Legal
Privacy Policy
ℹ️ Plain language summary — what matters most
- · We collect your name, email, address, and order history to run the platform. Nothing more than what we need.
- · We never sell your personal data to any third party. Ever.
- · We use a secure payment processor for payments, Cloudinary for images, and Supabase for our database.
- · You can request to see, correct, or delete your data at any time by emailing privacy@ruyte.com.
- · We use cookies for login sessions, analytics, and optional personalisation. You can opt out.
- · Canadian law (PIPEDA and, for Quebec residents, Quebec Law 25) primarily governs how we handle your data. If you are in the EU, UK, or California, additional rights may apply — see Section 14.
01
Who we are
Ruyte Inc. ("Ruyte", "we", or "us") is a federally incorporated Canadian company operating a curated multi-brand fashion marketplace at ruyte.com.
For the purposes of Canadian privacy law, Ruyte Inc. is the data controller responsible for personal information collected through the Ruyte platform. We are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec Law 25 (Act respecting the protection of personal information in the private sector).
Designated Privacy Officer: Ruyte Inc. has designated a Privacy Officer responsible for overseeing compliance with this policy and applicable privacy laws. Contact: privacy@ruyte.com
Privacy Impact Assessments (PIA): As required by Quebec Law 25, Ruyte conducts Privacy Impact Assessments before deploying new technologies that process personal information. Our current PIA covers account management, order processing, payment infrastructure, image processing, email delivery, search, analytics and database infrastructure.
| Detail | Information |
|---|---|
| Legal name | Ruyte Inc. |
| Jurisdiction | Ontario, Canada |
| Privacy contact | privacy@ruyte.com |
| General support | info@ruyte.com |
| Governing privacy law | PIPEDA (Canada) + Quebec Law 25 (Act 64) + applicable provincial legislation |
| Quebec Law 25 (Bill 64) | Applies to all customers in Quebec. Effective September 2023. Provides expanded rights including right to data portability and right to be forgotten. Requires designation of a Privacy Officer and 72-hour breach notification to the Commission d'accès à l'information (CAI). |
02
Scope of this policy
This Privacy Policy applies to all personal information collected by Ruyte Inc. through the Ruyte website and subdomains, any Ruyte mobile applications, interactions with our support team, brand seller applications, and all communications we send.
03
Plain language summary
What we collect: Name, email, shipping address, payment transaction status and references, order history, browsing activity, and device/browser information for security and analytics. Ruyte does not receive or store your full card number or security code.
What we do with it: Run the marketplace, process and deliver your orders, send you order updates, improve the platform, prevent fraud, and (with your permission) send you marketing emails.
What we never do: We never sell your personal data. We never share it with advertisers for targeting. We never use your data in ways not described in this policy without asking you first.
04
Information you give us
We collect personal information you provide in the following circumstances:
Account registration
First name, last name, email address, and password (stored as a cryptographic hash). If you register via Google, we receive the name and email from that account.
Making a purchase
Shipping address, billing address, and optional phone number. Card information is entered directly into secure payment-provider fields and is never stored by Ruyte.
Product reviews
Written review, star rating, and any photos you choose to upload. Published alongside your first name and first initial of your last name (e.g. 'Sara M.').
Customer support
Content of your messages, your email, and any attachments. Retained for up to 36 months.
Brand seller applications
Full name, business name, email, phone, website URL, Canadian Business Number, and application answers.
05
Information we collect automatically
| Data type | What it is | Why we collect it |
|---|---|---|
| IP address | Your internet connection's address | Security, fraud prevention |
| Browser & device | Browser type, OS, screen size | Optimise display, debug errors |
| Pages visited | Which pages you view and in what order | Analytics, improve navigation |
| Search queries | What you search for on the Platform | Improve search results |
| Clickstream data | Which products you click, add to cart | Personalise recommendations |
| Error logs | Technical errors during your session | Debug and improve the Platform |
06
Information from third parties
- Social login (Google, Apple): Name and email only. We do not receive your password.
- Safepay: Card details are entered in Safepay-hosted secure fields. Ruyte receives the transaction status, charged amount and currency, limited card metadata and provider reference needed to verify, refund and support an order. Ruyte never receives or stores the full card number or CVC.
- Brand Sellers: Tracking numbers and fulfilment status updates.
07
How we use your data
| Purpose | Legal basis |
|---|---|
| Processing and fulfilling orders | Contract performance |
| Sending order confirmations & updates | Contract performance |
| Customer support | Contract performance / Legitimate interest |
| Processing returns & refunds | Contract performance |
| Fraud detection & prevention | Legitimate interest |
| Platform analytics & improvement | Consent (opt-in via cookie banner; analytics not collected without explicit consent) |
| Marketing emails (with consent) | Consent |
| Ruyte Rewards programme | Contract performance |
| Legal compliance | Legal obligation |
08
Legal basis for processing
Your consent: We rely on consent for analytics cookies and marketing communications. Consent for these purposes is collected separately and explicitly — creating an account or making a purchase does not constitute consent to analytics or marketing. You can withdraw consent at any time via cookie settings or email preferences.
Contract performance: Much of our data processing is necessary to fulfil our contractual obligations — processing your order, delivering your products, managing your account.
Legitimate interests: Fraud prevention, security monitoring, and platform analytics.
Legal obligation: We may retain certain data to comply with applicable law, including CRA tax requirements.
09
Marketing communications
We send marketing emails only to users who have explicitly opted in. You can unsubscribe at any time by clicking "Unsubscribe" at the bottom of any marketing email, or in My Account → Profile → Email preferences. Unsubscribe requests are processed within 10 business days.
10
Who we share data with
We share personal data only in the limited circumstances below. We never sell your personal data.
- Brand Sellers: Receive only the customer and order information reasonably necessary to fulfil, support or return their products. The Brand Seller Agreement and applicable data-processing terms restrict that information to authorized purposes, require appropriate security and breach notification, and require deletion or de-identification when it is no longer needed, subject to legal record-retention duties.
- Service providers: Safepay processes card payments. Couriers and logistics providers receive the minimum recipient, address, phone, parcel, order and customs information needed to deliver and clear each parcel. Image, database, email, search and hosting providers process data on our behalf under contractual safeguards.
- Legal disclosure: If required by law, court order, or governmental authority.
- Business transfers: If Ruyte is acquired or merges with another company. You will be notified before your data becomes subject to a different privacy policy.
11
Third-party services
| Service | Purpose | Privacy policy |
|---|---|---|
| Safepay | Secure card fields, authentication, payment processing, verification and refunds in the settlement currency shown at checkout | getsafepay.com/privacy |
| Supabase | Database & authentication infrastructure | supabase.com/privacy |
| Cloudinary | Product image storage & delivery (CDN) | cloudinary.com/privacy |
| Resend | Transactional & marketing email delivery | resend.com/privacy |
| Algolia | Product & brand search indexing | algolia.com/privacy |
| Vercel | Website hosting, CDN & analytics (Vercel Analytics) | vercel.com/legal/privacy-policy |
| Authentication (Sign in with Google). Name and email only. | policies.google.com/privacy | |
| Couriers / 3PL providers | Parcel booking, delivery, tracking, customs clearance and returns. The selected provider is recorded against each shipment. | Provider policy shown in tracking or supplied on request |
12
Data storage & transfers
Database location: Ruyte's primary Supabase database is hosted in the US West (Oregon) region on AWS infrastructure. While Supabase is a Canadian-friendly service, our current database instance is not physically located in Canada. We are committed to migrating to the AWS Canada (Central) region. If you require Canadian data residency (e.g. for Quebec Law 25 purposes), contact privacy@ruyte.com.
International transfers: Some payment, hosting, image, email and search providers may process data outside your country. Where applicable, Ruyte uses contractual and privacy safeguards and conducts the assessments required for Quebec residents.
13
Data retention
| Data type | Retention period | Reason |
|---|---|---|
| Account information | Duration of account + 2 years | Account management, dispute resolution |
| Order records | 7 years | CRA tax & financial record requirements |
| Support conversations | 3 years | Quality assurance, dispute resolution |
| Marketing consent records | Until withdrawal + 3 years | CASL compliance |
| Security logs | 12 months | Security monitoring, fraud detection |
| Analytics data | 26 months rolling, then aggregated and anonymised | Platform improvement (raw events purged; aggregate trends retained) |
14
Your privacy rights
Under PIPEDA and applicable Canadian privacy law, you have the following rights:
Right of access
Request a copy of all personal data we hold about you
Right of correction
Request correction of inaccurate or incomplete data
Right of deletion
Request deletion of your personal data (subject to legal obligations)
Right to withdraw consent
Withdraw consent for marketing or non-essential processing at any time
Right of portability
Request your data in a structured, machine-readable format
Right to complain
Lodge a complaint with Canada's Privacy Commissioner at priv.gc.ca
Additional rights — EU and UK residents (GDPR / UK GDPR): You also have the right to object to processing based on legitimate interest, the right to restrict processing, and the right not to be subject to solely automated decision-making with significant legal effects. You may lodge a complaint with your local data protection authority.
California residents (CCPA/CPRA): You have the right to know what personal information is collected and how it is used, the right to opt out of the sale or sharing of personal information (Ruyte does not sell personal data), and the right to non-discrimination for exercising your rights.
Quebec residents (Law 25): You have expanded rights to portability, correction, de-indexing, and the right to know how automated processing affects decisions about you. Contact our Privacy Officer for requests.
To exercise any right, email privacy@ruyte.com with the subject line "Privacy Request". We will respond within 30 days. Many rights can also be exercised directly in My Account → Settings.
15
Cookies & tracking
| Cookie type | Purpose | Opt out? |
|---|---|---|
| Essential | Login sessions, shopping cart, security tokens. Required for the site to work. | No — required |
| Functional | Remembering your preferences (language, currency). | Yes — some features may break |
| Analytics | Understanding how visitors use the Platform (anonymised data). | Yes — via cookie preferences |
| Marketing | Measuring effectiveness of our marketing campaigns. | Yes — via cookie preferences |
16
Children's privacy
The Platform is not directed at or intended for persons under the age of 18. We do not knowingly collect personal information from children or minors.
Hard minimum age: 18 years. Ruyte does not accept accounts from persons under 18 under any circumstances, with or without parental consent. If we become aware that a user under 18 has created an account, we will delete the account and all associated personal information immediately.
COPPA (United States): We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided personal information, we will delete it immediately.
Quebec Law 25: We do not knowingly collect personal information from any person under 16 in Quebec.
If you believe a child has provided personal information to Ruyte without appropriate consent, or if you are a parent wishing to review, correct, or delete your child's information, contact us immediately at privacy@ruyte.com. We will respond within 5 business days and take appropriate action.
17
Security & breach notification
Our security measures include:
- TLS 1.3 encryption for all data in transit
- Encryption at rest for the database and file storage (provided by infrastructure providers Supabase and Cloudinary per their published security standards)
- bcrypt (cost factor 12) password hashing — we cannot recover your password
- Multi-factor authentication (TOTP) available and encouraged for Ruyte staff with administrative access
- Periodic security reviews and vulnerability assessments
- Provider-hosted card fields — Ruyte never stores full card numbers or security codes
- Rate limiting and bot protection on all authentication endpoints
Data breach notification:
| Law | Trigger | Timeline | Who is notified |
|---|---|---|---|
| PIPEDA (Canada) | Real risk of significant harm to individuals | As soon as feasible | OPC + affected individuals |
| Quebec Law 25 | Confidentiality incident affecting personal information | Within 72 hours of becoming aware | Commission d'accès à l'information (CAI) + affected individuals |
| GDPR (EU) | Breach likely to result in risk to rights and freedoms | Within 72 hours | Supervisory authority + affected individuals |
In the event of a breach, we will: (1) contain and assess the incident, (2) notify regulators within required timeframes, (3) notify affected individuals with a plain-language description of what happened, what data was involved, and what steps you should take. To report a security concern, email security@ruyte.com.
18
Changes to this policy
When we make material changes, we will update the "Last updated" date, send an email notification to registered users, and display a prominent notice on the Platform for at least 14 days. Previous versions are available on request from privacy@ruyte.com.
19
Contact & complaints
Privacy Officer
We respond to all privacy inquiries within 30 days.
Privacy inquiries: privacy@ruyte.com
Security concerns: security@ruyte.com
General support: info@ruyte.com
Office of the Privacy Commissioner of Canada
Website: priv.gc.ca · Phone: 1-800-282-1376 · Address: 30 Victoria Street, Gatineau, QC K1A 1H3