Cedar's PC Wallet Privacy and Data Protection Policy
Version 1.0 · Last updated September 16, 2026
Applies to: Everyone whose information is handled through the Wallet
| Version | 1.0 |
|---|---|
| Last updated | September 16, 2026 |
| Effective | Effective upon production launch of wallet.cedarspc.ca |
| Applies to | customers, account requesters, staff, Owner, and other individuals whose information is handled through the Wallet |
| Organization | Cedar's PC Ltd |
|---|---|
| Privacy contact | Joseph Kaba, Owner | cedars.pc@gmail.com |
| Mailing address | 3696 97 St NW, Edmonton, AB T6E 5S8 |
| Website | wallet.cedarspc.ca |
| Primary framework | Alberta Personal Information Protection Act (PIPA); PIPEDA where applicable |
1. Purpose and scope
This Privacy and Data Protection Policy explains how Cedar's PC Ltd collects, uses, discloses, protects, retains, and provides access to personal information connected with the Cedar's PC Wallet. It applies to customer accounts, account requests, staff and Owner accounts, bookings, messages, notifications, trade-credit transactions, cash-outs, audit activity and related security functions.
Cedar's PC is responsible for personal information under its custody or control, including information handled by service providers on its behalf. Cedar's PC will collect, use and disclose personal information only for reasonable purposes and to the extent reasonably necessary for those purposes, subject to applicable law.
2. Privacy responsibility and contact
The designated Privacy Contact is Joseph Kaba, Owner. Privacy questions, access requests, correction requests and complaints may be sent to cedars.pc@gmail.com or mailed to 3696 97 St NW, Edmonton, AB T6E 5S8.
3. Personal information we collect
3.1 Customers
-
First and last name; email address; phone number; full postal address; and date joined.
-
Assigned level, perks, badges and account status.
-
Credit transaction history, trade-in records, redemptions, cash-out records, balance calculations and related ledger records.
-
Bookings, message threads, notifications and customer service records.
-
Staff notes about the account, including account flags and reasons where used for security, fraud prevention or account administration. These are visible only to authorized staff.
-
Confirmation that an in-person identification check was completed where required. Cedar's PC does not store government identification numbers or images in the Wallet.
-
Confirmation that a signature was obtained for a redemption or cash-out where required; any paper signature record is handled as a business record outside the Wallet unless the system is later changed and this Policy is updated.
3.2 Account requesters
-
Name, email, phone number, address, notes submitted with the request, and the date and time of Terms/privacy acknowledgement.
-
Security and abuse-prevention information associated with the request, including rate-limit state and reCAPTCHA verification information.
3.3 Staff and Owner users
-
Full name, role label, work email, phone number, and optional personal or contact notes maintained for account administration.
-
Granted permissions, two-step sign-in status, account status and security state.
-
Manager PIN in one-way hashed form where a PIN is assigned. The readable PIN is not stored.
-
Audit activity showing significant actions taken in the Wallet, including the user, time, and affected record or function.
3.4 Information we do not store in the Wallet
-
Payment-card numbers, bank account details or payment credentials.
-
Government identification numbers or images.
-
Passwords in readable form.
4. Why we collect and use information
-
To create, approve, administer and secure Wallet accounts.
-
To record Cedar Credit transactions, redemptions and cash-outs, calculate balances and preserve a reliable ledger history.
-
To identify the correct customer at the counter and help prevent fraudulent redemption, cash-out or account misuse.
-
To manage trade-ins, bookings, customer messages and service notifications.
-
To apply account levels, perks and badges.
-
To manage staff access, permissions and employment-related account administration.
-
To maintain auditability, investigate errors or suspected abuse, respond to complaints, and meet legal obligations.
Cedar's PC does not sell or rent personal information, share it with advertisers, or use it for third-party advertising profiling. The Wallet's level system is used only for Cedar's PC account and program purposes.
5. Consent and notice
Where consent is required, Cedar's PC will provide understandable notice of the purpose for collecting, using or disclosing personal information and a reasonable opportunity to consent or decline. Some information may be handled without consent where applicable law permits, including reasonable personal employee information used to establish, manage or end an employment relationship or information required for security, legal or fraud-prevention purposes.
You may withdraw or change consent for optional uses, subject to legal, contractual and operational limits. If withdrawing consent prevents Cedar's PC from safely or lawfully operating the Wallet account, Cedar's PC will explain the resulting consequences, which may include deactivation of portal access.
6. Who can see personal information
Customers can access only their own Wallet information. Staff access is controlled by individual permissions. Staff who do not have permission to view customer personal information are not shown those personal details. Customers are not shown which staff member handled a transaction.
Within Cedar's PC, personal information is available only to the Owner and authorized staff who require access for assigned work. Staff activity involving significant actions is recorded in the audit log.
7. Service providers, cross-border processing and disclosures
Cedar's PC uses service providers to host and process the Wallet, support database and application infrastructure, send or receive operational email, and protect the public account-request form from automated abuse. These providers may process personal or technical information only as needed for the applicable service or under their governing terms.
| Service | Provider | Processing location | Purpose |
|---|---|---|---|
| Wallet hosting/database | Lovable and its infrastructure/service subprocessors | Lovable Cloud region selected for the project (Lovable supports US, EU and Asia-Pacific regions) and locations used by its listed subprocessors | Host, store, operate, secure and support the Wallet application and database |
| Operational email/contact | Google Gmail | Google's global processing locations, which may include processing outside Canada | Send and receive operational correspondence through cedars.pc@gmail.com |
| Bot protection | Google reCAPTCHA / Google Cloud | Google and its Google Cloud subprocessors may process data outside Canada under applicable Google Cloud terms | Security, fraud and abuse prevention on the public account-request form |
Because these services may process information outside Canada, personal information may be accessible to courts, law-enforcement agencies or other authorities under the laws of the jurisdiction where it is processed. Questions about current providers, processing locations, and Cedar's PC practices regarding service providers outside Canada may be directed to the Privacy Contact in Section 2.
Cedar's PC may also disclose personal information where permitted or required by law, for example in response to valid legal process, to protect rights or safety, or to investigate suspected fraud. Cedar's PC does not disclose customer information to advertisers.
8. reCAPTCHA and essential technical data
The public account-request form uses invisible reCAPTCHA v3 to reduce automated abuse. reCAPTCHA may process browser, device, interaction and security signals and may use the _grecaptcha cookie or similar technical mechanisms for risk analysis.
As of April 2, 2026, Google states that reCAPTCHA customers act as data controllers for their end-user data and Google acts as a data processor for reCAPTCHA Customer Data under the applicable Google Cloud Terms of Service and Cloud Data Processing Addendum. Cedar's PC therefore explains the reCAPTCHA purpose in this Policy as security, fraud and abuse prevention.
The Wallet also uses technical information necessary for authentication, rate limiting, session security and account protection. Cedar's PC will update this Policy before introducing non-essential advertising or behavioural tracking technologies.
9. Security safeguards
Cedar's PC uses administrative, technical and access-control safeguards appropriate to the sensitivity of the information held. Current Wallet safeguards include:
-
Row-level database rules intended to prevent signed-in customers from accessing another customer's records.
-
Protected server-side routines for money-affecting and administrative actions, with identity and permission checks.
-
No anonymous access to customer data tables.
-
Immutable transaction records in normal operation, with corrections handled by recorded reversals or adjustments.
-
Hashed manager PINs and non-readable password storage.
-
Mandatory two-step sign-in for Owner and staff; optional two-step sign-in for customers.
-
Breached-password checking, current-password confirmation for sensitive changes, rate limits and reCAPTCHA on the public request form.
-
Audit logging of significant actions.
No security system can guarantee absolute protection. Cedar's PC reviews and improves safeguards as reasonably necessary.
10. Retention and deletion
Cedar's PC retains personal information only for as long as reasonably required for the business, security, accounting, fraud-prevention, audit or legal purposes for which it is held. Information that is no longer reasonably required will be securely destroyed or anonymized, subject to applicable law.
Transaction and audit records are designed as long-term, non-editable business records. Closing or deactivating a Wallet does not automatically remove those records. Cedar's PC will retain them for as long as reasonably required for the purposes above rather than treating account closure as a deletion request for the ledger.
Account-request records that never become approved customer accounts are retained only as long as reasonably necessary to assess and administer the request, prevent duplicate or abusive submissions, resolve disputes, and meet legal obligations. When those purposes no longer require the record, it will be securely deleted or anonymized.
11. Accuracy, access and correction
You may ask Cedar's PC for access to your personal information and may request correction of factual errors or omissions, subject to exceptions allowed by law. Requests should be made in writing to the Privacy Contact and include enough information to identify the records requested.
Customers may also request correction of account details such as name, contact information and address. A correction to profile information does not rewrite historical ledger transactions; where a financial record requires correction, Cedar's PC uses a documented reversal or adjustment.
12. Account deactivation and withdrawal of consent
A customer may ask to deactivate their Wallet portal access. Deactivation ends access to the portal but does not automatically delete records that Cedar's PC reasonably needs to retain for ledger, audit, security, business or legal purposes. Cedar Credit does not expire merely because portal access is deactivated.
Where you withdraw consent for an optional use of information, Cedar's PC will stop that use where required by law. Some core information is necessary to operate or secure a Wallet; withdrawing consent to those core functions may make continued Wallet access impracticable.
13. Privacy incidents and breach response
Cedar's PC maintains procedures to respond to suspected or confirmed privacy incidents. If a breach involving personal information creates a real risk of significant harm, Cedar's PC will notify the Office of the Information and Privacy Commissioner of Alberta and affected individuals where required by applicable law, and will take reasonable steps to contain the incident and reduce harm.
14. Staff and employee information
Staff and Owner accounts generate personal employee information and audit records used to establish, manage, secure and, where applicable, end the employment or work relationship. Cedar's PC will provide reasonable notice of these uses and limit staff information handling to reasonable employment, security, compliance and operational purposes.
Staff and Owner users must also review the Cedar's PC Wallet Staff Acceptable Use, Confidentiality and Security Agreement, which governs how authorized users may access and handle customer and business information.
15. Questions, complaints and regulator contact
Questions, access or correction requests, and privacy complaints should first be directed to Cedar's PC's Privacy Contact:
| Privacy Contact | Joseph Kaba, Owner |
|---|---|
| Organization | Cedar's PC Ltd |
| cedars.pc@gmail.com | |
| Mailing address | 3696 97 St NW, Edmonton, AB T6E 5S8 |
If you are not satisfied with Cedar's PC's response, you may have the right to contact the Office of the Information and Privacy Commissioner of Alberta or another privacy regulator with jurisdiction over the matter.
16. Changes to this Policy
Cedar's PC may update this Policy when its practices, service providers, Wallet features or legal requirements change. The Wallet will display the current version and effective date. Material changes will be brought to affected users' attention and, where required, renewed consent or acknowledgement will be obtained.