security code.

Payment providers collect and use information under their own terms and privacy notices, including for authorization, fraud prevention, chargebacks, regulatory checks, and settlement. If financing, instalments, digital wallets, or buy-now-pay-later services are offered, the provider may make an independent eligibility or credit decision. Customers should review the provider's notice before choosing that method.

6. Information Collected Automatically

When a person uses the site, servers and commerce tools may collect internet protocol address, browser type, device type, operating system, language, approximate location derived from network information, referring and exit pages, timestamps, session identifiers, pages viewed, searches, cart actions, checkout events, errors, and security or fraud signals.

This information helps deliver pages, remember preferences, secure accounts, keep carts functioning, measure performance, detect abuse, troubleshoot errors, understand navigation, and improve merchandising. We seek to avoid using precise location, sensitive inference, or persistent cross-site tracking unless the feature is disclosed, lawfully configured, and supported by appropriate consent or another legal basis.

7. Cookies and Similar Technologies

Cookies, pixels, local storage, software development kits, tags, and similar technologies may be used. Essential technologies support functions such as secure login, cart memory, checkout, fraud prevention, load balancing, and privacy preferences. Preference tools remember choices. Analytics tools measure use. Marketing tools may support attribution, audience measurement, or relevant advertising when enabled.

The technologies actually used depend on Shopify settings, the theme, installed apps, and marketing integrations. Optional categories should be controlled through the store's cookie banner or privacy settings where required. Browser controls can block or delete cookies, but blocking essential cookies may prevent checkout or account features. Clearing cookies may also clear a recorded privacy choice.

8. Why We Use Personal Information

We use personal information to present the store, create and maintain accounts, process payments, accept or decline orders, provide order confirmation, fulfil and deliver purchases, support returns and warranties, communicate about service issues, maintain transaction records, prevent fraud, protect customers and systems, comply with law, and establish or defend legal claims.

We also may use information to understand product demand, measure site performance, improve navigation, personalize content or recommendations, request feedback, administer promotions, and market products. Non-essential marketing, profiling, or advertising uses are subject to the consent and choice mechanisms required by applicable law. We do not condition a purchase on consent to unnecessary marketing.

9. Consent

We seek meaningful consent by explaining, in accessible language, what information is collected, the purposes, relevant third-party disclosures, and reasonably foreseeable consequences. Consent may be express or implied depending on sensitivity, reasonable expectations, and law. Express consent is generally used for sensitive information or an unexpected use that creates a meaningful residual risk of harm.

An individual may withdraw consent for an optional use, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not invalidate earlier lawful processing and may affect a requested feature. Information necessary to complete an order, detect fraud, comply with tax or accounting duties, resolve a dispute, or protect security may still be used without optional marketing consent where law permits.

10. Orders, Fulfilment, and Customer Service

Order information is shared as reasonably necessary with warehouses, suppliers, carriers, payment providers, fraud-prevention tools, customer-service systems, and technology providers. Each receives only the categories appropriate to its role, such as a carrier receiving contact and address information needed for delivery or a warehouse receiving product and packing details.

Support records are used to authenticate the request, understand the history, document decisions, coordinate with providers, and improve service. Calls or chats are not recorded unless a notice is provided where required. Photographs or diagnostic evidence should be limited to the product and issue. We do not ask for passwords or full payment-card details through ordinary email.

11. Shopify and Platform Services

The store is powered by Shopify. Shopify processes customer and merchant information to provide commerce infrastructure, checkout, hosting, security, fraud prevention, analytics, and other enabled services. In some contexts Shopify acts on the merchant's instructions, while in others it determines its own purposes under its privacy policy, for example certain Shop, Shop Pay, security, or network features.

Shopify may use vendors and infrastructure in multiple jurisdictions. Customers can review Shopify's consumer privacy notice and privacy controls for information about Shopify's own practices. Questions about this merchant's order, marketing choices, or use of data should be directed to the merchant first; questions about Shopify's independent processing may need to be directed to Shopify.

12. Service Providers

We may engage providers for hosting, commerce, payment, fraud screening, order management, warehousing, shipping, customer support, email, analytics, advertising, reviews, accounting, professional advice, security, and data storage. Providers are expected to use personal information only for authorized services or another lawful disclosed purpose and to protect it with measures appropriate to sensitivity.

Before enabling a provider, the merchant should assess what information the tool receives, where it is processed, its retention, permissions, contract, security, and privacy settings. Removing an app from Shopify does not necessarily erase information already held by the provider; offboarding should include revoking access and requesting return or deletion where appropriate.

13. Advertising, Analytics, and Personalization

If enabled, analytics providers may help measure visits, conversions, device patterns, and campaign performance. Advertising partners may use identifiers, cookie data, or event information to measure ads or show relevant content. Depending on applicable law, this activity may be treated as targeted advertising, sharing, profiling, or another regulated practice requiring notice, consent, or an opt-out.

The store should configure Shopify Customer Privacy settings, cookie controls, and advertising integrations for each market in which it operates. A user may change available choices through the cookie banner, privacy link, provider controls, or browser settings. Opting out of targeted advertising does not necessarily stop contextual advertising or essential measurement that law permits.

14. Commercial Electronic Messages

Promotional email or text messages are sent only with consent or another basis permitted by Canada's Anti-Spam Legislation. Requests for consent identify the sender, explain the purpose, provide contact information, and state that consent can be withdrawn. Each commercial electronic message includes identification information and a working, readily performed unsubscribe mechanism where required.

Unsubscribe requests are processed without delay and no later than the period required by law, which under CASL is generally 10 business days. A customer may continue to receive non-promotional communications reasonably necessary for an existing order, requested support, security notice, product recall, warranty issue, or other transactional relationship.

15. Legal and Business Disclosures

We may disclose personal information when reasonably necessary to comply with applicable law, a court order, subpoena, warrant, regulatory requirement, tax or customs obligation, lawful request, product safety process, or to protect rights, safety, systems, customers, or the public. We assess requests and disclose only what we reasonably believe is required or permitted.

Information may also be disclosed in connection with a proposed or completed financing, merger, acquisition, reorganization, insolvency, sale of assets, or transfer of the store, subject to appropriate confidentiality and lawful-use conditions. If control changes, the successor must handle personal information consistently with applicable law and any commitments that continue to apply.

16. Cross-Border Processing

Shopify and other providers may process or store information outside the customer's province or outside Canada. While in another jurisdiction, information may be subject to that jurisdiction's laws and may be accessible to courts, law enforcement, national security, or regulatory authorities in accordance with those laws.

The merchant remains accountable for information transferred to a provider for processing to the extent required by applicable Canadian law. Reasonable steps may include contract terms, security review, access limits, incident duties, and transparency. A customer may ask the Privacy Officer for general information about relevant processing locations or provider categories.

17. Retention and Destruction

We retain personal information only as long as reasonably necessary for identified purposes and legal obligations. Order, invoice, tax, accounting, warranty, fraud, and dispute records may be kept for several years and are generally retained for up to seven years after the relevant transaction or longer when a specific law, claim, investigation, or hold requires it. Marketing records are kept until consent is withdrawn or the purpose ends, with suppression records retained to honour an opt-out.

Support, website, analytics, and security records have shorter or role-specific schedules where practical. When information is no longer required, we delete, securely destroy, or anonymize it, subject to backup cycles and technical constraints. Anonymization is used only where the information is not reasonably expected to identify an individual under the applicable legal standard.

18. Security Safeguards

We use administrative, technical, and physical safeguards proportionate to sensitivity, amount, distribution, format, and risk. Measures may include role-based access, unique accounts, multifactor authentication, encryption in transit, platform security features, secure payment processing, logging, backups, provider controls, staff instructions, patching, and procedures for verifying sensitive requests.

No internet transmission or storage system is perfectly secure. Customers should use strong unique passwords, protect devices and email accounts, sign out of shared devices, and contact us if they suspect unauthorized account activity. We will never ask a customer to send a password or complete card security code by ordinary email.

19. Confidentiality Incidents

If we become aware of unauthorized access, use, disclosure, loss, or another confidentiality incident, we take reasonable steps to contain it, assess affected information and individuals, reduce harm, preserve evidence, and prevent recurrence. We document incidents as required and cooperate with Shopify, providers, insurers, advisers, regulators, and law enforcement where appropriate.

We notify affected individuals and the relevant privacy regulator when the applicable statutory threshold is met, including federal real-risk-of-significant-harm requirements or Quebec serious-injury requirements where applicable. A notice describes the incident and protective steps to the extent permitted and useful; notification may be delayed when law enforcement or law requires it.

20. Accuracy

We seek to keep personal information as accurate, complete, and current as necessary for the purpose. Customers can update some account information directly and should promptly correct delivery or contact details. We may verify a material correction before applying it, particularly when the request affects account access, delivery, payment, fraud risk, or another person's information.

A correction request should identify the disputed information and the accurate replacement. If we do not agree that a record should be changed, we explain the reason where required and may note the disagreement. Historical transaction records may be preserved rather than overwritten when accuracy, tax, audit, or dispute rules require an audit trail.

21. Access, Correction, and Other Rights

Subject to legal exceptions, an individual may ask whether we hold personal information about them, request access, ask for correction, withdraw optional consent, challenge compliance, or request information about our practices. Depending on applicable law, additional rights may include deletion, portability, de-indexing, cessation of dissemination, or information about automated decisions.

Send a request to the Privacy Officer at info@hesterandcook.shop. Describe the request and the account or transaction involved. We may ask for proportionate identity verification and will not request more information than reasonably needed. We respond within the period required by applicable law, explain any lawful refusal, and provide information about available complaint or review channels.

22. Quebec-Specific Transparency

Where Quebec's private-sector privacy law applies, the highest authority in the enterprise is responsible for personal information unless the function is delegated in writing. The title and contact information of the Privacy Officer must be published. At collection, individuals receive clear information about purposes, means, rights of access and rectification, withdrawal of consent, relevant recipient categories, and the possibility of processing outside Quebec.

If technology is used to identify, locate, or profile an individual, the store should disclose that use and the means available to activate the relevant function. Privacy settings for a public technological product or service should provide the highest level of confidentiality by default where the law requires. Assessments and governance steps required for transfers or automated processing should be completed before deployment.

23. Children and Minors

The store is intended for adults and is not directed to children under 13. We do not knowingly collect personal information directly from a child who cannot provide meaningful consent. In Quebec, personal information concerning a minor under 14 is not collected from the minor without parental or tutor consent unless the collection is clearly for the minor's benefit, as permitted by law.

A parent or guardian who believes a child supplied information should contact the Privacy Officer. We will verify the request and take appropriate steps. Product age ratings and safety warnings are separate from privacy eligibility; an adult purchaser remains responsible for selecting and supervising products intended for a minor.

24. Complaints

A privacy concern should first be sent to the Privacy Officer at info@hesterandcook.shop. Include enough detail for us to investigate but do not send unnecessary sensitive information. We record the concern, review relevant practices and providers, and communicate the outcome or next steps. Good-faith complaints do not affect access to products or support.

If the concern is not resolved, the individual may contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator, including the Commission d'accès à l'information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, or the Office of the Information and Privacy Commissioner of Alberta, depending on jurisdiction.

25. Changes to This Policy

We may update this policy to reflect legal, platform, provider, technology, or business changes. The current version is posted with an effective date. If a change is material to consent or creates a new use or disclosure outside reasonable expectations, we provide additional notice and seek new consent where required. Earlier versions should be retained internally so the store can demonstrate what notice applied at a relevant time.