Privacy Policy
Storm Developments
Storm Buckets - S3-Compatible Object Storage
Effective Date: 06/06/2026
Last Updated: 09/18/2026
1. Who We Are
Storm Developments is a Canadian cloud infrastructure company based in Ontario, Canada. We operate Storm Buckets, an S3-compatible object storage service hosted on Canadian infrastructure.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use Storm Buckets, and what rights you have over that information.
Privacy Officer and Contact:
Mathew Storm
Storm Developments
Ontario, Canada
contact@stormdevelopments.ca
2. Our Commitment
Storm Developments operates under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles, which form the foundation of this policy.
We collect only what we need. We keep it only as long as necessary. We do not sell it. We do not share it except as described in this policy.
3. What Personal Information We Collect
We collect only the personal information necessary to provide and operate Storm Buckets.
Account information:
-
Your email address
-
Your chosen username
-
Your password (stored as a one-way hash, which we cannot reverse)
-
Account creation date
-
What you tell us at signup: whether you are an individual, a small business, a nonprofit or other (required), and, if you give them, your organization, where you heard about Storm, who referred you and a short introduction. Staff read it to know who we serve and how you found us, and no automated decision is made from it. A referrer's name is used only for that. It is never shown to the person named or matched against our accounts. Deleted with your account.
-
The versions of our Terms of Service and Acceptable Use Policy you accepted, and when. If you tick the product updates box, when you ticked it. Updates start only after you verify your email. Deleted with your account.
Usage and technical information:
-
IP address at the time of login and API requests. S3 API source addresses
are collected from trusted network hops for security and abuse-pattern
detection and are deleted with the access log within 90 days. -
Browser user agent and referring page, captured when an account signup or login is attempted. We use these to distinguish real signups from automated abuse. Kept for up to 90 days.
-
Ten recovery codes, issued at your first sign-in after your address is verified, stored only as one-way hashes we cannot reverse, and whether you confirmed saving them. They are your own way past any second step at sign-in, the browser-verification code and the authenticator app's code if you set one up, and are deleted when account recovery replaces your address or when you close your account.
-
If you set up an authenticator app: the app's secret, stored encrypted under a key that is kept outside the database, the date you set it up, and the time step of the last code we accepted, which is what stops a code being used twice. It exists only to check the six-digit code your app shows at sign-in. A setup you do not finish is refused after ten minutes and deleted within a day. The secret is deleted the moment you remove the app, when account recovery replaces your address, or when you close your account. It appears on no admin screen and in no email; the notices we send when the app is added or removed carry the fact and the date only.
-
If you request account recovery with an access key: a one-time nonce, stored as a hash and deleted within the hour, and a record of the request holding the time, the key's id and name, when it takes effect, and how it ended. It is what the notice to your address and the banner on your profile are built from. A copy goes to Storm's operator at the moment the request opens, with counts and dates already on your account beside it (open sessions and their last activity, last sign-in, remembered browsers, account keys; never an IP address), so that every request is reviewed by a person inside its 48-hour window and can be stopped. The proof itself is read off the access log the key already writes (Section 7): one request for an object name Storm chose, matched by equality and never read for meaning. The record loses the key, its name and the new address when the request closes and is deleted 90 days later, and immediately if you close your account.
-
Browsers you let us remember, by leaving "Remember this browser for longer sessions" checked at sign-in (it is checked by default; uncheck it on a machine you do not control): a name, the browser and operating system, when it was last used and from which IP address, and when its session expires. Only a sign-in with that box checked adds a browser to the list on your profile. Whether logging out removes it is your own setting, "Forget browsers when their session ends", on unless you turn it off: on, logging out or an idle sign-out forgets the browser; off, the browser stays on the list until your session length or re-verify cadence runs out or you forget it, and its name and dates are all that stay. You can forget any browser at any time, which also signs it out. A forgotten browser loses its IP address and browser details immediately; a browser whose session ended or expired loses them within a day, whichever way that setting is set. A sign-in with the box unchecked is not remembered: we keep no name, browser or IP address for it, it ends when the browser closes or after 24 hours at the latest, and your profile shows only how many such sign-ins are open, with one control to sign them all out.
-
Bucket names and storage usage metrics (object count, total size)
-
Access key names and permissions (secret key values are shown once at creation and are not displayed again; see Section 9)
-
A record of each request that changes what is stored, and whether we allowed it. When you upload or delete an object, our storage gate checks the request against the capacity your account holds before it reaches the storage layer. We keep what it decided and why: which access key made the request, the operation, the number of bytes, the capacity figures the decision was measured against, and the time. It is how we can tell you why one of your requests failed at a particular moment, which is a question we could not answer before. It holds no file contents, no object names, no bucket names, and no IP address. We keep each record for 14 days and then delete it in full.
-
A record of every change to your storage capacity. Each entry stores a reason category (for example, founding alpha, a feedback bounty, a paid plan change, or a manual adjustment), the amount of capacity added or removed, and the date. This history is the source of truth for how much storage your account has, and you can view it on your profile. It holds no free-text content. We keep it for as long as your account exists, and delete it in full when you close your account.
-
Saved bucket filters you create in the dashboard: the name you give each one and the bar state it captures (search text, selected tags, sort order). They exist only so you can re-apply a filter later, and nothing else reads them. Delete one at any time from the dashboard; all of them are deleted when you close your account.
-
The gate you set before each Buckets control action: open, your password, a code sent to your email, a code from your authenticator app, or closed. When your Buckets account opens, every gate that can close is stored as closed and stays read-only until you hold a paid block or join the alpha. Your first payment or alpha approval returns those gates to their defaults, recorded as our change, not yours. You can see and change all of it on the Control Gates tab, including whether we email you when it changes, and it is deleted with your account.
-
While a check is in progress: which action you are confirming, which check it asked for, a one-way hash of the code if one was emailed to you, how many wrong tries you have made, and when it expires. There is one at a time per action, a new one replaces it, and it is deleted when you answer it, when it expires, and when you close your account.
-
Jobs you start from the dashboard, such as clearing a bucket: the bucket, the kind, when it started and ended, and why it stopped if it did
-
Timestamps of account activity
Support communications:
-
Any information you provide when contacting us by email
-
Product feedback you submit through the dashboard's feedback form (a category and your written message, tied to your account so we can act on it). Feedback is deleted 90 days after we mark it handled, and immediately if you close your account. Any image you flag as containing personal information is destroyed as soon as we write back about it, whether or not the thing you reported is fixed by then; every attached image is destroyed within 90 days of upload regardless.
-
The rest of that conversation. Feedback is a thread: we reply to you on it, and you can write back. We keep each reply, who wrote it, and when. Our replies are written to you and are visible to you alone. A reply is deleted with the thread it belongs to, on the same timeline, never on a separate one. Writing back reopens the thread, which means it is unhandled again and its 90-day deletion clock stops until we answer you.
-
In-app notifications we send you about your own account, such as when we reply to a piece of your feedback or resolve it. Each one stores the message we showed you, when it was sent, and whether you have read or saved it, tied to your account. We record no IP, device, or location data with a notification. A notification is deleted 90 days after it is sent unless you save it, immediately when you clear it yourself, and immediately if you close your account.
-
A short email when you send us feedback and another when we answer it. The receipt confirms your feedback is in our queue; the reply notice tells you an answer is waiting. Each says which category you wrote about and links to your dashboard. Neither contains the reply, and neither contains anything you wrote. That is deliberate: an email sits in your inbox where we cannot delete it, so putting the conversation in one would break the promise above that a reply is deleted with its thread and on no separate timeline. You can turn these emails off at any time, either in the feedback form or from the link at the bottom of every one of them. Turning them off does not affect account emails such as password resets. Whether you have them on or off is stored against your account and deleted when you close it.
If you buy paid capacity:
Paid capacity is sold on an invoice Storm issues, paid by Interac e-Transfer from your bank. To issue one we need a billing name and a billing address, which you enter once in your dashboard and can change there; they are printed on each invoice. Each invoice records your account, the endpoint, the number of blocks and months, the amount in CAD, its number and its dates, and a copy of the billing name as it stood when it was issued. We keep no card number, no bank account number and no record of the transfer itself: the transfer runs between your bank and ours, and we record only that the invoice was paid and when. You can also ask for capacity from the dashboard before an invoice exists; that request records the endpoint, blocks and months you asked for, is deleted when we issue the invoice for it, and otherwise 365 days after you made it.
Before 2026-10-04 the dashboard carried an upgrade control, and opening it recorded that your account did, with the date, so we could tell you when billing opened. Nothing writes those records any more; the ones that exist are deleted 365 days after the click, and immediately if you close your account.
If you take a survey we offer:
We sometimes offer a short survey inside the dashboard, and completing one earns your account a permanent grant of storage capacity. Taking it is optional. Nothing about your account changes if you skip it, and nothing changes based on what you answer: the grant is the same for everyone who completes it, and no answer affects your capacity, your price, your position in any queue, or what we show you.
If you take one, we keep your answers and which account gave them. Tying answers to an account is deliberate, and it is the reason the survey is worth running: we are trying to understand the shape of the people using Storm, and answers we cannot tie to an account cannot tell us that. One question is an optional free-text box, and whatever you write there is kept the same way as the rest. We record no IP address, no device, and no partial progress. If you open a survey and do not finish it, nothing is saved at all.
We use the answers to size our infrastructure, to describe the product accurately, and to build what we build next around real needs instead of our guesses (Section 4). We never ask what you would pay, and no answer sets your price.
Your answers are deleted once we have finished using them for that, or 12 months after the survey closes, whichever comes first (Section 10). You can ask us to delete your answers at any time without closing your account (Section 11), and the storage capacity you earned stays.
If you report abuse or send us a copyright notice:
You do not need an account to report abuse, and most people who do are not our customers. When you write to abuse@stormdevelopments.ca we keep what you send us: your name, your contact email, the location you identified, the body of your report, and the authority you state you are acting under. We use it to assess and act on the report and to reply to you. We do not log your IP address or your user agent when you write to us.
For a copyright notice, Canada's notice-and-notice regime requires us to forward the notice to the customer responsible for the material. Your notice, including your identity, reaches that customer. This is how the regime is designed to work, and our abuse page says so before you write.
If you ask us about a product before becoming a customer:
You do not need an account to tell us you are interested in something we are building. When you use an interest form, such as the one for Storm Buckets Private, we keep your name, your email address, your organization if you give one, and whatever details you choose to write about what you need. We use it for one thing: to follow up with you about the product you asked about. We do not add you to a mailing list from it, and we do not record your IP address or your user agent with the enquiry.
If we never follow up, or you tell us no, the enquiry stops having a purpose. Those are deleted 365 days after you send them. If we are in conversation with you, or you become a customer, we keep the enquiry as part of that relationship instead (Section 10).
Notes we keep about the people we work with:
When you are a customer or have sent us an enquiry, Storm's operator and the staff who work with customers may write private notes about you, such as what you asked for and what we said we would follow up on. Only Storm sees them. They are deleted when your account closes, with your enquiry when it is deleted, and with your newsletter subscription when that is deleted (Section 10). They are part of the copy we send you if you ask for the information we hold about you (Section 11).
If you sent us an enquiry and later create a Storm account with the same email address, we show the enquiry together with your account, so we see one person instead of two. Notes we write after that are kept with your account. Closing your account deletes your enquiries and every note on them.
If you write to us, we may add you ourselves with your name and email address, and your organization if you gave it, so we can follow up on what you wrote. Being added does not put you on a mailing list and sends you nothing. We delete what we added 365 days after we last recorded a conversation with you, and sooner if you close your account or ask us to.
Markers we put on the people we work with:
The staff who work with customers may also mark you with a short marker from a list Storm keeps, such as "Business email" or "Reached out to us first", so they can see at a glance how we know you. A marker is Storm's own judgement about you, not something you told us, and one can record a security concern about an account. Any marker may leave Storm by its name in the summaries our staff tools prepare, beside your username or the name you gave us, and never with your email address or IP address. Every time a marker is put on you or taken off, we record who did it and when. Your markers and that record are kept and deleted with the notes above (Section 10). Every marker on you and that record are part of the copy we send you if you ask for the information we hold about you (Section 11).
What we do not collect:
-
The content of files you store in Storm Buckets. We do not read, index, or analyze your stored data, with one narrow exception: our Import and Backup features. If you use them to copy data from an external S3-compatible bucket, our infrastructure reads that data to copy it into your Storm bucket, and if you request a restore test afterward, it reads a small sample of the copied files to verify the transfer worked. This only happens for a transfer or test you start yourself, or a backup schedule you configured, and we do not index, analyze, or retain that content beyond completing the operation.
-
Payment credentials. Invoices are paid by Interac e-Transfer between your bank and ours; we never see or store a card number or a bank account number (see Section 8).
-
Tracking cookies or third-party analytics data
-
Location data beyond IP address
4. Why We Collect It
We collect and use your personal information for the following purposes only:
-
To provide the service: creating and managing your account, authenticating access, serving your stored data
-
To operate and maintain infrastructure: monitoring storage usage, enforcing quotas, diagnosing and fixing technical problems
-
To plan and describe the service: understanding what our customers store, what they need, and what brought them to Storm, so we can size our infrastructure and explain the product accurately. We learn this only from what you tell us at signup and from optional surveys you choose to take, never by inference from your stored files or your usage
-
To communicate with you: sending service notices, responding to support requests, notifying you of changes to these terms or the service
-
To enforce our Terms of Service: investigating violations of our Acceptable Use Policy
-
To comply with legal obligations: responding to lawful requests from Canadian government authorities
We will not use your personal information for any purpose not listed here without first obtaining your consent.
5. How We Collect It
We collect personal information:
-
Directly from you when you register an account or contact us
-
Automatically when you use the service (IP addresses, usage metrics, access logs)
We do not purchase personal information from third parties or collect it from external sources.
6. Consent
By creating an account, you consent to the collection, use, and storage of your personal information as described in this policy.
You may withdraw consent at any time by closing your account. Withdrawal of consent means we will delete your personal information in accordance with Section 10 of this policy, and you will no longer be able to use Storm Buckets.
To provide you with the service, some data collection is necessary and cannot be opted out of while you remain a user.
7. Where Your Data Is Stored
All personal information and stored data is hosted on servers physically located in Canada, operated by Storm Developments.
We do not transfer your stored files to servers outside Canada.
Our compute servers run on dedicated hardware leased from Canadian Web Hosting in British Columbia. Your stored files reside on storage hardware leased from ServaRica in Montreal, Quebec. Both providers operate entirely within Canada. Storm Developments controls the operating system and all software running on this hardware. The providers supply physical hosting and network connectivity, and do not have logical access to your account data or stored files.
Some limited operational processing involves third-party service providers, listed in Section 8. Where any such provider operates outside Canada, we identify it there. We remain accountable for the protection of your personal information under applicable Canadian law.
Visitors to customer-hosted websites: Storm Buckets can serve a customer's bucket as a public website. When it does, our infrastructure logs the IP addresses of visitors to that website for traffic metering and abuse protection. These logs follow the same retention as all access logs: deleted within 90 days (Section 10). We do not use them for any other purpose. The customer who operates the website is responsible for their own site's privacy notice to its visitors.
8. Who We Share Your Information With
We do not sell your personal information. We do not share it with advertisers, data brokers, or marketing platforms.
We may share your personal information only in the following limited circumstances:
-
Legal requirements: if required by a valid Canadian court order, warrant, or other lawful legal process, we may be required to disclose account information. Where permitted by law, we will notify you before complying.
-
Safety: if we have a good-faith belief that disclosure is necessary to prevent imminent harm to a person, we may share relevant information with appropriate authorities.
-
Business transfer: if Storm Developments is acquired or its assets are transferred, your information may be transferred as part of that transaction. We will notify you before this occurs and you will have the opportunity to close your account.
-
Payment: Storm issues the invoice and you pay it by Interac e-Transfer from your own bank to ours. No payment processor sits between us, and no card or bank account number is collected or stored by Storm; your bank handles the transfer under its own terms. If we ever add a payment processor we will name it in this section before any payment goes through it.
-
Email delivery: we use Resend to deliver the emails we send you (service notices and, if you subscribed, our newsletter). Your email address and the message content pass through Resend to reach you. Resend is a US-based service, and its privacy policy applies to email delivery. See resend.com.
-
Documentation search: we use Cohere for embedding and retrieving and ranking search results when you search our documentation. The text you type into the search box is sent to Cohere to run that search. Cohere is a Canadian company, headquartered in Toronto. Cohere's privacy policy applies to this processing. See cohere.com/privacy.
We will not share your information beyond what is described above.
9. How We Protect Your Information
We take reasonable technical and organizational measures to protect your personal information, including:
-
Passwords are stored as one-way hashes and cannot be reversed
-
All connections to Storm Buckets use TLS encryption in transit
-
Secret keys are shown once at creation and are not displayed again. To authenticate your requests, a secret key is held on our servers and is used only for that purpose, never to access the content of your stored files.
-
The administrative dashboard Storm staff use to operate the service cannot create access keys, attach keys to your buckets, or display your keys. Those operations are blocked in our control plane, and any administrative action taken on an account is recorded in an internal audit log.
-
Storm does not access the content of your files to operate the service, with two exceptions. First, features you run yourself that require it: our Import and Backup features read data from an external bucket to copy it into your Storm bucket, and an optional restore test reads a small sample of the copied files to verify the transfer. These only happen for an operation you start or a backup schedule you configured, and we do not index, analyze, or retain that content beyond completing it. Second, we may access, restrict, preserve, or remove content where required by law or to address illegal or abusive use, as described in our Terms of Service. Any such administrative action is recorded in our internal audit log.
-
Access to production systems is restricted to authorized personnel
-
Infrastructure management uses mutual TLS and HMAC-signed commands via Storm Pulse
No system is completely secure. If we become aware of a breach of security safeguards that creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as required by PIPEDA, and keep a record of the breach.
10. How Long We Keep Your Information
We retain your personal information for as long as your account is active.
When you close your account:
-
Your stored files and buckets are deleted from our storage infrastructure within 30 days
-
Your account record (email, username, usage history, and what you told us at signup with the record of what you accepted) is deleted within 30 days
-
Access logs may be retained for up to 90 days for security and fraud investigation, after which they are deleted
-
The record of admitted and refused storage requests described in Section 3 is deleted in full 14 days after the request it describes. Closing your account does not extend it, and nothing keeps it on a per-account timer: 14 days is shorter than the 30 days in which we delete your account record, so these records are already gone by then.
-
Where an activity or audit record is kept longer than 90 days (for example, your account activity history or our internal audit trail), the IP address is removed from that record after 90 days. IP addresses are not retained beyond 90 days even when the surrounding record is kept.
-
Your capacity grant history is deleted together with your account record. It is not kept on a separate timer; it exists only for as long as your account does.
-
Invoices are tax records and are the one exception to the 30-day deletion. The Income Tax Act (s. 230(4)) and the Excise Tax Act (s. 286(3)) require us to keep them for six years from the end of the taxation year they belong to, and we delete them in full when that period ends. From the moment your account is deleted an invoice holds only the billing name it was issued to, the endpoint, the blocks, months, amount, number and dates; it is no longer linked to any account, and your email, username and billing address are gone with the account record.
-
If you use our Import feature, we keep a record of each import plan (which buckets, when, how long each step took, whether it succeeded) so you can check its status and history. This record is deleted together with your account record, on the same timeline, not on a separate timer. We do not keep the external access credentials you enter to start an import; they are used once, in memory, to run the import you requested, and are discarded when it finishes or times out, regardless of outcome.
-
Job records are deleted 90 days after the job ends, and with your account
-
If you set up our Backup feature, we store the access credential for your external source so scheduled runs can use it. It is encrypted at rest, used only to run the schedule you configured, and never written to logs. Disconnecting the source or deleting the backup setup destroys the credential immediately; closing your account destroys it with the rest of your data. We keep a record of each backup run (which buckets, when, whether it succeeded); run records are deleted after 90 days, and the whole history is deleted with your account.
Survey answers are deleted once we have finished using them for the purpose we stated when we asked, or 12 months after that survey closes, whichever comes first. After that we may keep the anonymous totals, meaning how many people picked each answer, which identify nobody. We do not keep what anyone wrote in a free-text box, and we do not keep who answered. Closing your account deletes your answers sooner, with the rest of your account record. The capacity grant a completed survey earned is part of your capacity history and stays for as long as your account does; it records the survey, the amount, and the date, never your answers.
Product enquiries from people who are not customers are kept for 365 days after you send them, and are then deleted, unless we are in conversation with you about the product or you have become a customer. This applies to the interest forms described in Section 3.
Abuse reports and copyright notices are kept for 12 months after the matter is closed, and are then deleted. The Copyright Act requires us to retain the records associated with a notice for six months, or one year where court proceedings begin, and this period covers that obligation. This applies whether or not the person who reported has an account with us.
We delete your data on these timelines except where we are required by law to preserve it, such as a preservation demand, a court order, or our mandatory reporting obligations for illegal content. In those cases we keep only the data the law requires, only for as long as it requires, and then delete it.
We do not retain backups of deleted data beyond these periods.
11. Your Rights Under PIPEDA
Getting your data out
Your files are yours and you do not need us to hand them back. Storm Buckets is S3-compatible, so every object you store can be listed and downloaded with any standard S3 client, using your own access keys, at any time. There is no proprietary format, no export request, and no step where we sit between you and your data. If you leave, you copy your data out with the same tools you used to put it in.
Your activity history downloads from the dashboard as NDJSON. An export covers the view you are looking at, including whatever filters you have applied, up to 5,000 rows per file. Where there is more, the export says so on its last line, and narrowing the filters retrieves the rest. The first line records the scope and filters it was generated with. The copy you download is yours to safeguard once it leaves our systems.
Your account record, meaning your email, username, and capacity grant history, is visible in your profile; your billing details and every invoice we have issued you are visible in your dashboard. A single-file export of that record is not built yet. Until it is, ask us at contact@stormdevelopments.ca and we will send it within 30 days.
Your rights
You have the following rights regarding your personal information:
-
Access: you have the right to request a copy of the personal information we hold about you. We will respond within 30 days of receiving a written request. We may charge a minimal administrative fee as permitted under PIPEDA.
-
Correction: if any personal information we hold about you is inaccurate or incomplete, you have the right to request that we correct it.
-
Deletion: you may request deletion of your personal information by closing your account or by contacting us directly. See Section 10 for deletion timelines.
-
Withdrawal of consent: you may withdraw consent for any non-essential processing at any time. See Section 6.
-
Complaint: if you believe your privacy rights have been violated, you may file a complaint with the Office of the Privacy Commissioner of Canada:
Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec K1A 1H3
priv.gc.ca
1-800-282-1376
To exercise any of these rights, contact us at contact@stormdevelopments.ca. We may ask you to verify your identity before processing your request.
12. Cookies
Storm Buckets uses two cookies. Neither is used for tracking or advertising, and we do not use third-party cookies, analytics cookies, or advertising cookies.
-
Session cookie. Strictly necessary for the service to function. Deleted when you log out or your session expires; on a browser where you unchecked the remember box, it also ends when the browser closes.
-
Trusted device cookie. Set only when a sign-in carries "Remember this browser for longer sessions" checked, which it is by default unless you uncheck it. It ties the browser to its entry in the remembered list on your profile, one entry for each account remembered on that browser, at most five. Your account's entry is removed when you forget the browser, and when you log out or your session ends if "Forget browsers when their session ends" is on for your account, which it is unless you turn it off. The cookie itself is deleted when its last entry goes, and otherwise lives as long as the longest session length among the accounts remembered on that browser allows, up to 30 days.
13. Children's Privacy
Storm Buckets is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If you believe we have collected information from a minor, contact us immediately at contact@stormdevelopments.ca and we will delete it.
14. Working Toward Quebec's Law 25
This policy reflects our obligations under PIPEDA, which governs us today. We are working toward alignment with Quebec's Law 25 (the Act respecting the protection of personal information in the private sector). We do not yet claim Law 25 compliance.
Steps we are working toward:
-
A French-language version of this policy and of the service
-
Written data processing agreements with the service providers that process personal information on our behalf
-
A privacy impact assessment before any transfer of personal information outside Quebec
-
A confidentiality-incident register, and notification to the Commission d'accès à l'information where an incident presents a risk of serious injury
-
A single-file export of your account record. Your stored files are already portable by design and your activity history already downloads (Section 11). What is missing is one structured file containing the account record itself.
We already designate a named Privacy Officer (Section 1) and limit how long we keep personal information (Section 10).
Until these are in place, this policy and our PIPEDA obligations govern.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top and notify you by email at least 14 days before changes take effect, except where changes are required immediately by law.
Your continued use of Storm Buckets after changes take effect constitutes acceptance of the updated policy.
16. Contact and Complaints
If you have any questions about this Privacy Policy or how we handle your personal information, contact our Privacy Officer:
Mathew Storm
Storm Developments
Ontario, Canada
contact@stormdevelopments.ca
We will respond to all privacy inquiries within 30 days.