Privacy Policy
In compliance with Quebec Law 25 on the protection of personal information.
Last updated: May 10, 2026
This policy complies with Quebec Law 25 (Act to modernize legislative provisions respecting the protection of personal information) and the Personal Information Protection and Electronic Documents Act (PIPEDA) of the Government of Canada.
1. Privacy Officer
In accordance with Quebec Law 25, the privacy officer for Citadelle Jiu-Jitsu is:
[Founder's Full Name]
Citadelle Jiu-Jitsu
964 Rue Mainguy, Québec, QC G1V 3S4
Phone: 418-564-1047
Email: citadellejj@gmail.com
2. Personal Information We Collect
We collect only the information necessary to provide our services:
- Account creation: first name, last name, email address, encrypted password, phone number (optional)
- Trial session: name, email, phone, age, martial arts experience, preferred date, optional message
- Contact form: name, email, subject, message
- Memberships: payment data processed directly by Stripe Inc. — we never store your credit card information
- Shop: order data and purchase history
3. Purposes of Collection
Your information is used exclusively to:
- Manage your member account and subscription
- Confirm and coordinate your trial session
- Process your shop orders
- Respond to your contact messages
- Send payment and order confirmations
- Improve our services and site security
We do not use your information for marketing without your explicit consent.
4. Third-Party Sharing
Your information is never sold. It may be shared with:
- Stripe Inc. — online payment processing (PCI DSS Level 1 certified). Privacy policy: stripe.com/privacy
- Horizon 91 — website developer and host. Access limited to technical maintenance only.
5. Data Retention
- Active member accounts: retained while the account is active
- Inactive accounts: deleted after 3 years of inactivity
- Trial session requests: retained 2 years for follow-up
- Contact messages: retained 1 year
- Order data: retained 7 years (Canadian tax obligation)
6. Your Rights (Quebec Law 25)
You have the right to:
- Access: review the information we hold about you
- Rectification: correct inaccurate information
- Erasure: request deletion of your data (subject to legal retention obligations)
- Portability: receive your data in a structured, readable format
- Withdrawal of consent: withdraw your consent at any time
To exercise these rights, contact us at citadellejj@gmail.com. We will respond within 30 days as required by law.
7. Security
- HTTPS encryption across the entire site (TLS)
- Passwords hashed with bcrypt — never stored in plain text
- Secure token authentication (HttpOnly, SameSite cookies)
- Admin access protected by database role verification
- Payments processed by Stripe (PCI DSS Level 1 certified)
8. Cookies
This site uses only essential functional cookies:
- Authentication session: HttpOnly cookie to maintain your login (deleted on logout)
- Language preference: remember your FR/EN choice
No advertising or third-party tracking cookies are used on this site.
9. Policy Updates
We may update this policy at any time. The last modified date appears at the top of this page. For significant changes, we will notify you by email if you have an account.
10. Right to File a Complaint
If you believe your rights have not been respected, you may file a complaint with the competent authority for your jurisdiction: