Your personal information
Privacy policy
Compliant with the Act to modernize legislative provisions as regards the protection of personal information (Bill 25, Quebec).
Last updated: May 13, 2026
1. Preamble
Recarma Studio takes great care in protecting your privacy and the security of your personal information. This policy describes the information we collect through this website, how we use it, who may have access to it, and the rights you have under Quebec's Bill 25.
By using this website and booking our services, you acknowledge having read this policy.
2. Data controller
The data controller is Recarma Studio, whose contact details are listed in our legal notice.
Personal Information Protection Officer (PIPO) — in accordance with Bill 25, a person within our organization is designated as responsible for the protection of your information. You may reach this person:
- by phone at +15817774388
- [TO COMPLETE — PIPO contact email]
3. Personal information collected
We collect only the information necessary to deliver our services:
| Category | Data |
|---|---|
| Identity | First name, last name |
| Contact | Email address, phone number, preferred language |
| Vehicle | Make, model, year, color, size (compact, sedan, SUV, truck), notes |
| Booking | Requested services, date and time, amount, promo code used |
| Payment | Stripe session ID, deposit amount, payment status. We never store your credit card numbers — these are processed directly by Stripe. |
| Communications | History of transactional emails and SMS sent (confirmations, reminders, review requests) |
| Reviews | Rating (positive / neutral / negative) and public comment, if you choose to submit a post-service review |
| Technical data | IP address, browser type, pages visited, timestamps, session identifiers |
4. Purposes of processing
Your information is used exclusively for:
- Booking management — creation, confirmation, modification, cancellation
- Payment processing — deposit and balance collection via Stripe
- Transactional communication — confirmation emails and SMS, day-before reminders, invoices, review requests
- Service delivery — to identify you on arrival and personalize the experience
- Loyalty program — to count your visits and generate a reward coupon (if applicable)
- Service improvement — anonymized analysis of reviews to evolve our offering
- Legal and accounting obligations — retention of invoices, tax filings (GST/QST)
5. Legal basis
We process your information on the following bases:
- Contract performance — to deliver the service you ordered
- Legal obligation — for invoice retention and tax declarations
- Legitimate interest — for site security and fraud prevention
- Consent — for non-transactional communications or non-essential cookies (if applicable)
6. Recipients of your information
Your information is never sold, rented or exchanged. It is accessible only to:
- Authorized personnel of Recarma Studio, strictly as necessary to perform their duties
- Our technical subprocessors, listed below, contractually bound by confidentiality obligations
7. Subprocessors and transfers outside Quebec
We use the following providers to operate this site. When possible, we choose Canadian regions to limit transfers outside Quebec.
| Provider | Purpose | Storage location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, backups | Montreal, Quebec (ca-central-1) |
| Stripe Payments Canada Ltd. | Payment processing | Canada (with transfers to Stripe, Inc. in the United States) |
| Amazon SES | Transactional email delivery | Montreal, Quebec (ca-central-1) |
| Amazon SNS | Confirmation and reminder SMS | Montreal, Quebec (ca-central-1) |
| Recarma | Booking and administration platform | Montreal, Quebec (ca-central-1) |
| Google LLC (Gemini API) | Automatic detection of license plates on service photographs, for anonymization prior to publication. Optional visual optimizations (brightness, sharpness, framing). Transient processing: no data is used by Google to train its models (Gemini API, commercial mode). | United States (transient processing, no retention) |
Transfers of certain data to Stripe, Inc. in the United States are framed by standard contractual clauses and Stripe's data protection commitments (PCI-DSS Level 1). Transfers to Google LLC (Gemini API) are likewise framed by standard contractual clauses and limited to transient image processing, with no retention or use for AI model training.
8. Retention period
- Booking and invoicing data — 7 years (Quebec accounting and tax obligation)
- Customer contact details — as long as you remain an active customer, then 3 years after your last booking
- Customer reviews — as long as relevant to informing the public, unless deletion is requested
- Technical data (server logs, sessions) — 30 days
- Backups — 7 days rolling rotation
- Cancelled or unconfirmed bookings — 90 days
9. Security
We implement the following measures to protect your information:
- Encryption — HTTPS/TLS for all communications with the site
- Administrator passwords — hashed with bcrypt, never stored in plain text
- Sensitive data encrypted at rest — third-party API keys, authentication secrets
- Multi-factor authentication (MFA) — mandatory for administrator accounts
- Automatic backups — encrypted, retained for 7 days
- Access logging — to detect suspicious activity
- No banking data stored — payments are processed by Stripe (PCI-DSS Level 1)
10. Your rights (Bill 25)
In accordance with Quebec's Bill 25, you have at all times the following rights:
- Right of access — obtain a copy of the information we hold about you
- Right to rectification — correct inaccurate, incomplete or ambiguous information
- Right to withdraw consent — for processing based on your consent
- Right to discontinuation of dissemination — request that a public review or content about you no longer be displayed
- Right to de-indexation — request that your information no longer be indexed by search engines
- Right to portability — receive your data in a structured, commonly used format
- Right to deletion — subject to legal retention obligations (notably 7 years for invoices)
To exercise any of these rights, contact our Personal Information Protection Officer . We commit to responding within 30 days. Identity verification may be required before processing your request.
11. Cookies
The use of cookies on this site is detailed in our cookie policy.
12. Policy updates
This policy may be updated at any time to reflect changes in our services or legislation. The date of the last update is shown at the top of the page. Any substantial change will be communicated to active customers by email.
13. Complaint to the Commission d'accès à l'information (CAI)
If, after contacting us, you believe your rights are not being respected, you may file a complaint with the Commission d'accès à l'information du Québec (CAI):
- Website: www.cai.gouv.qc.ca
- Phone: 1-888-528-7741 (toll-free in Quebec)
- Address: 525, boulevard René-Lévesque Est, Suite 2.36, Quebec City (Quebec) G1R 5S9