← Back to smallreads

Privacy Policy

Last updated: March 20, 2026

1. Introduction

smallreads ("we", "us", or "our") operates the website smallreads.ca. This Privacy Policy explains how we collect, use, disclose, and protect your personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.

By using smallreads, you consent to the practices described in this policy. If you do not agree, please do not use our service.

2. Information We Collect

We may collect the following types of personal information:

  • Account information: Your email address and display name when you create an account.
  • Profile information: Display name, bio, and reading preferences you choose to provide. Avatars are randomly generated and not collected from you.
  • Usage data: Books you track, ratings, reviews, and reading activity within the app.
  • Authentication data: Information from third-party sign-in providers (e.g. Google) that you use to log in, limited to your email and basic profile.
  • Technical data: Essential cookies required for authentication and session management.

3. How We Use Your Information

We use your personal information to:

  • Provide, maintain, and improve the smallreads service.
  • Authenticate your identity and manage your account.
  • Enable social features such as sharing reading activity with friends.
  • Send transactional emails (e.g. magic link sign-in, account notifications).
  • Respond to your inquiries and support requests.

We do not sell your personal information to third parties.

4. Analytics

We may use privacy-friendly analytics tools (such as Umami) to collect anonymized, aggregate usage metrics. These tools do not use cookies, do not collect personally identifiable information, and do not track you across websites. This data helps us understand how the service is used so we can improve it.

5. Cookies

smallreads uses only essential cookies required for authentication and session management. We do not use advertising, tracking, or non-essential cookies. Because we only use strictly necessary cookies, no cookie consent banner is required.

6. Cross-Border Data Transfers

smallreads is operated from Canada. However, some of our hosting infrastructure and service providers are located in the United States (US West region). This means your personal information may be transferred to, stored, and processed in the United States.

When your data is stored or processed outside of Canada, it may be subject to the laws of that jurisdiction, including lawful access requests by US law enforcement or government agencies. We take steps to ensure that any third-party service providers handling your data are contractually obligated to protect it with safeguards comparable to those required under Canadian privacy law.

7. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with our services. If you delete your account, we will delete or anonymize your personal information within a reasonable timeframe, except where we are required to retain it by law.

8. Your Rights

Under PIPEDA, you have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of your personal information.
  • Withdraw your consent to our collection or use of your information.

To exercise any of these rights, please contact us at the address below.

9. Data Security

We implement reasonable technical and organizational safeguards to protect your personal information, including encryption in transit (TLS) and at rest, access controls, and secure authentication practices. However, no method of transmission or storage is 100% secure.

10. Data Breach Notification

In the event of a data breach that poses a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required under PIPEDA's breach notification requirements.

11. Third-Party Services

We may use third-party services for authentication (e.g. Google Sign-In), hosting, and email delivery. These providers only receive the minimum information necessary to perform their services and are bound by their own privacy policies.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of smallreads after changes are posted constitutes acceptance of the revised policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:

Email: d@velunny.com