Privacy Policy
Effective date: June 25, 2026 | Last updated: June 25, 2026
1. Introduction and Scope
This Privacy Policy explains how Deepika Shukla, carrying on business as The Chanderi Cedar ("The Chanderi Cedar," "we," "us," or "our") collects, uses, discloses, retains, and protects your personal information when you visit our website at www.thechandericedar.com (the "Site"), contact us, or otherwise interact with us, and in connection with the products we sell through third-party marketplaces (together, the "Services").
How our sales work. Our Site is an informational and brand website used to showcase our handcrafted products; we do not sell products or process payments directly through the Site. Purchases are made through third-party online marketplaces — currently Etsy, Amazon, Faire, The Folklore, and Wolf & Badger — which operate their own checkout, payment, and shipping and are governed by their own privacy policies (see Sections 3 and 9). Our products are available to customers in Canada and internationally, depending on the marketplace.
In this Policy, "you" means any individual whose personal information we handle — including customers, prospective customers, business (wholesale) buyers, and website visitors.
We handle personal information in accordance with applicable privacy laws, including:
the federal Personal Information Protection and Electronic Documents Act (PIPEDA), SC 2000, c. 5, and its ten Fair Information Principles (Schedule 1);
British Columbia's Personal Information Protection Act (PIPA), SBC 2003, c. 63;
Canada's Anti-Spam Legislation (CASL), SC 2010, c. 23, for commercial electronic messages;
for residents of Quebec, the Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, as modernized by Law 25 (SQ 2021, c. 25);
for individuals in the European Economic Area (EEA), the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR");
for individuals in the United Kingdom, the UK GDPR and the Data Protection Act 2018 (UK); and
for residents of California, the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act ("CCPA/CPRA"), and comparable laws in other U.S. states.
By using the Services, you acknowledge the practices described in this Policy. Where the law requires your consent, we will obtain it as described below.
2. Who We Are and How to Contact Us (Accountability)
Under PIPEDA's first principle (Accountability) and BC PIPA, we are responsible for the personal information under our control. We have designated our Founder, Deepika Shukla, as the individual accountable for our compliance with this Policy and applicable privacy laws (our "Privacy Officer"). For Quebec residents, the Founder also serves as the person in charge of the protection of personal information required by Law 25.
Privacy Officer (Founder) — The Chanderi Cedar
Deepika Shukla, Founder, carrying on business as The Chanderi Cedar
132-328 Wale Road, Colwood, BC V9B 0J8, Canada
Email: hello@thechandericedar.com
Telephone: +1 (250) 221-1110
3. The Personal Information We Collect
"Personal information" means information about an identifiable individual. The information we collect depends on how you interact with us.
3.1 Information you provide to us directly through the Site:
Enquiry and contact details — when you contact us or complete our contact form: your name, email address, and the contents of your message.
Communications — the contents of any emails or messages you send us.
We do not currently operate a newsletter or marketing list. Because checkout does not occur on our Site, we also do not collect your payment-card details or process payments ourselves.
3.2 Information we collect automatically (Usage Data):
When you visit the Site, we and our analytics provider automatically collect technical information using cookies and similar technologies (see Section 6), including your IP address, device and browser type, operating system, referring URLs, pages viewed, and the dates and times of your visit. Where permitted, this may include an approximate location derived from your IP address.
3.3 Information we receive from third-party marketplaces:
When you buy our products through a marketplace such as Etsy, Amazon, Faire, The Folklore, or Wolf & Badger, that marketplace collects and processes your personal information — including your payment and delivery details — under its own privacy policy. As a third-party seller, we receive only the limited information the marketplace makes available to us to manage our sales, which may include order and transaction details, limited customer or business-buyer information needed for fulfilment, customer service, returns, tax, and accounting, and aggregated sales reports. We do not receive your full payment-card number. We handle any such information in accordance with this Policy.
3.4 Sensitive information. We do not seek to collect "sensitive" personal information (such as health, biometric, or government-identification numbers), and we ask that you not send it to us. Where any information is more sensitive, we protect it accordingly, consistent with PIPEDA Principle 4.7 and applicable law.
4. How We Use Your Personal Information, and Our Legal Bases
We use personal information only for purposes that a reasonable person would consider appropriate in the circumstances — the standard set by PIPEDA, s. 5(3) — and we identify our purposes at or before collection (PIPEDA Principle 2). Where the GDPR/UK GDPR applies, we also rely on a lawful basis under Article 6, identified below.
To respond to your enquiries and provide customer support. GDPR basis: our legitimate interests in responding to you (Art. 6(1)(f)); and performance of a contract where we deal with you directly (Art. 6(1)(b)).
To manage and support sales made through marketplaces — including customer-service follow-up, returns, and wholesale relationships. GDPR basis: legitimate interests (Art. 6(1)(f)) and, where applicable, contract (Art. 6(1)(b)).
To send marketing communications if we introduce them in future, and only where you have consented. GDPR basis: consent (Art. 6(1)(a)). CASL would govern any email/SMS marketing.
For analytics, to understand and improve the Site and our products. GDPR basis: legitimate interests (Art. 6(1)(f)) and, for non-essential cookies, consent.
For security, fraud prevention, and protecting our rights and customers. GDPR basis: legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)).
To comply with legal, tax, accounting, and regulatory obligations (see Section 12). GDPR basis: legal obligation (Art. 6(1)(c)).
If we ever wish to use your personal information for a new purpose not described here, we will update this Policy and, where required, obtain your consent.
5. Consent
Under PIPEDA and BC PIPA, we collect, use, and disclose personal information with your knowledge and consent, except where the law permits or requires otherwise. Consent may be express (for example, opting in to any future marketing) or implied (for example, sending us an enquiry so we can reply), with the form of consent reflecting the sensitivity of the information.
You may withdraw your consent at any time (and, where the GDPR applies, withdraw consent as easily as you gave it), subject to legal or contractual restrictions and reasonable notice, by contacting our Privacy Officer. Withdrawing consent may limit our ability to provide certain Services (for example, we may be unable to respond to an enquiry without your contact details).
6. Cookies and Similar Technologies
We use cookies and similar technologies ("Cookies") to operate and improve the Site. The categories we use are:
Strictly necessary Cookies — set by WordPress (and the WooCommerce plugin used to display our catalogue) to operate your session and core Site functions; and
Performance/analytics Cookies — we use Google Analytics to understand how visitors use the Site.
We do not currently use third-party advertising or cross-context behavioural-advertising Cookies (such as social-media or ad-network pixels). If this changes, we will update this Policy and, where required, obtain your consent.
Your choices. Most browsers let you refuse or delete Cookies through their settings; doing so may affect Site functionality. Where required by law — including for visitors in the EEA/UK under the ePrivacy Directive (Directive 2002/58/EC) and for Quebec residents — we request consent for non-essential Cookies through a cookie banner before they are set, and you can change your preferences at any time. Because there is no common standard for browser "Do Not Track" signals we do not respond to them, but where required (for example, under the CCPA) we honour recognised opt-out preference signals such as the Global Privacy Control (GPC).
7. Marketing Communications
We do not currently operate a newsletter or send marketing emails. We use the WP Mail SMTP plugin, routed through Google Workspace, to send operational emails such as replies to your enquiries.
If we introduce marketing or promotional communications in future, we will comply with CASL, SC 2010, c. 23 (and, for recipients in the United States, the CAN-SPAM Act, 15 U.S.C. §§ 7701–7713) — obtaining consent before sending, identifying ourselves, and including a working unsubscribe mechanism in every message — and you will be able to opt out at any time.
8. How We Disclose Personal Information
We do not sell your personal information. We disclose personal information only as described here:
Service providers and processors who perform functions on our behalf, under contractual confidentiality and security obligations:
website platform and infrastructure: WordPress and the WooCommerce plugin (developed by Automattic Inc.), together with our website hosting provider;
analytics: Google Analytics (provided by Google LLC); and
email: Google Workspace (provided by Google LLC), used for our business email and, via the WP Mail SMTP plugin, to deliver operational emails.
Third-party marketplaces (Etsy, Amazon, Faire, The Folklore, and Wolf & Badger) through which our products are sold; these operate under their own privacy policies (see Section 9).
Where you direct or consent, for example if you ask us to share information with a third party.
For legal and protective reasons — to comply with law, respond to lawful requests (such as subpoenas, court orders, or warrants), enforce our Terms, or protect the rights, property, or safety of The Chanderi Cedar, our customers, or others.
Business transfers — in connection with a merger, financing, acquisition, insolvency, or sale of all or part of our business, subject to this Policy.
Our service providers and the marketplaces use your information in accordance with their own privacy notices; we are not responsible for their independent practices.
9. Third-Party Marketplaces and Links
Our products are sold through third-party online marketplaces, currently Etsy, Amazon, Faire, The Folklore, and Wolf & Badger (which include both retail and wholesale platforms, serving customers in Canada and internationally). When you purchase through a marketplace, you are transacting with that marketplace, not directly with us, and your personal information — including payment and shipping details — is collected and handled by the marketplace under its own privacy policy and terms. We encourage you to review each marketplace's privacy policy, including those of Etsy (etsy.com/legal/privacy), Amazon (amazon.ca / amazon.com), Faire (faire.com), The Folklore (thefolklore.com), and Wolf & Badger (wolfandbadger.com).
Our Site may also link to other websites or platforms we do not control. This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices.
10. International Data Transfers (Cross-Border Processing)
We are based in Canada, and our service providers (such as Google, which provides our email and website analytics) — and the marketplaces through which our products are sold — may store or process personal information in Canada, the United States, the United Kingdom, the EEA, and other countries. As a result, personal information may be transferred to, stored in, and accessed from jurisdictions outside your own, where it may be subject to lawful access by courts, law enforcement, and authorities under local laws.
Consistent with PIPEDA's accountability principle, we use contractual and other reasonable means to ensure a comparable level of protection for personal information transferred to our service providers. For Quebec residents, before disclosing personal information outside Quebec we conduct the assessment required by Law 25. Where personal information is transferred out of the EEA or UK, the transfer relies on a recognised mechanism — such as an adequacy decision (Canada benefits from a partial EU adequacy decision for PIPEDA-covered commercial organisations) or the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Agreement/Addendum).
11. Data Retention
We keep personal information only as long as necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law. The criteria we use include whether we need the information to provide the Services, to respond to you, to comply with legal obligations, and to resolve disputes or enforce our agreements.
In particular, we retain business and transaction records for the period required by Canadian tax and record-keeping law — generally six (6) years from the end of the tax year to which they relate — under the Income Tax Act, RSC 1985, c. 1 (5th Supp.), s. 230, and the Excise Tax Act, RSC 1985, c. E-15, s. 286 (GST/HST). When personal information is no longer required, we securely delete, destroy, or anonymise it.
12. How We Protect Your Information (Safeguards)
We maintain physical, organisational, and technological safeguards appropriate to the sensitivity of the information, consistent with PIPEDA Principle 7 (Safeguards), BC PIPA, s. 34, and (where applicable) the security requirements of the GDPR (Article 32). Because our Site runs on self-managed WordPress, these measures include keeping our platform and plugins up to date, using a reputable hosting provider, enabling encryption in transit (TLS/SSL), restricting administrative access, and limiting the personal information we collect and retain. Payment processing is handled by the marketplaces and their processors, which maintain PCI DSS compliance.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please use care when sending information to us, and keep any account credentials confidential.
13. Data Breaches
We maintain procedures to detect and respond to security incidents. If a breach of security safeguards creates a real risk of significant harm to you, we will notify you and report to the Office of the Privacy Commissioner of Canada (OPC), and keep records, as required by PIPEDA and the Breach of Security Safeguards Regulations, SOR/2018-64. For Quebec residents, we will also comply with the confidentiality-incident requirements of Law 25, including notifying the Commission d'accès à l'information and affected individuals where the incident presents a risk of serious injury. Where the GDPR/UK GDPR applies, we will notify the competent supervisory authority within 72 hours where required, and affected individuals where there is a high risk to their rights and freedoms.
14. Your Privacy Rights
Your rights depend on where you live. Rights are not absolute and may be subject to legal exceptions; we may need to verify your identity before responding (see Section 15).
14.1 Canada (PIPEDA and BC PIPA), all users:
Access the personal information we hold about you and information about how it has been used and disclosed;
Correct inaccurate or incomplete personal information;
Withdraw consent, subject to legal or contractual limits; and
Make a complaint to us and to the OPC or the OIPC BC (see Section 19).
For Quebec residents, additionally under Law 25: the right to data portability (to receive computerised personal information in a structured, commonly used technological format), the right to de-indexing/cessation of dissemination in certain circumstances, and the right to information about, and to contest, automated decision-making (see Section 16).
14.2 EEA and UK (GDPR/UK GDPR): the rights to access; rectification; erasure ("right to be forgotten"); restriction of processing; data portability; to object to processing (including direct marketing and processing based on legitimate interests); rights relating to automated decision-making; to withdraw consent at any time; and to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).
14.3 California (CCPA/CPRA): the rights to know/access the personal information collected and the categories of sources, purposes, and recipients; to delete; to correct; to opt out of the "sale" or "sharing" of personal information and of targeted advertising; to limit the use and disclosure of sensitive personal information; and to non-discrimination for exercising your rights. You may use an authorised agent and may appeal a denial. If you visit our Site with the Global Privacy Control (GPC) signal enabled, we will treat it as a valid opt-out for that browser/device.
14.4 Other U.S. states. Residents of states such as Virginia, Colorado, Connecticut, and Utah may have comparable rights under their state privacy laws; we honour those rights where they apply.
15. How to Exercise Your Rights
To exercise a right, contact our Privacy Officer (Section 2). We may need to verify your identity before responding, and you may authorise an agent to act for you with proof of authorisation. We will respond within the time required by law — generally within 30 days under PIPEDA, and within one month under the GDPR/UK GDPR, subject to permitted extensions. We do not charge a fee except where permitted (for example, for manifestly unfounded or excessive requests). If we refuse a request, we will explain why and tell you how to challenge our decision.
16. Automated Decision-Making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Where the GDPR (Article 22) or Quebec's Law 25 applies, you have the right to be informed of, and in certain cases to contest, such processing and to request human intervention.
17. Children's Privacy
The Services are intended for adults and are not directed to children. In British Columbia, the age of majority is 19. We do not knowingly collect personal information from children. In the United States, we comply with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, and do not knowingly collect personal information from children under 13; where the GDPR applies, we do not knowingly collect personal information from children below the applicable digital-consent age (13–16, depending on the country). If you believe a child has provided us with personal information, please contact our Privacy Officer and we will take appropriate steps to delete it.
18. International Customers and Visitors
Our products are offered to customers in Canada and internationally through the marketplaces listed in Section 9. Any purchase you make through a marketplace is governed by that marketplace's own terms and privacy policy and is subject to the laws of your jurisdiction. If you interact with our Site or provide information to us from outside Canada, your personal information will be handled in accordance with this Policy and applicable law, and may be transferred to and processed in Canada and other countries (see Section 10).
19. Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our practices or for operational, legal, or regulatory reasons. We will post the updated Policy on the Site, revise the "Last updated" date, and, where required by law, take additional steps such as notifying you or obtaining your consent. Your continued use of the Services after an update takes effect constitutes acknowledgement of the revised Policy.
20. Complaints
If you have a concern about how we handle your personal information, please contact our Privacy Officer first (Section 2); we will investigate and respond. If you are not satisfied, you may contact the relevant authority:
the Office of the Privacy Commissioner of Canada (OPC) — 30 Victoria Street, Gatineau, Quebec K1A 1H3; priv.gc.ca;
the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) — oipc.bc.ca;
for Quebec residents, the Commission d'accès à l'information du Québec (CAI) — cai.gouv.qc.ca;
in the United Kingdom, the Information Commissioner's Office (ICO) — ico.org.uk; and
in the EEA, your local Data Protection Authority.
21. Contact Us
For any questions about this Privacy Policy or our handling of your personal information, or to exercise your rights:
The Chanderi Cedar — Privacy Officer
Deepika Shukla, Founder, carrying on business as The Chanderi Cedar
132-328 Wale Road, Colwood, BC V9B 0J8, Canada
Email: hello@thechandericedar.com
Telephone: +1 (250) 221-1110
Website: www.thechandericedar.com