Privacy policy
Last updated: 2026-08-22
This policy describes exactly what this site collects, why, how long it keeps it, and what you can require of us. It is written in plain language, as the law requires.
Who is responsible
The person responsible for the protection of personal information is Joanie Rondeau. For any question, or any request for access, correction or deletion, write to info@fermeclementoise.com. We answer within 30 days.
What we collect, and why
We collect nothing “just in case”. Each item below serves one specific purpose, and that purpose is named.
- To process and ship an order: first name, last name, email, phone and shipping address. Without them we cannot ship anything to you, nor send your receipt.
- If you create an account: the same information, plus a fingerprint of your password. We never keep the password itself — nobody here can read it, or choose one on your behalf.
- If you write through the contact form: name, email, phone if you give one, your message, and the IP address it came from — that last one only to block automated spam.
- On each failed sign-in: the email address that was tried and the IP address, to prevent someone from guessing a password by brute force.
- If you tick the newsletter box: your email, to write to you about new products. The box is separate from the purchase and unticked by default: saying yes is a deliberate act.
What we do not do
- We do not sell, rent or trade your information. Ever, to anyone.
- This site contains no tracking tools: no Google Analytics, no Facebook pixel, no ad network. Nobody measures your browsing.
- No decision about you is made automatically, and we build no profile of your habits.
- No card number ever touches this server. Payment happens on Square’s page, and we receive only a confirmation.
Cookies
This site sets two cookies, and only two. The first holds your session for the length of your visit. The second holds your cart, so it survives closing the tab. Both are strictly necessary to the service you asked for, which is why no banner asks you to accept them: there is nothing else to accept.
Who else has access
- Square, to take payments. Receives your name, email, phone, shipping address and the contents of the order.
- Our hosting provider, which hosts the site and the database, and carries our email.
- Nobody else. No other service, no other partner.
Information sent outside Québec
Square is an American company: the information needed for payment is therefore processed outside Québec and may be subject to the laws of the country where it is held. We chose Square because its compliance with payment industry standards (PCI-DSS) spares us from handling card numbers ourselves — which protects you more than keeping everything here would.
How long we keep your information
Nothing is kept indefinitely. Once the period passes, the information is destroyed or anonymised.
- Orders and invoices: six years after the end of the financial year. That period is not ours — tax law requires it.
- Customer account and saved addresses: as long as the account exists. You can delete it yourself, at any time.
- Messages sent through the contact form: 24 months. The IP address that came with them: 30 days.
- Failed sign-in attempts: 30 days.
- Abandoned carts: 90 days.
- Password reset links: valid for one hour, then erased.
- Newsletter subscription: until you withdraw it.
Your rights
The law gives you rights over your information. Exercising them is free and requires no justification.
- Know what we hold about you, and obtain a copy of it.
- Have anything inaccurate or incomplete corrected.
- Have your account and your information deleted, except what a law obliges us to keep — your invoices, in particular.
- Receive your information in a machine-readable format, to take it elsewhere.
- Withdraw your consent to the newsletter, without affecting your orders.
- Complain to the Commission d’accès à l’information du Québec if our answer does not satisfy you.
If you have an account, deleting and exporting your information is done directly from your account area. Otherwise, write to us: we answer within 30 days.
How we protect it
The site is served entirely over HTTPS. Passwords are turned into irreversible fingerprints. Every database query is parameterised, which makes injection impossible. The application code sits outside the web server’s reach, and access to the management portal is rate-limited.
In case of an incident
If a confidentiality incident presented a risk of serious injury, we would notify the people affected and the Commission d’accès à l’information promptly. We keep a register of any incident, as the law requires.
Changes
If this policy changes, the update date above will show it. An important change will be signalled to you, not slipped in quietly.