Privacy Policy
Last updated:
This policy explains how Raccoon Ventures Inc., a Canadian corporation registered in Quebec, doing business as TrimCarbon (“we”, “us”), handles personal information when you visit trimcarbon.com, create an account, buy carbon credits through us, or contact us. It applies wherever you live; some sections apply only in certain places and say so.
Summary
- We collect what we need to run your account and buy and retire carbon credits for you: your email, a password hash, optional name and profile picture, your subscription, and your orders.
- Payments are handled by Stripe. Your card details go to Stripe directly and never reach our servers.
- Credits are bought and retired by CNaught in an account it keeps for you. Retirements are public registry records and can't be undone, even if you delete your TrimCarbon account.
- Browser analytics (PostHog) only run after you accept them. You can change your mind at any time with Privacy choices.
- We send you marketing emails only if you opt in, and you can stop them at any time.
- We don't sell your personal information, share it for targeted advertising, or show ads.
- You can delete your account yourself from the Account page, and ask us for a copy of your data at contact@mail.trimcarbon.com.
Who we are and how to reach us
Raccoon Ventures Inc. is responsible for your personal information (the “controller” under the GDPR and Brazil's LGPD). We are a company based in Quebec, Canada:
Raccoon Ventures Inc.73C Boulevard des Prairies
Laval, Quebec H7N 2T2
Canada
contact@mail.trimcarbon.com
Person in charge of personal information
Under Quebec's Act respecting the protection of personal information in the private sector (“Law 25”), our person in charge of the protection of personal information is JP Valery, Chief Executive Officer. You can reach them at contact@mail.trimcarbon.com or by mail at the address above, marked “Attention: Privacy”.
We have not appointed a representative in the European Union or the United Kingdom (Article 27 of the GDPR and of the UK GDPR), given the small scale of our activity there. If you are in the EU or the UK, contact us directly at contact@mail.trimcarbon.com.
We have not appointed a data protection officer (encarregado) under Brazil's LGPD, as small processing agents may choose not to (ANPD Resolution CD/ANPD 2/2022). If you are in Brazil, contact us at contact@mail.trimcarbon.com.
Wherever you are, you can contact us directly about anything in this policy.
What we collect and why
We collect information you give us (when you sign up, buy, or write to us), information your browser sends when you use the site, and information from the services that work for us: Stripe tells us whether a payment succeeded, CNaught tells us the status of your orders and where your credits came from, and our host tells us the country and region your connection comes from.
The legal basis column applies if you are in the EU, the EEA or the UK (and, with the equivalent grounds, in Brazil). The bases are explained under Legal bases.
| Information | Why we use it | Legal basis | How long |
|---|---|---|---|
| Account: email address, password (stored only as a one-way hash), name (optional), profile picture (optional), language, whether your email is verified | Create and run your account, sign you in, write to you in your language | Contract | Until you delete your account |
| Sign-in and security: sessions (IP address, browser and device description), passkeys (public key, credential ID, authenticator type), two-factor settings (encrypted authenticator secret and backup codes), one-time email codes (stored hashed), email verification and password reset tokens | Keep you signed in, protect your account, spot suspicious sign-ins | Contract; legitimate interests (account security) | Sessions: until you sign out or they expire (7 days after last use). Codes and tokens: until used or expired (3 minutes to 1 hour). Passkeys and two-factor settings: until you remove them or delete your account. |
| Subscription: Stripe customer ID, plan, kg per billing period, billing interval, status, period and cancellation dates | Charge you, manage your subscription, show your plan | Contract; legal obligation (accounting and tax records) | Billing records, including invoices and receipts at Stripe: 6 years after the end of the year of the transaction, as tax and accounting law requires, even if you delete your account. |
| Offset fulfilment: your CNaught account ID, and a ledger of each payment (Stripe payment ID, kg, amount, CNaught order ID, status). While a payment is being fulfilled, our workflow service holds your account ID, the payment ID and the kg | Buy and retire the credits each payment pays for, exactly once, and show your orders and certificates | Contract; legal obligation (accounting records) | Ledger: 6 years after the end of the year of the payment, as accounting law requires. If you delete your account, the ledger is no longer linked to it. Workflow run data: for the retention period Vercel sets for our account, then deleted. |
| Orders at CNaught: order number, kg, price, date, the projects your credits came from, certificate links. Your CNaught account is named with an internal ID, or with the name you choose for your certificates. Never with your email | Retire credits on your behalf and give you proof of retirement | Contract | Kept by CNaught. Retirements are permanent public registry records and stay after you delete your account |
| Messages you send us through the contact, high-volume, support or feedback forms, or by email: name, email, message, and optionally your aircraft and flight hours | Answer you and prepare quotes | Legitimate interests (answering enquiries); steps before a contract | 2 years after our last exchange |
| Emails we send you: your address, the message, delivery status | Email verification, password reset, sign-in codes, subscription confirmations and cancellations, order confirmations, a one-time welcome email from our founder, team invitations, and marketing emails if you opt in | Contract; legitimate interests (the welcome email); consent (marketing emails) | Delivery logs at Resend: for the retention period Resend sets for our account, then deleted |
| Marketing email choice: whether you opted in, and the date you did | Send marketing emails only to people who agreed, and show that you agreed | Consent | Until you delete your account |
| Consent records: a random visitor ID, your choices, the policy version, the date, your country and region, and your browser description. Where the law expects stronger proof (for example in the EU, EEA, UK and Quebec), also your IP address and language | Remember your choices and be able to prove them | Legal obligation (proof of consent); legitimate interests | Your choices expire after 365 days. Records: 3 years after you make the choice. |
| Browser analytics, only after you accept them: pages visited, clicks and other interactions, what you enter in our calculators (aircraft, hours), referrer, device and browser, approximate location derived from your IP address, a random analytics ID, and your account ID if you are signed in. Error reports from your browser | See how the site is used, find and fix problems, improve it | Consent | For the retention period PostHog sets for our account, then deleted |
| Account events recorded by our servers: your account ID (never your name or email) with the event and its details, such as your language, plan, kg, amount paid or payment ID. The events are sign-up, email verified, checkout started, subscription started or cancelled, offset order placed, payment refunded or disputed, and account deleted | Measure sign-ups, conversion and cancellations; check that every payment was fulfilled | Legitimate interests (running and improving the business) | For the retention period PostHog sets for our account, then deleted |
| Technical and security data: IP address, browser description, pages requested, timestamps and errors in our hosting logs; bot-detection signals on forms and sign-up; request counters per IP address | Run and debug the service, block bots and abuse, enforce rate limits | Legitimate interests (security and availability) | Hosting logs: for the retention period Vercel sets for our account, then deleted; used only to run and secure the service. Request counters: replaced each time window (seconds to minutes). |
Marketing emails. We send them only if you opt in, with the checkbox at sign-up, which is unticked by default, or the setting on the Account page. We record the date you agreed. You can withdraw at any time on the Account page or with the unsubscribe link in any marketing email. Emails you need to use the service, such as email verification, receipts, order confirmations and our founder's one-time welcome email, are sent whatever you choose.
If you join or run a team account (currently offered only to some customers), we also keep the organization's name, logo, members, roles and pending invitations, including the invitee's email.
We don't ask for sensitive information such as health data. The only “sensitive” information in the Californian sense is your sign-in credentials, which we use only to sign you in. Passkeys use your device's fingerprint or face unlock locally: we receive a public key, never biometric data.
We don't make decisions about you based solely on automated processing, and we don't build profiles about you for advertising.
Legal bases
Under the GDPR and the UK GDPR, we rely on these bases (Brazil's LGPD has equivalent ones):
- Contract: to provide the service you signed up or paid for, and to take steps you ask for before signing up.
- Legal obligation: to keep accounting and tax records and to prove consent.
- Consent: for browser analytics and marketing emails. You can withdraw it at any time; that doesn't affect what happened before. For marketing emails, this is also the express consent that Canada's anti-spam law (CASL) requires.
- Legitimate interests: where the use is something you would reasonably expect and doesn't override your rights. Ours are: keeping accounts and the service secure and free of bots and abuse; answering messages; measuring sign-ups, conversion and cancellations from our own account events; sending a single welcome email after sign-up; and keeping proof of your consent choices. You can object to any of these (see Your rights).
Who we share it with
We use the following service providers. They process personal information on our behalf, under contracts that limit what they can do with it.
| Provider | What for | What information | Where |
|---|---|---|---|
| Vercel Inc. | Hosting, server functions and logs; Vercel BotID bot detection on the contact forms and sign-up; Vercel Workflow, which runs payment fulfilment | Everything the site handles passes through it; logs hold IP address, browser description and pages requested; BotID reads browser and device signals; Workflow holds your account ID, the Stripe payment ID and the kg | United States |
| PlanetScale | Our PostgreSQL database | Account, sign-in, subscription, fulfilment ledger, consent records and request counters | United States (us-east) |
| Stripe | Payments, subscriptions, the billing portal, invoices and receipts | Name, email, billing details and card details you give Stripe, purchase history. We store only your Stripe customer ID | United States and Ireland |
| CNaught Inc. | Buys and retires carbon credits for you in an account it keeps for you, and issues certificates | An internal ID or the name you choose for your certificates as the account name, order amounts (kg, price) and dates | United States |
| Resend | Sends our emails and delivers contact form messages to us. Also receives and stores the emails you send to our addresses, such as contact@mail.trimcarbon.com | Email address, name, and the content of the email (codes, links, your message) | United States |
| PostHog | Product analytics and error tracking | See the analytics rows in the table above | United States (PostHog US Cloud) |
| Cloudflare (R2 storage) | Stores profile pictures and organization logos | The image you upload. Its web address contains your account ID and is readable by anyone who has it | United States |
Stripe also uses some information as an independent controller for its own purposes, such as fraud prevention and legal compliance, under the Stripe Privacy Policy. Stripe's checkout and billing pages are run by Stripe.
We also disclose personal information:
- Publicly, where you choose to: certificates for your orders have a public link, and anyone you share it with can see the order. CNaught records retirements on public carbon registries. We never give CNaught your email. If you choose a name for your certificates (on the My account page, or before you buy), CNaught gets that name and shows it on the certificates of your next orders. A certificate keeps the name it was issued with. Profile pictures are stored at a public web address.
- When the law requires it, for example to answer a valid court order, or when it's needed to protect someone's safety or to establish or defend our legal rights.
- If our business changes hands, to the buyer or successor, who must keep protecting it as this policy says. We will tell you if that happens.
We don't sell personal information, rent it, or share it for targeted (“cross-context behavioural”) advertising. We don't run ads or advertising trackers.
Some images on our pages come from Unsplash. Our own server fetches and resizes them, so your browser doesn't contact Unsplash. The preview images used when someone shares a link to our site are generated by a service run by our founder, which receives no information about visitors from our pages.
International transfers
We are in Quebec, Canada. The providers listed in Who we share it with process your information in the United States (Stripe also in Ireland), under their data processing terms, which require them to protect it. Your information may therefore be stored and processed outside your province or country, where privacy laws may differ and where courts and authorities may be able to access it under local law.
- From the EU, EEA and UK: the European Commission considers Canada adequate for organizations covered by PIPEDA, and the UK recognizes Canada too. For processing in the United States, our providers rely on their certification under the EU-US Data Privacy Framework (and its UK extension) where they have one, and otherwise on the European Commission's standard contractual clauses (with the UK addendum) in their data processing terms.
- From Brazil: we transfer data where the LGPD allows it, for example where the transfer is needed to perform our contract with you.
Cookies and similar technologies
Cookies are small files a site stores in your browser; local storage and session storage are similar. We use these:
| Name | Set by | Purpose | Duration | Category |
|---|---|---|---|---|
Next-Locale | TrimCarbon | Remembers the language of the pages you visit | Until you close your browser | Functional |
better-auth.session_token | TrimCarbon | Keeps you signed in | 7 days, renewed as you use the site; until you close your browser if you untick "Remember me" | Strictly necessary |
better-auth.dont_remember | TrimCarbon | Records that you signed in without "Remember me" | Until you close your browser | Strictly necessary |
better-auth.two_factor | TrimCarbon | Links a sign-in to its pending two-factor check | 10 minutes | Strictly necessary |
better-auth.better-auth-passkey | TrimCarbon | Holds the one-time challenge while you add or use a passkey | 5 minutes | Strictly necessary |
better-auth.admin_session | TrimCarbon | Set only for our administrators | Until the administrator session ends | Strictly necessary |
c15t (cookie and local storage) | TrimCarbon (c15t consent tool, run on our servers) | Remembers your privacy choices | 365 days | Strictly necessary |
c15t-pending-*, c15t:pending-* (local storage) | TrimCarbon (c15t) | Queues a consent choice that couldn’t be saved yet, for example when you are offline | Until it is saved | Strictly necessary |
theme (local storage) | TrimCarbon | Remembers light or dark mode | Until you clear it | Functional |
Cookies starting with KP_ | Vercel BotID | Tells people from bots on the contact forms and sign-up | Set by Vercel, which determines their lifetime | Strictly necessary (security) |
ph_[project key]_posthog (cookie and local storage) | PostHog | A random analytics ID and the current visit, so pages and actions can be counted | 365 days | Measurement (only with consent) |
ph_[project key]_window_id, ph_[project key]_primary_window_exists (session storage) | PostHog | Tells browser tabs apart within a visit | Until you close the tab | Measurement (only with consent) |
__ph_opt_in_out_[project key] (local storage) | PostHog | Records that you turned analytics on or off, once PostHog has been loaded | Until you clear it | Measurement |
Over HTTPS, browsers see our sign-in cookie names with a __Secure- prefix. Stripe sets its own cookies on its checkout and billing pages, which are on Stripe's domains and covered by Stripe's cookie policy. PostHog is only downloaded once you accept analytics; until then it sets nothing.
Your consent choices
Our consent tool, c15t, runs on our own servers and stores your choices in our database. Wherever you are, a banner asks you to accept or decline analytics. Analytics stay off unless you press Accept. If you decline, we remember that.
The wording of the banner follows the law where you are, based on the country and region of your connection, which our host looks up.
Your choice lasts 365 days, after which we ask again. You can change it at any time with , here or at the bottom of every page. Turning analytics off stops PostHog from collecting anything further and from storing anything in your browser.
If your browser sends a Global Privacy Control signal, there is nothing more for us to do: we never sell or share personal information, and analytics only run after you accept. The same goes for the older “Do Not Track” signal.
Your rights
Depending on where you live, you have some or all of these rights. We extend the core ones (access, correction, deletion, a copy of your data, and withdrawing consent) to everyone.
EU, EEA and UK
Under the GDPR and the UK GDPR you can ask us to give you access to your personal information, correct it, delete it, restrict how we use it, or give you a copy in a portable format. You can object at any time to uses based on our legitimate interests, and withdraw consent at any time. You can complain to your local data protection authority (listed by the European Data Protection Board) or, in the UK, the Information Commissioner's Office. We'd appreciate the chance to sort it out with you first.
Quebec and the rest of Canada
Under Law 25 and the federal PIPEDA you can ask to access your personal information, have it corrected, and withdraw your consent. Under Law 25 you can also receive the information you gave us in a structured, commonly used technological format. In Quebec you can also ask us to stop disseminating your information or de-index a link to it where the law allows, and to be told about any decision made solely by automated processing (we don't make any). You can complain to the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada.
We use the country and region of your connection only to show the consent notice that fits the law where you are. Apart from the consent record you create when you make a choice, we don't store it. Our analytics derive an approximate location from your IP address, and stay off until you accept them.
California and other US states
If you live in California, we give you the rights of the CCPA (as amended by the CPRA), whether or not these laws apply to us: the right to know what personal information we collect, use and disclose; to access, correct and delete it; to opt out of its sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for using these rights. You can use an authorized agent; we may ask the agent for proof and ask you to confirm your identity.
- We don't sell personal information or share it for cross-context behavioural advertising, and haven't in the past 12 months. We have no knowledge of selling or sharing information about anyone under 16.
- We use sensitive personal information (your sign-in credentials) only to provide the service, so the right to limit doesn't apply.
- A Global Privacy Control signal needs no further action from us, as explained in Your consent choices.
| Category | Examples from TrimCarbon | Collected | Disclosed for a business purpose to |
|---|---|---|---|
| Identifiers | Name, email, account ID, IP address, analytics ID | Yes | Vercel, PlanetScale, Stripe, Resend, PostHog, CNaught (account ID, and the name you choose for your certificates) |
| Personal information in customer records (Cal. Civ. Code 1798.80(e)) | Name, email; billing details and card number are collected by Stripe, not by us | Yes | Stripe, Resend, PlanetScale |
| Protected classification characteristics | None | No | Not applicable |
| Commercial information | Plan, kg purchased, payments, orders and certificates | Yes | Stripe, CNaught, PostHog (account events), Vercel Workflow |
| Biometric information | None. Passkeys check your fingerprint or face on your device only | No | Not applicable |
| Internet or other electronic network activity | Pages viewed and interactions (with consent), browser and device, logs | Yes | Vercel, PostHog |
| Geolocation data | Approximate location (country, region) from your IP address. Never precise location | Yes | Vercel, PostHog |
| Audio, electronic, visual or similar information | Profile picture, if you upload one | Yes | Cloudflare |
| Professional or employment information | None (team accounts hold an organization name and your role in it) | No | Not applicable |
| Education information | None | No | Not applicable |
| Inferences | None; we don’t build profiles | No | Not applicable |
| Sensitive personal information | Account sign-in credentials (email with password) | Yes | PlanetScale, Vercel (password stored as a hash only) |
Sources, purposes and retention for each category are in What we collect and why.
Residents of other US states with privacy laws (for example Virginia, Colorado, Connecticut, Oregon or Texas) may have similar rights to access, correct, delete and port their data, and to opt out of targeted advertising, sale and profiling, which we don't do. If we turn down your request, you can appeal by replying to our answer; if we turn down the appeal, you can contact your state's attorney general.
Brazil
Under the LGPD you can ask us to confirm whether we process your data; access it; correct incomplete, inaccurate or outdated data; anonymize, block or delete data that is unnecessary, excessive or processed unlawfully; port it to another provider; delete data processed with your consent; learn who we share it with; learn what happens if you don't consent; and withdraw consent. You can complain to the Autoridade Nacional de Proteção de Dados (ANPD).
How to use your rights
- Change your details: your name, picture, language, password, passkeys and two-factor settings are on the Account page. Billing details are in the Stripe billing portal, which you open from the Account page.
- Delete your account: use “Delete account” on the Account page. See Retention and account deletion for what that removes and what stays.
- Everything else (a copy of your data, a portable export, correcting something you can't edit, objecting, restricting, or any question): email contact@mail.trimcarbon.com from the address on your account, or tell us how to reach you.
- Analytics: change your choice at any time with .
- Marketing emails: turn them off on the Account page, or use the unsubscribe link in any marketing email.
We may need to confirm it's really you, usually by replying from the email on your account. We answer within 30 days, or sooner where the law requires it (for example, 15 days for some requests under Brazil's LGPD). If the law gives us more time and we need it, we'll tell you why. Using your rights is free.
Retention and account deletion
We keep personal information only as long as we need it for the purposes above; the table in What we collect and why gives the period for each kind. After that we delete it or make it anonymous.
Information that our providers hold for us, such as email delivery logs, analytics events, hosting logs and workflow run data, is kept for the retention period each provider sets for our account, then deleted. We use it only for the purposes above.
Deleting your account from the Account page cancels any active subscription in Stripe, and deletes your account, sessions, passkeys and profile picture. It does not delete:
- your orders and certificates at CNaught. Retiring a credit is permanent and is recorded on a public registry, and certificates keep the name they were issued with;
- billing records, including the fulfilment ledger and the invoices and receipts at Stripe, which we keep for 6 years after the end of the year of each transaction, as tax and accounting law requires. The ledger is no longer linked to your account;
- analytics events tied to your account ID, which are kept for the analytics retention period unless you ask us to delete them;
- messages you sent us, which we keep for 2 years after our last exchange;
- consent records, which aren't linked to your account.
Children
TrimCarbon is not directed at children under 16, and we don't knowingly collect personal information from them. Accounts and purchases are for adults (see our Terms and Conditions). If you think a child has given us personal information, write to contact@mail.trimcarbon.com and we'll delete it.
Security
We protect your information with measures that include:
- encrypted connections (HTTPS) everywhere;
- passwords stored only as one-way hashes, one-time sign-in codes stored hashed, and two-factor secrets stored encrypted;
- email verification before first sign-in, optional passkeys and two-factor authentication;
- rate limits on sign-in and other account actions, and bot detection on sign-up and our forms;
- card payments handled entirely by Stripe, which is certified to the PCI DSS standard;
- access to personal information limited to the people and providers who need it.
No system is perfectly secure. If a confidentiality incident creates a risk of serious harm to you, we will tell you and the authorities as the law requires, and we keep a record of incidents.
Changes to this policy
We will post any new version here with a new “Last updated” date. If a change is significant, for example a new purpose or a new kind of provider, we will tell you by email (if you have an account) and on the site at least 30 days before it takes effect, and ask for your consent again where the law requires.
Contact
Questions, requests or complaints about privacy: write to contact@mail.trimcarbon.com, or by mail to:
Raccoon Ventures Inc.73C Boulevard des Prairies
Laval, Quebec H7N 2T2
Canada
contact@mail.trimcarbon.com