Skip to content
Hand-poured in Canada — free shipping on orders over $50
Bassline Baits

Privacy Policy

Read this bit first. I wrote this in good faith to describe what this site actually does with your information. It is a starting template, not legal advice — I pour fishing lures, I’m not a lawyer. Before anyone relies on it in a way that matters, it should be reviewed by someone who knows Canadian privacy law. If something in here doesn’t match how the site really behaves, tell me on the contact page and I’ll correct it.

Last updated: 26 July 2026.

The short version

  • I collect your name, email and shipping address so I can pack a box and get it to your door.
  • Your card number never touches this server. It goes straight to the payment processor on their own encrypted form.
  • Nothing is sold, rented, or handed to a marketing list. Not now, not once the shop gets bigger.
  • You can ask me what I hold on you and ask me to fix it if it’s wrong. That’s your right under Canadian law, and it takes one email.

Who is accountable for this

Bassline Baits is one person hand-pouring soft plastics in small batches in Canada. There is no marketing department here and no CRM full of your habits — there’s a pour pot, a shipping scale, and an order list.

Canadian privacy law for a business like this one is PIPEDA — the Personal Information Protection and Electronic Documents Act. It applies to personal information collected in the course of commercial activity, which is exactly what an online order is. PIPEDA requires that a real person be accountable for that information. That person is me, [[NEEDS: his first name]] — the same one mixing plastic and printing labels. You reach me through the contact page.

What I actually collect

When you place an order

WooCommerce checkout asks for what a shipment needs and nothing extra:

  • Your name
  • Your email address (order confirmation, shipping notice, and me emailing you if something’s out of stock)
  • Your shipping address, and billing address if it’s different
  • A phone number, only if a carrier needs one for delivery
  • What you ordered, what you paid, and when — your order history
  • Any note you leave in the order notes box

That order record lives in the site’s WooCommerce database on the web host’s server. I look at it to pack the order and to answer you if you write in about it.

Your payment details

This is the part people care most about, so plainly: your full card number never touches this server and I never see it. Payment is handled by [[NEEDS: confirm whether Stripe, PayPal, or both are live — delete whichever you don’t use]], and the card fields at checkout are that processor’s own, not mine. What comes back to me is confirmation that the payment cleared, the last four digits, and the card brand, so I can match a payment to a box. Refunds run back through the same processor.

When you’re just looking

You can browse the shop, read through a species page like smallmouth bass, or work your way down the journal without giving me anything. No account required to read. The server and Cloudflare do log standard technical stuff — IP address, browser type, the page requested, the time — which is how any web server on earth works and how bad traffic gets filtered out.

When you email me

If you use the contact page, I get whatever you type plus your email address so I can reply. I keep those threads because half of them are useful — someone tells me a colour ran too soft in cold water and that changes the next batch.

Email marketing

Order-related emails (confirmation, shipping) are transactional and go out automatically. There is no marketing list at the moment. If I start one, Canada’s anti-spam law (CASL) means you have to actively opt in — no pre-ticked boxes, no adding you because you bought something — and every message carries a working unsubscribe link. This page gets updated before that ever happens.

Cookies, and what each one is doing

No cookie on this site is here to follow you around the internet. Here’s the honest list of what’s in play:

Cookie Set by What it does How long it lasts
woocommerce_cart_hash, woocommerce_items_in_cart WooCommerce Remembers what’s in your cart so it isn’t empty when you come back to the tab Session
wp_woocommerce_session_… WooCommerce Links your browser to your cart and checkout details held on the server About 2 days
_lscache_vary LiteSpeed Cache Tells the server to serve you a live page instead of a cached one once you have a cart or are logged in Session
__cf_bm, cf_clearance Cloudflare Separates real visitors from bots and blocks abusive traffic before it reaches the site 30 minutes to a year
wordpress_logged_in_…, wp-settings-… WordPress Only if you have an account — keeps you logged in Session to 1 year

Analytics: if I connect a stats tool to see which baits people actually read about, it goes in this table with a plain description before it goes live, and I’ll pick one that measures pages rather than people. You can block or clear cookies in your browser at any time. Do that and the cart will forget you, but the site still works.

Who else sees your information, and why

Who What they get Why they need it
The payment processor Your card details, name, email, billing address To take the payment and screen it for fraud. They hold the card data, not me.
Canada Post (or another carrier if a package needs it) Your name, shipping address, and contact details for tracking To physically deliver the box
The web host The site database and server logs sit on their machine To run the site at all
Cloudflare IP addresses and request data passing through DNS, security filtering, and speed

That’s the whole list. No data brokers, no list rental, no ad-network pixels selling your visit to a bidder. The only other case is a legal one: if I were ever legally required to hand something over — a court order, a lawful demand from a Canadian authority — I’d have to comply.

Some of it is handled outside Canada

Payment processors, Cloudflare, and possibly the email that carries your order confirmation operate servers outside Canada, mostly in the United States and the EU. PIPEDA allows a Canadian business to transfer personal information to a provider in another country for processing, but you’re owed the disclosure: while your information is on a foreign provider’s servers, it’s subject to that country’s laws, including lawful access by that country’s courts and agencies. I stay accountable for it either way, and I only use providers with published security and privacy commitments.

How long any of this is kept

  • Order records: the Canada Revenue Agency expects business records to be kept six years from the end of the tax year they relate to, so order and payment records stay that long. That’s a legal obligation and it’s the one thing I can’t delete on request.
  • Customer account details: until you ask me to close the account, then removed apart from what has to stay in the order record above.
  • Contact-page emails: roughly two years, then deleted, unless the thread is tied to a warranty or a dispute.
  • Server and security logs: weeks, not years. They rotate out on their own.
  • Cart cookies: they expire on the schedule in the table above.

Seeing it, fixing it, or getting it deleted

Under PIPEDA you have the right to ask what personal information an organization holds about you, what it’s been used for, who it’s been shared with, and to have anything inaccurate corrected. To use it, send a request through the contact page with the email address you ordered under and, if you have it, an order number — that’s how I confirm I’m sending your information to you and not to somebody else. I’ll respond within 30 days, which is the deadline PIPEDA sets, and it costs you nothing.

You can also ask me to delete what isn’t legally required to stay. Say the word and the account goes, the mailing list entry goes, the email thread goes. The tax-record side of an order has to remain.

If you think I’ve handled something badly and my answer doesn’t satisfy you, you can take it to the Office of the Privacy Commissioner of Canada. I’d rather you came to me first so I can actually fix it.

Keeping it safe

The whole site runs over HTTPS, so checkout is encrypted end to end. Card data isn’t stored here because it never arrives here. Account passwords are stored hashed, not in plain text. Cloudflare sits in front of the site filtering junk traffic, and the software gets kept up to date.

No website is bulletproof and I’m not going to claim otherwise. If there were ever a breach that created a real risk of significant harm to you, PIPEDA requires me to notify you and report it to the Privacy Commissioner. I’d tell you regardless — I’d want to be told.

Kids

This is a fishing-tackle shop, not a site aimed at children, and orders should be placed by an adult. I don’t knowingly collect personal information from anyone under 13. If you’re a parent or guardian and you think your kid entered their information here, get in touch and I’ll delete it. Young anglers are welcome to read every word on the site — fishing runs on kids getting hooked early — they just shouldn’t be the one at checkout.

When this policy changes

If the shop adds a tool that changes what’s collected — analytics, a mailing list, a different payment processor — this page gets updated before that tool goes live, and the “last updated” date at the top changes with it. Anything substantial gets called out plainly here rather than quietly reworded. Nothing gets applied retroactively to information you already gave me under an older version. It’s worth checking the date if you’re about to order.

Questions

Anything in here you want explained in plain terms, anything you want to see, correct or delete — the contact page reaches me directly. A real person reads it, usually the same day.