Privacy Policy
Last updated: May 2025 · Soca Sizzle Distributors Ltd.
1. Who We Are
Soca Sizzle Distributors Ltd. (“Soca Sizzle”, “we”, “us”, or “our”) is a Canadian company registered in Ontario that imports and distributes authentic Caribbean products and fresh produce across Canada. Our website is socasizzledistributorsltd.ca. This Privacy Policy explains how we collect, use, disclose, and protect your personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
2. Information We Collect
We collect the following categories of personal information:
- Account information: Name, email address, phone number, and password (stored as a one-way hash).
- Order information: Delivery address, order history, product preferences, and order notes.
- Payment information: We do not store your credit card details. Payments are processed securely by Square (see Section 4).
- Business information (wholesale): Company name, business registration details, and purchasing volume for wholesale applications.
- Usage data: Pages visited, session duration, and interaction events collected via PostHog analytics (see Section 4).
- Error data: Technical error reports collected via Sentry to help us identify and fix bugs.
3. How We Use Your Information
- To process and fulfill your orders and communicate order status.
- To send transactional emails (order confirmations, delivery updates, receipts).
- To send review invitation emails after your order is fulfilled (you may opt out at any time).
- To manage your account, saved addresses, and preferences.
- To evaluate and manage wholesale partner applications.
- To improve our website, product catalog, and customer experience.
- To comply with Canadian tax, legal, and regulatory obligations.
4. Third-Party Services
We share your information with the following trusted third-party services only to the extent necessary to operate our platform:
- Square (squareup.com): Processes all credit and debit card payments. Your card details are sent directly to Square and never touch our servers. Square is PCI-DSS Level 1 certified.
- Resend (resend.com): Delivers transactional emails on our behalf. Your email address is shared with Resend solely to deliver emails you have requested or consented to.
- Vercel (vercel.com): Hosts our website and application infrastructure. Your data is processed on Vercel's servers in accordance with their privacy policy.
- Supabase (supabase.com): Stores your account, order, and application data in a secure PostgreSQL database hosted in Canada or the United States.
- PostHog (posthog.com): Collects anonymized usage analytics (page views, funnel events). No personally identifiable information is sent to PostHog.
- Sentry (sentry.io): Receives technical error reports. Error data may include session context but is used solely for debugging.
We do not sell, rent, or trade your personal information to any third party for marketing purposes.
5. Cookies and Tracking
Our website uses cookies and local storage to maintain your session (login state), save your shopping cart between visits, and remember your unit preference (lbs/kg). We use analytics cookies (PostHog) to understand how visitors use our site. You may disable cookies in your browser settings, though this may affect site functionality.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to fulfill the purposes described in this policy. Order records are retained for a minimum of 7 years to comply with Canadian tax and accounting requirements. You may request deletion of your account and associated personal information at any time (see Section 8).
7. Security
We implement industry-standard security measures including encrypted data transmission (HTTPS/TLS), one-way password hashing (bcrypt), JWT-based authentication with 8-hour session expiry, and access controls that restrict data access to authorized personnel only. Payment data is handled entirely by Square and is never stored on our servers.
8. Your PIPEDA Rights
Under PIPEDA, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information in your account.
- Withdraw consent for non-essential communications (e.g., review invitations) at any time.
- Request deletion of your account and personal data, subject to legal retention requirements.
- Lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) if you believe your rights have been violated.
To exercise any of these rights, contact us at support@socasizzledistributorsltd.ca. We will respond within 30 days.
9. Children's Privacy
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on our website. Your continued use of our services after changes take effect constitutes your acceptance of the revised policy.
11. Contact Us
For privacy-related questions or requests, contact our Privacy Officer at:
Soca Sizzle Distributors Ltd.
Ontario, Canada