Glitching logo

Privacy Policy

(Effective April 30, 2025)

Welcome!

Welcome to Glitching! We hope you will enjoy and appreciate using our “Platform”, which includes: (i) visiting or using the Website at https://www.glitching.ai (the “Website” which includes all subpages and subdomains); (ii) the Glitching online “Application” available at https://www.glitching.ai/dashboard where you can access your “Account” if you have signed up for a “Subscription” to help set up and manage your AI-powered Ecommerce store (your “Online Store”) and related functions; and (iii) various other online services offered by Glitching.

SSTL Technologie Inc., the company that owns and operates Glitching and the Platform, want you to know we take your privacy and protection of personal data very seriously. We are providing this Privacy Policy (the “Policy”) to tell you about who we are, what personal data we collect from you and about you, and what we do with your personal data, all while you use the Platform or otherwise interact with us. The Policy also explains your rights under the law, and how you can contact us and the necessary authorities to enforce those rights. We ask that you please read it carefully.

Key Elements / Summary of this Policy

Here are the key elements of this Policy so you can know the important parts right away to make an informed decision about your consent for our collection, use and disclosure of your personal data. By submitting any personal data to us via any means, you consent to such collection, use and disclosure. You can find the details in the rest of the Policy.

Personal data we collect from you but only with your consentWhat we do with itThird parties we share it with
Contact Information (your email address)Respond to your inquiryCompanies that provide email services
Promotion Information (your email address)Send you promotional emailsCompanies that provide communications services such as Klaviyo
Subscription Information (your email address, country and postal / zip code, and optionally your phone number)Manage your Account, check for fraud, communicate with you about the Platform, and enable logging in to your AccountCompanies that provide the infrastructure and software for the Platform, such as Vercel, and communications services
Billing Information (credit card information)Process the payments for your Subscription Fees or CreditsPayment processors such as Paddle

Some Terms and Definitions

Before we get started with the details, here are a few terms we think you should know as you read this Policy.

“Data Protection Laws” refers to the laws that are designed to protect your personal data and privacy in the place where you live. These include the following:

  1. The “GDPR”, the European Data Protection Law which stands for “General Data Protection Regulation”, with the official name Regulation (EU) 2016/679 of the European Parliament and of the Council;
  2. The “UK GDPR” which applies to our activities in the United Kingdom; please note that when this Policy refers only to the “GDPR”, this includes the UK GDPR, as applicable;
  3. “PIPEDA” (Personal Information Protection and Electronic Documents Act), which is the Canadian Data Protection Law that applies to our activities in Canada;
  4. Quebec’s Act Respecting the Protection of Personal Information in the Private Sector as amended by Law 25 (the “Quebec Private Sector Act”), which applies to our activities in Quebec;
  5. The California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act which applies to our activities in the United States in certain circumstances; and
  6. Other state privacy laws in force in the United States, such as those which are currently in force in Colorado, Connecticut, and Virginia.

“Personal data” – this is information we collect from you or about you and which is defined in the GDPR as “any information relating to an identified or identifiable natural person.” It can be as simple as your name or your email, or something more complicated like an online identifier (usually a string of letters and / or numbers) that gets attached to you. Under PIPEDA and the Quebec Private Sector Act, the equivalent concept is “personal information”, which is roughly the same. Any mention of “personal data” in this Policy shall also mean personal information.

Other terms and definitions used in this Policy may be found in our Terms of Use, and will have the same meaning in this Policy as they do there.

About Us and Contacting Us

SSTL Technologie Inc. is a duly-incorporated company in the Province of Quebec, Canada that owns and operates the Platform and the “Glitching” name and trademarks. Where this Policy refers to “Glitching”, it may refer to SSTL Technologie Inc. and / or its affiliates, and their shareholders, officers, directors, employees, agents, partners, principals, representatives, successors and assigns, depending on the context.

Under the GDPR, SSTL Technologie Inc.is a “data controller”. That means we collect personal data directly from you and determine the purpose and means of “processing” that data. “Processing” is a broad term that means collection, use, storage, transfer or any other action related to your personal data; it is used in this Policy in that way. Under PIPEDA, SSTL Technologie Inc. is an “organization”, and under the Quebec Private Sector Act, SSTL Technologie Inc. is an “enterprise”. Under PIPEDA, SSTL Technologie Inc. “collects, uses, and discloses” your personal data, and under the Quebec Private Sector Act, SSTL Technologie Inc. “collects, holds, uses or communicates to third persons” your personal data. When you read “processing” in this Policy, you can substitute either of those phrases.

If you want to ask us anything about what’s in this Policy, or anything else privacy- or data- related, or exercise any of your available privacy rights, you can email:

Samuel Di quinzio, Glitching Privacy and Data Protection Officer
privacy@glitching.ai

Here is the mailing address for you as well:

Glitching Privacy and Data Protection Officer
12655 69e Avenue (R.-d.-P.)
Montréal, Québec
Canada
H1C 1L5

Your Rights

You have the following rights regarding your personal data held by Glitching, and other privacy rights. Please note that not necessarily all of these rights may be available to you; this depends on the Data Protection Laws where you are located that apply to you. These rights may be exercised without affecting the price you pay for any of the Platform. Notwithstanding that, exercising certain of these rights may affect your ability to use some or all of the Platform.

If you wish to exercise any of these rights, please contact our Privacy and Data Protection Officer at the contact information above, or refer to certain relevant sections further in this Policy.

Personal Data Collected from You and What We Use It For

In the table below, please find all the personal data we may collect from you directly, what we use it for, and the legal basis under the GDPR for us having and processing this personal data. Under PIPEDA, the Quebec Private Sector Act, and the American Data Protection Laws, the legal basis is your informed consent, and by submitting this personal data you acknowledge having granted this consent to Glitching.

Personal data categoryPersonal data processedWhat we use it for (the “purpose” of processing)Legal basis for processing under the GDPR
Contact InformationEmail addressRespond to your inquiry when you fill out a contact form on the WebsiteYour consent in giving us this information
Promotion InformationEmail addressSend you our promotional emailsYour consent in giving us this information, or performance of a contract between you and us
Subscription InformationEmail address, country and postal / zip code, and optionally your phone numberManage your Account, check for fraud, communicate with you about the Platform, and enable logging in to your AccountYour consent and performance of a contract between you and us
Billing Information*Credit card number, credit card expiry date, card security code (CVV), and possibly billing addressProcess the payments for your Subscription Fees or CreditsYour consent in giving us this information

*Please note that your Billing Information is collected via the Website, but is only ever stored on servers controlled by Third-Party Payment Processors; Glitching does not have access to your Billing Information. Please refer to the Terms of Use for more information.

Where you have provided personal data by your consent, if withdraw your consent to use such data, we will no longer be able to provide the Platform (or certain portions of it) to you.

Personal Data Collected About You from Third Parties and What We Use It For

We generally do not get personal data about you from third parties. Exceptionally, to the extent that advertising and analytics identifiers are generated from third parties, these may be considered personal data collected from third parties, and you can find details about that further below in this Policy.

Sensitive Personal Data

We do not collect any of what the GDPR or the Quebec Private Sector Act considers sensitive personal data from you, unless you voluntarily submit it to us, which we encourage you not to do.

Who We Transfer Your Personal Data To

We routinely share some of your personal data with certain types of third parties who are identified in the table below along with what they do with it. Some of those third-party recipients may be based outside your home jurisdiction. If you are in the European Economic Area or the U.K., please see the “Transfer of Your Personal Data Outside of the European Economic Area” further down in this Policy for more information including on how we safeguard your personal data when this occurs. If you are in Quebec, please see the “Transfer of Your Personal Data Outside of Quebec” section further down in this Policy for information on how we safeguard your personal data when this occurs.

We will share personal data with law enforcement or other public authorities if: (1) we are required by applicable law in response to lawful requests, including to meet national security or law enforcement requirements; (2) if we believe it is necessary in order to investigate, prevent, or take action regarding illegal activities, fraud, or situations involving potential threats to the safety of any person, or any violation of Glitching’s Terms of Use; or (3) if we believe it is necessary to investigate, prevent, or take action regarding situations that involve abuse of the Platform infrastructure or the Internet in general (such as voluminous spamming or denial of service attacks).

We may also share personal data: (1) to a parent company, subsidiaries, joint ventures, or other companies under common control with Glitching (in which case we will require such entities to honour this Policy); or (2) if Glitching merges with another entity, is subject to a corporate reorganization, sells or transfers all or part of its business, assets or shares (in which case we will require such entity to assume our obligations under this Policy, or inform you that you are covered by a new privacy policy).

We will never share your personal data with other third parties except under these circumstances. We do not sell or rent your personal data to any third party for direct marketing purposes or any other purpose.

Personal data categoryWho we transfer it toWhat they do with it
Contact informationCompanies that provide email services such as MicrosoftHelp us to send you a reply to your inquiry
Promotion informationCompanies that provide communications services such as Klaviyo, as detailed more fully in the Email Communications section belowStore it and send you promotional emails
Subscription InformationCompanies providing technical infrastructure and software for the Platform, such as Google Firebase and VercelControl your logging in to your Account so you can access the Application
Billing InformationPayment processing companies, such as PaddleProcess the payments of your Subscription Fees and Credits
Advertising identifiersCompanies providing online advertising and advertising trackingShow you ads for Glitching and the Platform when you are on the internet and provide us with information about our ads, as further detailed in the Glitching Advertising section below
Analytics identifiers and IP addressesCompanies that provide data analytics, such as Google AnalyticsProvide us with analytics as to how the Platform is used, and to trace fraudulent activities, as further detailed in the Limited Gathering of Information section below

Email Communications and Compliance with Anti-Spam Laws

Glitching uses Klaviyo to manage our mailing list and send out promotional emails. We also send out emails related to various Platform functions, including via Paddle (Klaviyo and Paddle, the “Email Service Providers”). Personal data is transferred to the Email Service Providers in order to manage the mailing list and for the emails to be sent out properly. Your Promotion Information and Subscription Information is only used to send out emails; the Email Service Providers do not use this personal data for any other purpose, and will not transfer or sell your personal data to any other third party. For more information about how Klaviyo treats your persona data, please refer to Klaviyo's Data Processing Agreement.

You may unsubscribe from Glitching’s mailing list at any time, by following the link at the bottom of those Glitching emails. Other types of emails, such as transactional, relational, and other emails related to certain Platform functions will not have an opt-out option as they are necessary for the use of the Platform.

Glitching’s practices in regards to its email are designed to be compliant with anti-spam laws, specifically the law unofficially called “CASL”, or Canada’s Anti-Spam Law (S.C. 2010, c. 23), and the American CAN-SPAM Act. If you believe you have received email in violation of these laws, please contact us using the contact information further up in this Policy.

SMS Communications

If you opt-in to receive SMS communications from Glitching, we collect and process the following information:

We use this information to:

You can opt-out of receiving SMS communications at any time by texting STOP to our designated number or by contacting us at support@glitching.ai. Standard message and data rates may apply for SMS services.

We do not share your mobile phone number or SMS content with third parties for their marketing purposes. However, we may share this information with service providers who assist us in delivering SMS communications.

Glitching Advertising and Opting Out

Glitching is continuously evaluating and modifying our use of various advertising networks, which may change from time to time. In this section you will find all the advertising networks that Glitching currently uses and instructions for opting out of them. You may also opt out or decline such advertising by refusing or deleting the appropriate cookie, as described further in this Policy. For a more permanent solution, you may also opt out of such advertising by using the NAI (Network Advertising Initiative) online opt-out tool.

Generally, these ad networks work by delivering you advertisements that will be of particular interest to you when you use their website and / or apps, based on your browsing and activity history interacting with the Platform.

The table below identifies the advertising networks we currently use, as well as links and instructions on opting out. By visiting the Website or using the Platform and accepting the appropriate cookie through our cookie banner, you consent to our advertising to you in this manner, understanding that generally you can opt out any time.

Advertising networkLink(s) and instructions to opt out
Google AdWords and Display NetworkAdjust your Google ad settings or use the WebChoices online opt-out tool.
Facebook AdsAdjust your Facebook Ad Preferences settings while logged in.
Instagram AdsAdjust settings within the Instagram app or via your linked Instagram Ad Preferences.
TikTok AdsPlease note you cannot opt out of TikTok Ads without resorting to ad blocker software. However, you can control certain privacy settings related to TikTok Ads by following their instructions.

Finally, Glitching uses the third-party advertising tracking software Hyros and AnyTrack in order to track effectiveness of our advertising. You are only identifiable to them by alphanumeric string, but if you want to not be tracked in this way, you can refuse the cookie in the cookie pop up or delete the appropriate cookie as described below.

Limited Gathering of Information for Statistical, Analytical and Security Purposes

Glitching automatically collects certain information using the “Third-Party Analytics Programs” Google Analytics and PostHog, to help us understand more about our Website visitors and Platform users and how they use the Platform, but none of this information identifies you personally, except via an alphanumeric string and as described in the next paragraph. For example, each time you visit the Website, we automatically collect (as applicable) your IP address, browser and computer or device type, access times, the web page from which you came, the web page(s) or content you access, and other related information. We use information collected in this manner only to better understand your needs and the needs of Website visitors and Platform users in the aggregate. Glitching also makes use of information gathered for statistical purposes to keep track of the number of visits to the Platform, the specific pages on the Platform, and users with a view to introducing improvements to the Platform and our marketing activities.

In addition, PostHog provides us with additional information about how users who have Accounts interact with the Platform. To that end, we transfer your Subscription Information (your email address) to PostHog so that we can measure certain aspects of the Platform and our users. If you want to not be tracked in this way, you can refuse the cookie in the cookie pop up or delete the appropriate cookie as described below.

Your IP address and other relevant information we collect using the Third-Party Analytics Programs may be used in order to trace any fraudulent or criminal activity, or any activity in violation of the Glitching Terms of Use.

Tracking Technology (“Cookies” and Related Technologies)

Glitching uses tracking technology (“cookies” and related technology such as tags, pixels and web beacons) in the Platform and by interacting with the Platform you agree to their use. Cookies are small text files placed on your computer or device when you visit a website or use an online service, in order to track use of the website or service and to improve the user experience by storing certain data on your computer or device. By default, all non-necessary cookies are turned off when you first visit the Website; you can use our cookie management tool in the cookie banner presented to you to accept or decline categories of cookies.

Specifically, we use cookies and related technologies for the following functions:

Your browser can be set to refuse cookies or delete them after they have been stored. You can refer to your browser’s help section for instructions, but here are instructions for the most commonly-used browsers and operating systems:

Please note that deleting or blocking certain cookies may reduce your user experience by requiring you to re-enter certain information, including information required to use the Platform. Furthermore, deleting certain necessary cookies may prevent certain functions, or the entirety of the Platform, from working at all.

How We Protect Your Personal Data

We have implemented very strict technical and organisational procedures for ensuring that, by default, only the personal data which is necessary for each specific purpose of the processing are processed by us. These procedures prevent your personal data from being lost; or used or accessed in any unauthorised way.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory authority of a suspected data security breach where the Data Protection Laws requires us to do so, and within the time frame required by the applicable Data Protection Law.

Glitching uses only industry best practices (physical, electronic and procedural) in keeping any data collected (including personal data) secure. In addition, we use third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to operate the Platform, and these third parties have been selected for their high standards of security, both electronic and physical. For example, Glitching uses Google’s Firebase and Vercel, recognized leaders in secure data, for hosting of the Platform and related data, and storage of data including personal data.

All information, including personal data, is transferred with encryption using Secure Sockets Layer (“SSL”) or Transport Layer Security (“TLS”), robust security standards for Internet data transfer and transactions. You can use your browser to check Glitching’s valid SSL security certificates on the Website.

Our Third-Party Payment Processor, Paddle, is PCI DSS v4.0.0-compliant, ensuring that your Billing Information is secure.

Internal Procedures and Policies

In addition to the measures to protect your personal data described in the previous section, we have drafted and implemented certain internal procedures and policies regarding personal data, including the following:

  1. A framework for the keeping and destruction of the personal data, including where we may keep anonymized data;
  2. Defining and describing the roles and responsibilities of the members of Glitching personnel throughout the life cycle of the personal data;
  3. A process for dealing with individual complaints and requests for personal data and exercising of the individual’s rights under Data Protection Laws;
  4. A management and IT policy and procedure for addressing potential data breach incidents involving personal data in the custody of Glitching.

Transfer of Your Personal Data Outside of the European Economic Area (EEA) and the U.K.

For our European users, we endeavour to keep your personal data inside the EEA or the U.K. (as applicable). However, certain of our data processors (and Glitching) are in other countries where your personal data may be transferred. However, these countries are limited to countries with particular circumstances that protect your data, specifically:

That’s it! You have the right, however, to refuse to have your data transferred outside the EEA. Please contact our Privacy and Data Protection Officer to make that request. Please note that making this request may prevent you from being able to use a portion or all of the Platform.

Transfer of Your Personal Data Outside of Quebec

For our Quebec users and visitors, we endeavour to keep your personal data in Quebec. However, certain of our third-party service providers are in other provinces or countries where your personal data may be transferred. When this happens, we do the following to safeguard your personal data:

  1. We will perform what the Quebec Private Sector Act calls an “Assessment of the privacy-related factors” (what is generally called a “Privacy Impact Assessment,” or “PIA”) prior to the personal data leaving Quebec. If the PIA does not meet our standards and the standards required by the Quebec Private Sector Act, we will not transfer your personal data to such a service provider; and
  2. If the PIA allows us to transfer the personal data to such a service provider outside Quebec, we will sign what is generally called a “Data Processing Agreement,” or DPA, with the service provider, which protects the person data transferred to them and limits their use of it to what we have contracted with them to do. This DPA will adhere to the requirements of the Quebec Private Sector Act.

Supervisory Authorities and Complaints

If you are in the EEA or the U.K, under the GDPR you have the right to make a complaint to the appropriate supervisory authority. If you are not satisfied with the response received or the actions taken by our Privacy Officer, or if you would like to make a complaint directly about Glitching’s data practises, we invite you to contact the supervisory authority in your country. For example, if you are in the U.K., you should contact the Information Commissioner’s Office who is the supervisory authority. You can reach them in a variety of ways, including by phone (0303 123 1113 in the UK) and mail (Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF). If you are in France, you should contact the Commission Nationale de l'Informatique et des Libertés who is the supervisory authority there. Their contact information can be found here.

The full listing of all Data Protection Authorities (the supervisory authorities) across the EEA can be found here.

If you are in Canada, you can make a complaint to the Office of the Privacy Commissioner here. If you are in Québec, you can make a complaint to the Commission d’accès à l’information, with the instructions for contacting them on their website.

Data Retention

Your personal data will only be kept for as long as it is necessary for the purpose needed for that processing. For example, we will only retain your Subscription Information for as long as you have a Subscription with us.

We may have to keep your data for a longer period of time to satisfy our requirements under any applicable law, including anti-spam laws, or to protect our legal interests.

In some cases, where permitted by the Data Protection Laws, we may keep personal data that has been anonymized, for our legitimate business purposes.

Children’s Privacy Statement

The Platform is only intended for persons who are 18 years old for a resident of a Canadian province or the age of majority in any other country.

The Data Protection Laws have various age limits as to the minimum age required for us to hold personal data about an individual. We do not knowingly collect any personal data from a child under those minimum ages. If we become aware that we have inadvertently received personal data from a person under the minimum ages through the Platform, we will delete such information from our records.

Changes to This Privacy Policy

The date at the top of this page indicates when this Policy was last updated. Every now and then, we will have to update this Policy, and we will update it no less than once every 12 months. You can always find the most updated version at this URL, and we will always post a notice on the Platform if we make significant changes. If you have a Glitching Account, we will also email you to tell you the Policy has been updated, and what the important changes are.


Thanks for reading! Please keep your personal data safe; we promise to do the same.

© SSTL Technologie Inc. 2025

GLITCHING