Privacy

At Saponetti Inc. (“Saponetti” or “we”), we recognize the importance of your privacy. We are committed to using your personal information responsibly and only to the limited extent needed to serve you better.

Application of Privacy Policy

This Privacy Policy regulates how we internally use, protect and disclose to third parties during commercial activities any personal information within our possession collected from you through your use and access of our website and other services. This Privacy Policy applies to our directors, officers, partners, employees, contractors and authorized representatives (“Staff”). It is at all times subject to the requirements of the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (“PIPEDA”). Additionally, how we use or disclose your personal information may also be subject to the requirements of Canada’s anti-spam Legislation, S.C. 2010, c. 23 (“CASL”). Any terms not defined herein have the meaning that PIPEDA attributes to them, and this Privacy Policy is meant to be consistent with PIPEDA, or where PIPEDA is silent on a matter then CASL.

Governing law

This Privacy Policy is governed by the laws of Ontario and the laws of Canada as applicable herein. It is not a contract and will be treated as a non-contractual set of policies and practices binding on Staff of our Ontario or Canadian entity under Principle 4.1.4 (PIPEDA, Schedule 1).

Accountability for your privacy

Our Privacy Information Officer is responsible for ensuring that Staff complies with this Privacy Policy. He or she can be contacted at:

Saponetti Inc.
Attention: Privacy Information Officer
615C Brock Ave,
Toronto, Ontario, M6H 3P1
Email: [email protected]

The identity of our Privacy Information Officer is available upon written request as required by Principle 4.1.2 (PIPEDA, Schedule 1).

Responsibilities of Privacy Information Officer

The Privacy Information Officer is responsible for

  1. Implementing procedures contained in this Privacy Policy to protect personal information;
  2. Training our Staff to comply with this Privacy Policy and PIPEDA and communicating to Staff information about changes and updates to our Organization’s policies and practices relating to Personal Information;
  3. Enforcing this Privacy Policy and correcting any potential or actual instances of breach; and
  4. Reviewing and responding to any communication or notice relating to this Privacy Policy or PIPEDA.

Our purpose

We are Toronto’s first and only soap delivery company offering premium, Canadian-made, environmentally friendly and hypoallergenic, soaps and detergents for home and personal care. We bulk-buy all our products and deliver them to you in reusable glass mason jars. We collect, use, and disclose personal information for the following purpose:

  • Respond to inquiries about our products, refill services and other services we provide;
  • Process initial product orders, facilitate refill requests, invoice for fees and generally administer our ecommerce platform;
  • Verify any information provided to us about our customers;
  • Advise you of new products and services; and
  • Share with Staff, contractors, consultants, affiliates and other parties who require such information to assist us with:
    • establishing, maintaining and managing our relationship with you;
    • processing orders for you; and
    • delivering our products to you.

In addition to the foregoing, we may collect, use and disclose personal information for any other purpose we may indicate to you from time to time. Where personal information has been transferred to use as a “third party for processing” under Principle 4.1.3 of PIPEDA, we will also collect, use, and disclose that personal information in accordance with any purpose set out in any contract between us and the person or entity from whom we have received the personal information.

If we change the Purpose set out above we give notice of the change on our website and we will post an updated Privacy Policy.

Personal information we collect and use

To fulfill our purpose, we collect the following kinds of personal information:

  1. Names and contact information for our customers. This includes addresses, phone numbers, email for both work and home;
  2. Credit Card Information for the purpose of processing initial orders and refill orders; and
  3. Photos, messages and other files posted to Saponetti’s Facebook, Instagram or other social media accounts.

Cookies

As permitted by section 10(8) of CASL, when you visit our website, we may place one or more “cookies” on the hard drive of your computer to track your visit. A cookie is a small data file that is transferred to your hard drive through your web browser and can only be read by the website that placed the cookie on your hard drive. The cookie acts as an identification card and allows ours website to identify you and to record your passwords and preferences.

The cookie allows us to track your visit to the website so that we can better understand your use of our website so that we can customize and tailor the website to better meet your needs. Most browsers are set to accept cookies but you can usually change this if you so desire. It should be noted that if cookies are not accepted, you may be unable to access a number of web pages found on the website

Links to other websites

From time to time, we may introduce on our website links to other sites run by third parties not affiliated with Saponetti. We would encourage you to review the privacy policies on those sites before providing your personal information. They may be less stringent than ours. Please note that we do not accept responsibility privacy practices, policies or actions for those third parties.

Obtaining consent

Implied informed consent

Use of our website and services is voluntary. When collecting, using and disclosing personal information about you, we rely on your implied consent when you give us your personal information on request of your own free will. This is provided that we collect that information in the ordinary course of our business in accordance with our Purpose.

Express informed consent

When PIPEDA allows us to proceed without consent, or we imply your consent (as discussed above), we do not seek express consent. In all other cases, our Staff will contact you (either by telephone, e-mail or in person), identify a new purpose for which we need your information and seek your express consent. We do not collect personal information from children (anyone under 18) over the telephone or in person without a parent’s express oral consent.

If we are collecting the information online, we will request that you supply personal information in fields on web pages containing a link to this Privacy Policy. You will be able to expressly consent by checking a checkbox and submitting the information electronically. We do not knowingly collect information from children (anyone less than 18 years old). However, when collecting personal information electronically (by web-form or e-mail) we do not verify the age of the person from whom we are collecting. In the absence of any indication to the contrary, we will assume anyone supplying us with information online is over 18 years of age. Parents are strongly encouraged to discuss responsible internet use and personal information disclosure with their children.

Withdraw consent

You can withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice, by sending an e-mail to our Privacy Information Officer at the contact information above. In some circumstances, a change in or withdrawal of consent may severely limit our ability to provide products or services to you. We will inform you of any implications connected to withdrawing your consent.

If you have asked us to put you on an email list to provide you with certain information on a regular basis, and such emails constitute “commercial electronic messages” or “CEMs” under CASL, you may ask us to remove you from the list at any time (using the unsubscribe instructions provided with each email and on the site where you signed up).

Limiting collection, use, disclosure and retention

We use our best efforts to limit the personal information we collect, use and disclose solely those details we need to fulfill our Purpose. We have designed our standard forms only to collect the information that we foresee we will need. We do not collect, use and disclose personal information using deceptive, fraudulent or unlawful means.

Need-to-know disclosure

When using and disclosing information to third parties, we only disclose on a need-to-know basis. Also, it is our practice to disclose personal information only after ensuring that appropriate contractual safeguards are in place as contemplated in Principle 4.1.3 of Schedule 1 of PIPEDA.

Retaining records

We keep records of the work performed and services provided by us in accordance with applicable regulatory requirements and professional standards. These records may include personal information. We may continue to retain such records even after you no longer use our website or services or your account on our website is terminated for any reason.

Destruction of personal information

We destroy electronic information by deleting it and, when hardware is discarded, we ensure that the hard drive is physically destroyed. We shred paper containing personal information and ensure that it is disposed of properly to prevent accidental disclosure.

Ensuring accuracy

In order to fulfill our Purpose to a high quality standard, we ask you to update your personal information and maintain appropriate contact preferences from time to time. You also have the right to contact us in order to verify that the information we have on file is accurate.

We do not, as a practice, contact you in order to ensure that the personal information we have in accurate. We may take reasonable steps to do so when using that information in course of providing you with an ongoing product or service, provided our Staff is in regular contact with you. Otherwise, we strongly encourage you to contact us and ensure that the information we have in your file is up-to-date.

Our safeguards to protect you

We respect the privacy of our customers, employees and other stakeholders. We will protect that privacy as vigorously as possible. The methods we use include:

  • Storing personal information in electronic and physical files and on physical premises that are secure and to which access is restricted; and
  • Password-protected computers (including on laptops, desktops and smart-phones) and the use of technology safeguards, such as firewalls, encryption and intrusion detection, to prevent hacking or unauthorized computer access.

Unfortunately, no data transmission over the Internet or by electronic mail can be guaranteed to be 100% secure. As a result, while the website strives to protect your personal information, we cannot warrant the security of any information you transmit to us, and you do so at your own risk.

Mobile devices and remote access

When using laptops, smartphones and mobile devices outside the office, we are required to take reasonable steps to ensure that these devices are not lost or stolen. These devices may not be stored in vehicles or left unattended for any reason while out of the office.

Staff may also remotely access the office network from a personal computer. Such access is only permitted if the computer has technology safeguards equal to, or better than, those on the computers belonging to our organization. Under no circumstances may Staff store data from our office network on a personal computer.

Regular review of safeguards

We recognize that technology and security measures evolve at a remarkable pace. So at Saponetti we periodically review our personal information safeguards with our Information Technology consultants and in-house experts. We want to ensure that our safeguards exceed industry best-practice.

Open privacy practices

It is our practice to post the most up-to-date version of this Privacy Policy on our website at http://www.saponetti.ca. You can also obtain a copy of this policy by sending an e-mail to our Privacy Information Officer at the address above.

Your ability to access your information

You may review any personal information we have on you in our files by making a written request to our Privacy Information Officer at the address above.

Please include sufficient details in your request about the type of information that you would like to see about yourself. Please sign your request and send it by regular mail and we will contact you within 30 days of receipt. Please note that we only respond if you are making a request relating to your own personal information. We will not grant access to personal information about someone else.

We will be pleased to provide you with access to your personal information as long as it does not fall within an express PIPEDA exception. Examples of such exceptions include, but are not limited to, information protected by solicitor-client privilege; information generated in the course of a formal dispute resolution process; information about another individual where disclosure would reveal confidential commercial information; or information disclosed to the police or other lawful authorities where we are required to withhold disclosure.

Please note that summary information is available on request, subject to the terms above, but more detailed requests requiring archive or other retrieval costs may be subject to our normal professional and disbursement fees.

Questions or concerns

Should you have any questions or concerns about this Privacy Policy or how we handle your information-access request, please direct them to our Privacy Information Officer. He or she will be pleased to respond and if necessary investigate the matter.

We reserve the right to change our Privacy Policy at any time by posting a new version on our website. In the event of a conflict between this version and another, the version that is later in time prevails.