Last updated: April 2, 2026
RGPD/GDPRLPRPDE/PIPEDAAES-256TLS 1.3
Privacy Policy
ClearLoads · clear-loads.com
✓ Summary
- Your check-in data is strictly personal and never sold
- AES-256 encryption at rest, TLS 1.3 in transit — hosted in Canada
- Export or delete your data in 1 click from your dashboard
- No advertising or third-party tracking cookies
- Contact: support@clear-loads.com — response within 24h
1. Data Controller
ClearLoads is the data controller for your personal data. ClearLoads is a commercial brand operated under Canadian law (Quebec). For data protection inquiries: support@clear-loads.com. Postal address available upon request.
2. Data Collected and Legal Bases
ClearLoads collects the following data under GDPR Article 6 legal bases:
• Check-in data (mental load, emotional state, physical energy — 1-5 scores): legal basis = contract performance (art. 6.1.b) — necessary to provide the service.
• Email address: legal basis = contract performance (authentication, account access, Premium trial reminders) and consent (newsletter if subscribed).
• Payment data: processed exclusively by Stripe. ClearLoads never sees your card details.
• Navigation data (technical logs): legal basis = legitimate interest (security, fraud prevention, service maintenance).
ClearLoads does NOT collect health data under GDPR Art. 9 (sensitive data). Check-in scores are wellness self-assessments, not medical diagnoses.
3. Processing Purposes
Your data is used exclusively to:
• Provide your visual mirror and check-in results
• Calculate your trends and patterns (free and Premium plans)
• Personalize recommended micro-actions
• Manage your account and subscription
• Send account-related communications (trial reminders, payment confirmations)
• Improve the service in an aggregated and anonymous manner
ClearLoads does NOT use your data for: targeted advertising, commercial profiling, reselling to third parties, or training third-party AI models.
4. Retention Periods
• Check-in data: retained for 24 months after last account activity, then automatically deleted.
• Email: retained for the duration of your subscription + 12 months (legal accounting obligations).
• Payment data: managed by Stripe per their retention policies (generally 7 years for tax compliance).
• Technical logs: 90 rolling days.
• Account deletion: immediate deletion of all check-in data. Email may be retained for 30 additional days for security reasons.
5. Data Recipients
ClearLoads never sells your data. We share only with the following sub-processors, bound by GDPR-compliant Data Processing Agreements (DPA):
• Supabase Inc. (USA): database hosting, Montreal (Canada) region. Covered by EU Standard Contractual Clauses (SCC). Privacy: supabase.com/privacy
• Stripe Inc. (USA): payment processing only. Never receives your check-in data. PCI DSS Level 1 certified. Privacy: stripe.com/privacy
• Resend Inc. (USA): transactional email delivery (your email address only). Covered by SCC. Privacy: resend.com/privacy
No other third parties. If this changes, you will be notified 30 days in advance.
6. International Transfers
Some sub-processors (Supabase, Stripe, Resend) are headquartered in the USA. Transfers are governed by:
• EU Standard Contractual Clauses (SCC) under Commission Decision 2021/914
• Data Privacy Framework (DPF) for Stripe
• Technical security measures (end-to-end encryption)
For Canadian users, transfers comply with PIPEDA (Personal Information Protection and Electronic Documents Act).
7. Security
ClearLoads implements state-of-the-art technical and organizational security measures:
• AES-256 encryption of data at rest
• TLS 1.3 for all communications in transit
• Magic link authentication — no stored passwords
• Production data access limited to authorized personnel
• Regular code security reviews
• SOC 2 Type II certified infrastructure (Supabase)
In case of a data breach affecting your rights, ClearLoads will notify you within 72 hours per GDPR Art. 34.
8. Cookies and Similar Technologies
ClearLoads uses only strictly necessary cookies:
• next-auth.session-token: secure session authentication (duration: session + 30 days). Strictly necessary.
• clearloads-theme: light/dark theme preference (duration: 12 months). Functional.
• clearloads-locale: preferred language (duration: 12 months). Functional.
ClearLoads uses NO:
• Advertising or retargeting cookies
• Third-party tracking or analytics cookies (Google Analytics, Facebook Pixel, etc.)
• Social media sharing cookies
Strictly necessary cookies do not require prior consent under the ePrivacy Directive.
9. Your Rights
Under GDPR (Articles 15-22) and PIPEDA, you have the following rights:
• Right of access: export all your data as CSV from Dashboard → Settings → Export.
• Right to rectification: update your information from Dashboard → Settings.
• Right to erasure: complete deletion from Dashboard → Settings → Delete my account. Processed immediately.
• Right to data portability: CSV export available self-service.
• Right to object: for legitimate interest processing (technical logs), contact support@clear-loads.com.
• Right to restriction: available on request at support@clear-loads.com.
To exercise rights: support@clear-loads.com — response time: 30 days maximum (legal deadline).
You may lodge a complaint with your national supervisory authority (CNIL in France, CAI in Quebec, ICO in the UK).
10. Minors
ClearLoads is for persons aged 16 or older (or the minimum legal age in your country). ClearLoads does not knowingly collect data from minors. If you believe a minor has provided us data, contact support@clear-loads.com for immediate deletion.
11. Policy Changes
ClearLoads may update this policy. For substantial changes affecting your rights, you will be notified by email with 30 days' notice. The current version is always available at clear-loads.com/en/privacy.
12. Contact and Complaints
Privacy questions:
Email: support@clear-loads.com
Response within 24h (business days), 48h (weekends)
For GDPR rights requests: 30-day legal deadline.
Supervisory authorities:
• UK: ICO — ico.org.uk
• Quebec: CAI — cai.gouv.qc.ca
• EU: edpb.europa.eu
⚕️ ClearLoads is a wellness tool — not a medical device. In crisis, contact 988 (US/Canada), 116 123 (Samaritans UK), or your local emergency line.