Privacy Policy
1. Introduction
Thank you for visiting our website. This Privacy Policy explains how Elora Toronto ("we", "us", "our") collects, uses and protects your personal data when you use our website. Personal data refers to any information that can be used to identify you.
Elora Toronto is the data controller responsible for processing personal data on this website in accordance with the General Data Protection Regulation (GDPR) and applicable Canadian privacy legislation.
For security reasons, this website uses SSL/TLS encryption to protect the transmission of personal data. You can recognise an encrypted connection by the "https://" prefix and the lock icon in your browser.
2. Data Collection When Visiting Our Website
When you visit our website without registering or submitting information, we only collect the data your browser automatically transmits to our server. This includes:
- Pages visited on our website
- Date and time of access
- Amount of data transferred
- Referring URL
- Browser type and version
- Operating system
- IP address (anonymised where possible)
This data is processed on the basis of our legitimate interest in ensuring the stability, security and functionality of our website (Art. 6(1)(f) GDPR). Data is not shared with third parties unless required for investigating unlawful use.
3. Cookies
We use cookies to improve your experience and enable certain features. Cookies are small text files stored on your device.
- Session cookies are deleted automatically when you close your browser.
- Persistent cookies remain on your device for a set duration and allow us to recognise your browser on future visits.
Some cookies are essential for core functionality such as remembering items in your shopping cart. Where cookies process personal data, processing is based on Art. 6(1)(b) GDPR (contract performance) or Art. 6(1)(f) GDPR (legitimate interest).
We may work with advertising partners who place third-party cookies. You will be informed separately when this applies.
You can configure your browser to accept, reject or alert you about cookies. Disabling cookies may limit certain website features.
4. Contact
When you contact us via email or a contact form, we collect the personal data you provide. This data is used solely to respond to your enquiry (Art. 6(1)(f) GDPR). If your enquiry relates to a contract, processing is based on Art. 6(1)(b) GDPR.
Your data is deleted once your request has been fully resolved, unless we are required to retain it by law.
5. Customer Accounts and Orders
When you create a customer account or place an order, we process your personal data to fulfil the contract (Art. 6(1)(b) GDPR). You may request deletion of your account at any time by contacting us.
After contract completion, your data is retained only for the legally required retention periods and then deleted, unless you have consented to further use.
6. Newsletter and Direct Marketing
Newsletter subscription — If you subscribe to our newsletter, we use your email address to send you regular updates about our products and offers. We use a double opt-in process: after signing up, you will receive a verification email with a confirmation link. By clicking the link, you consent to receiving newsletters (Art. 6(1)(a) GDPR). You may unsubscribe at any time via the link included in every email.
Existing customers — If you provide your email address during a purchase, we may send you offers for similar products based on our legitimate interest in direct marketing (Art. 6(1)(f) GDPR). You may opt out at any time.
7. Order Processing and Payment
We share your data with shipping companies for delivery and with payment providers for payment processing, as necessary to fulfil the contract (Art. 6(1)(b) GDPR).
PayPal — If you pay via PayPal, your payment data is shared with PayPal (Europe) S.à r.l. et Cie. PayPal may conduct credit checks based on legitimate interest. PayPal Privacy Policy
Klarna / Sofort — If you choose Klarna or Sofort, your data is shared with Klarna Bank AB for payment processing. Klarna Privacy Policy
8. Social Media
We may use social media plugins (e.g. Facebook, Instagram) in a privacy-friendly format that prevents automatic data transfer when the page loads. Data is only transmitted to the respective platform when you actively click on a social media button.
9. Online Advertising
Google Ads — We use Google Ads conversion tracking to measure the effectiveness of our advertising campaigns. Cookies may be placed to track interactions with our ads. These cookies expire after 30 days and do not personally identify you. Google Privacy Policy
Facebook Pixel — With your explicit consent (Art. 6(1)(a) GDPR), we use the Meta Pixel to track user behaviour after viewing or clicking a Facebook advertisement. This helps us evaluate ad effectiveness and improve future campaigns. The data collected is anonymous to us, however Meta may link it to your profile in accordance with its own data policy. You may withdraw consent at any time. Meta Privacy Policy
Google Remarketing — We use Google Ads Remarketing to display relevant advertisements across Google's network and third-party websites, based on your previous visits. This processing is based on our legitimate interest in effective marketing (Art. 6(1)(f) GDPR). You may disable ad-related cookies via Google Ads Settings or the Digital Advertising Alliance.
10. Web Analytics
We use Google Analytics with IP anonymisation to understand how visitors use our website. Data may be transferred to servers in the United States under the EU–US Data Privacy Framework. You may opt out of tracking by installing the Google Analytics Opt-out Browser Add-on.
11. Your Rights
Under applicable data protection law, you have the following rights regarding your personal data:
- Access — Request information about the personal data we hold about you (Art. 15 GDPR).
- Rectification — Request correction of inaccurate or incomplete data (Art. 16 GDPR).
- Erasure — Request deletion of your personal data under the conditions of Art. 17 GDPR.
- Restriction — Request restriction of processing in certain circumstances (Art. 18 GDPR).
- Portability — Receive your data in a structured, machine-readable format or request transfer to another controller (Art. 20 GDPR).
- Withdraw consent — Withdraw any consent you have given at any time, with future effect (Art. 7(3) GDPR).
- Objection — Object to processing based on legitimate interests at any time. If you object, we will stop processing unless we can demonstrate compelling grounds (Art. 21 GDPR).
- Complaint — Lodge a complaint with a supervisory authority in your country of residence (Art. 77 GDPR).
If your data is used for direct marketing, you may object at any time and we will cease processing for that purpose immediately.
12. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy or to comply with legal retention obligations (e.g. commercial or tax law). Once these periods expire, your data is routinely and securely deleted.
13. Contact
If you have questions about this Privacy Policy or wish to exercise any of your rights, please contact us at support@eloratoronto.com