PRIVACY POLICY

Effective Date: September 9, 2025

Holistic Haven Clinic, registered in Ontario, Canada, respects your privacy. This Privacy Policy explains how we collect, use, share, and protect personal information. While governed by Canadian law (PIPEDA), this policy applies to users worldwide.

  • Personal Information: name, email, billing information, purchase details.
  • Technical Information: IP address, device/browser data, and usage information via cookies and similar technologies.
  • To process purchases, deliver Content, and provide support;
  • To operate, secure, and improve our website and offerings;
  • To communicate about orders, updates, and (with consent where required) marketing;
  • To comply with legal, tax, and regulatory obligations.
  • Contract (fulfilling your purchase and providing access);
  • Legitimate interests (site security, fraud prevention, product improvement);
  • Consent (non-essential cookies/marketing; you can withdraw anytime);
  • Legal obligation (e.g., accounting, regulatory compliance).

We use cookies and similar technologies. See our Cookie Policy for categories, choices, and retention. Non-essential cookies are used only with appropriate consent (e.g., EU/UK opt-in).

We do not sell or rent personal information. We may share limited data with trusted providers (e.g., payment processors, hosting, analytics) under contracts requiring appropriate safeguards. We may disclose information if required by law.

Your data may be processed in countries outside your residence (including Canada and the U.S.). Where required, we use safeguards such as Standard Contractual Clauses or equivalent mechanisms.

We keep: (a) purchase and tax records for 6 years from the end of the applicable tax year; (b) support and account correspondence for 24 months after your last interaction; (c) analytics event data for up to 14 months; and (d) marketing consent and unsubscribe records while we send messages and for 3 years thereafter. We delete or anonymize personal information once it is no longer needed. In all cases, we follow the storage-limitation principle and applicable laws (e.g., PIPEDA/GDPR/UK GDPR), and disclose periods or criteria as required by the CPRA.

We employ reasonable technical and organizational measures to protect personal information. No method of transmission or storage is 100% secure.

  • Canada (PIPEDA): access and correction;
  • EU/UK (GDPR): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent;
  • California (CCPA/CPRA): right to know, delete, correct, and opt out of “sale” or “sharing” (for targeted advertising).

To exercise rights, email [email protected]. We will verify and respond within 30–45 days as required.

We send marketing emails only with your express consent and include an unsubscribe link in every message. Transactional messages (e.g., receipts) may still be sent.

  • Canada: You may contact the Office of the Privacy Commissioner of Canada (OPC) if unresolved.
  • EU/UK: You may lodge a complaint with your local supervisory authority.

Please contact us first at [email protected] so we can help.

Our services are not directed to children under 13. We do not knowingly collect their data.

We may update this Policy. Material changes will be posted here with an updated Effective Date.