Privacy Policy
Last Updated: March 27, 2026
Your privacy matters to us. This policy explains how GlowPicked collects, uses, and protects your personal information when you visit our website or use our services.
Person responsible for the protection of personal information (Loi 25):
Francis Levesque, Data Protection Officer — privacy@trente6ai.com
The Quick Summary
📊 What We Collect
Email addresses, browsing behavior, and basic analytics. We don't collect sensitive personal data.
🎯 Why We Collect It
To send you beauty recommendations, improve our product research, and understand what content you find helpful.
🔒 How We Protect It
Industry-standard encryption, secure servers, and we never sell your data to third parties.
🚪 Your Rights
You can access, update, or delete your data anytime. Just contact us.
Information We Collect
Information You Provide Directly
- Email Address: When you subscribe to our newsletter
- Contact Information: When you contact us with questions
- Survey Responses: When you participate in our research
- Comments: If you comment on our articles (future feature)
Information Collected Automatically
- Website Usage: Pages visited, time spent, click patterns
- Device Information: Browser type, operating system, IP address
- Referral Data: How you found our website
- Analytics Data: Performance metrics and user behavior
Information We Don't Collect
- ❌ Social Security Numbers or government IDs
- ❌ Financial information or credit card data
- ❌ Health records or medical information
- ❌ Biometric data or facial recognition
- ❌ Location tracking (beyond general geographic region)
How We Use Your Information
Send You Beauty Recommendations
We use your email to send weekly newsletters with our latest product reviews and beauty discoveries.
Improve Our Research
We analyze browsing patterns to understand which products and reviews are most helpful to visitors.
Website Analytics & Performance
We track website performance, popular content, and technical issues to improve user experience.
Customer Support
We use contact information to respond to your questions, complaints, or feedback.
Legal Compliance
We may use information to comply with legal obligations or protect our rights.
How We Protect Your Information
Encryption
All data transmitted to and from our website is encrypted using SSL/TLS technology.
Secure Hosting
Our website is hosted on Netlify's secure infrastructure with industry-standard protections.
Access Controls
Only authorized personnel have access to personal information, and access is logged.
Regular Audits
We regularly review our security practices and update them to address new threats.
Data Retention
We only keep personal information as long as necessary and securely delete it when no longer needed.
Breach Notification
In accordance with Quebec's Law 25 (Loi 25), in the event of a confidentiality incident involving your personal information that presents a serious risk of harm, we commit to:
- Notifying the Commission d'acces a l'information du Quebec within 72 hours of becoming aware of the incident
- Notifying you as soon as possible if the incident presents a serious risk of harm to you
- Maintaining a register of confidentiality incidents as required by law
This obligation also meets the requirements of GDPR Article 33 (72-hour notification to supervisory authority) and PIPEDA breach reporting requirements.
Data Retention
We retain personal information only as long as necessary for the purposes described in this policy:
- Email subscriptions: Until you unsubscribe or request deletion
- Analytics data: Aggregated and anonymized; raw data retained for up to 26 months
- Contact inquiries: Up to 24 months after the last interaction
- Survey responses: Up to 36 months, then anonymized or deleted
- Server logs: Up to 90 days for security and troubleshooting purposes
When data is no longer needed, it is securely deleted or anonymized so that it can no longer be associated with you.
Your Privacy Rights
🇨🇦 Quebec (Loi 25)
🇪🇺 European Union (GDPR)
🇺🇸 California (CCPA/CPRA)
🇨🇦 Canada (PIPEDA)
How to Exercise Your Rights
To exercise any of these rights, contact our Data Protection Officer at privacy@trente6ai.com or privacy@glowpicked.com with:
- Your full name and email address
- Specific right you want to exercise
- Any additional details that help us locate your data
We'll respond within 30 days (or as required by applicable law) and may ask for identity verification to protect your privacy.
International Data Transfers
GlowPicked is based in Canada, but our website and services may involve data transfers to other countries, including the United States, where our service providers are located.
How We Protect International Transfers:
- Use service providers with adequate data protection measures
- Implement data processing agreements with all vendors
- Ensure appropriate safeguards are in place
- Comply with applicable cross-border data transfer laws
Specific International Transfers:
- United States: Google Analytics, Netlify hosting, email services
- European Union: Some AI analysis services (with appropriate safeguards)
Children's Privacy
GlowPicked is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information immediately.
If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us immediately at privacy@glowpicked.com.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
How We'll Notify You of Changes:
- Update the "Last Updated" date at the top of this page
- Send email notifications for significant changes (if you're subscribed)
- Post notices on our website for major policy updates
We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect your information.
Droits des utilisateurs / User Rights
GlowPicked is a static website. We do not collect personal data server-side. Any data processing (analytics cookies, newsletter subscriptions) is minimal and based on your consent.
Your rights under Loi 25 (Quebec), GDPR, PIPEDA, and CCPA/CPRA
Request a copy of any personal data we hold about you.
Ask us to correct inaccurate or incomplete information.
Request that we delete your personal data.
Receive your data in a structured, machine-readable format (JSON or CSV).
Withdraw your consent for data processing at any time.
File a complaint with the Commission d'acces a l'information du Quebec or your local supervisory authority.
How to exercise your rights
Send your request to: privacy@trente6.ai
We will respond within 30 days. We may ask for identity verification to protect your privacy.
As GlowPicked is a static site, most personal data exists only if you subscribed to our newsletter. You can unsubscribe at any time via the link in any email we send you.
Contact Us About Privacy
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
🛡️ Data Protection Officer (DPO)
Francis Levesque
Responsible for personal information protection under Loi 25 and GDPRprivacy@glowpicked.com
For fastest response to privacy inquiries📝 General Contact
Use our contact form for non-urgent privacy questions
📍 Mailing Address
GlowPicked Privacy Team
Trente6 AI
Quebec, Canada