Home/Privacy Policy
Privacy
Policy
How Graination collects, uses and protects your personal information — including the images and materials you trust us with.
Effective · July 30, 2026 · Last updated · July 30, 2026
1 · Summary
We collect the information needed to process orders, develop and scan film, provide services, communicate with you, run accounts and memberships, prevent fraud, meet legal obligations and operate the business. We do not sell your personal information.
Some of what we handle is unusual for a shop: your film, negatives and scans are personal information too, and photographs of identifiable people are personal information about them. We treat that material with the same care we treat the film itself. We handle personal information in line with applicable Canadian privacy law, including PIPEDA.
2 · Information we collect
Contact and account information — name, email address, telephone number, account details and authentication information.
Order and transaction information — products and services ordered, order number, service selections, film format and process information, scanner and add-on options, negative handling instructions, order notes, transaction records, billing information and shipping information.
Film, image and service information — information contained in or associated with the film, negatives, photographs, scans, prints, artwork, digital files and print files you submit, along with related order and service metadata. Photographs containing identifiable individuals may themselves be personal information.
Booking and membership information — bookings, session details, membership status, access records and membership transactions, where applicable.
Communications — emails, contact-form submissions, customer-support messages, order communication and complaint records.
Device and website information — IP address, browser and device information, server and security logs, cookies and similar identifiers, where the website collects them.
Marketing preferences — subscription preferences, consent records and unsubscribe records.
Fraud and security information — information used to detect, investigate and prevent fraud, misuse and security incidents, where applicable.
Payment information. Payment transactions may be processed by third-party payment service providers. We receive and retain the information needed to administer the transaction, while payment credentials may be handled directly by the payment provider depending on the payment method used.
3 · How we use information
We use personal information to:
- process orders and take payment;
- develop, scan and print film, and deliver digital files;
- arrange physical pickup and shipping;
- administer bookings, memberships and space access;
- provide customer support and respond to questions;
- run accounts and keep them secure;
- prevent and investigate fraud and misuse;
- keep records required for legal, accounting and tax purposes;
- operate, maintain and improve the website and our services;
- understand how the site is used, where analytics are in place;
- send marketing communications where permitted by law and consented to.
4 · Consent & your choices
Some information is necessary to provide what you've asked for — we can't develop a roll without knowing whose it is, what process it needs and how to return it. Where information is required to fulfil an order or service, providing it is a condition of that transaction.
Optional uses are different. Marketing is optional, never bundled into checkout or account registration, and never required to buy anything. You can withdraw consent to optional uses at any time, subject to reasonable notice, legal and contractual restrictions, and information we need to retain for legitimate legal, accounting or security purposes. Withdrawing consent doesn't make earlier lawful processing invalid.
Unsubscribing from marketing doesn't stop the non-promotional messages needed to administer an existing order, account, booking or membership.
5 · Service providers & sharing
We share personal information with service providers who help us run the business, limited to what they need to do their job. These fall into categories such as:
- payment processing;
- website and e-commerce infrastructure, and hosting;
- cloud and file storage, including scan delivery;
- email and SMS delivery;
- shipping and carriers;
- booking and membership systems;
- website analytics, where in use;
- security and fraud prevention;
- professional, accounting and legal support where needed.
We may also disclose information where required or permitted by law, to respond to a lawful request, to protect our rights or the safety of others, or in connection with a business transaction where the recipient is bound to protect the information.
Where information is processed. Our service providers may process or store information in Canada, in the United States, or in other jurisdictions depending on the provider. Information processed outside Canada may be subject to the laws and lawful access processes of the jurisdiction where it is held.
6 · Cookies & website technologies
Necessary technologies keep the site working — your cart, checkout, login, session handling, security and core functionality. These can't reasonably be switched off without breaking the site.
Optional analytics and marketing technologies, where used, help us understand how the site is used or measure a campaign. Where the site uses optional technologies of this kind, they follow the cookie preference choice offered on the site, and you can revisit that choice. We don't design cookie prompts where accepting is easy and declining is buried.
You can also control cookies through your browser settings, though blocking necessary cookies may stop parts of the site from working.
7 · Retention
How long we keep information depends on why we have it:
- the purpose it was collected for, and whether that service is complete;
- whether you have an ongoing account, membership or customer relationship with us;
- accounting and tax record requirements;
- other legal obligations;
- open disputes or potential claims;
- fraud prevention and security needs;
- ordinary operational backup cycles.
Download links. Customer-facing scan download links normally expire after two weeks — please download promptly and keep your own backup. Link expiry is a customer-access timeline, not a statement that every internal copy is destroyed at that moment; internal retention follows the factors above.
8 · Access, correction & privacy requests
Subject to applicable law, you may ask us to:
- confirm whether we hold personal information about you;
- give you access to that information;
- tell you how it has been used or disclosed;
- correct information that is factually inaccurate or incomplete;
- withdraw consent for optional activities.
You can also ask about the deletion or disposal of personal information that's no longer required, subject to the legal, accounting, security and operational retention requirements described above.
We may need to verify your identity before acting on a request — particularly for anything involving your images or order history. We'll respond as quickly as reasonably possible, and generally within 30 calendar days, subject to extensions permitted by applicable law.
If you have a privacy concern we haven't resolved, you may contact the Office of the Privacy Commissioner of Canada.
9 · Security & privacy incidents
We use reasonable safeguards appropriate to the information we handle, covering our systems, our premises and how staff access customer material. No method of transmission or storage is completely secure, and we don't claim otherwise.
We maintain procedures for responding to privacy and security incidents, and make notifications or reports where required by applicable law.
10 · Changes to this policy
We may update this policy as our services or systems change. The current version is always posted here with its effective date. Where a change is material, we'll take reasonable steps to bring it to your attention.
11 · Privacy Officer & contact
Privacy questions, access requests, corrections, complaints and consent choices can be directed to our Privacy Officer:
- Privacy Officer — Graination Inc.
- BSMT-204 Spadina Ave, Toronto, ON M5T 2C2, Canada
- contact@graination.ca · (647) 426-1277
