Privacy Policy

Effective Date: May 19, 2025  ·  Contact:

1. Introduction

Rainföll ("we," "our," or "us") operates the website rainfoll.ca (the "Site") and sells shower positioning devices directly to consumers. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Site, sign up for our mailing list, make a purchase, or participate in our crowdfunding campaigns.

This Policy is designed to comply with applicable Canadian federal and provincial privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (Law 25 / Bill 64), the European Union's General Data Protection Regulation (GDPR), the United Kingdom's UK GDPR, and the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA).

By accessing or using our Site, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

2. Who We Are (Data Controller)

Rainföll is the data controller for the purposes of this Privacy Policy. We are a Canadian incorporated entity operating from Canada.

Contact Information:
Email:
Website: https://rainfoll.ca

3. Information We Collect

3.1 Information You Provide Directly

We collect information you voluntarily provide, including:

  • Full name and email address (when you sign up for our mailing list or reservation list)
  • Payment information (processed securely by Stripe — we do not store your full card number)
  • Billing and shipping address (for order fulfillment)
  • Phone number (if provided during checkout)
  • Communications you send us (e.g., support requests, questions)

3.2 Information Collected Automatically

When you visit our Site, we may automatically collect:

  • IP address and approximate geographic location
  • Browser type, device type, and operating system
  • Pages visited, time spent on pages, and navigation paths
  • Referring URLs and UTM campaign parameters
  • Cookie identifiers and analytics data (via Google Analytics 4)

3.3 Information from Third Parties

We may receive information from:

  • Stripe: payment confirmation and fraud signals
  • Google Analytics: aggregated usage data and conversion events
  • Email marketing platforms: open rates and engagement signals

4. How We Use Your Information

We use your personal information for the following purposes:

  • To process and fulfill your orders and reservations
  • To send you transactional emails (order confirmations, shipping updates)
  • To send you marketing communications (with your consent)
  • To analyze Site usage and improve our products and user experience
  • To detect and prevent fraud or unauthorized activity
  • To comply with legal obligations
  • To manage our customer support and respond to inquiries

We will not use your personal information for automated decision-making that produces legal or similarly significant effects without your explicit consent.

5. Legal Bases for Processing (GDPR / UK GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process your personal data under the following legal bases:

  • Contractual Necessity: Processing required to fulfill your order or reservation.
  • Legitimate Interests: Analytics, fraud prevention, and improving our products, where these interests are not overridden by your rights.
  • Consent: For marketing emails and non-essential cookies. You may withdraw consent at any time.
  • Legal Obligation: Where required by applicable law.

6. Cookies and Tracking Technologies

Our Site uses cookies and similar tracking technologies. These include:

  • Essential cookies: Required for basic Site functionality
  • Analytics cookies: Google Analytics 4, used to understand Site usage
  • Marketing cookies: Used to track campaign performance via UTM parameters

We display a cookie consent banner upon your first visit. Non-essential cookies are only activated after you provide consent. You may withdraw your consent or manage cookie preferences at any time through the cookie settings accessible on our Site.

For more information about how Google uses your data, see: https://policies.google.com/privacy

7. Sharing and Disclosure of Your Information

We do not sell your personal information. We may share your information with:

  • Stripe, Inc.: For payment processing. Stripe is PCI-DSS compliant. See stripe.com/privacy.
  • Google LLC: For analytics (Google Analytics 4). See policies.google.com/privacy.
  • Email Service Providers: To send transactional and marketing emails.
  • Logistics and fulfillment partners: To deliver your order.
  • Legal authorities: If required by law, court order, or to protect our rights.

All third-party processors are bound by contractual obligations to protect your data and use it only for the purposes we specify.

8. International Data Transfers

Your personal information may be transferred to and processed in countries outside your country of residence, including the United States and Canada. These countries may have different data protection laws than your home country.

For transfers from the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms, to ensure your data receives adequate protection.

For Quebec residents: Any communication of personal information outside Quebec is governed by a privacy impact assessment (PIA) and a written agreement ensuring equivalent protection, as required under Quebec Law 25.

9. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Policy, or as required by law:

  • Customer order data: 7 years (for tax and accounting purposes)
  • Marketing email lists: Until you unsubscribe or withdraw consent
  • Analytics data: Up to 14 months (Google Analytics default)
  • Support communications: 2 years after resolution

When personal information is no longer needed, we securely delete or anonymize it.

10. Your Rights

10.1 All Users (Canada — PIPEDA & Law 25)

  • Right to access the personal information we hold about you
  • Right to correct inaccurate or incomplete information
  • Right to withdraw consent for non-essential uses
  • Right to lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC) or the Commission d'accès à l'information du Québec (CAI)

10.2 Quebec Residents (Law 25 Enhanced Rights)

  • Right to data portability: Receive your data in a structured, commonly used, and technological format
  • Right to erasure ("right to be forgotten"): Request deletion of your personal information, subject to legal exceptions
  • Right to be informed of automated decision-making
  • Right to be notified of a privacy breach that presents a risk of serious injury

10.3 EEA and UK Residents (GDPR / UK GDPR)

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object to processing (Article 21)
  • Right to lodge a complaint with your local supervisory authority (e.g., CNIL in France, ICO in UK)

10.4 California Residents (CCPA / CPRA)

California residents have the right to:

  • Know what personal information we collect and how it is used
  • Delete personal information we have collected (subject to exceptions)
  • Opt-out of the sale or sharing of personal information (we do not sell personal information)
  • Non-discrimination for exercising your privacy rights
  • Correct inaccurate personal information
  • Limit the use of sensitive personal information

To exercise any of these rights, contact us at:

11. Children's Privacy

Our Site is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16 without verified parental consent, we will delete it promptly. If you believe we may have collected information from a child, please contact us at .

12. Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These measures include HTTPS encryption, access controls, and secure third-party processors.

However, no method of transmission over the internet is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.

In the event of a privacy breach that presents a risk of serious injury, we will notify affected individuals and the appropriate regulatory authorities as required by applicable law (including PIPEDA, Quebec Law 25, and GDPR).

13. Quebec Language Compliance

In compliance with the Charter of the French Language (Bill 101) and Quebec's consumer protection obligations, a French version of this Privacy Policy ("Politique de confidentialité") is available on this page by selecting "Français" above. In the event of any conflict between the English and French versions, the French version shall prevail for Quebec residents.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the effective date at the top of this Policy, and, where required by law, by providing notice via email or a prominent notice on our Site. We encourage you to review this Policy periodically.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Rainföll
Email:
Website: https://rainfoll.ca

We will respond to all requests within 30 days, as required by applicable law. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant privacy authority in your jurisdiction.