Legal

Privacy Policy

How One Stop Shop handles personal information about website visitors, people who enquire, and clients.

Effective date: 28 September 2026 · Last reviewed: 28 September 2026 · Applies to: onestopshopsconsulting.com and the services described on it

1. Who we are and scope

One Stop Shop (“OSS”, “we”, “us”) is a Canadian sole-proprietor business providing managed server hosting, media server and application hosting, server setup, maintenance, migration and audit services. This policy describes how we handle personal information — information about an identifiable individual — in the course of running this website and providing those services.

We are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law, and we follow its ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Where a client is located in a province with substantially similar legislation (Quebec, British Columbia, Alberta) or in the European Union, we also honour the additional rights those laws provide when they apply.

This policy covers three groups of people: visitors to this website, enquirers who email us, and clients who purchase services. Section 10 addresses, separately, the data that clients store on servers we manage for them.

2. What information is collected

2.1 Website visitors

This website is a set of static pages. It has no accounts, no forms that submit data, no comment system and no e-commerce. It sets no cookies and loads no third-party scripts, fonts, analytics or advertising. The only information processed when you visit is what any web server necessarily receives: your IP address, the page requested, the date and time, the referring page (if your browser sends one) and your browser's user-agent string. This is recorded in standard server access logs for security and operational purposes only (see Section 5).

2.2 Enquirers

When you email us, we receive whatever you choose to send: your email address, your name if you include it, and the content of your message — typically a description of your current setup and what you want hosted. We ask that you not send passwords, private keys or other access credentials in an enquiry email; if they are sent regardless, they are deleted from our mailbox and you are asked to rotate them.

2.3 Clients

To provide services and issue invoices, we collect and hold: your name and, if applicable, business name; email address; billing address (required for correct sales-tax treatment); the payment method details necessary to receive payment (for card payments, this is handled by our payment processor — we never see or store full card numbers); correspondence with you; and the technical documentation of the servers we manage for you, which may include account usernames you have chosen and the names of applications you run.

We do not collect government identification numbers, dates of birth, or any sensitive categories of information, and we do not purchase or otherwise acquire information about you from third parties.

3. Why it is collected and the legal basis

We collect and use personal information only for the following purposes, which a reasonable person would consider appropriate in the circumstances:

  • To respond to your enquiry and provide a recommendation and quote.
  • To provide the services you have purchased: provisioning, configuring, monitoring and maintaining servers, and communicating with you about them.
  • To invoice you and collect payment, and to meet our own record-keeping obligations under Canadian tax law.
  • To operate and secure this website and our own systems, including detecting and preventing abuse.
  • To comply with legal obligations, such as responding to a lawful request from a Canadian court or authority.

We do not use personal information for advertising, profiling, or automated decision-making, and we do not sell, rent or trade it to anyone.

By emailing us, you consent to our using your contact details and message to reply to you. By becoming a client, you consent to the collection and use described in Section 3 for the duration of the relationship and the retention periods in Section 8. Where we ever wish to use your information for a new purpose not described here, we will ask for your consent first.

We send no marketing email. Every message a client receives from us is transactional: invoices, monthly reports, maintenance notices, incident notifications and direct correspondence. Should we ever introduce a newsletter or other commercial electronic messages, we will comply with Canada's Anti-Spam Legislation (CASL): express opt-in consent, sender identification, and a working unsubscribe mechanism.

You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by contacting us as described in Section 15. Withdrawing consent for information we need to provide a service (for example, a billing address) may mean we cannot continue to provide that service.

5. Cookies, analytics and this website

This website does not set cookies of any kind — not functional, not analytical, not advertising. It does not embed content from third parties and does not use any analytics service. We therefore have no cookie banner, because there is nothing to consent to.

Server access logs (described in Section 2.1) are held by the web server on infrastructure we control for a maximum of 30 days and then deleted automatically. They are reviewed only when investigating a security event or an operational fault. They are not used to identify individual visitors, and no attempt is made to combine them with other information.

Because the website is served through a reverse proxy, the IP address recorded may be that of the proxy rather than of the visitor; where the visitor address is available it is treated as described above.

6. Who information is shared with

We share personal information only with the service providers necessary to run the business, and only the minimum they need. As of the effective date these are:

  • Email provider (Google LLC — Gmail / Google Workspace). All email correspondence, including enquiries, is received, stored and sent through Google's email service. Google processes this data under its own terms and privacy policy and may store it outside Canada (see Section 7).
  • Infrastructure provider (Hetzner Online GmbH, Germany). Hetzner supplies the physical and virtual servers on which client services run and on which this website is hosted. Hetzner does not receive client names or contact details from us; it processes the IP traffic and stored data of those servers as a data processor under German and EU law.
  • Payment processor. When you pay by credit card, the card details are entered directly with and processed by a PCI DSS-compliant payment processor; we receive only a confirmation, the last four digits and card brand for reconciliation. Interac e-Transfer payments are processed by your bank and ours.
  • Accounting and tax. Invoice records, which contain your name, address and the amounts paid, are kept in accounting software and may be reviewed by our accountant for tax filing purposes.

We may also disclose personal information where required or permitted by law — for example, in response to a valid subpoena, warrant or court order issued by a Canadian authority — and, in that event, we disclose only what is legally required and will notify you unless prohibited from doing so.

If the business is ever sold or transferred, personal information may be transferred to the successor as part of that transaction, and this policy (or one at least as protective) will continue to apply to it.

7. Where information is stored and cross-border transfers

Correspondence and enquiry records are stored by our email provider, Google, whose infrastructure is located primarily in the United States and other countries. Client server data is stored on Hetzner infrastructure in Germany, Finland or (at the client's election) the United States. Accounting records are kept in Canada.

Personal information stored outside Canada is subject to the laws of the jurisdiction where it is held, and may be accessible to the courts, law enforcement and national-security authorities of that jurisdiction. We select providers with strong contractual and technical protections, but we cannot guarantee that foreign authorities will not seek access under their own laws. By contacting us or engaging our services you acknowledge this transfer.

8. How long information is kept

We keep personal information only as long as needed for the purpose it was collected, and then delete or anonymize it. Specific periods:

  • Website access logs: 30 days.
  • Enquiries that do not lead to an engagement: deleted 12 months after the last message, so that a returning enquirer's context is available for a reasonable period.
  • Client correspondence and server documentation: for the duration of the engagement plus 12 months, to allow for post-termination questions and handover support.
  • Invoices, payment records and related identifying details: 7 years after the end of the tax year to which they relate, as required by the Income Tax Act and Excise Tax Act. Where you request deletion sooner, the records are retained but access is restricted to what tax compliance requires.
  • Client data on managed servers and in backups: see Section 10.

9. How information is protected

We apply safeguards proportionate to the sensitivity of the information: multi-factor authentication on every account that holds client information; hardware security keys for infrastructure access; SSH key-only, non-root access to servers; encrypted disks and encrypted, access-controlled backups; TLS for all data in transit; and a policy of never storing client credentials in plaintext (secrets are kept in an encrypted vault). Because One Stop Shop is operated by a single person, access to personal information is limited to that person and to the contracted providers listed in Section 6.

No system is perfectly secure. If a safeguard fails, Section 12 describes what happens.

10. Client data hosted on managed servers

Clients store their own data — files, media libraries, databases, application content, and in some cases personal information about their own users, family members or customers — on servers we manage. In relation to that data, the client is the organization responsible for it and we act on the client's instructions as a service provider. We do not access, read or use client content except as necessary to perform the contracted services (for example, restoring a backup, diagnosing a fault, or applying an update), and only to the extent required.

Our commitments regarding client-hosted data:

  • We do not monitor the contents of client files or libraries, and we do not disclose them to anyone except as compelled by law.
  • Backups are encrypted; on request, the encryption key can be held by the client so that we cannot read backup contents.
  • Monitoring collects operational metrics (CPU, memory, disk, uptime, service health) and does not inspect content.
  • On termination, client data is exported to the client and then securely erased from servers and backups within the period stated in our Terms of Service, currently 14 days after the final paid day, except where a longer retention is required by law.
  • If we receive a legal demand or abuse complaint concerning content on a client's server, we notify the client promptly unless prohibited, and give them the opportunity to respond before taking action, except where immediate action is legally required or necessary to prevent harm to others.

Clients who host personal information about others on their servers are responsible for their own compliance with applicable privacy law, and for having appropriate consent from those individuals. We will cooperate with a client's reasonable requests to help them meet those obligations.

11. Your rights: access, correction, deletion, withdrawal

You have the right to:

  • Access the personal information we hold about you, learn how it has been used and to whom it has been disclosed;
  • Correct information that is inaccurate or incomplete;
  • Request deletion of information that we are not legally required to keep;
  • Withdraw consent to further collection, use or disclosure, subject to legal or contractual restrictions;
  • Ask questions or complain about our handling of your information.

To exercise any of these rights, email onestopshopcommunications@gmail.com with the subject line “Privacy request”. We will confirm your identity — usually simply by replying to the email address we have on file — and respond within 30 days, as PIPEDA requires. If we need more time we will tell you why and when to expect a response. There is no fee for access requests. If we refuse a request (for example, because the information must be retained for tax purposes or contains another person's information), we will explain why and how you can challenge the decision.

12. Breach notification

If we experience a breach of security safeguards involving personal information under our control, and it is reasonable to believe the breach creates a real risk of significant harm to you, we will notify you directly as soon as feasible, report the breach to the Office of the Privacy Commissioner of Canada as PIPEDA requires, and notify any other organization that may be able to reduce the harm. We keep a record of every breach, whether or not it meets the reporting threshold, for at least 24 months.

For client-hosted data (Section 10), we notify the affected client of any security incident affecting their server as soon as feasible and in any case within 24 hours of confirming it, so that they can meet their own notification obligations.

13. Children

Our services are offered to adults and businesses. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us and we will delete it.

14. Changes to this policy

We review this policy at least annually and whenever we change a provider or practice it describes. Changes are posted on this page with an updated effective date. Material changes affecting current clients are also communicated by email before they take effect. The policy in force at any time is the one published here.

15. Contact and complaints

The operator of One Stop Shop is the person accountable for compliance with this policy and with PIPEDA. Questions, requests and complaints should be sent to onestopshopcommunications@gmail.com. We take every complaint seriously, will investigate it, and will tell you the outcome and any steps taken.

If you are not satisfied with our response, you have the right to complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca), which oversees compliance with PIPEDA, or to the privacy regulator of your province where provincial law applies.