Privacy policy
Version 2026-09 · Last updated September 9, 2026
This policy has not yet been reviewed by a lawyer.
This policy describes what PrintFlows does today. We'll post a new version, with a new date, when that changes.
PrintFlows is based in Montréal, Québec. We're subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and to Québec's Act respecting the protection of personal information in the private sector, as amended by Law 25.
This policy says what we collect, why, who sees it, where it lives, how long we keep it, and what you can make us do about it.
1. Who's responsible
Privacy questions: [email protected]
Under Law 25, PrintFlows has to have a person responsible for how it handles personal information. That person answers access and deletion requests, handles complaints, and signs off on privacy impact assessments before we start anything new that touches personal data.
Everything sent to [email protected] reaches them. [email protected] works too, and gets forwarded.
We answer within 30 days. If we need longer, we'll tell you why before those 30 days are up.
2. What we collect, and why
We collect only what a step actually needs.
2.1 When you create an account
| What | Why |
|---|---|
| Name | To identify you to a maker on an order |
| Email address | Sign-in, order updates, receipts |
| Password (stored as a hash, never in plain text) | To let you in and nobody else |
| Language preference | To show you the site and emails in English or French |
| Phone number (optional) | Passed to a carrier when a delivery goes wrong |
2.2 When you upload a file
The file itself, its name, its size, and the geometry we measure from it (volume, dimensions, triangle count, whether the mesh is closed). We don't inspect what your design is, and we don't index it for search.
2.3 When you place an order
Delivery address, delivery instructions, what you ordered, what you paid, the tax charged and the province it was based on, and the order's whole history.
We never see your card number. Card details go straight to Stripe. What comes back to us is the last four digits, the card brand, and whether the payment worked.
2.4 When you become a maker
Shop details, printers and materials, pricing, and (for verification) government photo ID, proof of address, and business registration where it applies. Your banking details go to Stripe, not to us.
2.5 When you use the site
Pages you looked at, your IP address, your browser and device type, and error reports when something breaks. Security logs (sign-ins, failed sign-ins, password changes) are kept whatever your cookie choices, because they're how we spot someone trying to break into your account.
Analytics stay off until you consent (section 6).
2.6 When you message someone
Messages between customers and makers are stored so both sides have a record and so we can look at them if a dispute comes up. Support conversations are stored the same way.
3. Our legal basis
Under Law 25 and PIPEDA we need your consent, or a legal basis, for each purpose. We rely on:
- Performing the contract: everything needed to take your order, get it printed, ship it, take payment and pay the maker. You can't opt out of this and still use the service.
- Legal obligation: keeping tax and payment records for the periods required by Canadian law.
- Legitimate interest: fraud prevention, security logging, and fixing errors.
- Your consent: analytics cookies, marketing email, and anything else marked optional. You can withdraw consent at any time, in your settings or through the unsubscribe link.
Withdrawing consent for something optional doesn't affect your orders.
4. Who we share it with
We don't sell personal information. We've never sold it, and this policy would have to change before we could.
4.1 Makers
When you send a quote request, the maker sees: your first name, your file and its print settings, your delivery province and, if you asked to be quoted on shipping, your postal code. They don't see your full address until you've paid and the order is theirs. They never see your email address, phone number or payment details through PrintFlows.
4.2 Service providers
| Provider | What they do for us | Where the data sits |
|---|---|---|
| Vercel | Hosts and serves the website | United States |
| Neon | Hosts our database | United States |
| Cloudflare | CDN, and R2 storage for uploaded files | United States |
| Stripe | Payments, payouts, identity data for makers | United States |
| Resend | Sends our email | United States |
| Upstash | Rate limiting and job scheduling | United States |
| Sentry | Error reporting | United States |
Each is bound by contract to use the data only to provide the service and to protect it.
4.3 When the law requires it
We disclose personal information when a valid legal demand requires it: a court order, a warrant, or a statutory obligation. Unless we're prohibited from telling you, we'll tell you.
4.4 If the business changes hands
If PrintFlows is sold or merged, account data would transfer with it. We'd tell you before that happened, and the buyer would be bound by this policy until they gave you notice of a new one.
5. Where your data is, and what that means
Your personal information is stored and processed in the United States, on the providers listed in section 4.2. It leaves Canada.
Law 25 requires us to say this plainly and to assess the transfer before making it. We've assessed each provider on: the contractual protections they offer, their security certifications, and the fact that US authorities can compel disclosure under laws such as the CLOUD Act and FISA, protections a Canadian resident cannot rely on the way a US person can.
Our judgement is that these transfers give the information adequate protection given how sensitive it is and how much of it there is. We use providers with signed data-processing agreements and standard contractual clauses, we encrypt in transit and at rest, and we send each provider only the fields it needs.
You should know this before you sign up. If US storage isn't acceptable to you, PrintFlows isn't the right service for you right now.
6. Cookies
Short version: essential cookies are always on because sign-in doesn't work without them. Analytics is off until you say yes. Nothing tracks you across other websites, and there are no advertising cookies.
The cookie policy has the full list and how to change your choices, which you can do at any time.
7. How long we keep things
| What | How long |
|---|---|
| Account details | While the account is open, then 30 days after you close it |
| Uploaded files | Until you delete them, or 12 months after their last order finishes |
| Orders, payments, invoices | 7 years after the order, as tax and accounting law requires |
| Messages between users | 3 years after the order finishes |
| Maker verification documents | Deleted within 90 days of a decision; we keep the decision itself |
| Support conversations | 3 years |
| Security logs | 12 months |
| Analytics (with consent) | 14 months |
| Audit log of administrative actions | 7 years |
A scheduled job runs the deletions. Anything past its retention period is removed even if nobody asks.
The 7-year hold on financial records is why deleting your account doesn't erase your order history: we're required to keep it. What we do is disconnect it from your profile and strip what isn't needed to satisfy the record-keeping rule.
8. Your rights
Under PIPEDA and Law 25 you can:
- See what we hold about you. A written answer, or a machine-readable export.
- Get it corrected if it's wrong.
- Get a portable copy: a structured file you can take elsewhere (Law 25 data portability, in force since September 2024).
- Ask us to delete it, subject to the retention we're legally required to keep.
- Withdraw consent for anything optional.
- Object to automated decision-making. PrintFlows doesn't make decisions about you by algorithm alone: maker matching is a filter, not a decision, and verification and disputes are decided by a person. If that ever changes, we'll tell you and give you a way to ask for human review.
- Complain. To our privacy officer first. If you're not satisfied, to the Commission d'accès à l'information du Québec, or to the Office of the Privacy Commissioner of Canada.
Two of these are self-serve, in your settings: Download your data and Delete your account. For the rest, write to the privacy officer.
We don't charge for these requests. We'll ask you to confirm who you are before we act on one, so nobody else can use it against you.
9. Keeping it safe
- Everything moves over TLS, and is encrypted at rest by our providers.
- Passwords are hashed with a slow algorithm designed for the job. We can't read yours.
- New passwords are checked against known breach lists. Length matters more than symbols.
- Two-factor sign-in is available to everyone and required for administrators.
- Access to production data is limited to people who need it, and administrative actions are written to an audit log with a name and a timestamp.
- Card data never touches our servers. Maker banking data never touches our servers.
- Errors are reported to Sentry with personal fields stripped.
No system is perfectly secure. What we can promise is that we designed for the failure cases and that we'll tell you when one happens.
10. If there's a breach
If a confidentiality incident creates a risk of serious harm, Law 25 requires us to notify the Commission d'accès à l'information and the people affected without delay. PIPEDA requires much the same.
We will:
- Contain it and work out what was reached.
- Notify the CAI and the Office of the Privacy Commissioner where the threshold is met.
- Email everyone affected, in plain language: what happened, what data, what we've done, what you should do.
- Record it in our incident register, which Law 25 requires us to keep whether or not the incident was reportable.
We won't sit on a breach while we decide how it looks.
11. Children
PrintFlows isn't for people under 18, and we don't knowingly collect their information. If you think a child has given us personal information, write to the privacy officer and we'll delete it.
12. Changes to this policy
We'll post any change here with a new version and date. For a change that materially affects your rights, we'll email registered users at least 30 days before it takes effect. Where a change requires new consent under Law 25, we'll ask for it rather than assume it.
13. How to reach us
Privacy: [email protected]
General: [email protected]
Post: PrintFlows, Montréal, Québec, Canada
Commission d'accès à l'information du Québec: cai.gouv.qc.ca
Office of the Privacy Commissioner of Canada: priv.gc.ca
PrintFlows · Montréal, Québec, Canada