Privacy Notice
The pilot collects very little. This page says exactly what, why and where.
Version 2026-08-01-payments
Who is responsible
The privacy officer/contact and legal operator identity are not configured. That is a public launch blocker. Pilot reviewers should contact the person who provided access.
When configured this section will read: [legal entity — set WATERLOGGED_LEGAL_NAME], [registered address — set WATERLOGGED_LEGAL_ADDRESS], privacy contact [privacy contact — set WATERLOGGED_PRIVACY_EMAIL].
Person accountable for personal information (Quebec Law 25 s.3.1): not yet appointed — [privacy officer — set WATERLOGGED_PRIVACY_OFFICER]. Until a named person is published, the privacy contact above is the route for every request described on this page.
Information collected and why
- Watch request. If you submit an email address, Waterlogged stores the address, sailing identifier, request time, source and the consent sentence shown at submission. The only purpose is to provide the operational alert requested for that sailing. The sender is not built in this pilot, so recording a request does not currently send a message.
- Access cookie. A signed, HTTP-only cookie records the sailing, access tier and expiry for reports unlocked in this browser. It contains no name, email or card data. Clearing browser cookies removes it.
- Order record. Every unlocked report writes one order line: a retrieval code, the sailing, the price, the version of the Terms that was on screen, the time, and — if you gave one — the email address for recovering that purchase. The address is optional at checkout and is used for exactly two things: matching a recovery request (/recover) and handling a refund. It is not used for marketing.
- Request and security logs. The web server or future host may record standard technical data such as time, requested path, IP address, user agent and errors to operate and secure the service. The submitted email is not deliberately written to application logs.
This release uses no advertising tracker, third-party analytics pixel or payment processor and collects no card details. Waterlogged does not sell personal information and does not use a watch request for marketing.
Consent and email rules
Submitting the unchecked watch form is an affirmative request for the identified operational message. It is not consent to a newsletter or promotion. Any future alert sender must identify Waterlogged, include a working stop method, record consent, and honour withdrawal. Promotional content requires a separate consent and is outside this pilot.
Retention and deletion
Watch requests are deleted automatically 180 days after the scheduled sailing, or sooner on a verified request. This is not a promise waiting on a scheduled job: the store applies the rule on every write, so an expired address is removed the next time the file is touched, on any host, whether or not a maintenance task was ever configured. Malformed or unrecognised records are quarantined for operator review rather than guessed at, and the repository carries a tested removal/purge function plus an operating runbook. A periodic purge is still scheduled on the production host so that a store nobody is writing to is cleared as well.
Order records are kept while they can still be needed for recovery, refunds, chargebacks and the tax and accounting records a seller is required to keep — that obligation is measured in years, not months, and it is the reason an order line outlives a watch request. The optional email address on an order is erased on verified request except where a retention obligation requires the transaction record itself to be kept, in which case it is reduced to what that obligation needs.
Access-cookie expiry is encoded in the cookie. Technical log retention must be configured with the production host and disclosed here before launch; it is not yet represented as a fixed period because no production host is active.
Access, correction, deletion and complaints
You may ask whether Waterlogged holds a watch request or an order for you, request access or correction, withdraw a request, or ask for deletion. Identity will be verified before any personal information is disclosed or removed. Waterlogged will record and respond to privacy complaints and will explain any lawful reason a request cannot be completed.
How to ask, and what happens. Send the address you used — and, for an order,
the WL-XXXX-XXXX retrieval code from your receipt — to the privacy contact below
with the word "delete" in the subject.
- Watch requests are removed in full from every sailing, or from a single sailing if that is what you ask for. Nothing is retained about you afterwards.
- Order records have the email address removed. Where the transaction itself must be kept for tax, accounting or refund-dispute reasons, what remains is the order code, the sailing, the amount and the date — a record of a sale, not a record of a person.
- The access cookie is on your own device and is not ours to delete: clear your browser cookies and it is gone.
We aim to confirm in writing within 30 days, which is the outer limit set by Quebec's Law 25 and by comparable rules elsewhere. A request that cannot be completed gets a written reason and a route to complain — to us first, and then to the privacy regulator where you live.
During the private pilot, send the request to the person who provided access.
Service providers, location and incidents
The current watch store is a local server file and is not sent to an email or analytics provider. Before production hosting, every processor, storage location and cross-border transfer must be inventoried, contractually controlled and added here. Access is limited to operators who need it, and backups containing watch requests must follow the same deletion and security rules.
Suspected loss or unauthorised access must be contained, documented and assessed under the applicable breach-notification rules. This notice will be updated when the host, mailer or payment processor changes the actual data flow.