Privacy notice
Privacy notice.
Effective: [TBD-LEGAL]
Working draft pending legal review. Clauses bracketed with [TBD-LEGAL] are placeholders awaiting counsel sign-off. The final posted version supersedes this draft.
1. Who we are
- Norcut Railings LTD — British Columbia, Canada.
- Trade-only B2B supplier of aluminum railing systems.
- Contact: [TBD-LEGAL: privacy address — or fall back to sales contact].
2. What we collect
- Quote requests: name, company, role, email, phone, project details.
- Estimator submissions: the fields above plus the encoded estimator spec for the run.
- Stock-notify requests: email and qualifier (Contractor, Developer, Installer, or Other).
- Account applications: the fields above plus business credentials [TBD-LEGAL: enumerate required documents].
- Site analytics: pseudonymous page-view data via Google Analytics (Measurement ID G-L7DZ0S4Z7X). IP anonymization is on.
3. Why we collect it
- Respond to quote and notify requests.
- Maintain trade-account credentials and order history.
- Improve the site.
- We do not sell, rent, or trade personal information.
4. Legal basis (PIPEDA)
- Implied consent for sales communication initiated by the contact (quote, notify).
- Express consent for non-essential analytics (see Cookies below). [TBD-LEGAL: confirm with counsel].
5. Cookies
- Strictly necessary: session, CSRF, and Vercel deployment routing.
- Analytics: Google Analytics cookies (gtag.js). Loaded only in production. IP anonymization on.
- No advertising cookies. No third-party tracking.
6. Retention
- Quote and notify records: 5 years for trade-account history. [TBD-LEGAL: confirm].
- Analytics: 14 months default in GA4. [TBD-LEGAL: confirm with counsel].
- Backups: 90-day rolling.
7. Your rights
- Access, correction, and deletion of your records — write to [TBD-LEGAL: privacy contact].
- Withdraw consent for analytics at any time. Note: a cookie banner is not currently shown; we operate under PIPEDA implied-consent for B2B trade traffic. [TBD-LEGAL: confirm scope].
8. Cross-border data
Vercel hosts the site infrastructure. Customer data may transit US-based edge locations. [TBD-LEGAL: detail Vercel data residency and applicable PIPEDA cross-border disclosures].
9. Changes
We will note the effective date of any update at the top of this page.
10. Contact
Privacy inquiries: [TBD-LEGAL: dedicated privacy address]. General sales: [TBD-LEGAL: confirm sales address from contact page].
