Privacy Policy
Effective July 31, 2026 · Version 2026-07-31
This page is maintained by Bricktra to explain how the Bricktra application handles personal information. It is app-owned content, not an independent certification or audit.
1. Who is responsible for your information
Bricktra, 1984 rue St-Thomas, Longueuil, Québec, Canada, is the enterprise responsible for the personal information processed by Bricktra. Under Quebec's Law 25 the person in charge of the protection of personal information is the Bricktra operator, reachable at bricktra@simonmarin.ca. That address is also the contact point for access, correction, portability, withdrawal of consent, complaints, and any question about this policy.
2. What we collect and why
- Account data — email address, password hash (managed by our authentication provider), display name, store name, chosen language and preferences. Purpose: create and secure your account.
- Store and business data you enter or sync — orders, sale line items, expenses, shipping costs, boxes and carriers, consignments, wishlist and purchase records, pricing data. Purpose: provide the bookkeeping and analytics features you asked for.
- Third-party marketplace data — when you connect BrickLink, Chit Chats or Canada Post, we retrieve the order, shipping and tracking records tied to your store. These records can include buyer names, shipping addresses, order totals and messages, because they are part of the orders you fulfil.
- Integration credentials — API keys and tokens you provide, stored encrypted (AES-256-GCM) and used only to call the service you connected.
- Billing data — subscription status, plan, renewal date and a payment processor customer reference. We never see or store your full card number.
- Operational data — last activity timestamp, sync logs, API usage counters, consent records, an administrative audit log of privileged actions, and support messages or screenshots you send us. Purpose: security, abuse prevention, troubleshooting and legal compliance.
We do not sell your personal information, we do not use it for advertising, and we do not profile you for automated decisions that affect your rights.
3. Consent
We ask for your express consent to this policy and to the Terms of Service when you create your account, and again whenever we publish a materially new version. Each acceptance is recorded with the document version, the date and time, and a one-way hash of your IP address — the raw IP is not retained. You may withdraw consent at any time by deleting your account (section 8); withdrawing consent means we can no longer provide the service.
4. Buyer and third-party information
Where Bricktra processes information about your customers (for example a buyer's shipping address on an order you imported), we act as a service provider on your behalf: you remain responsible for that information towards your buyers, and we process it only to run the features you use. We do not contact your buyers except through actions you trigger in the app (for example posting feedback or a shipping notice to your marketplace account).
5. Where your data is stored and cross-border transfers
Bricktra is operated from Quebec, Canada, but its infrastructure and service providers are not all located in Quebec. Your personal information is stored and processed on servers outside Quebec, including in the United States and other jurisdictions, and is therefore subject to the laws of those jurisdictions, which may allow access by foreign authorities. Before entrusting information outside Quebec we assess the risk, and we rely on contractual commitments and the security measures of these providers.
The categories of providers we rely on:
- Application hosting and edge delivery — hosting and content-delivery infrastructure (global, including the United States) serves the app and runs its backend logic.
- Database, authentication and file storage — our managed backend platform (Lovable Cloud, built on Supabase infrastructure) stores your account, store data and uploaded files.
- Email delivery — a transactional email provider sends authentication and notification emails (recipient address and message content only).
- Payments — Stripe (United States/Ireland) processes subscription payments and holds your billing details under its own privacy policy.
- Marketplace and carrier APIs you connect — BrickLink (United States), Chit Chats (Canada), Canada Post (Canada). Data flows to and from these services only for the store you linked.
- Optional lookup and AI features — when you use catalogue lookups or AI assistance, the query content is sent to the corresponding provider. We do not send your buyer data for model training.
We can provide the current list of service providers on request at bricktra@simonmarin.ca.
6. How long we keep it
- Account and store data: for as long as your account is active.
- Buyer details imported from marketplaces and carriers (shipping addresses, buyer usernames, tracking event history and raw carrier payloads): automatically anonymized once the related order is older than the retention period configured for the account — 24 months by default, adjustable by the seller between 6 and 24 months in Settings → Security. Indefinite retention of buyer details is not offered. A daily job performs this anonymization: street address, recipient name, phone number and full postal code are removed (only country, province/state and a coarse postal prefix remain), buyer usernames are replaced by a non-reversible pseudonym, tracking history keeps status and date only, and raw payloads are stripped of personal fields. Order details — items, quantities, amounts, fees, dates, order numbers, tracking numbers and store names — are business records and are kept so accounting history remains complete.
- After you request deletion: erased at the end of the 30-day grace period described in section 8.
- Sync logs and API usage counters: rolling operational window, then discarded.
- Consent records, administrative audit entries and billing records: retained after account closure only as long as needed to meet legal, accounting and evidentiary obligations.
7. How we protect it
- Encryption in transit (HTTPS) and at rest on our managed backend.
- Row-level database access rules so each account can only reach its own records; privileged operations run server-side only.
- Integration credentials encrypted with a dedicated key, never displayed back in full.
- Server logs are scrubbed of buyer names, addresses and order identifiers.
- An append-only audit log of administrative actions, and a "sign out everywhere" control.
- Backend jobs authenticated with a dedicated secret, separate from public app keys.
No system is perfectly secure. If a confidentiality incident presents a risk of serious injury, we will keep a record of it and notify affected users and the Commission d'accès à l'information du Québec as required by Law 25.
8. Your rights, and deleting your account
You may access, correct, or receive a portable copy of your personal information, withdraw your consent, ask us to stop disseminating information, or complain about how we handle it. Write to bricktra@simonmarin.ca and we will answer within 30 days. Most of your data is directly visible and editable in the app, and each page offers CSV export.
You can delete your account yourself in Settings → Security → Delete account. Your account is disabled immediately and all associated data is permanently erased 30 days later. During those 30 days you can cancel the request by signing in again, or by writing to us. Deletion removes your store data, integration credentials, notifications and preferences; some billing and consent records are kept as described in section 6.
If you are unsatisfied with our response, you may contact the Commission d'accès à l'information du Québec, or the Office of the Privacy Commissioner of Canada under PIPEDA.
9. Cookies and analytics
Bricktra uses browser storage strictly to keep you signed in and to remember interface preferences (theme, language, sorting, print settings). We do not use advertising cookies or third-party cross-site trackers.
10. How we assess privacy risk
Before launching a feature that involves personal information, or before entrusting information to a provider outside Quebec, we carry out a privacy impact assessment proportionate to the sensitivity of the data: what is collected, why, who can reach it, where it is stored, how long it is kept, and what mitigations apply. The current assessment is documented internally and covers account data, marketplace order data (including buyer addresses), integration credentials, billing data and cross-border transfers. A summary is available on request at bricktra@simonmarin.ca.
11. Changes to this policy
We will publish any new version here, bump the version number, and ask you to accept it the next time you sign in.