Privacy Policy
Last updated: June 03, 2026
This Privacy Notice for Ekstia Creations Inc. (“we,” “us,” or “our”), describes how and why we might collect, store, use, and share (“process”) your information when you use our services (“Services”). This includes when you visit our digital storefront at http://www.ekstia.com, create a client account, utilize our custom design portal, or consult with us in person.
Reading this Privacy Notice will help you understand your privacy rights and choices under Canadian federal and provincial regulations. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you have any questions, you can reach us directly at info@ekstia.com.
TABLE OF CONTENTS
- WHAT INFORMATION DO WE COLLECT?
- HOW DO WE PROCESS YOUR INFORMATION?
- WHAT LEGAL BASES DO WE RELY ON?
- WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
- DO WE USE COOKIES AND TRACKING TECHNOLOGIES?
- HOW LONG DO WE KEEP YOUR INFORMATION?
- HOW DO WE KEEP YOUR INFORMATION SAFE?
- DO WE COLLECT INFORMATION FROM MINORS?
- WHAT ARE YOUR PRIVACY RIGHTS?
- CONTROLS FOR DO-NOT-TRACK FEATURES
- DO WE MAKE UPDATES TO THIS NOTICE?
- HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
1. WHAT INFORMATION DO WE COLLECT?
Personal Information You Disclose to Us
We collect personal information that you voluntarily provide to us when you register an account on our website, express interest in our custom services, upload design files, or communicate with our studio.
The personal information we collect depends entirely on your interactions with our custom milestone process and may include:
- Identity & Contact Data: First and last names, email addresses, phone numbers, billing addresses, and physical shipping/delivery addresses.
- Account Credentials: Usernames, passwords, and security/authentication configurations used to access your private client portal.
- Bespoke Project Data: Custom jewelry design specifications, physical measurements (such as ring sizes), project notes, lifestyle preferences, and user-uploaded reference images or sketches used to generate 3D CAD models.
- Transaction & Payment Data: We collect information necessary to track your milestone deposits and balances (such as order histories, invoices, and fulfillment statuses). To facilitate checkout, our platform accepts major credit cards, including Visa, MasterCard, and American Express. All actual credit card processing is handled securely by our external, PCI-compliant third-party partners (Stripe, PayPal, and QuickBooks Payments). We do not store raw credit card numbers on our servers.
Information Automatically Collected
When you navigate our website, our system automatically logs standard technical information via cookies and web servers. This information does not reveal your specific identity but includes:
- Device & Usage Data: Your Internet Protocol (IP) address, browser characteristics, device operating system, language preferences, referring URLs, and historical data regarding how and when you interacted with our web pages. This data is strictly used to maintain security, optimize mobile responsiveness, and track basic internal analytics.
2. HOW DO WE PROCESS YOUR INFORMATION?
We process your personal information only when we have a valid legal reason to do so under Canadian law. Specifically, we use your data to:
- Manage Client Accounts: To facilitate account creation, secure user authentication, and maintain your private custom portal.
- Execute Custom Orders: To manage your 3-step milestone process, including design collaborations, CAD file links, manufacturing fulfillment, and order delivery.
- Studio Communications: To respond to your direct inquiries, provide design updates, send milestone payment alerts, and manage local consultation handovers.
- Operational Safety: To protect our digital services against unauthorized access, monitor for fraud, and maintain system security.
- Legal Compliance: To satisfy our corporate accounting duties, respond to legal requests, or comply with applicable tax regulations under the Canada Revenue Agency (CRA).
3. WHAT LEGAL BASES DO WE RELY ON?
Under the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) and the Alberta Personal Information Protection Act (PIPA), we process your data based on:
- Express Consent: When you explicitly agree to share your information for custom design projects, user account creation, or email correspondence.
- Contractual Necessity: When processing your data is strictly required to fulfill our design and fabrication obligations to you.
- Legitimate Business Interests: To secure our website infrastructure, prevent fraud, and continuously optimize our client service experience.
4. WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
We only share your data with specific, trusted third parties who are essential to executing your custom jewelry service. These include:
- International Sourcing & Manufacturing Partners: Technical design parameters, customized dimensions (such as ring sizes), and anonymous project identifiers are shared with our trusted overseas production facility to accurately execute your approved CAD model.
- Global Logistics & Couriers: Your name, shipping address, contact number, and commercial customs values are shared with global delivery services (UPS and FedEx) to clear international border customs and complete secure transport to our studio.
- Payment Infrastructure Providers: Transaction and billing data are securely routed to Stripe, PayPal, or QuickBooks Payments to process major credit cards and securely manage your custom milestone deposits and final balances.
- Essential Tech Stack Support: Anonymized technical metrics are shared with our web hosting provider, security plugins, and standard diagnostic tools to keep our storefront functioning flawlessly.
We will never sell, lease, or distribute your personal details to outside marketing brokers or third-party advertisers.
5. DO WE USE COOKIES AND TRACKING TECHNOLOGIES?
Yes. We use standard browser cookies and web pixels to maintain security, ensure your user login session stays active, save your interface preferences, and analyze overall traffic trends.
We utilize Google Analytics to monitor general, aggregate website performance. You can easily choose to set your web browser to reject or delete cookies via your personal browser settings. To completely opt-out of Google Analytics tracking across the web, you can visit: https://tools.google.com/dlpage/gaoptout.
6. HOW LONG DO WE KEEP YOUR INFORMATION?
We only retain your personal information for as long as necessary to fulfill the design and service purposes outlined in this notice, unless a longer retention window is strictly required by Canadian law.
- Portal Account Profiles: If you choose to terminate or delete your client account, your personal user profile, design attachments, and login credentials will be deactivated and deleted from our active database within thirty (30) days.
- Corporate Financial Records: Please note that any transaction data, structural invoices, signed design confirmations, and tax-related receipts cannot be instantly deleted. Under the Canada Revenue Agency (CRA) guidelines, we are legally required to securely retain corporate financial records for a minimum of seven (7) years following the transaction date.
7. HOW DO WE KEEP YOUR INFORMATION SAFE?
We utilize appropriate technical and organizational safeguards designed to protect the security of any personal information we process. This includes secure socket layer (SSL) encryption for data transfers and strict access controls over client portals.
However, despite our best efforts, no transmission over the internet can ever be guaranteed 100% secure. Transmission of personal data to and from our Services is at your own risk, and you should always ensure you are accessing your client portal from a secure network environment.
8. DO WE COLLECT INFORMATION FROM MINORS?
We do not knowingly solicit data from or market our custom design services to individuals under eighteen (18) years of age. By using our website, you represent that you are at least 18 years old. If we discover that an account has been created by a minor under 18, we will immediately deactivate the account and permanently delete all associated data from our active database records. If you believe we have accidentally collected data from a minor, please contact us at info@ekstia.com.
9. WHAT ARE YOUR PRIVACY RIGHTS?
Because our operations are based in Alberta, Canada, you hold distinct rights under PIPEDA and the Alberta PIPA regarding your personal data. These include:
- The Right of Access: You can request a clear copy of the personal information we currently hold on file for you.
- The Right of Rectification: You can request that we update, correct, or amend any inaccurate or incomplete details in your client profile.
- The Right of Erasure: You can request that we delete your user account and personal details (subject to the legal CRA retention limits outlined in Section 6).
- The Right to Withdraw Consent: You can withdraw your consent to our data processing at any time by contacting our studio.
To exercise any of these rights, or to opt-out of standard marketing updates, please email us directly at info@ekstia.com.
10. CONTROLS FOR DO-NOT-TRACK FEATURES
Most major web browsers include a Do-Not-Track (“DNT”) setting you can switch on to signal your online privacy preferences. Because there is currently no finalized, uniform global technology standard for recognizing these signals, our platform does not automatically respond to automated DNT browser requests at this stage.
11. DO WE MAKE UPDATES TO THIS NOTICE?
Yes. We will update this policy from time to time to accurately reflect changes in our studio’s custom service workflows, payment tools, or evolving Canadian privacy laws. The updated version will be marked by the “Revised” date at the top of the page. If we introduce major structural changes to how we process data, we will prominently post an update alert on our homepage or email you a direct notification.
12. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have any questions, concerns, or requests regarding this policy, or if you wish to update or delete any personal information we hold, you may contact us via email at: info@ekstia.com
Your requests will be reviewed and acted upon by our internal Privacy Officer in full accordance with applicable Canadian data protection regulations.