GeoBrakes

Privacy Policy

Last updated: April 2026

GeoBrakes Inc. (referred to in this policy as 'GeoBrakes', 'we', 'our', or 'us') operates the website geobrakes.ca and is committed to protecting the personal information of every person who visits, browses, or purchases through our platform. This Privacy Policy explains what information we collect, how we use it, with whom we share it, and the choices you have regarding your personal information. By using our website or placing an order with us, you acknowledge that you have read, understood, and agreed to this policy in its entirety. Where there is any conflict between this policy and applicable law, applicable law governs.

Applicable Law

GeoBrakes collects and handles personal information in accordance with the following legislation:

Federal law: the Personal Information Protection and Electronic Documents Act (PIPEDA), which governs the collection, use, and disclosure of personal information in the course of commercial activity across Canada.

Quebec provincial law: Law 25, officially known as the Act to modernize legislative provisions as regards the protection of personal information, which is fully in force and applies to any organization that collects or uses the personal information of Quebec residents. Penalties under Law 25 reach up to C$25 million or 4% of worldwide turnover for non-compliance.

Alberta and British Columbia provincial law: the Personal Information Protection Act (PIPA) applies to organizations operating in or collecting personal information from residents of Alberta and British Columbia.

Commercial email law: Canada's Anti-Spam Legislation (CASL) governs all commercial electronic messages sent by GeoBrakes to Canadian recipients. Penalties under CASL reach up to $10 million CAD per violation for organizations.

Where Quebec's Law 25 or another provincial law imposes stricter requirements than PIPEDA, the stricter standard applies. GeoBrakes has adopted Quebec's Law 25 requirements as its baseline standard across all Canadian operations.

1. Information We Collect

We collect only the minimum personal information necessary to fulfill the purposes described in this policy. We collect personal information that you provide to us directly, information that is automatically collected when you interact with our website, and in limited cases information from third-party sources.

1.1 Information You Provide Directly

Identity information: your name, email address, phone number, and billing and shipping address provided when creating an account or placing an order
Vehicle information: the year, make, and model of your vehicle when using our fitment selector tool
Payment information: credit card number, expiry date, and security code processed through our secure payment gateway — we do not store complete payment card numbers on our systems at any time
Account credentials: username and hashed password if you create a registered account — we never store passwords in plain text
Communications: the content of any messages you send to our customer support team through email, phone, live chat, or our contact form
Reviews and feedback: any product reviews, ratings, or feedback you submit through our platform

1.2 Information Collected Automatically

Log and device data: your IP address, browser type, operating system, device identifiers, and the pages you visit on our website
Usage data: how you navigate our website, which products you view, what searches you conduct, and how long you spend on each page
Cookie data: information stored in cookies, pixel tags, and similar tracking technologies as described in Section 6 of this policy
Location data: general geographic location inferred from your IP address — we do not collect precise GPS location without your explicit consent

1.3 Information from Third Parties

Payment processors: transaction confirmation and fraud risk signals from our payment processing partners
Shipping carriers: delivery confirmation and tracking updates from our logistics partners
Analytics providers: aggregated and anonymized website traffic and behavior data from services such as Google Analytics

2. How We Use Your Information

We use the personal information we collect only for the following purposes. We will not use your personal information for any purpose not described in this policy without first obtaining your express consent.

2.1 Order Fulfillment and Account Management

We use your name, address, email, phone number, vehicle information, and payment details to process your order, confirm your purchase, arrange delivery through our shipping partners, issue receipts and invoices, respond to order-related inquiries, and manage your account if you have registered with us. This use is necessary for the performance of the contract you enter into when you place an order with GeoBrakes.

2.2 Customer Support

We use your contact information and order history to respond to support requests, resolve complaints, process returns and exchanges, and provide guidance on installation or fitment questions. This use is necessary for our legitimate interest in providing effective after-sale service and maintaining customer satisfaction.

2.3 Website Operation and Improvement

We use automatically collected usage data and log data to monitor website performance, diagnose technical issues, protect against fraudulent activity, analyze how customers navigate our catalogue, and make improvements to our product listings, search functionality, and checkout process.

2.4 Marketing Communications

With your express and freely given consent, we may use your email address to send you promotional communications about new products, special offers, and brake service reminders relevant to the vehicles in your account profile. All marketing emails comply with Canada's Anti-Spam Legislation (CASL) and include a clear and functional unsubscribe mechanism in every message. You may withdraw your consent at any time by clicking the unsubscribe link in any marketing email or by contacting us at sales@geobrakes.com or calling +1 (416) 855-1496. We will process all unsubscribe requests within 10 business days as required by CASL. Withdrawing consent to marketing communications does not affect your ability to place orders or receive transactional messages about existing orders.

2.5 Legal Compliance and Fraud Prevention

We may use and retain your personal information where necessary to comply with applicable Canadian federal and provincial laws and regulations, to respond to lawful requests from government authorities or law enforcement agencies, to enforce our Terms of Service, to detect and prevent fraud or unauthorized access to our systems, and to protect the rights, property, and safety of GeoBrakes, our customers, and the public.

3. Sharing Your Information

GeoBrakes does not sell your personal information to third parties under any circumstances. We do not allow our marketing partners to use your personal data for their own independent purposes. We share your information only in the following strictly limited circumstances and only to the extent necessary for the stated purpose.

3.1 Service Providers

We share your personal information with trusted third-party service providers who assist us in operating our business — including payment processors, shipping carriers, customer support software platforms, email marketing providers, and website analytics services. All service providers are subject to written data processing agreements that require them to handle your personal information only for the specific purpose for which it was shared, to maintain appropriate security standards, and to strictly prohibit use of your data for their own purposes.

3.2 Cross-Border Data Transfers

Where personal information is transferred outside of Canada or Quebec to a service provider located in another jurisdiction, GeoBrakes conducts a Privacy Impact Assessment (PIA) to evaluate the risks of that transfer before it occurs, as required under Quebec's Law 25. We will only proceed with the transfer if adequate protections are in place. Quebec residents will be notified before their personal information is communicated outside of Quebec where required by law.

3.3 Legal and Regulatory Requirements

We may disclose your personal information if required to do so by applicable Canadian federal or provincial law, court order, or lawful government authority. Before making any such disclosure, we will take all reasonable steps to verify the legal basis for the request. We may also disclose information where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of GeoBrakes, our customers, or others.

3.4 Business Transfers

In the event that GeoBrakes is involved in a merger, acquisition, sale of substantially all assets, or other business reorganization, your personal information may be transferred to the successor entity. We will notify you by email and by a prominent notice on geobrakes.ca at least 30 days before your personal information becomes subject to a different privacy policy. You will have the right to withdraw your personal information before the transfer takes effect wherever legally permitted.

3.5 What We Will Never Do

We will never sell your personal information. We will never share your personal information with advertisers for their own targeting purposes without your express consent. We will never use your personal information in automated decision-making that produces legal or similarly significant effects without providing you meaningful human review and the right to contest the outcome.

4. Privacy Impact Assessments

In accordance with Quebec's Law 25, GeoBrakes conducts a Privacy Impact Assessment (PIA) before launching new technology projects, information systems, or making significant changes to existing systems that involve the collection, use, or communication of personal information. PIAs evaluate the privacy risks of new initiatives and identify measures to mitigate those risks before deployment. Records of completed PIAs are maintained by our Privacy Officer.

5. Data Storage and Security

Your personal information is stored on secure servers located in Canada. We implement comprehensive technical and organizational security measures to protect your personal information against unauthorized access, loss, misuse, alteration, or destruction. These measures include:

SSL/TLS encryption for all data transmitted between your browser and our servers
Hashing of all account passwords — plain text passwords are never stored
Restricted access controls limiting personal data access only to employees who require it to perform their specific job functions
Regular security monitoring, penetration testing, and vulnerability assessments
Automatic session timeouts for inactive logged-in accounts
Regular secure encrypted backups

Data Breach Notification: In the event of a confidentiality incident involving personal information that presents a risk of serious injury to any affected individual, GeoBrakes will notify the Office of the Privacy Commissioner of Canada and the Commission d'accès à l'information du Québec (for Quebec residents) as required by law, and will notify affected individuals without unreasonable delay. Notifications will include a description of what happened, the type of information involved, the steps we are taking to reduce the risk of harm, and how to contact our Privacy Officer.

No method of electronic data storage or transmission is completely secure. If you become aware of any security vulnerability or unauthorized access affecting your account, please notify us immediately at sales@geobrakes.com or call +1 (416) 855-1496.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with our services. We also retain personal information for as long as necessary to comply with our legal obligations, resolve disputes, enforce our agreements, and fulfill the purposes described in this policy. We do not retain personal information beyond what is reasonably necessary for these purposes.

Order records — including your name, address, vehicle information, and purchase history — are retained for a minimum of 7 years in accordance with Canadian federal and provincial tax and commercial record-keeping requirements. Marketing consent records are retained for as long as you remain subscribed and for a reasonable period thereafter to demonstrate CASL compliance. When personal information is no longer required, we securely delete or irreversibly anonymize it.

You may request access to your personal information or request deletion of information not required for legal retention purposes by contacting us at sales@geobrakes.com or calling +1 (416) 855-1496.

7. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, remember your vehicle selection and cart contents, analyze website traffic, and in some cases facilitate targeted advertising. You will be presented with a cookie consent notice when you first visit our website.

For Quebec residents: in accordance with Law 25, we will not use cookies or tracking technologies for non-essential purposes without your prior and informed consent. You have the right to withdraw that consent at any time without penalty or restriction to our core services.

The types of cookies we use include:

Essential cookies: required for the website to function correctly, including session management, cart persistence, and secure checkout. These do not require your consent as they are necessary for the service you have requested.

Performance cookies: collect anonymized data about how visitors use our website. We use Google Analytics for this purpose. These require your consent.

Functional cookies: remember your preferences such as your selected vehicle, language, and currency. These require your consent.

Advertising cookies: used to serve relevant advertisements on platforms including Meta and Google based on your browsing activity on our website. These require your explicit consent and can be withdrawn at any time.

You can manage or withdraw your cookie consent at any time through the cookie settings panel on our website or through your browser settings. Withdrawing cookie consent does not affect cookies already placed before withdrawal.

8. Your Rights Under Canadian Privacy Law

GeoBrakes is committed to honoring the following rights fully and without unnecessary delay or obstruction. These rights apply to all Canadian residents under PIPEDA and applicable provincial legislation.

Right of access: you have the right to request a copy of all personal information we hold about you, information about how it is being used, and a list of any third parties to whom it has been disclosed.

Right to correction: you have the right to request that we correct personal information that is inaccurate, incomplete, or out of date.

Right to withdraw consent: where our use of your personal information is based on your consent, you have the right to withdraw that consent at any time, subject to legal or contractual restrictions.

Right to deletion: you have the right to request deletion of your personal information that is no longer necessary for the purposes for which it was collected, subject to our legal retention obligations.

Right to data portability (Quebec residents): under Law 25, you have the right to receive your personal information in a structured, commonly used, and machine-readable format, and to have it transmitted to another organization where technically feasible. We will fulfill portability requests within 30 days of receipt.

Right to de-indexing (Quebec residents): under Law 25, you have the right to request that personal information published online about you be de-indexed or no longer disseminated, where you believe it was collected without consent or in violation of the law.

Right to be informed of automated decisions (Quebec residents): under Law 25, you have the right to be informed when a technology product makes an automated decision about you that produces significant effects, and the right to have a human review that decision.

Right to make a complaint: you have the right to make a complaint about our privacy practices to the Office of the Privacy Commissioner of Canada at www.priv.gc.ca or by calling 1-800-282-1376. Quebec residents may also contact the Commission d'accès à l'information du Québec at www.cai.gouv.qc.ca.

To exercise any of these rights, please contact our Privacy Officer at sales@geobrakes.com or call +1 (416) 855-1496 with the subject line 'Privacy Request — Canada'. We will acknowledge all requests within 5 business days and respond fully within 30 days. We may need to verify your identity before processing a request.

9. Third-Party Links

This Privacy Policy applies only to geobrakes.ca and does not govern the privacy practices of any linked third-party site. GeoBrakes is not responsible for the privacy practices, security standards, or content of any external website. We encourage you to review the privacy policy of any website you visit through a link on our platform before providing any personal information.

10. Children's Privacy

Our website and services are not directed at children under the age of 16. We do not knowingly collect personal information from children under 16 without verifiable parental or guardian consent. If we become aware that we have collected personal information from a child under 16 without appropriate consent, we will take immediate steps to delete that information. If you believe we may have collected information from a child under 16, please contact us immediately at sales@geobrakes.com or call +1 (416) 855-1496 and we will investigate and respond within 48 hours.

11. Limitation of Liability

To the maximum extent permitted by applicable Canadian law, GeoBrakes shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from any unauthorized access to your personal information by third parties, provided that GeoBrakes has implemented the security measures described in this policy and has not acted with gross negligence or willful misconduct. GeoBrakes's total liability for any privacy-related claim shall not exceed the total amount paid by you for orders placed through geobrakes.ca in the 12 months preceding the claim.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our information practices, applicable Canadian law, or our business operations. We will notify you of any material changes by posting the updated policy on this page with a revised 'Last updated' date and, where the changes are significant, by sending a notification to the email address associated with your account at least 14 days before the changes take effect. Your continued use of geobrakes.ca after the effective date of any material changes constitutes your acknowledgment of those changes.

13. Contact Our Privacy Officer

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact our Privacy Officer:

Company: GeoBrakes Inc.
Phone: +1 (416) 855-1496
Email: sales@geobrakes.com
Subject line: Privacy Request — Canada

Business hours: Monday to Friday 9AM to 6PM EST, Saturday 9AM to 4PM EST.

We are committed to working with you to reach a fair and timely resolution of any privacy concern. If you are not satisfied with our response, you have the right to contact:

Office of the Privacy Commissioner of Canada: www.priv.gc.ca or 1-800-282-1376
Commission d'accès à l'information du Québec (Quebec residents): www.cai.gouv.qc.ca
Office of the Information and Privacy Commissioner of Alberta (Alberta residents): www.oipc.ab.ca
Office of the Information and Privacy Commissioner for British Columbia (BC residents): www.oipc.bc.ca