CapecraftDigital
  • Home
  • Services
  • Packages
  • How We Work
  • Why Us
  • Blog
  • Contact
  • Get a Free Quote
Back to Home

Privacy Policy

Last Updated: May 25, 2026

1. Introduction

Capecraft Digital ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website capecraftdigital.com or use our web development, e-commerce, SEO, and related services.

Data Protection Contact: For privacy-related inquiries, data subject requests, or to report a concern, contact our Privacy Officer at privacy@capecraftdigital.com.

Service Providers

We use the following third-party service providers to operate our website and deliver our services. Each provider has entered into a data processing agreement and processes data only in accordance with our instructions:

  • Cloudflare — CDN, DDoS protection, SSL termination, and Turnstile anti-spam. Cloudflare processes IP addresses and request metadata for security purposes. See Cloudflare Privacy Policy.
  • Microsoft Clarity — We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising. We mask all sensitive text fields (emails, names, passwords) in recordings. By using our site, you agree that we and Microsoft can collect and use this data. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
  • Stripe — Payment processing. Stripe handles all credit card data; we never see or store full card numbers. See Stripe Privacy Policy.
  • ipapi.co — IP geolocation for country-based content (GDPR-compliant). We use your IP address to detect your country and city so we can:
    • Show a country-specific banner suggesting you switch to your local version of our tools.
    • Show a city-specific banner with local service information relevant to your location.
    • Automatically rewrite links to point to your country's content (blog posts, tools).
    This data is processed in real-time and not permanently stored by us. You can dismiss these banners via the close button, which sets a cookie to remember your preference. See ipapi.co Privacy Policy.
  • Google Fonts / Cloudflare CDN — Content delivery network for fonts and stylesheets.

2. Information We Collect

We may collect information about you in a variety of ways, including:

  • Personal Data: Name, email address, telephone number, and business details voluntarily provided via contact forms and checkout.
  • Derivative Data: IP address (hashed for privacy), browser type, operating system, access times, and pages viewed.
  • Financial Data: All payment processing is handled securely by Stripe, our third-party payment processor. We do not store, process, or have access to your full credit card numbers, CVV codes, or bank account details on our servers. We store transaction metadata (package, amount, date, payment method brand and last 4 digits, and order reference) necessary for order fulfillment, customer support, and legal compliance. Stripe's handling of your payment data is governed by their Privacy Policy.

International Data Transfers: Your data may be stored and processed in Canada (our primary hosting location), the United States (Stripe payment processing, GitHub backup storage), and other jurisdictions where our service providers operate. We take reasonable steps to ensure that data transferred internationally receives an adequate level of protection through contractual safeguards and by selecting service providers with strong privacy commitments. By using our services, you consent to these transfers.

3. Use of Your Information

We use collected information to: provide and maintain services, process requests, send service updates, improve our website, and comply with legal obligations.

4. Disclosure of Your Information

We may share your information with service providers, in response to legal requests, to protect our rights, or with your explicit consent.

5. Security

We implement administrative, technical, and physical security measures to protect your personal information. No transmission method is 100% secure, but we strive to use commercially acceptable means.

6. Data Retention

We retain your personal data only as long as necessary to fulfill the purposes described in this policy:

  • Contact form submissions: Retained for 2 years after last communication, then permanently deleted.
  • Purchase records: Retained for 7 years to comply with tax and legal obligations (Canada Revenue Agency requirements). After 7 years, personally identifiable information is removed; anonymized transaction records may be kept for business analytics.
  • Email correspondence: Retained for the duration of the client relationship plus 2 years.
  • Website analytics data: Retained for 26 months.

When retention periods expire, data is securely deleted or anonymized.

7. Cookies

We use essential cookies and similar tracking technologies for site functionality, security (Cloudflare Turnstile anti-spam), and basic analytics. No non-essential cookies are loaded before you provide consent via our cookie banner. For detailed information about the specific cookies we use, their purposes, and how to manage your preferences, please see our Cookie Policy. You can instruct your browser to refuse all cookies, but some features may not function properly.

8. Marketing Communications

Service-Related Communications (Contractual): We send service-related emails including purchase confirmations, project status updates, invoices, and support communications as part of our contractual obligation to you. These communications are necessary for the performance of our services and do not require separate marketing consent.

Marketing Communications (Opt-In Only): We will only send marketing or promotional emails (newsletters, offers, service updates not related to an active project) if you have explicitly opted in via a checked consent box on our contact form or checkout page. You can withdraw marketing consent at any time via the unsubscribe page or by replying "UNSUBSCRIBE" to any marketing email. Unsubscribing from marketing does not affect your receipt of service-related communications for active projects.

Data Sharing: We do not sell, rent, trade, lease, or otherwise disclose your personal data to third parties for monetary or other valuable consideration, or for their own marketing, advertising, or promotional purposes. Your personal data is used solely to provide and improve our services to you.

9. Your Rights

Depending on your jurisdiction, you may have rights to access, update, delete, or restrict processing of your personal data. You may unsubscribe from our mailing list at any time. Contact us to exercise these rights.

10. Children's Privacy

Our services are not directed to individuals under 18. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this policy periodically. Changes will be posted on this page with an updated "Last Updated" date.

12. GDPR Compliance (EU Visitors) & International Privacy

Our services are intended for customers in Canada, the United States, and India. If you are a consumer in the European Economic Area (EEA), the UK, Switzerland, Australia, or New Zealand, you are not eligible to purchase our services per our Terms & Conditions. However, if you visit our website from any jurisdiction, the following rights are available to you under applicable data protection laws including the General Data Protection Regulation (GDPR), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), India's Digital Personal Data Protection Act, 2023 (DPDP Act), the California Consumer Privacy Act (CCPA), and other applicable US state privacy laws:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data. We will process deletion requests within 30 days and confirm once data has been erased from our active systems. Important: Certain data must be retained to comply with legal obligations — for example, purchase records containing personal data are retained for 7 years under Canada Revenue Agency requirements. In such cases, we will restrict processing of the data to legal retention purposes only, delete it from all non-required systems, and permanently delete it upon expiry of the legal retention period. Contact form submissions are deleted within the retention periods stated in §6.
  • Right to Restrict Processing: Request limitation of how we use your data.
  • Right to Data Portability: Request transfer of your data to another service in a structured, commonly used format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local or national data protection supervisory authority if you believe your privacy rights have been violated. In Canada, you may contact the Office of the Privacy Commissioner of Canada. In India, the Data Protection Board of India (once established under the DPDP Act, 2023) will handle complaints.

Legal Basis for Processing: We process personal data on the following legal bases: (a) contractual necessity — to fulfill orders, deliver services, and communicate about active projects; (b) consent — for contact form submissions, marketing opt-ins, and non-essential cookies; (c) legitimate interests — for website analytics, security (fraud prevention, rate limiting), and service improvement, where such interests are not overridden by your rights; and (d) legal obligation — for tax records, regulatory compliance, and responding to lawful requests from authorities. For customers in India, processing is based on "legitimate uses" as defined under the DPDP Act, 2023, including performance of contract and compliance with law.

We do not use automated decision-making or profiling that produces legal effects concerning you.

To exercise any of these rights, email privacy@capecraftdigital.com with your request and the email address associated with your data. We will verify your identity before processing to prevent unauthorized access. We will respond within 30 days as required by applicable law.

13. Data Breach Notification

In the event of a data breach involving personal information that poses a real risk of significant harm, we will:

  • Notify affected individuals without unreasonable delay, describing the nature of the breach, the data involved, and recommended steps to protect against harm.
  • Report the breach to the relevant supervisory authority as required by applicable law — including the Office of the Privacy Commissioner of Canada under PIPEDA, and corresponding authorities in other jurisdictions where legally required.
  • Maintain an internal breach register documenting all incidents, their impact, and remedial actions taken.

We maintain administrative, technical, and physical safeguards designed to prevent unauthorized access, disclosure, alteration, or destruction of personal data. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

14. Contact Us

Questions about this Privacy Policy? Contact us at:
Capecraft Digital
Email: privacy@capecraftdigital.com

CapecraftDigital

Professional web development services for businesses in Canada, the United States, India, Australia, the United Kingdom, Singapore, New Zealand, UAE, Brazil, Nigeria, and the Philippines. We create stunning, results-driven websites for businesses of all sizes.

Quick Links

  • Home
  • Packages
  • Services
  • How We Work
  • Why Us
  • Blog
  • Contact

Services

  • Web Development
  • E-Commerce
  • SEO Services
  • UI/UX Design
  • Maintenance

Legal

  • Track Order
  • Privacy Policy
  • Refund Policy
  • Terms & Conditions
  • Cookie Policy
  • Unsubscribe

© 2026 Capecraft Digital. All rights reserved.

Serving businesses across Canada, US, India, UK, Australia, Singapore, New Zealand, UAE, Brazil, Nigeria, and Philippines