For the purposes of this Privacy Policy, the following terms have the meanings set out below. Capitalized terms not defined herein have the meanings assigned to them in the SSMS Terms of Service.
"Authorized User" means any individual granted access to the Platform by a Client, including Client Admins, Standard Users, and Viewers.
"CAI" means the Commission d'accès à l'information du Québec, the supervisory authority responsible for overseeing compliance with Quebec privacy legislation.
"Client Data" means all data, content, and materials uploaded, submitted, or stored on the Platform by or on behalf of a Client, including SKU data, product images, PDF specification sheets, marketing assets, metadata, and product information. Client Data is primarily publicly available product information and is not classified as personal data.
"Data Controller" means the entity that determines the purposes and means of processing personal data. SSMS is the Data Controller for personal data collected through the Platform and landing page.
"OPC" means the Office of the Privacy Commissioner of Canada, the federal supervisory authority responsible for overseeing compliance with PIPEDA.
"Personal Data" means any information about an identifiable individual, as defined under the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act respecting the protection of personal information in the private sector (Law 25).
"Platform" means the Smart SKU Management System web application (app.smartskumanagementsystem.com) and all associated services, APIs, and infrastructure operated by SSMS.
"Privacy Officer" means the individual designated by SSMS as responsible for privacy compliance, as required by Quebec Law 25.
"Prospect" means an individual who submits information through the SSMS marketing site (smartskumanagementsystem.com) inquiry form but has not entered into a subscription agreement with SSMS.
2.1 Manuel Delorme, carrying on business as a sole proprietorship (entreprise individuelle) under the registered trade name « Smart SKU Management System », registered in the Québec enterprise register under NEQ 2281430332 ("SSMS"), is the Data Controller for all personal data collected through the Platform and the SSMS marketing site. SSMS is not an incorporated entity; the Data Controller, and the person accountable under PIPEDA and Quebec Law 25, is Manuel Delorme personally.
2.2 In accordance with Quebec Law 25, SSMS has designated a Privacy Officer responsible for ensuring compliance with applicable privacy legislation, handling privacy inquiries, and overseeing the organization's personal data practices.
2.3 The Privacy Officer may be contacted at:
2.4 All privacy-related inquiries, complaints, requests to exercise data subject rights, and correspondence with the OPC or CAI should be directed to the Privacy Officer at the contact information above.
3.1 This Privacy Policy applies to all personal data collected, used, disclosed, and stored by SSMS through:
(a) the Platform, including account registration, authentication, and platform usage;
(b) the SSMS marketing site, including the prospect inquiry form; and
(c) any direct communications between SSMS and individuals in connection with the Platform or related services.
3.2 This Privacy Policy does not apply to:
(a) Client Data (product information, SKU data, digital assets, and metadata) uploaded by Clients to the Platform — Client Data consists of publicly available product information and is governed by the Terms of Service and Data Processing Agreement; or
(b) the practices of third-party websites, services, or platforms that may be linked from the SSMS marketing site or Platform.
3.3 SSMS is committed to compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act respecting the protection of personal information in the private sector (Law 25) in all its personal data handling practices.
4.1 SSMS collects the following categories of personal data:
| Category | Data Elements | Source |
|---|---|---|
| Account Information | Full name, email address, job title, organization name | Provided by the Client Admin during user provisioning or account registration |
| Authentication Data | Login credentials (managed by Clerk), session tokens | Generated during account creation and authentication |
| Network and Device Data | IP addresses, browser type and version, device type, operating system | Collected automatically during Platform access |
| Usage Data | Pages viewed, features used, actions performed, timestamps of activity | Collected automatically during Platform usage |
| Communication Data | Correspondence with SSMS, support requests, feedback | Provided directly by the individual |
| Prospect Inquiry Data | Name, company name, email address, use case description | Provided by Prospects via the landing page inquiry form |
| Self-Serve Signup Data | Full name, work email address, company name, IP address, timestamp | Provided directly by a prospective customer at self-serve signup, before a tenant account is created |
| Legal Consent Record | The legal-document versions accepted (ToS, Privacy Policy, DPA, AUP), content hashes, the signer's IP address, and timestamp | Recorded automatically when the signer affirmatively accepts the click-wrap at signup (immutable, append-only) |
| Billing Data | Billing contact name and email, billing address, business tax identifiers | Provided at checkout and processed by Stripe; payment-card data is held by Stripe, not stored by SSMS |
4.2 SSMS does not intentionally collect:
(a) sensitive personal data, including health information, biometric data, financial account numbers, government-issued identification numbers, or information about racial or ethnic origin, political opinions, religious beliefs, or sexual orientation;
(b) personal data from minors under the age of eighteen (18); or
(c) personal data beyond what is described in Section 4.1.
5.1 SSMS collects and processes personal data for the following purposes:
| Purpose | Data Categories Used | Justification |
|---|---|---|
| Account Management | Account Information, Authentication Data | Creating and maintaining user accounts, managing access permissions, and provisioning Authorized Users within Client Tenants |
| Service Delivery | Account Information, Network and Device Data, Usage Data | Operating the Platform, authenticating users, delivering features, and ensuring service functionality |
| Platform Analytics | Usage Data, Network and Device Data | Understanding Platform usage patterns, identifying areas for improvement, and informing product development decisions. Analytics are performed on aggregated, anonymized data where possible |
| Communication | Account Information, Communication Data | Responding to inquiries, providing support, delivering service notifications, and communicating changes to the Platform or these terms |
| Security and Fraud Prevention | Network and Device Data, Authentication Data, Usage Data | Detecting and preventing unauthorized access, monitoring for security threats, and maintaining the integrity of the Platform |
| Legal Compliance | All categories as necessary | Fulfilling legal obligations, responding to regulatory inquiries, and maintaining records required by applicable law |
| Prospect Management | Prospect Inquiry Data | Responding to prospect inquiries, evaluating business fit, and following up on potential client engagements |
5.2 SSMS does not process personal data for any purpose other than those described in Section 5.1, unless additional consent is obtained or processing is otherwise permitted by applicable law.
6.1 Under PIPEDA, SSMS relies on the following legal bases for the collection, use, and disclosure of personal data:
(a) Consent — Authorized Users consent to the collection and processing of their personal data through acceptance of the Terms of Service by the Client Admin on behalf of the Client organization. Prospect consent is obtained through the landing page inquiry form submission.
(b) Legitimate Business Interest — SSMS processes aggregated, anonymized usage data for platform analytics and product improvement. This processing does not involve identifiable personal data and serves the legitimate interest of improving service quality.
(c) Legal Obligation — SSMS processes personal data as necessary to comply with applicable laws, including PIPEDA, Law 25, and other regulatory requirements.
6.2 SSMS limits the collection of personal data to what is necessary for the identified purposes (PIPEDA Principle 4: Limiting Collection) and does not use or disclose personal data for purposes other than those for which it was collected, except with consent or as required by law (PIPEDA Principle 5: Limiting Use, Disclosure, and Retention).
7.1 For Authorized Users, consent to the collection and processing of personal data is obtained through the Client Admin's acceptance of the Terms of Service on behalf of the Client organization. The Client is responsible for ensuring that its Authorized Users are informed of this Privacy Policy and the personal data collected in connection with their use of the Platform.
7.2 For Prospects, consent is obtained at the point of data collection through the landing page inquiry form, which includes a clear notice referencing this Privacy Policy.
7.3 Consent may be withdrawn at any time by contacting the Privacy Officer at the address specified in Section 2.3. Withdrawal of consent may result in SSMS's inability to provide the Services or respond to inquiries, as applicable. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
7.4 SSMS obtains explicit, informed consent as required by Quebec Law 25 for all personal data collection. Consent is not bundled with unrelated terms, and the purposes of data collection are clearly communicated at the point of collection.
7.5 Self-Serve Signup (Click-Wrap). For self-serve customers, the prospective customer provides explicit, informed consent at signup by affirmatively accepting the Terms of Service, this Privacy Policy, the Data Processing Agreement, and the Acceptable Use Policy through a conspicuous, not-pre-checked click-wrap action, before any payment or account creation. SSMS records the accepted document versions, content hashes, the signer's IP address, and the timestamp as an immutable record of consent.
7.6 Privacy by Default; Profiling and Cookies. Consistent with Quebec Law 25, SSMS applies privacy by default: any optional privacy settings default to the highest level of privacy. SSMS does not engage in profiling or behavioural advertising. SSMS uses cookies and similar technologies that are strictly necessary to operate the Platform (for example, authentication and session management); any non-essential cookies or analytics technologies, if used, are deployed only with the individual's separate, explicit, opt-in consent.
8.1 SSMS uses the following third-party service providers to process personal data in connection with the operation of the Platform:
| Service | Provider | Purpose | Personal Data Handled | Location |
|---|---|---|---|---|
| Amazon RDS for PostgreSQL | Amazon Web Services, Inc. | Per-tenant relational database | User account records, audit logs | us-east-1 (United States) |
| Amazon S3 | Amazon Web Services, Inc. | Asset storage, Legal Vault document archival | Signed legal documents containing signer identity | us-east-1 (United States) |
| Clerk | Clerk, Inc. | User authentication, identity, and session management | User identity, email, name, authentication metadata, session tokens | United States |
| Amazon SES | Amazon Web Services, Inc. | Transactional email delivery (notifications, legal-activation prompts) | Recipient email addresses, email subject and body | us-east-1 (United States) |
| Amazon CloudWatch | Amazon Web Services, Inc. | Infrastructure monitoring and logging | Usage metrics, application logs | us-east-1 (United States) |
| Amazon SNS | Amazon Web Services, Inc. | Operational alarm delivery to the operator | Operational metadata only (no Personal Data) | us-east-1 (United States) |
| AWS Secrets Manager | Amazon Web Services, Inc. | Storage of platform credentials/configuration secrets | Service credentials only (no Personal Data) | us-east-1 (United States) |
| Amazon KMS | Amazon Web Services, Inc. | Management of data-at-rest encryption keys | Encryption keys only (no Personal Data) | us-east-1 (United States) |
| Amazon CloudFront | Amazon Web Services, Inc. | Content delivery network: Platform application and marketing-site delivery; public-link asset distribution (legacy/fallback of two CDN vendors) | Request IP, request timestamp, application and asset content | Global edge network (origin: us-east-1) |
| Bunny.net | BunnyWay d.o.o. (Slovenia, EU) | Content delivery network + edge storage for public-link asset distribution (one of two CDN vendors) | Request IP, request timestamp, asset binary content | Edge storage: New York (United States); global edge cache incl. Toronto |
| Stripe | Stripe, Inc. / Stripe Payments Canada Ltd. | Payment processing, subscription billing, Stripe Tax (GST/HST + QST) | Billing contact name and email, billing address, payment-card data (held by Stripe as PCI-DSS Level 1 processor; SSMS does not store card numbers), business tax identifiers | United States |
| Cloudflare | Cloudflare, Inc. | Authoritative DNS resolution; inbound email routing (Email Routing) | DNS query data; inbound email addresses (no Client Data) | Global anycast network |
8.2 The Amazon Web Services, Inc. subprocessors listed in Section 8.1 maintain SOC 2 Type II, ISO 27001, and ISO 27018 certifications. Clerk, Inc. maintains SOC 2 Type II certification and hosts authentication and identity data in the United States. Cloudflare, Inc. maintains SOC 2 Type II and ISO 27001. Stripe, Inc. maintains PCI-DSS Level 1, SOC 1 and SOC 2 Type II, and ISO 27001 certifications. Bunny.net (BunnyWay d.o.o.) is certified to ISO/IEC 27001 (information-security management; certified September 2024) and represents that it processes data in compliance with the EU GDPR. Current certifications are available from each provider on reasonable request.
8.3 SSMS shall notify Clients of changes to its subprocessors with at least thirty (30) days' prior written notice, as further described in the Data Processing Agreement.
8.4 SSMS requires all subprocessors to implement appropriate technical and organizational measures to protect personal data and to process such data only in accordance with SSMS's documented instructions.
9.1 All personal data collected by SSMS is hosted in the United States. The core application infrastructure (database, storage, transactional email, monitoring) is operated by Amazon Web Services in its us-east-1 region (United States). User authentication, identity, and session data is managed by Clerk (Clerk, Inc.), hosted in the United States. Public-link asset content is additionally delivered and cached by two content-delivery networks — Amazon CloudFront and Bunny.net; Bunny.net edge storage is located in New York, United States (the CDN vendor offers no Canadian storage region), with global edge caching that may include a Toronto edge node. Payment and billing data is processed by Stripe in the United States. DNS resolution and inbound email routing for SSMS domains are provided by Cloudflare on its global network. No personal data is stored at rest in Canada.
9.2 As required by Section 17 of Quebec's Act respecting the protection of personal information in the private sector (Law 25), SSMS discloses the following regarding the cross-border transfer of personal data:
(a) Purpose of Transfer: Personal data is transferred to the United States for the purpose of hosting, storing, and processing such data on cloud infrastructure necessary to operate the Platform and deliver the Services.
(b) Recipients: (i) Amazon Web Services, Inc., a subsidiary of Amazon.com, Inc., headquartered in Seattle, Washington, United States, operating the core Platform infrastructure; (ii) Clerk, Inc. (United States), providing user authentication, identity, and session management; (iii) Bunny.net, operated by BunnyWay d.o.o. (Slovenia, EU), operating one of the two content-delivery networks, with edge storage in New York, United States; (iv) Stripe (Stripe, Inc., United States, and/or Stripe Payments Canada Ltd.), processing payment and billing data; and (v) Cloudflare, Inc. (United States), providing DNS resolution, edge security, and inbound email routing for SSMS domains on its global network, processing DNS query data and inbound email envelope and message data.
(c) Protection Measures: The following safeguards are in place to protect personal data transferred outside of Canada:
9.3 Individuals may obtain additional information about the cross-border transfer of their personal data by contacting the Privacy Officer at the address specified in Section 2.3.
10.1 SSMS retains personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable law (PIPEDA Principle 5: Limiting Use, Disclosure, and Retention).
10.2 The following retention periods apply:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Active User Accounts | Duration of the Client's subscription | Personal data retained as long as the account is active and the Client maintains a subscription |
| Cancelled / Suspended Tenant Account Data | Thirty (30) days from the start of the post-cancellation grace state, then permanently and irreversibly deleted (cryptographic decommissioning), subject to any legal hold | A 30-day reactivation / export window measured from the cancellation-effective (grace) date; after it the data is cryptographically shredded. Matches the Billing Terms and SSMS's automated, audited retention process |
| Legal Consent Records | Retained in a write-once (WORM) legal vault for the duration of the subscription plus a statutory retention period (currently set to seven (7) years) | Required to evidence the customer's acceptance of the agreements (proof of consent), per the platform's immutable legal-vault retention |
| Abandoned Signup Consent Records | Pre-tenant click-wrap consent records for signups that do not result in a paid subscription are expired and garbage-collected shortly after signup, and are never bound to a later account | Avoids retaining orphaned consent records for signups abandoned before payment |
| Authentication Logs and Audit Records | Retained for a minimum of one (1) year after account closure, or longer if required by applicable law | Required for security auditing, regulatory compliance, and incident investigation |
| Usage-Metering Data (SKU volume, slot-x-SKU rollups) | Retained per-tenant daily for the duration of the subscription plus a configurable window of up to ninety (90) days for rolling analytics; aggregated, de-identified rollups may be retained indefinitely for capacity-planning purposes | Required for subscription-tier capacity monitoring, migration prediction, and fair-use overage detection (ref: Epic 42 usage-metering architecture; see docs/stories/epic-42-per-tenant-usage-metering/42-4-usage-data-retention-and-integrity.md) |
| Prospect Inquiry Data | Twelve (12) months from the date of submission, or until deletion is requested by the Prospect, whichever is earlier | Retained to allow reasonable follow-up; deleted after the retention period or upon request |
| Communication Records | Duration of the business relationship plus two (2) years, or longer if required by applicable law | Retained for continuity of support and dispute resolution |
10.3 Upon expiration of the applicable retention period, personal data is permanently deleted from all active systems, databases, and storage. Where technically feasible, deletion is verified and documented.
10.4 SSMS may retain anonymized, aggregated data that does not identify any individual indefinitely for the purposes of platform analytics and product improvement.
11.1 In accordance with PIPEDA and Quebec Law 25, individuals whose personal data is held by SSMS have the following rights:
(a) Right of Access — the right to request confirmation of whether SSMS holds personal data about them and, if so, to obtain a copy of that data in a comprehensible format;
(b) Right of Correction — the right to request correction of personal data that is inaccurate, incomplete, or ambiguous;
(c) Right of Deletion — the right to request deletion of personal data that is no longer necessary for the purposes for which it was collected, subject to SSMS's legal retention obligations;
(d) Right of Portability — the right to request that personal data be provided in a structured, commonly used, and machine-readable format, to the extent technically feasible; and
(e) Right to Withdraw Consent — the right to withdraw consent to the collection, use, or disclosure of personal data, subject to legal or contractual restrictions.
11.2 Response Timelines. SSMS shall respond to all data subject rights requests within thirty (30) days of receipt, as required by PIPEDA. If SSMS is unable to fulfill a request within this timeframe, the individual will be notified of the reason for the delay and the expected date of response.
11.3 How to Exercise Rights. Data subject rights requests should be submitted to the Privacy Officer at the contact information provided in Section 2.3. SSMS may require identity verification before processing a request to prevent unauthorized access to personal data.
11.4 Denial of Requests. SSMS may deny a data subject rights request in whole or in part where:
(a) the request is unfounded, excessive, or repetitive;
(b) providing access would reveal confidential commercial information;
(c) the data is subject to legal privilege; or
(d) denial is otherwise permitted by applicable law.
In the event of a denial, SSMS shall provide written reasons for the denial and inform the individual of their right to file a complaint with the OPC or the CAI (PIPEDA Principle 10: Challenging Compliance).
12.1 SSMS implements technical and organizational measures to protect personal data against loss, unauthorized access, disclosure, alteration, and destruction (PIPEDA Principle 7: Safeguards). These measures include:
12.2 Encryption:
(a) All personal data at rest is encrypted using AES-256 encryption.
(b) All personal data in transit is encrypted using TLS 1.2 or higher.
12.3 Tenant Isolation:
(a) Each Client operates within a dedicated Tenant consisting of a dedicated Amazon RDS for PostgreSQL database, dedicated S3 storage prefix, and a dedicated Clerk Organization scoping its users' identities and authentication.
(b) Tenant isolation ensures complete separation of personal data between Clients — no co-mingling of user data occurs.
12.4 Access Controls:
(a) SSMS implements role-based access controls for all internal personnel.
(b) Access to personal data is restricted to SSMS personnel with a documented need-to-know for the performance of their duties.
(c) All administrative access is logged in immutable, append-only audit trails.
12.5 Audit Logging:
(a) All administrative actions on the Platform are recorded in immutable, append-only audit logs.
(b) Audit logs are retained and protected against tampering.
12.6 Legal Vault:
(a) Signed legal documents are archived using S3 Object Lock (Write Once Read Many) — providing tamper-proof, immutable records of consent.
12.7 SSMS reviews and updates its security measures periodically to address evolving threats and to maintain an appropriate level of protection for personal data.
13.1 In the event of a confidentiality incident involving personal data that presents a risk of serious injury to affected individuals, SSMS shall:
(a) notify the Commission d'accès à l'information du Québec (CAI) within seventy-two (72) hours of becoming aware of the incident, as required by Quebec Law 25;
(b) notify affected individuals without unreasonable delay, providing:
(c) where applicable, notify the Office of the Privacy Commissioner of Canada (OPC) in accordance with PIPEDA's breach notification requirements; and
(d) notify affected Clients in accordance with the Data Processing Agreement.
13.2 SSMS maintains a register of all confidentiality incidents, including those that do not meet the threshold for notification, as required by Law 25.
13.3 SSMS shall cooperate with affected individuals, Clients, and regulatory authorities in the investigation and resolution of any confidentiality incident.
14.1 When a Prospect submits the landing page inquiry form, SSMS collects: name, company name, email address, and use case description.
14.2 Prospect data is collected for the purposes of:
(a) responding to the Prospect's inquiry;
(b) evaluating business fit and potential engagement; and
(c) following up with the Prospect regarding SSMS's services.
14.3 Prospect data is retained for a maximum of twelve (12) months from the date of submission, or until the Prospect requests deletion, whichever is earlier.
14.4 Prospects may request deletion of their data at any time by contacting the Privacy Officer at the address specified in Section 2.3. SSMS shall process deletion requests within thirty (30) days.
14.5 If a Prospect enters into a subscription agreement with SSMS, their data transitions to the "Active User Accounts" retention category described in Section 10.2.
15.1 SSMS does not sell, rent, trade, or otherwise disclose personal data to third parties for commercial or marketing purposes.
15.2 SSMS discloses personal data to third parties only as described in Section 8 (Third-Party Data Processors and Subprocessors) and only for the purposes identified in this Privacy Policy.
16.1 In accordance with Quebec Law 25, SSMS is committed to conducting Privacy Impact Assessments (PIAs) for:
(a) any new project, system, or initiative involving the collection, use, or disclosure of personal data;
(b) any material change to existing data processing practices; and
(c) any transfer of personal data outside of Quebec.
16.2 PIAs are conducted under the oversight of the Privacy Officer and are used to identify and mitigate privacy risks before implementation.
16.3 The results of PIAs inform SSMS's data protection practices and are retained as part of SSMS's compliance records.
17.1 SSMS may update this Privacy Policy from time to time to reflect changes in data processing practices, legal requirements, or business operations.
17.2 Material Changes. For material changes — including changes to the categories of personal data collected, the purposes of processing, data sharing practices, or data subject rights — SSMS shall:
(a) provide at least thirty (30) days' prior written notice to affected individuals (for Authorized Users, via notice to the Client Admin);
(b) update the "Last Updated" date and version number at the top of this document; and
(c) where required, obtain renewed consent before implementing the changes.
17.3 Non-Material Changes. Non-material changes (formatting corrections, typographical fixes, clarifications that do not alter the substance of any provision) may be made without prior notice. A changelog of all non-material changes shall be maintained and made available upon request.
17.4 The current version of this Privacy Policy is always available on the SSMS marketing site and within the Platform.
For all privacy-related inquiries, data subject rights requests, complaints, or questions about this Privacy Policy, please contact:
Privacy Officer Manuel Delorme — o/a « Smart SKU Management System » (sole proprietorship, NEQ 2281430332) Name: Manuel Delorme, Founder & Privacy Officer Email: privacy@smartskumanagementsystem.com Mailing Address: 305-2370, rue Belvédère Sud, Sherbrooke, QC, J1H 0N8, Canada
If you are not satisfied with SSMS's response to a privacy inquiry or complaint, you have the right to file a complaint with:
This Privacy Policy is structured to satisfy PIPEDA's 10 fair information principles:
| Principle | Section(s) |
|---|---|
| 1. Accountability | Sections 2, 16, 18 |
| 2. Identifying Purposes | Sections 5, 14 |
| 3. Consent | Section 7 |
| 4. Limiting Collection | Sections 4, 6.2 |
| 5. Limiting Use, Disclosure, and Retention | Sections 5.2, 6.2, 10, 15 |
| 6. Accuracy | Section 11.1(b) |
| 7. Safeguards | Section 12 |
| 8. Openness | Sections 3, 17 |
| 9. Individual Access | Section 11 |
| 10. Challenging Compliance | Sections 11.4, 18 |
This document is publicly accessible on the SSMS marketing site and within the Platform. The Privacy Officer may be contacted at the address specified in Section 18 for any questions or concerns.