1. Who we are
Sieraden Online Inc. ("Sieraden", "we", "us") is incorporated in Ontario, headquartered at 215 Spadina Avenue, Toronto, ON M5T 2C7. We operate the website at sieraden-online.com — an editorial portal and skin marketplace serving the Canadian esports scene. Questions about this policy go to privacy@sieraden-online.com. Our Privacy Officer responds within 30 days as required by Canadian law.
2. What we collect
- Account & order data — email, display name, linked game accounts, billing details. Collected when you place an order, subscribe to the newsletter, or reach the support inbox.
- Payment data — handled by Stripe (Visa, Mastercard, AMEX, Interac), PayPal, and BitPay (crypto). We never see your full card number or wallet seed phrases.
- Browsing data — pages visited, referrer URL, device type, anonymised IP. Aggregated through Plausible Analytics, hosted in Germany. No cross-site tracking.
- Chat transcripts — when you use the live chat, the conversation is stored for 90 days to improve responses and audit support quality.
3. Why we collect it
We use your information to deliver the orders you place, send you the digests you ask for, settle skin trades against your linked game account, and improve the portal. We do not sell or rent personal data to third parties — that includes the newsletter subscribers list, the order history, and chat transcripts.
4. Cookies and similar technologies
We set a small number of strictly necessary cookies (session id, CSRF token) plus an optional preferences cookie that remembers your filter selections. Analytics are cookie-less through Plausible. If you load embedded Twitch or YouTube streams, those platforms set their own cookies under their respective policies. See the dedicated cookies page for the full list.
5. Your rights
Under PIPEDA and Quebec's Law 25 you have the right to access your data, ask for corrections, port a copy to another provider, withdraw consent and request deletion. Email privacy@sieraden-online.com and we will verify your identity and respond within 30 days. EU and UK visitors enjoy equivalent GDPR rights, including the right to lodge a complaint with their local supervisory authority.
6. Data retention
Order records are kept for seven years to satisfy CRA bookkeeping requirements. Newsletter subscriber data is kept until you unsubscribe. Chat transcripts auto-delete after 90 days. Aggregated, non-identifiable analytics are kept indefinitely.
7. Security
All traffic uses TLS 1.3 with HSTS preloaded. Production databases sit in Toronto-region servers and are encrypted at rest. Two factor authentication is mandatory for every Sieraden employee with access to customer data. We undergo a CPA Canada security audit every six months.
8. International transfers
Most of your data stays in Canada. Stripe processes some payment data in the United States under their Standard Contractual Clauses agreement; PayPal stores transaction metadata in Luxembourg. We do not transfer data to jurisdictions without an adequacy ruling.
9. Children
Sieraden services are intended for visitors aged 16 and over. We do not knowingly collect data from anyone younger. If you believe a child has provided us data, email privacy@sieraden-online.com and we will delete it.
10. Changes to this policy
If we update this policy in a way that materially affects your rights, we will notify newsletter subscribers by email at least 14 days before the change takes effect, and post the previous version on this page for reference.