Privacy policy
Last updated: April 2026
Our Commitment to Your Privacy
At Crystal Beaute we believe transparency extends beyond our ingredient lists. We are committed to protecting your personal information and being clear about how we collect, use, and safeguard it. This Privacy Policy explains our practices in plain language — because you deserve to understand what happens to your information just as much as you deserve to understand what goes into your products.
This Privacy Policy applies to personal information collected through our website at www.CrystalBeaute.co and through any purchase or interaction you have with us. Crystal Beaute operates in compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
Section 1 — Information We Collect
We collect personal information that is necessary to provide our products and services to you. This includes:
Information you provide directly:
- Name and contact information — first name, last name, email address, phone number
- Billing and shipping address
- Payment information — processed securely through Shopify's encrypted payment system. We do not store your full credit card details on our servers
- Account login credentials if you create an account
- Communications you send us — emails, contact form submissions, customer service inquiries, reviews, and feedback
Information collected automatically when you visit our website:
- Device information — IP address, browser type and version, operating system, device type
- Usage data — pages visited, time spent on pages, links clicked, referring URLs
- Location data — general geographic location based on IP address
- Cookie data — as described in Section 4 below
Information from third parties:
- If you interact with us through social media platforms such as Instagram, TikTok, or Facebook we may receive information consistent with your privacy settings on those platforms
- Shopify, our e-commerce platform, collects certain information as part of processing your order. Please review Shopify's Privacy Policy at shopify.com/legal/privacy for details on their practices
Section 2 — How We Use Your Information
We collect and use your personal information only for the purposes for which it was provided and for related legitimate business purposes. Specifically we use your information to:
- Process and fulfill your orders including payment processing, shipping, and order confirmation
- Communicate with you about your order status, tracking information, and any issues with your purchase
- Respond to your customer service inquiries and requests
- Send you marketing communications — including promotions, new product announcements, and brand updates — where you have opted in to receive them
- Improve our website, products, and customer experience through analysis of usage data
- Comply with legal obligations and enforce our Terms of Service
- Detect, investigate, and prevent fraudulent transactions and other illegal activities
- Personalize your experience on our website
We will not use your personal information for purposes beyond those listed above without your consent, except where required or permitted by law.
Section 3 — Legal Basis for Processing
We process your personal information on the following grounds:
Contract performance — processing your order and fulfilling our obligations to you as a customer requires us to use your personal information.
Legitimate interests — operating and improving our business, preventing fraud, and communicating with customers are legitimate interests that require limited use of personal information.
Consent — where we send marketing communications or use non-essential cookies we do so on the basis of your consent which you may withdraw at any time.
Legal obligation — we may process your information where required to comply with applicable Canadian law.
Section 4 — Cookies
A cookie is a small file downloaded to your device when you visit our website. We use cookies to make your browsing experience better and to understand how our website is being used.
Types of cookies we use:
Strictly necessary cookies — essential for the website to function. These cannot be disabled as they enable core functions such as shopping cart and checkout. No consent is required for these.
Performance and analytics cookies — help us understand how visitors interact with our website by collecting anonymous usage data. This helps us improve the site experience.
Functional cookies — remember your preferences such as language, region, and login status so you do not have to re-enter information on each visit.
Marketing and advertising cookies — used to deliver relevant content and advertisements and to track the effectiveness of our marketing campaigns.
Most cookies we use are persistent and expire between 30 minutes and two years from the date they are downloaded to your device. Session cookies expire when you close your browser.
Managing cookies: You can control and manage cookies through your browser settings — typically found in your browser's Tools or Preferences menu. Removing or blocking cookies may impact your experience on our website and some features may no longer function fully. For more information on managing cookies visit www.allaboutcookies.org.
Please note that blocking cookies may not fully prevent information sharing with third parties such as advertising partners. To opt out of certain uses of your information by these parties please follow the instructions in Section 5 below.
Section 5 — Sharing Your Information
We do not sell your personal information. We do not share your personal information with third parties except in the following circumstances:
Service providers — we share information with trusted third-party service providers who assist us in operating our business. These include:
- Shopify Inc. — our e-commerce platform provider, based in Ottawa, Canada. Shopify processes order and payment data on our behalf
- Shipping carriers — your name and shipping address are shared with our carrier partners to fulfill your delivery
- Email marketing platforms — if you have opted in to marketing communications your email address may be shared with our email service provider
- Analytics providers — anonymous usage data may be shared with analytics tools to help us understand website performance
All service providers are contractually required to protect your information and use it only for the purposes for which it was shared.
Legal requirements — we may disclose your information where required by law, court order, or government authority, or where necessary to protect the rights, property, or safety of Crystal Beaute, our customers, or others.
Business transfers — in the event of a merger, acquisition, or sale of assets your personal information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.
We do not transfer your personal information outside of Canada and the United States except where necessary to fulfill your order or where you have given explicit consent. Where transfers occur we ensure appropriate safeguards are in place.
Section 6 — Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected — including providing our services to you, complying with legal obligations, resolving disputes, and enforcing our agreements.
Specifically:
- Order information is retained for a minimum of 7 years as required by Canadian tax and accounting law
- Customer account information is retained for as long as your account remains active
- Marketing opt-in data is retained until you withdraw consent
- Cookie data is retained for the period specified in Section 4
When your information is no longer required we will securely delete or anonymize it.
Section 7 — Your Rights
Under PIPEDA and applicable Canadian privacy law you have the following rights regarding your personal information:
Right of access — you have the right to request access to the personal information we hold about you and to receive information about how it is being used.
Right to correction — you have the right to request correction of any inaccurate or incomplete personal information we hold about you.
Right to withdrawal of consent — where we process your information on the basis of consent you may withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing conducted prior to withdrawal.
Right to unsubscribe — you may opt out of marketing communications at any time by clicking the unsubscribe link in any email we send or by contacting us directly.
Right to complain — you have the right to make a complaint to the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.
Section 8 — Data Security
We take the security of your personal information seriously. We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- SSL encryption across our website
- Encrypted payment processing through Shopify's PCI-compliant payment system
- Access controls limiting who within our operation can access personal information
- Regular review of our data collection, storage, and processing practices
Please note that no method of transmission over the internet or electronic storage is completely secure. While we implement commercially reasonable security measures we cannot guarantee absolute security. If you believe your information has been compromised please contact us immediately.
Section 9 — Do Not Track
Some browsers include a Do Not Track feature that signals to websites that you do not want your online activity tracked. As there is no consistent industry standard for responding to Do Not Track signals our website does not currently alter its data collection practices in response to these signals. You may manage your privacy preferences through cookie settings as described in Section 4.
Section 10 — Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make changes we will update the date at the top of this policy. We encourage you to review this policy periodically. Your continued use of our website following any changes constitutes acceptance of the updated policy. For significant changes we will make reasonable efforts to notify you directly.
Section 11 — Contact & Complaints
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or would like to make a complaint about our privacy practices please contact us:
Crystal Beaute Co. Email: info@crystalbeaute.co Website: www.CrystalBeaute.co
Crystal Beaute Co. — Rooted in wisdom. Made for now.
All Right Reserved Without Prejudice; U.C.C. 1-207 / 308, U.C.C. 1-103