2609699 Ontario Inc., carrying on business as Hey Jeff Maeck (“Hey Jeff Maeck”, “we”, “us”, or “our”), is responsible for personal information under our control. This policy explains what we collect through heyjeffmaeck.com, why we collect it, how it is handled, and the choices available to you.
Our practices are designed around Canada’s PIPEDA fair-information principles, including accountability, meaningful consent, limited collection and retention, safeguards, openness, and individual access. Separate agreements and privacy notices may apply when you deal with one of Jeff’s other businesses or follow a link to an external website.
Privacy at a glance
- we collect contact, account, purchase, email-preference, and limited technical information needed to run the service;
- we do not sell or rent personal information and do not use advertising trackers;
- Stripe handles payment-card details, while we keep the transaction and fulfilment records needed to provide the purchase;
- the only application cookie is the essential sign-in cookie, although embedded media providers may use their own technologies;
- you can unsubscribe from marketing at any time and ask to access or correct your information; and
- additional deletion, restriction, objection, portability, and complaint rights may apply where you live.
Information we collect and where it comes from
- Information you provide: your name, email address, enquiry topic and message; subscription request; and anything else you choose to send to Jeff.
- Account information: your email address, name when available, customer identifier, access entitlements, lesson progress, hashed session and sign-in-token records, and sign-in activity records showing when a confirmed account session began, was last active, or was signed out.
- Purchase and fulfilment information: the products or services purchased, amount, currency, order status, Stripe customer and transaction identifiers, refunds, tickets, downloads, appointments, and related fulfilment records.
- Email preferences: subscription source and status, consent time, unsubscribe time, suppression status, and records needed to send or troubleshoot requested messages.
- Technical and security information: request and service logs, browser and network information available to Cloudflare, and short-lived rate-limit records. Email addresses and IP addresses used for application rate limiting are stored as one-way hashes rather than in readable form.
We collect this information directly from you, automatically when you use the service, and from Stripe when you complete or refund a purchase. Stripe collects payment-card and checkout details on its hosted page. We receive the customer and transaction information needed to record and fulfil the order, but we do not receive or store your full card number.
We do not ask for health information, biometric identifiers, government identification numbers, precise location, or other sensitive personal information through this website. Please do not include sensitive information in a contact message unless it is genuinely necessary for your request.
Why we collect, use, and disclose it
- to answer enquiries and provide requested customer support;
- to authenticate customers and administrators and protect their accounts;
- to process, record, reconcile, and fulfil purchases and refunds;
- to provide course access, progress records, downloads, tickets, appointments, and event reminders;
- to maintain consent and suppression records and send marketing only where permitted;
- to detect misuse, rate-limit requests, investigate errors, and secure the service;
- to maintain business, tax, accounting, dispute, and compliance records; and
- to operate, maintain, and improve the website and its services.
We limit collection, use, and disclosure to purposes a reasonable person would consider appropriate in the circumstances. We do not sell or rent personal information. If we need information for a materially new purpose, we will explain it and obtain consent where required.
When you submit the contact form, Cloudflare Workers AI processes the enquiry topic and message to draft a short automatic acknowledgement. The acknowledgement is identified only as coming from heyjeffmaeck.com, does not pretend to be personally written by Jeff, and uses fixed safeguards plus topic-specific guidance. Jeff receives the original enquiry and is copied on the acknowledgement. If the drafting service is unavailable or its output does not pass the website’s checks, the website uses a prewritten topic-specific acknowledgement instead. The email address is also recorded as a pending marketing subscription and receives a separate confirmation email. It does not join the marketing list unless the recipient completes that confirmation step within 48 hours.
Consent and other legal grounds
Canadian privacy law centres on meaningful consent and purposes a reasonable person would consider appropriate. Where another law that applies to your interaction requires a specific legal basis, we rely on:
- contract: to create and administer an account, process a purchase, and deliver a course, download, ticket, appointment, or related support;
- consent: for marketing email and any other optional use for which we ask permission;
- legal obligations: for tax, accounting, consumer-protection, privacy, and other records the law requires us to keep; and
- legitimate interests or comparable lawful grounds: to secure the service, prevent fraud and misuse, troubleshoot errors, operate the website, and understand service performance, where those interests are not overridden by your rights.
You may withdraw consent for future processing that depends on consent. Withdrawal does not make earlier lawful processing invalid and does not stop processing that is necessary for a purchase, a legal obligation, security, or another lawful ground.
Consent and email marketing
New website subscribers receive a confirmation email and must complete the confirmation step before joining the marketing list. Every marketing email identifies the sender and includes a working unsubscribe method. We action unsubscribe requests without charge and no later than the period required by law. We do not send marketing to a suppressed address.
Customer and audience records migrated from an earlier platform retain their recorded subscription status. An address recorded as unsubscribed remains in a suppression record so we can respect that choice; it is not treated as permission to send marketing. Transactional messages needed to provide a purchase or account may still be sent.
Canada’s anti-spam guidance explains the requirements for consent, sender identification, and unsubscribe mechanisms.
Cookies, analytics, and embedded services
The application uses an essential first-party hjm_session cookie after sign-in. It is marked secure on HTTPS, unavailable to browser scripts, and used only to authenticate the account. Customer sessions can remain active for up to 400 days from their most recent authenticated use and administrator sessions for up to 12 hours, with the expiry renewed during authenticated use. Signing out deletes the current session.
The website application does not include advertising cookies or a third-party analytics script. Cloudflare processes requests and supplies traffic and security information at the network edge. We use that information in aggregate and when needed to maintain availability, investigate errors, or prevent misuse.
Some pages include media or documents from Cloudflare Stream, Google Docs, YouTube, Instagram, Spotify, Vimeo, or TikTok. When an embedded item loads, that provider receives standard request information such as your IP address, browser details, referring page, and interaction with the item, and may use cookies or similar technologies under its own policy. You can avoid that transfer by not loading or interacting with the embedded item and, where provided, use the first-party text or link instead.
Protected course lessons may display supporting material through an embedded Google Docs reader. A first-party text version remains available beneath each embedded document.
We do not use personal information for behavioural advertising or make decisions that produce legal or similarly significant effects based solely on automated processing. Automated security and rate-limit checks may temporarily reject a request; contact us if you believe a legitimate request was blocked.
Service providers and transfers
We use service providers to operate the website: Cloudflare for hosting, databases, storage, security, rate limiting, video, and the constrained contact-acknowledgement drafting described above; Stripe for checkout, payments, discounts, and refunds; Resend for outbound email; and the embedded-media providers described above when their content is used. GitHub stores versioned public website content and deployment source, not the customer database. Providers receive only the information reasonably needed to perform their role and handle it under their own contracts and privacy terms.
Providers may process or store information outside Canada, including in the United States. While there, information may be subject to the laws and lawful access processes of that jurisdiction. We remain accountable for personal information transferred to a service provider for processing.
We assess providers in light of the information they handle and use contractual, access, and technical safeguards appropriate to their role. You may contact the Privacy Officer for more information about the safeguards relevant to a particular transfer.
We may also disclose information when you direct us to, when required or authorized by law, to investigate fraud or protect rights and safety, to establish or defend a legal claim, or as part of a lawful business sale or reorganization subject to appropriate safeguards.
How long we keep information
- sign-in links expire after 15 minutes and subscription-confirmation links after 48 hours; expired token records are removed by scheduled cleanup;
- customer sessions expire after up to 400 days of inactivity and administrator sessions after up to 12 hours; expired sessions are removed by scheduled cleanup;
- sign-in activity records are retained for up to 365 days after the last recorded activity, unless they remain connected to an active session;
- hashed contact rate-limit records are removed after approximately 48 hours;
- contact enquiries are kept in the receiving email systems only as long as reasonably needed to respond, maintain the relationship, or address a legal issue;
- order, payment, refund, entitlement, ticket, and related records are retained as needed to provide the purchase and meet tax, accounting, fraud-prevention, and legal obligations;
- lesson-progress records are retained with the associated account while access is provided; and
- consent and unsubscribe records may be retained for as long as needed to demonstrate consent and ensure an unsubscribe is not accidentally reversed.
When information is no longer needed, it is deleted or anonymized where practical. A deletion request may not remove records that we must retain for a transaction, legal obligation, security investigation, or unresolved dispute.
Safeguards and privacy incidents
Safeguards include encrypted transport, hosted payment processing, restricted and time-limited administrative access, hashed authentication tokens, access-controlled storage, signed course-video playback, rate limiting, and operational logging. No system can promise absolute security, but we maintain safeguards proportionate to the sensitivity and amount of information involved.
We investigate suspected privacy incidents. Where PIPEDA requires it, we report a breach that creates a real risk of significant harm to the Office of the Privacy Commissioner of Canada, notify affected individuals, inform another organization that may reduce the risk, and retain the required breach record.
Your choices and rights
You may ask whether we hold personal information about you; request access to it and an account of how it has been used or disclosed; request correction of inaccurate or incomplete information; withdraw consent subject to legal and contractual limits; or make a privacy complaint. Depending on the law that applies where you live, you may also request deletion, restriction of processing, a portable copy of information you provided, or object to certain processing. You may object to direct marketing at any time.
These rights are not absolute. For example, we may need to retain transaction records required by law or information needed to protect another person’s rights, secure the service, or resolve a legal claim.
Send a written request through the contact form or email the Privacy Officer at itsjeff@heyjeffmaeck.com. Describe the right you want to exercise and the account or email address involved. We may need to verify your identity before releasing, exporting, deleting, or changing information. We generally respond within 30 calendar days and at little or no cost, subject to the timeframes, extensions, fees, and exceptions permitted by applicable law. If a request is refused, we will explain the reason and available complaint route where required.
Children, changes, and complaints
The website and professional education products are not directed to children under 16. Do not provide a child’s personal information without the authority and consent required by law.
We may update this policy as the service, providers, or legal requirements change. The date above identifies the current version. If a change materially affects how existing personal information is used, we will provide prominent website notice, email affected account holders where appropriate, and obtain consent where required.
Privacy questions or complaints can be sent to Privacy Officer, 2609699 Ontario Inc., 549 Brittania Crescent, Kitchener, Ontario N2R 0B1, Canada; by email at itsjeff@heyjeffmaeck.com; or by telephone at +1 226 972 4014. We will investigate and respond. If a concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada or, where another privacy law applies, the data-protection authority responsible for your location.