Privacy Policy
Last updated: March 4, 2026
Hills Collectibles (“Company,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable Canadian privacy laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website at www.hillscollectibles.com (the “Website”), make purchases, or interact with our services.
By using the Website or providing personal information to us, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree with this policy, please do not use our Website or services.
We operate from the Greater Toronto Area (GTA), Canada, and this policy applies to all users, including international visitors. However, if you are accessing the Website from outside Canada, you are responsible for compliance with local laws.
Accountability
We are responsible for the personal information under our control. We have designated a Privacy Officer to oversee our compliance with PIPEDA and handle privacy-related inquiries. Contact details are provided at the end of this policy.
Information We Collect
We collect personal information only when necessary and with your consent, limiting it to what is required for the purposes identified below.
Personal Information You Provide (Voluntarily)
- Contact details: Name, email address, phone number, shipping/billing address.
- Payment information: Credit card details, processed securely via third-party providers (we do not store full card numbers).
- Account information: Username, password (hashed), and preferences if you create an account.
- Communication data: Inquiries, feedback, or messages sent via contact forms or email.
- Transaction details: Purchase history, order preferences, and consignment information (e.g., for estate items).
Automatically Collected Information
- Device and usage data: IP address, browser type/version, operating system, pages visited, time/date of visit, time spent on pages, referral sources, and error logs.
- Cookies and tracking: We use cookies, web beacons, and similar technologies for analytics, session management, and personalized content. See our Cookies section below.
- Log data: Server logs for security and performance monitoring.
We do not collect sensitive personal information (e.g., health data, racial origin) unless voluntarily provided and directly relevant (e.g., for custom requests).
How We Collect Information
- Directly from you: During registration, checkout, inquiries, or newsletter sign-ups.
- Automatically: Via cookies, analytics tools (e.g., Google Analytics), and server logs.
- From third parties: Payment processors, shipping carriers, or analytics providers, only as needed for services.
Purposes for Collecting and Using Your Information
We identify the purposes for collecting personal information at or before the time of collection. We use your information for:
- Processing orders, payments, and shipments.
- Managing your account and providing customer support.
- Communicating with you about orders, updates, or promotions (with opt-out options).
- Improving our Website and services through analytics and market research.
- Preventing fraud, ensuring security, and complying with legal obligations.
- Marketing (e.g., newsletters), only with your explicit consent.
We limit collection to what is necessary and will not use your information for incompatible purposes without additional consent.
Disclosure of Your Personal Information
We do not sell or rent your personal information. We may disclose it to:
- Third-party service providers: Payment processors (e.g., Stripe), shipping carriers (e.g., Canada Post, UPS), analytics tools (e.g., Google), and IT/hosting providers, solely for operational purposes.
- Affiliates or partners: For joint services, under strict confidentiality agreements.
- Legal authorities: If required by law, court order, or to protect our rights, property, or safety.
- Business transfers: In the event of a merger, acquisition, or sale of assets, where the acquirer agrees to adhere to this policy.
All disclosures are limited to what is necessary and comply with PIPEDA.
International Transfers
Your information may be stored or processed outside Canada (e.g., on secure cloud servers in the US). We ensure such transfers meet PIPEDA requirements through contracts that provide comparable protection levels. By using our services, you consent to these transfers.
Security of Your Personal Information
We implement reasonable safeguards to protect your information from unauthorized access, loss, theft, or misuse, including encryption, firewalls, access controls, and secure servers. Payment data is handled via PCI DSS-compliant processors.
However, no method is 100% secure. We cannot guarantee absolute security and disclaim liability for breaches beyond our control. You are responsible for maintaining the confidentiality of your account credentials.
Retention of Your Personal Information
We retain personal information only as long as necessary for the identified purposes, legal requirements, or dispute resolution (e.g., 7 years for tax records). When no longer needed, we securely delete or anonymize it.
Cookies and Tracking Technologies
We use cookies for essential functions (e.g., session management), performance (e.g., analytics), and marketing (e.g., targeted ads). Types include:
- Essential cookies: Necessary for Website functionality.
- Analytics cookies: To understand usage patterns.
- Marketing cookies: For personalized content, with consent.
You can manage cookies via browser settings, but disabling them may limit functionality. For details, review our Cookie Policy (if separate) or contact us.
Children’s Privacy
Our Website and services are not intended for children under 18. We do not knowingly collect information from minors. If we discover such data, we will delete it promptly.
Your Rights Under PIPEDA
You have the right to:
- Access: Request a copy of your personal information (may require a $300 fee; respond within 30 days).
- Correction: Update inaccurate or incomplete information (provide evidence; we will amend or note disputes).
- Withdraw Consent: Opt out of non-essential uses (e.g., marketing) at any time, though this may limit services. Essential data (e.g., for orders) cannot be withdrawn if it prevents fulfillment.
- Complaints: If you believe we’ve violated PIPEDA, contact our Privacy Officer. You may also complain to the Office of the Privacy Commissioner of Canada (OPC).
To exercise rights, contact us with verification. We may deny requests if legally required (e.g., fraud prevention).
Changes to This Privacy Policy
We may update this policy to reflect changes in practices or laws. We will post revisions here and notify you via email or Website notice for significant changes. Continued use constitutes acceptance.
Contact Us
For questions, requests, or complaints, contact our Privacy Officer:
Hills Collectibles Email: info@hillscollectibles.com
We comply with PIPEDA’s 10 fair information principles: Accountability, Identifying Purposes, Consent, Limiting Collection, Limiting Use/Disclosure/Retention, Accuracy, Safeguards, Openness, Individual Access, and Challenging Compliance.

