Privacy policy

PRIVACY POLICY — MALGVEN
Last updated: April 20, 2026


This Privacy Policy explains how MALGVEN ("we," "us," or "our"), headquartered in Quebec, Canada, collects, uses, discloses, and protects your personal information when you visit malgven.ca (the "Site"), use our services, make a purchase, or otherwise communicate with us (collectively, the "Services").

For the purposes of this Policy, "you" and "your" refer to any person using the Services, whether as a customer, visitor, or any other individual whose personal information we have collected.

Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read and understood this Policy. If you do not agree, please do not use the Services.

MALGVEN is committed to protecting your personal information in accordance with applicable laws, including:
- The Act Respecting the Protection of Personal Information in the Private Sector (Law 25, Quebec)
- The Personal Information Protection and Electronic Documents Act (PIPEDA, Canada)
- The General Data Protection Regulation (GDPR, European Union)
- The UK GDPR (United Kingdom)
- The Privacy Act 1988 and the Australian Privacy Principles (Australia)
- The California Consumer Privacy Act (CCPA, United States, where applicable)


---


1. DATA CONTROLLER & CONTACT INFORMATION

Data Controller:
MALGVEN
Website: malgven.ca
Email: contact@malgven.ca

For any questions regarding this Policy or to exercise your rights, please contact us at the address above. We are committed to responding within 30 calendar days, in accordance with the requirements of Law 25 and PIPEDA.


---


2. PERSONAL INFORMATION WE COLLECT

"Personal information" means any information that identifies you directly or indirectly.

2.1 – Information You Provide Directly

- Contact details: first name, last name, mailing address, email address, phone number
- Order information: billing address, shipping address, payment confirmation
- Account information: username, password, account preferences
- Communications: messages sent to our customer service team, contact form submissions

Some information is required to process your orders. If you choose not to provide it, we may be unable to deliver the requested Services.

2.2 – Information Collected Automatically

When you visit our Site, we may automatically collect certain technical data, including:

- IP address and approximate location data
- Browser type and operating system
- Pages visited, time spent on the Site, links clicked
- Traffic source (search engine, direct link, social media)

This data is collected through cookies, pixels, and similar technologies. Please refer to Section 6 (Cookies) for more information.

2.3 – Information Received from Third Parties

We may receive personal information from third-party partners, including:

- Shopify Inc. (e-commerce platform, hosted in the United States)
- Payment processors: Stripe, PayPal, and others
- Marketing and advertising partners (Meta, Google, etc.)
- Analytics services (Google Analytics or equivalent)

These third parties have their own privacy policies, which we encourage you to review.


---


3. PURPOSES AND LEGAL BASES FOR PROCESSING

We process your personal information only for specified, explicit, and legitimate purposes.

3.1 – Fulfilling Your Orders and Providing the Services

Purpose: Fulfilling orders, arranging delivery, managing returns and refunds, providing customer support.
Legal basis: Performance of a contract / Legal obligation

Important — Payment Data: MALGVEN does not collect, process, or store any payment information (card numbers, CVV, expiry dates, or banking details). This data is collected and processed directly and exclusively by our third-party payment providers (Shopify Payments, Stripe, PayPal, etc.) through their own secure, PCI-DSS certified infrastructures. MALGVEN has no access to this information at any point. We encourage you to review the privacy policies of these providers to understand how they handle your payment data:
- Shopify Payments: https://www.shopify.com/legal/privacy
- Stripe: https://stripe.com/privacy
- PayPal: https://www.paypal.com/privacy

3.2 – Communication and Customer Relationship Management

Purpose: Responding to your enquiries, sending order confirmations and shipping updates.
Legal basis: Performance of a contract / Legitimate interest

3.3 – Marketing and Promotional Communications

Purpose: Sending promotional emails, newsletters, personalised offers, and targeted advertisements.
Legal basis: Consent (you may withdraw your consent at any time — see Section 9)

Important: We do not send marketing communications by SMS without your explicit and prior consent, in accordance with Canada's Anti-Spam Legislation (CASL).

3.4 – Security, Fraud Prevention, and Rights Protection

Purpose: Detecting, preventing, and addressing fraudulent, illegal, or abusive activity, and protecting our Site and our customers.
Legal basis: Legitimate interest / Legal obligation

3.5 – Service Improvement and Analytics

Purpose: Analysing Site usage to improve our services, user experience, and product offerings.
Legal basis: Legitimate interest / Consent (depending on the type of cookies used)

3.6 – Legal Compliance

Purpose: Meeting our legal obligations and responding to requests from competent authorities.
Legal basis: Legal obligation


---


4. DATA PROCESSING BY OUR THIRD-PARTY TOOLS

MALGVEN is based in Canada (Quebec) and does not itself initiate any international transfer of personal data.

However, the third-party tools we use to operate our online store (e-commerce platform, payment processing, marketing, and analytics) are services hosted and operated by companies whose servers are located primarily in the United States. As a result, when you use our Site, some of your data may be automatically received and processed by these tools on servers located outside Canada, without any direct action by MALGVEN.

The tools concerned include:

- Shopify Inc. — e-commerce platform (servers in the United States)
- Shopify Payments, Stripe, PayPal — payment processing (servers in the United States)
- Google Analytics — traffic analytics (servers in the United States)
- Meta (Facebook/Instagram Pixel) — advertising and retargeting (servers in the United States)

MALGVEN has no control over the infrastructure of these providers and is not responsible for the location of their servers. Each of these providers is subject to its own legal obligations regarding data protection and has its own privacy policy, which we encourage you to review.

These providers are contractually bound to protect your data and operate in compliance with applicable legal frameworks (including the EU-U.S. Data Privacy Framework, standard contractual clauses, and PCI-DSS certification for payment processing).


---


5. DATA RETENTION

We retain your personal information only for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable law.

- Order and billing data: 7 years (Canadian tax and accounting obligations)
- Customer account data: duration of account activity + 3 years after the last interaction
- Customer service communications: 3 years
- Marketing data (consent records): until you withdraw your consent
- Browsing data and cookies: as defined by cookie settings, generally between 30 days and 2 years

Upon expiry of these periods, your data is securely deleted or anonymised.


---


6. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar technologies (pixels, web beacons, session identifiers) to ensure the proper functioning of the Site, analyse its usage, and improve the user experience.

Types of cookies we use:

Strictly Necessary Cookies
Essential to the operation of the Site (shopping cart, login session). These cannot be disabled.

Analytics and Performance Cookies
Used to measure Site traffic and analyse browsing behaviour (e.g., Google Analytics). Subject to your consent.

Advertising and Targeting Cookies
Used to display personalised advertisements and measure the effectiveness of our campaigns (e.g., Meta Pixel, Google Ads). Subject to your consent.

Functional Cookies
Used to remember your preferences (language, currency, etc.).

Managing Cookies:
You can manage or disable cookies through your browser settings or via our cookie consent banner when you visit the Site. Please note that disabling certain cookies may affect the functionality of the Site.

To learn more about cookies used by Shopify:
https://www.shopify.com/legal/cookies


---


7. DISCLOSURE OF YOUR PERSONAL INFORMATION

We do not sell your personal information to third parties.

We may disclose your personal information in the following circumstances:

7.1 – Service Providers

We work with trusted service providers to operate our Services, including:
- Shopify Inc. (e-commerce platform and hosting)
- Shopify Payments, Stripe, and PayPal (payment processing — these providers collect and store your payment data directly; MALGVEN has no access to it)
- Carriers and delivery services (Canada Post, DHL, UPS, etc.)
- Analytics and marketing services (Google, Meta, etc.)
- Email communication services

These providers access your data only to the extent necessary to perform their functions and are contractually bound to protect it.

7.2 – Legal Obligations

We may disclose your personal information if required by law, in response to a court order, a regulatory authority's request, or to protect our legal rights.

7.3 – Business Transfers

In the event of a merger, acquisition, asset sale, or other restructuring of MALGVEN, your data may be transferred. You will be notified in accordance with applicable law.

We never disclose sensitive personal information without your explicit consent.


---


8. YOUR RIGHTS

Depending on your country of residence, you have certain rights regarding your personal information.

8.1 – Rights for All Customers (Canada — Law 25 and PIPEDA)

- Right of access: obtain a copy of the personal information MALGVEN holds about you
- Right to rectification: correct inaccurate or incomplete information
- Right to erasure: request deletion of your data under the conditions provided by law
- Right to withdraw consent: withdraw your consent to marketing at any time
- Right to lodge a complaint: with the Commission d'accès à l'information du Québec (CAI) or the Office of the Privacy Commissioner of Canada (OPC)

8.2 – Additional Rights for Customers in the European Union (GDPR)

- Right to data portability
- Right to restriction of processing
- Right to object to processing based on legitimate interest
- Right not to be subject to automated decision-making
- Right to lodge a complaint with your national data protection authority (e.g., CNIL in France)

8.3 – Rights for Customers in the United Kingdom (UK GDPR)

Rights equivalent to those under the GDPR apply. You may lodge a complaint with the Information Commissioner's Office (ICO) at: www.ico.org.uk

8.4 – Rights for Customers in Australia

Under the Privacy Act 1988, you have a right of access and correction. You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at: www.oaic.gov.au

To exercise any of your rights, please contact us at contact@malgven.ca. We will process your request within 30 calendar days. We may require identity verification before acting on your request.


---


9. OPTING OUT OF MARKETING

You may opt out of our marketing communications at any time by:

- Clicking the unsubscribe link included in every promotional email
- Contacting us directly at contact@malgven.ca

Please allow up to 10 business days for your request to be processed. Please note that even after opting out of marketing, you will continue to receive essential transactional communications (order confirmations, shipping updates, etc.).


---


10. CHILDREN'S DATA

Our Services are intended exclusively for individuals aged 16 or older, or aged 13 or older with verifiable parental consent, in accordance with the legal requirements applicable in your country of residence.

We do not knowingly collect personal information from minors without appropriate parental consent. If we become aware that a minor has provided us with personal information without the required consent, we will delete that information as promptly as possible.

If you are a parent or guardian and believe your child has submitted their personal information to us, please contact us at contact@malgven.ca.


---


11. DATA SECURITY

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, disclosure, alteration, or destruction, including:

- Encryption of transmitted data (SSL/TLS)
- Restricted access to personal information, limited to authorised personnel only
- Regular monitoring of our systems

However, no security measure is entirely infallible. In the event of a privacy incident likely to cause you serious harm, we will notify you in accordance with our obligations under Law 25 and PIPEDA.


---


12. THIRD-PARTY WEBSITES AND LINKS

Our Site may contain links to third-party websites or platforms. MALGVEN is not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with any personal information.


---


13. CHANGES TO THIS POLICY

We may update this Privacy Policy periodically to reflect changes in our practices, legal obligations, or Services.

In the event of a material change, we will notify you by email or through a prominent notice on our Site prior to the change taking effect. The "Last updated" date will be revised accordingly.

Your continued use of the Services following the publication of any changes constitutes your acceptance of the updated Policy.


---


14. CONTACT & COMPLAINTS

For any questions, rights requests, or concerns regarding this Policy:

MALGVEN
Email: contact@malgven.ca
Website: malgven.ca

Competent Data Protection Authorities:

Canada (federal):
Office of the Privacy Commissioner of Canada (OPC)
www.priv.gc.ca

Quebec:
Commission d'accès à l'information (CAI)
www.cai.quebec.gouv.qc.ca

France:
Commission nationale de l'informatique et des libertés (CNIL)
www.cnil.fr

United Kingdom:
Information Commissioner's Office (ICO)
www.ico.org.uk

Australia:
Office of the Australian Information Commissioner (OAIC)
www.oaic.gov.au


---

This Privacy Policy is governed by the laws of the Province of Quebec and the applicable federal laws of Canada, without prejudice to the mandatory rights of consumers in their country of residence.