- Introduction and Data Controller
This Privacy Policy outlines how Linesmarthost (“we”, “us”, “our”) collects, uses, processes, and protects personal data obtained from visitors and customers (“you”, “your”) accessing our website at www.linesmarthost.com.
For the purposes of applicable data protection legislation—including the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), the EU General Data Protection Regulation (EU GDPR), the UK General Data Protection Regulation (UK GDPR), and applicable United States federal and state privacy laws—the data controller responsible for your personal information is:
Linesmarthost
Address: 1280 Dundas Street West, Toronto, ON M6J 1X2, Canada
Telephone: +1 (416) 762-7829
Email: restaurant@linesmarthost.com
- Personal Data We Collect
We collect personal information necessary to operate our commercial activities and fulfill transaction requests. The categories of data collected include:
Contact Information: Name, billing address, shipping address, email address, and telephone number.
Order and Transaction Details: Records of physical products purchased, delivery locations, transaction timing, and related communications.
Technical and Usage Data: IP address, browser type, device information, operating system, pages visited, and interaction logs collected via automated tracking tools.
- Purpose and Legal Grounds for Data Processing
We process personal data based on specific, defined legal grounds under global privacy frameworks:
Contract Performance: Processing required to receive payments, assemble packages, manage logistics, and deliver physical products ordered on our website.
Legal Compliance: Processing required to fulfill statutory accounting, taxation, customs disclosure, and commercial auditing obligations in Canada, Europe, and the United States.
Legitimate Interests: Processing required to maintain operational security, audit administrative records, improve general user experience, and prevent unlawful commercial activities.
Consent: Where applicable (such as direct promotional communication), processing is conducted based on explicit consent, which may be withdrawn at any time.
- Payment Processing and Third-Party Services
We do not store or directly handle sensitive credit card or debit card numbers on our local servers.
All financial transactions submitted through our website are transmitted directly to and processed by our third-party payment infrastructure provider, Stripe.
When an order is submitted, Stripe collects financial payment credentials, billing verification details, and transaction information to process payment authorization. The management of financial data by Stripe is governed by Stripe’s privacy policy and compliance controls.
We share contact and shipping details with logistical, warehousing, and transportation partners exclusively for the purpose of dispatching and delivering physical orders.
- Data Retention
We retain personal data only for as long as necessary to achieve the specific purposes outlined in this policy, including satisfying legal, regulatory, accounting, or reporting requirements.
Transactional and Order Data: Retained for up to seven (7) years following completion of an order to satisfy statutory taxation, commercial record-keeping, and legal compliance obligations in Canada, the European Union, the United Kingdom, and the United States.
Technical Log Data: Retained for up to twelve (12) months for internal network analysis and administration.
Communication Records: Retained for up to two (2) years from the date of last correspondence to handle standard customer inquiries.
Upon the expiry of applicable retention periods, personal data is securely deleted, overwritten, or anonymised.
- International Data Transfers
As a business operating in Canada, personal data collected from customers located in the European Economic Area (EEA), the United Kingdom, or the United States is processed and stored in Canada and other international jurisdictions where service providers operate.
Canada is recognised by the European Commission and the UK Government as providing an adequate level of personal data protection. When data is processed in or transferred to other jurisdictions, appropriate technical, contractual, and organisational measures are maintained in accordance with standard contractual clauses and relevant international data protection regulations.
- Individual Rights
Depending on your geographic location, you possess specific legal rights regarding your personal information:
Access and Rectification: You may request access to the personal data held about you or request corrections to inaccurate records.
Erasure (Right to be Forgotten): You may request the deletion of your personal data, subject to statutory obligations requiring continuous retention (such as tax compliance).
Restriction and Objection: You may object to data processing activities or request limits on specific processing activities.
Data Portability: You may request a copy of provided data in a structured, commonly used format.
Withdrawal of Consent: Where processing relies on consent, you may revoke that consent at any time without affecting prior lawful processing.
To exercise any of these rights, please contact us using the communication details provided in Section 1.
- Data Security Measures
We implement administrative, physical, and technical safeguards designed to protect personal data against unauthorised access, alteration, disclosure, or destruction.
Please note that no transmission method over the Internet or electrical storage infrastructure can be represented as completely impenetrable. While rigorous commercial standards are maintained, absolute security cannot be guaranteed.
- California and U.S. State Privacy Disclosures
For residents of California and applicable US jurisdictions:
We do not sell personal information to third parties.
We do not share personal information for cross-context behavioural advertising.
Residents have the right to request access, correction, and deletion of personal data without discriminatory treatment.
You also retain the legal right to lodge a formal complaint with the competent supervisory authority in your jurisdiction, such as the Office of the Privacy Commissioner of Canada (OPC), a European Data Protection Authority, the UK Information Commissioner’s Office (ICO), or your state Attorney General.