Privacy Policy
Roller Avenue - Level Up Mobile App
- We collect only what's needed to manage your account, your payments and your visits to our venues.
- Payments are processed by Clover; we never see or store your full card number.
- We don't sell your information, and we send no marketing without your explicit consent.
- You can access, correct, port or delete your information at any time by writing to the Privacy Officer below.
- Some of our providers are based in the United States (notably Clover and Sentry) — we have completed the privacy impact assessment required by Quebec's Law 25 (section 17).
This policy explains all of this in detail, in accordance with Quebec's Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1, "Law 25"). It applies to the services offered by Avenue du Patin Inc. ("we"), including the Roller Avenue and Level Up Games banners, the website www.rolleravenue.com (the "Website") and the mobile application Roller Avenue & Level Up Games (the "App").
1. Information we collect
We collect only the information needed for the purposes described in section 2.
Information you provide:
-
Identification: first name, last name, date of birth (where applicable).
-
Contact details: email, phone number, mailing address.
-
Account: username, password (hashed — never stored in plaintext), communication preferences.
-
Profile photo (optional): linked to your digital membership card to make in-venue identification easier.
-
Membership: subscription type, status, transaction history, member QR code.
-
Communications you send us (email, in-app message, contact form).
Payment information: When you pay, your card number is entered directly with Clover through a secure page. We never receive the full number or security code; we only receive a transaction identifier and, where applicable, the last four digits and the brand of the card.
Information automatically collected by the App:
-
Technical data: device model, OS version, language.
-
Usage data: features used, dates and times of access, IP address.
-
Crash data sent to Sentry when an error occurs (stack trace, screen state, internal user ID — never your password or payment data).
-
Authentication tokens stored in your device's secure enclave (iOS Keychain / Android Keystore), encrypted by the operating system.
Information collected on the Website: cookies, IP address, browser. The Website may embed third-party e-commerce widgets (for example for ticketing); those widgets are governed by their own privacy policies, which we encourage you to review before any purchase.
Information collected on premises: video surveillance for safety (notice posted at the entrance), registrations and contact details in case of an incident.
Minors: For children under 14, we collect information from the parent or legal guardian. We do not create a standalone App account for children under 14.
2. Why we use your information
We use your personal information only to:
-
Create and manage your account and membership (performance of the contract).
-
Process payments and provide receipts (performance of the contract).
-
Identify you at the counter via the QR code (performance of the contract).
-
Provide customer support (legitimate interest).
-
Detect and fix App and Website failures (legitimate interest).
-
Prevent fraud and secure our services (legitimate interest / legal obligation).
-
Send operational communications (service changes, membership expiry).
-
Send marketing communications — only with your consent, revocable at any time.
-
Comply with legal obligations (accounting, tax, government requests).
-
Improve our services through aggregated and anonymized analytics.
We do not make automated decisions that produce legal effects on you. If we ever do, we will inform you and offer the recourses provided by Law 25.
Consent: Where the law requires consent, we obtain it in a manner that is manifest, free, informed and given for specific purposes. You may withdraw it at any time; withdrawal does not affect the validity of prior processing or legal obligations we must continue to honour.
3. Sharing with third parties and transfers outside Quebec
We do not sell or rent your personal information. We share it only with the following categories of third parties, only to the extent necessary:
-
Payment processor: Clover / Fiserv (Canada and United States) — payment data (never received by us), amount, transaction ID.
-
Technical monitoring: Sentry / Functional Software (United States) — technical data, stack traces.
-
App stores: Apple (United States) and Google (United States) — App distribution.
-
Cloud hosting: Vercel (primarily United States) — account data, logs.
-
Website hosting: Wix (United States) — browsing data, contact forms.
-
Professional advisors (lawyers, accountants) in Quebec, as needed.
-
Public authorities in response to a legal obligation (warrant, order, lawful request).
The Website may also embed third-party e-commerce widgets (for example for ticketing). These widgets are governed by their own privacy policies; the information you enter into them is sent directly to the relevant providers and not to us.
Transfers outside Quebec: Several providers are located outside Quebec, in particular in the United States. Before such communications, we have completed a Privacy Impact Assessment in accordance with section 17 of Law 25, taking into account the sensitivity of the information, the purposes, the contractual and technical safeguards (encryption, access controls, providers' SOC 2 / ISO 27001 certifications) and the legal framework of the destination state. A written agreement with each recipient governs these transfers. Documentation may be provided to the Commission d'accès à l'information (CAI) on request, and to you by writing to the Privacy Officer below.
4. How long we keep your information
We retain your information only as long as necessary for the relevant purpose, or as required by law:
-
Active account: while the account is active.
-
Inactive account (no login or membership): up to 24 months, then anonymized or destroyed.
-
Payment data and invoices: 6 years after the end of the relevant fiscal year (federal and provincial tax requirement).
-
Sentry crash reports: 90 days, then automatically deleted.
-
Connection logs and IP addresses: 12 months.
-
Customer support communications: up to 24 months after resolution.
-
Video surveillance: up to 30 days, except for documented active incidents.
When information is no longer required, we destroy or anonymize it securely.
5. How we protect your information
We apply reasonable physical, organizational and technological security measures proportionate to the sensitivity of the information, including:
-
encryption in transit (TLS 1.2+);
-
encryption of authentication tokens at rest on the mobile device;
-
password hashing (passwords are never stored in plaintext);
-
role-based access controls and the principle of least privilege;
-
access logging and anomaly monitoring;
-
staff training and a confidentiality agreement with every provider that has access to data.
No system is foolproof. In the event of a confidentiality incident that creates a risk of serious injury, we will notify the CAI and affected individuals without delay, in accordance with section 3.5 of Law 25, and maintain an incident register for five years.
6. Your rights
Subject to legal exceptions, you have the right to:
-
access the information we hold about you and learn how it is used;
-
have any inaccurate, incomplete or ambiguous information corrected;
-
withdraw your consent to processing that depends on it;
-
request the cessation of dissemination, de-indexing or re-indexing of a hyperlink (Law 25 s. 28.1);
-
request the portability of your information in a structured and commonly used format (Law 25 s. 27);
-
request the deletion of your account and associated information (except where we are required by law to retain it);
-
file a complaint with our Privacy Officer, and then with the CAI.
To exercise any of these rights, write to the Privacy Officer below. We will respond within 30 days. No fees apply, except for transcription, reproduction or transmission, in which case we will inform you in advance.
You may at any time complain to the Commission d'accès à l'information du Québec: cai.gouv.qc.ca · 1 888 528-7741 · 525, boul. René-Lévesque Est, Suite 2.36, Québec (Québec) G1R 5S9.
7. Cookies and similar technologies
Our Website uses cookies for proper operation (essential cookies, always active), to remember your preferences (language, cart), to measure audience in aggregate, and — only with your prior consent — to display relevant commercial content. You can manage preferences via the consent banner or your browser settings.
The App does not use advertising cookies or cross-app tracking identifiers. As required by Law 25, the privacy settings offering the highest level of confidentiality are enabled by default.
Our services may contain links to third-party sites (social media, etc.). We are not responsible for the practices of these third parties; review their policies before providing them with information.
8. Changes to the policy and how to reach us
We may update this policy to reflect changes in our practices or in applicable law. For any material change, we will take reasonable steps to inform you (by email, in-App notice or banner on the Website) before it takes effect. The version in force is always the one posted on our Website with the most recent "Last updated" date.
Privacy Officer (Law 25, section 3.1):
-
Name: Jonathan Hamel
-
Title: Owner
-
Email: avenuedupatin@gmail.com
-
Mailing address: Avenue du Patin Inc., 7798 av. Rhéaume Montréal (Québec) H1K2S8 Canada
-
Phone: 514-803-9716
Any question, complaint or request concerning your personal information or this policy must be sent to this person.