Skip to content
TrimCarbon
Start offsetting

Privacy Policy

Last updated:

This policy explains how Raccoon Ventures Inc., a Canadian corporation registered in Quebec, doing business as TrimCarbon (“we”, “us”), handles personal information when you visit trimcarbon.com, create an account, buy carbon credits through us, or contact us. It applies wherever you live; some sections apply only in certain places and say so.

Summary

  • We collect what we need to run your account and buy and retire carbon credits for you: your email, a password hash, optional name and profile picture, your subscription, and your orders.
  • Payments are handled by Stripe. Your card details go to Stripe directly and never reach our servers.
  • Credits are bought and retired by CNaught in an account it keeps for you. Retirements are public registry records and can't be undone, even if you delete your TrimCarbon account.
  • Browser analytics (PostHog) only run after you accept them. You can change your mind at any time with Privacy choices.
  • We send you marketing emails only if you opt in, and you can stop them at any time.
  • We don't sell your personal information, share it for targeted advertising, or show ads.
  • You can delete your account yourself from the Account page, and ask us for a copy of your data at contact@mail.trimcarbon.com.

Who we are and how to reach us

Raccoon Ventures Inc. is responsible for your personal information (the “controller” under the GDPR and Brazil's LGPD). We are a company based in Quebec, Canada:

Raccoon Ventures Inc.
73C Boulevard des Prairies
Laval, Quebec H7N 2T2
Canada
contact@mail.trimcarbon.com

Person in charge of personal information

Under Quebec's Act respecting the protection of personal information in the private sector (“Law 25”), our person in charge of the protection of personal information is JP Valery, Chief Executive Officer. You can reach them at contact@mail.trimcarbon.com or by mail at the address above, marked “Attention: Privacy”.

We have not appointed a representative in the European Union or the United Kingdom (Article 27 of the GDPR and of the UK GDPR), given the small scale of our activity there. If you are in the EU or the UK, contact us directly at contact@mail.trimcarbon.com.

We have not appointed a data protection officer (encarregado) under Brazil's LGPD, as small processing agents may choose not to (ANPD Resolution CD/ANPD 2/2022). If you are in Brazil, contact us at contact@mail.trimcarbon.com.

Wherever you are, you can contact us directly about anything in this policy.

What we collect and why

We collect information you give us (when you sign up, buy, or write to us), information your browser sends when you use the site, and information from the services that work for us: Stripe tells us whether a payment succeeded, CNaught tells us the status of your orders and where your credits came from, and our host tells us the country and region your connection comes from.

The legal basis column applies if you are in the EU, the EEA or the UK (and, with the equivalent grounds, in Brazil). The bases are explained under Legal bases.

Personal information we process, why, on what basis, and for how long
InformationWhy we use itLegal basisHow long
Account: email address, password (stored only as a one-way hash), name (optional), profile picture (optional), language, whether your email is verifiedCreate and run your account, sign you in, write to you in your languageContractUntil you delete your account
Sign-in and security: sessions (IP address, browser and device description), passkeys (public key, credential ID, authenticator type), two-factor settings (encrypted authenticator secret and backup codes), one-time email codes (stored hashed), email verification and password reset tokensKeep you signed in, protect your account, spot suspicious sign-insContract; legitimate interests (account security)Sessions: until you sign out or they expire (7 days after last use). Codes and tokens: until used or expired (3 minutes to 1 hour). Passkeys and two-factor settings: until you remove them or delete your account.
Subscription: Stripe customer ID, plan, kg per billing period, billing interval, status, period and cancellation datesCharge you, manage your subscription, show your planContract; legal obligation (accounting and tax records)Billing records, including invoices and receipts at Stripe: 6 years after the end of the year of the transaction, as tax and accounting law requires, even if you delete your account.
Offset fulfilment: your CNaught account ID, and a ledger of each payment (Stripe payment ID, kg, amount, CNaught order ID, status). While a payment is being fulfilled, our workflow service holds your account ID, the payment ID and the kgBuy and retire the credits each payment pays for, exactly once, and show your orders and certificatesContract; legal obligation (accounting records)Ledger: 6 years after the end of the year of the payment, as accounting law requires. If you delete your account, the ledger is no longer linked to it. Workflow run data: for the retention period Vercel sets for our account, then deleted.
Orders at CNaught: order number, kg, price, date, the projects your credits came from, certificate links. Your CNaught account is named with an internal ID, or with the name you choose for your certificates. Never with your emailRetire credits on your behalf and give you proof of retirementContractKept by CNaught. Retirements are permanent public registry records and stay after you delete your account
Messages you send us through the contact, high-volume, support or feedback forms, or by email: name, email, message, and optionally your aircraft and flight hoursAnswer you and prepare quotesLegitimate interests (answering enquiries); steps before a contract2 years after our last exchange
Emails we send you: your address, the message, delivery statusEmail verification, password reset, sign-in codes, subscription confirmations and cancellations, order confirmations, a one-time welcome email from our founder, team invitations, and marketing emails if you opt inContract; legitimate interests (the welcome email); consent (marketing emails)Delivery logs at Resend: for the retention period Resend sets for our account, then deleted
Marketing email choice: whether you opted in, and the date you didSend marketing emails only to people who agreed, and show that you agreedConsentUntil you delete your account
Consent records: a random visitor ID, your choices, the policy version, the date, your country and region, and your browser description. Where the law expects stronger proof (for example in the EU, EEA, UK and Quebec), also your IP address and languageRemember your choices and be able to prove themLegal obligation (proof of consent); legitimate interestsYour choices expire after 365 days. Records: 3 years after you make the choice.
Browser analytics, only after you accept them: pages visited, clicks and other interactions, what you enter in our calculators (aircraft, hours), referrer, device and browser, approximate location derived from your IP address, a random analytics ID, and your account ID if you are signed in. Error reports from your browserSee how the site is used, find and fix problems, improve itConsentFor the retention period PostHog sets for our account, then deleted
Account events recorded by our servers: your account ID (never your name or email) with the event and its details, such as your language, plan, kg, amount paid or payment ID. The events are sign-up, email verified, checkout started, subscription started or cancelled, offset order placed, payment refunded or disputed, and account deletedMeasure sign-ups, conversion and cancellations; check that every payment was fulfilledLegitimate interests (running and improving the business)For the retention period PostHog sets for our account, then deleted
Technical and security data: IP address, browser description, pages requested, timestamps and errors in our hosting logs; bot-detection signals on forms and sign-up; request counters per IP addressRun and debug the service, block bots and abuse, enforce rate limitsLegitimate interests (security and availability)Hosting logs: for the retention period Vercel sets for our account, then deleted; used only to run and secure the service. Request counters: replaced each time window (seconds to minutes).

Marketing emails. We send them only if you opt in, with the checkbox at sign-up, which is unticked by default, or the setting on the Account page. We record the date you agreed. You can withdraw at any time on the Account page or with the unsubscribe link in any marketing email. Emails you need to use the service, such as email verification, receipts, order confirmations and our founder's one-time welcome email, are sent whatever you choose.

If you join or run a team account (currently offered only to some customers), we also keep the organization's name, logo, members, roles and pending invitations, including the invitee's email.

We don't ask for sensitive information such as health data. The only “sensitive” information in the Californian sense is your sign-in credentials, which we use only to sign you in. Passkeys use your device's fingerprint or face unlock locally: we receive a public key, never biometric data.

We don't make decisions about you based solely on automated processing, and we don't build profiles about you for advertising.

Under the GDPR and the UK GDPR, we rely on these bases (Brazil's LGPD has equivalent ones):

  • Contract: to provide the service you signed up or paid for, and to take steps you ask for before signing up.
  • Legal obligation: to keep accounting and tax records and to prove consent.
  • Consent: for browser analytics and marketing emails. You can withdraw it at any time; that doesn't affect what happened before. For marketing emails, this is also the express consent that Canada's anti-spam law (CASL) requires.
  • Legitimate interests: where the use is something you would reasonably expect and doesn't override your rights. Ours are: keeping accounts and the service secure and free of bots and abuse; answering messages; measuring sign-ups, conversion and cancellations from our own account events; sending a single welcome email after sign-up; and keeping proof of your consent choices. You can object to any of these (see Your rights).

Who we share it with

We use the following service providers. They process personal information on our behalf, under contracts that limit what they can do with it.

Service providers that process personal information for us
ProviderWhat forWhat informationWhere
Vercel Inc.Hosting, server functions and logs; Vercel BotID bot detection on the contact forms and sign-up; Vercel Workflow, which runs payment fulfilmentEverything the site handles passes through it; logs hold IP address, browser description and pages requested; BotID reads browser and device signals; Workflow holds your account ID, the Stripe payment ID and the kgUnited States
PlanetScaleOur PostgreSQL databaseAccount, sign-in, subscription, fulfilment ledger, consent records and request countersUnited States (us-east)
StripePayments, subscriptions, the billing portal, invoices and receiptsName, email, billing details and card details you give Stripe, purchase history. We store only your Stripe customer IDUnited States and Ireland
CNaught Inc.Buys and retires carbon credits for you in an account it keeps for you, and issues certificatesAn internal ID or the name you choose for your certificates as the account name, order amounts (kg, price) and datesUnited States
ResendSends our emails and delivers contact form messages to us. Also receives and stores the emails you send to our addresses, such as contact@mail.trimcarbon.comEmail address, name, and the content of the email (codes, links, your message)United States
PostHogProduct analytics and error trackingSee the analytics rows in the table aboveUnited States (PostHog US Cloud)
Cloudflare (R2 storage)Stores profile pictures and organization logosThe image you upload. Its web address contains your account ID and is readable by anyone who has itUnited States

Stripe also uses some information as an independent controller for its own purposes, such as fraud prevention and legal compliance, under the Stripe Privacy Policy. Stripe's checkout and billing pages are run by Stripe.

We also disclose personal information:

  • Publicly, where you choose to: certificates for your orders have a public link, and anyone you share it with can see the order. CNaught records retirements on public carbon registries. We never give CNaught your email. If you choose a name for your certificates (on the My account page, or before you buy), CNaught gets that name and shows it on the certificates of your next orders. A certificate keeps the name it was issued with. Profile pictures are stored at a public web address.
  • When the law requires it, for example to answer a valid court order, or when it's needed to protect someone's safety or to establish or defend our legal rights.
  • If our business changes hands, to the buyer or successor, who must keep protecting it as this policy says. We will tell you if that happens.

We don't sell personal information, rent it, or share it for targeted (“cross-context behavioural”) advertising. We don't run ads or advertising trackers.

Some images on our pages come from Unsplash. Our own server fetches and resizes them, so your browser doesn't contact Unsplash. The preview images used when someone shares a link to our site are generated by a service run by our founder, which receives no information about visitors from our pages.

International transfers

We are in Quebec, Canada. The providers listed in Who we share it with process your information in the United States (Stripe also in Ireland), under their data processing terms, which require them to protect it. Your information may therefore be stored and processed outside your province or country, where privacy laws may differ and where courts and authorities may be able to access it under local law.

  • From the EU, EEA and UK: the European Commission considers Canada adequate for organizations covered by PIPEDA, and the UK recognizes Canada too. For processing in the United States, our providers rely on their certification under the EU-US Data Privacy Framework (and its UK extension) where they have one, and otherwise on the European Commission's standard contractual clauses (with the UK addendum) in their data processing terms.
  • From Brazil: we transfer data where the LGPD allows it, for example where the transfer is needed to perform our contract with you.

Cookies and similar technologies

Cookies are small files a site stores in your browser; local storage and session storage are similar. We use these:

Cookies and browser storage on trimcarbon.com
NameSet byPurposeDurationCategory
Next-LocaleTrimCarbonRemembers the language of the pages you visitUntil you close your browserFunctional
better-auth.session_tokenTrimCarbonKeeps you signed in7 days, renewed as you use the site; until you close your browser if you untick "Remember me"Strictly necessary
better-auth.dont_rememberTrimCarbonRecords that you signed in without "Remember me"Until you close your browserStrictly necessary
better-auth.two_factorTrimCarbonLinks a sign-in to its pending two-factor check10 minutesStrictly necessary
better-auth.better-auth-passkeyTrimCarbonHolds the one-time challenge while you add or use a passkey5 minutesStrictly necessary
better-auth.admin_sessionTrimCarbonSet only for our administratorsUntil the administrator session endsStrictly necessary
c15t (cookie and local storage)TrimCarbon (c15t consent tool, run on our servers)Remembers your privacy choices365 daysStrictly necessary
c15t-pending-*, c15t:pending-* (local storage)TrimCarbon (c15t)Queues a consent choice that couldn’t be saved yet, for example when you are offlineUntil it is savedStrictly necessary
theme (local storage)TrimCarbonRemembers light or dark modeUntil you clear itFunctional
Cookies starting with KP_Vercel BotIDTells people from bots on the contact forms and sign-upSet by Vercel, which determines their lifetimeStrictly necessary (security)
ph_[project key]_posthog (cookie and local storage)PostHogA random analytics ID and the current visit, so pages and actions can be counted365 daysMeasurement (only with consent)
ph_[project key]_window_id, ph_[project key]_primary_window_exists (session storage)PostHogTells browser tabs apart within a visitUntil you close the tabMeasurement (only with consent)
__ph_opt_in_out_[project key] (local storage)PostHogRecords that you turned analytics on or off, once PostHog has been loadedUntil you clear itMeasurement

Over HTTPS, browsers see our sign-in cookie names with a __Secure- prefix. Stripe sets its own cookies on its checkout and billing pages, which are on Stripe's domains and covered by Stripe's cookie policy. PostHog is only downloaded once you accept analytics; until then it sets nothing.

Our consent tool, c15t, runs on our own servers and stores your choices in our database. Wherever you are, a banner asks you to accept or decline analytics. Analytics stay off unless you press Accept. If you decline, we remember that.

The wording of the banner follows the law where you are, based on the country and region of your connection, which our host looks up.

Your choice lasts 365 days, after which we ask again. You can change it at any time with , here or at the bottom of every page. Turning analytics off stops PostHog from collecting anything further and from storing anything in your browser.

If your browser sends a Global Privacy Control signal, there is nothing more for us to do: we never sell or share personal information, and analytics only run after you accept. The same goes for the older “Do Not Track” signal.

Your rights

Depending on where you live, you have some or all of these rights. We extend the core ones (access, correction, deletion, a copy of your data, and withdrawing consent) to everyone.

EU, EEA and UK

Under the GDPR and the UK GDPR you can ask us to give you access to your personal information, correct it, delete it, restrict how we use it, or give you a copy in a portable format. You can object at any time to uses based on our legitimate interests, and withdraw consent at any time. You can complain to your local data protection authority (listed by the European Data Protection Board) or, in the UK, the Information Commissioner's Office. We'd appreciate the chance to sort it out with you first.

Quebec and the rest of Canada

Under Law 25 and the federal PIPEDA you can ask to access your personal information, have it corrected, and withdraw your consent. Under Law 25 you can also receive the information you gave us in a structured, commonly used technological format. In Quebec you can also ask us to stop disseminating your information or de-index a link to it where the law allows, and to be told about any decision made solely by automated processing (we don't make any). You can complain to the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada.

We use the country and region of your connection only to show the consent notice that fits the law where you are. Apart from the consent record you create when you make a choice, we don't store it. Our analytics derive an approximate location from your IP address, and stay off until you accept them.

California and other US states

If you live in California, we give you the rights of the CCPA (as amended by the CPRA), whether or not these laws apply to us: the right to know what personal information we collect, use and disclose; to access, correct and delete it; to opt out of its sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for using these rights. You can use an authorized agent; we may ask the agent for proof and ask you to confirm your identity.

  • We don't sell personal information or share it for cross-context behavioural advertising, and haven't in the past 12 months. We have no knowledge of selling or sharing information about anyone under 16.
  • We use sensitive personal information (your sign-in credentials) only to provide the service, so the right to limit doesn't apply.
  • A Global Privacy Control signal needs no further action from us, as explained in Your consent choices.
Categories of personal information collected in the past 12 months (CCPA)
CategoryExamples from TrimCarbonCollectedDisclosed for a business purpose to
IdentifiersName, email, account ID, IP address, analytics IDYesVercel, PlanetScale, Stripe, Resend, PostHog, CNaught (account ID, and the name you choose for your certificates)
Personal information in customer records (Cal. Civ. Code 1798.80(e))Name, email; billing details and card number are collected by Stripe, not by usYesStripe, Resend, PlanetScale
Protected classification characteristicsNoneNoNot applicable
Commercial informationPlan, kg purchased, payments, orders and certificatesYesStripe, CNaught, PostHog (account events), Vercel Workflow
Biometric informationNone. Passkeys check your fingerprint or face on your device onlyNoNot applicable
Internet or other electronic network activityPages viewed and interactions (with consent), browser and device, logsYesVercel, PostHog
Geolocation dataApproximate location (country, region) from your IP address. Never precise locationYesVercel, PostHog
Audio, electronic, visual or similar informationProfile picture, if you upload oneYesCloudflare
Professional or employment informationNone (team accounts hold an organization name and your role in it)NoNot applicable
Education informationNoneNoNot applicable
InferencesNone; we don’t build profilesNoNot applicable
Sensitive personal informationAccount sign-in credentials (email with password)YesPlanetScale, Vercel (password stored as a hash only)

Sources, purposes and retention for each category are in What we collect and why.

Residents of other US states with privacy laws (for example Virginia, Colorado, Connecticut, Oregon or Texas) may have similar rights to access, correct, delete and port their data, and to opt out of targeted advertising, sale and profiling, which we don't do. If we turn down your request, you can appeal by replying to our answer; if we turn down the appeal, you can contact your state's attorney general.

Brazil

Under the LGPD you can ask us to confirm whether we process your data; access it; correct incomplete, inaccurate or outdated data; anonymize, block or delete data that is unnecessary, excessive or processed unlawfully; port it to another provider; delete data processed with your consent; learn who we share it with; learn what happens if you don't consent; and withdraw consent. You can complain to the Autoridade Nacional de Proteção de Dados (ANPD).

How to use your rights

  • Change your details: your name, picture, language, password, passkeys and two-factor settings are on the Account page. Billing details are in the Stripe billing portal, which you open from the Account page.
  • Delete your account: use “Delete account” on the Account page. See Retention and account deletion for what that removes and what stays.
  • Everything else (a copy of your data, a portable export, correcting something you can't edit, objecting, restricting, or any question): email contact@mail.trimcarbon.com from the address on your account, or tell us how to reach you.
  • Analytics: change your choice at any time with .
  • Marketing emails: turn them off on the Account page, or use the unsubscribe link in any marketing email.

We may need to confirm it's really you, usually by replying from the email on your account. We answer within 30 days, or sooner where the law requires it (for example, 15 days for some requests under Brazil's LGPD). If the law gives us more time and we need it, we'll tell you why. Using your rights is free.

Retention and account deletion

We keep personal information only as long as we need it for the purposes above; the table in What we collect and why gives the period for each kind. After that we delete it or make it anonymous.

Information that our providers hold for us, such as email delivery logs, analytics events, hosting logs and workflow run data, is kept for the retention period each provider sets for our account, then deleted. We use it only for the purposes above.

Deleting your account from the Account page cancels any active subscription in Stripe, and deletes your account, sessions, passkeys and profile picture. It does not delete:

  • your orders and certificates at CNaught. Retiring a credit is permanent and is recorded on a public registry, and certificates keep the name they were issued with;
  • billing records, including the fulfilment ledger and the invoices and receipts at Stripe, which we keep for 6 years after the end of the year of each transaction, as tax and accounting law requires. The ledger is no longer linked to your account;
  • analytics events tied to your account ID, which are kept for the analytics retention period unless you ask us to delete them;
  • messages you sent us, which we keep for 2 years after our last exchange;
  • consent records, which aren't linked to your account.

Children

TrimCarbon is not directed at children under 16, and we don't knowingly collect personal information from them. Accounts and purchases are for adults (see our Terms and Conditions). If you think a child has given us personal information, write to contact@mail.trimcarbon.com and we'll delete it.

Security

We protect your information with measures that include:

  • encrypted connections (HTTPS) everywhere;
  • passwords stored only as one-way hashes, one-time sign-in codes stored hashed, and two-factor secrets stored encrypted;
  • email verification before first sign-in, optional passkeys and two-factor authentication;
  • rate limits on sign-in and other account actions, and bot detection on sign-up and our forms;
  • card payments handled entirely by Stripe, which is certified to the PCI DSS standard;
  • access to personal information limited to the people and providers who need it.

No system is perfectly secure. If a confidentiality incident creates a risk of serious harm to you, we will tell you and the authorities as the law requires, and we keep a record of incidents.

Changes to this policy

We will post any new version here with a new “Last updated” date. If a change is significant, for example a new purpose or a new kind of provider, we will tell you by email (if you have an account) and on the site at least 30 days before it takes effect, and ask for your consent again where the law requires.

Contact

Questions, requests or complaints about privacy: write to contact@mail.trimcarbon.com, or by mail to:

Raccoon Ventures Inc.
73C Boulevard des Prairies
Laval, Quebec H7N 2T2
Canada
contact@mail.trimcarbon.com