About This Policy
This Privacy Policy describes how Project: Life (“we,” “us,” or “our”), collects, uses, and discloses information about you when you visit our website at www.getprojectlife.com (the “Site”), purchase our products, subscribe to our services, complete our product matching questionnaire, or otherwise interact with us.
Project: Life offers monthly subscription TCM herbal formulations for fertility wellness, matched to your individual profile through an online assessment. We serve clients in the United States and Canada. This Privacy Policy applies specifically to clients located in the United States and is written to comply with applicable US federal and state privacy laws, including the California Consumer Privacy Act of 2018 and the California Privacy Rights Act of 2020 (collectively, “CCPA/CPRA”).
By accessing the Site or purchasing our products, you agree to this Privacy Policy. If you do not agree, please discontinue use of the Site. This policy does not apply to information collected offline or through any third-party websites or applications that may link to or from the Site.
Questions about this policy? Contact us at support@getprojectlife.com or see the Contact section at the end of this document.
Children Under 18
The Site is not intended for children under 18 years of age. We do not knowingly collect personal information from anyone under 18. If you are under 18, do not use or provide any information on the Site.
If we learn that we have inadvertently collected personal information from a child under 18 without verification of parental consent, we will delete that information as quickly as practicable. If you believe we may have information from or about a child under 18, please contact us at support@getprojectlife.com.
What We Collect
We collect information in three ways: directly from you, automatically when you use the Site, and from third-party sources.
Information You Provide
Account and Registration
When you create an account or place an order, you provide your name, email address, phone number, billing address, and shipping address. We use this to fulfill your order, manage your subscription, and communicate with you.
The Assessment
To recommend an appropriate formulation, we ask you to complete a product matching questionnaire (the “Assessment”). The Assessment collects information about your wellness goals, cycle details, lifestyle factors, and product preferences. This information is used solely to match you with the most suitable formulation and to personalize your experience with Project: Life.
We do not use Assessment responses to diagnose, treat, cure, or prevent any condition, and we do not share identifiable Assessment responses with third parties for their independent use.
California residents: Certain Assessment responses may constitute “sensitive personal information” under CCPA/CPRA. See the California Privacy Rights section below for your related rights.
Orders and Transactions
When you make a purchase, we collect transaction details including products ordered, subscription tier, order amounts, and payment method. Payment card information is collected and processed directly by our payment processor — we do not store full card numbers on our systems.
Correspondence and Support
If you contact us by email, through a support form, or via our customer support platform, we collect the contents of your messages, your contact details, and a record of the interaction.
Surveys and Feedback
From time to time we may invite you to complete surveys or provide feedback about our products or your experience. Participation is voluntary.
Subscription Preferences
If you hold an active or paused subscription, we record your preferences regarding shipment timing, pause duration, cancellation reasons, and reactivation requests.
Information Collected Automatically
When you visit the Site, we and our service providers automatically collect certain information using cookies, web beacons, pixel tags, server logs, and similar technologies:
- Usage data — pages viewed, links clicked, time on page, referring URL, navigation paths
- Device and browser information — IP address, browser type, operating system, screen resolution
- Session data — visit date and time, session duration, unique device identifiers
- Transaction funnel data — steps completed or abandoned in checkout or Assessment flow
Information from Third Parties
We may receive information from third-party sources including:
- Advertising and analytics platforms providing aggregate audience and attribution data
- Our e-commerce platform provider, which processes transactions and provides order data
- Our subscription management provider, sharing subscription status and renewal information
- Customer support platforms forwarding correspondence and inquiry history
- Our product assessment platform, which routes questionnaire responses to our systems
Cookies and Tracking Technologies
Types of Cookies We Use
-
Essential: Strictly necessary cookies — required for the Site to function (shopping cart, login session)
-
Analytics: Used to measure Site performance and understand how visitors use the Site
-
Marketing: Used to deliver relevant advertising and measure ad effectiveness
You can control cookies through your browser settings. Disabling certain cookies may affect Site functionality. We honor browser-based Global Privacy Control (GPC) signals as described in the California Privacy Rights section.
Specific Tools We Use
Google Analytics 4
We use Google Analytics 4 to collect and analyze usage data. GA4 may collect your IP address (anonymized by default), session data, page interaction events, and e-commerce event data. To opt out of Google Analytics tracking, install the Google Analytics Opt-Out Browser Add-on at tools.google.com/dlpage/gaoptout.
Microsoft Clarity
We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our Site through behavioral metrics, heatmaps, and session replay. Site usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products and online activity. Additionally, we use this information for Site optimization, fraud and security purposes, and advertising. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement at privacy.microsoft.com.
First-Party Attribution
We use first-party attribution tools to understand which marketing channels lead to purchases. These tools use first-party cookies and server-side data to connect ad exposure to order activity without relying on third-party cross-site tracking.
Third-Party Tracking
Certain third parties may set cookies when you visit the Site, including our advertising platforms and analytics providers. These technologies may be used to measure ad effectiveness, retarget visitors with relevant ads, build aggregate audience profiles, and detect fraud.
To opt out of interest-based advertising from participating companies:
- Network Advertising Initiative: optout.networkadvertising.org
- Digital Advertising Alliance: optout.aboutads.info
Opting out of interest-based advertising does not mean you will stop seeing ads — it means ads will not be tailored to your inferred interests.
How We Use Your Information
We use the information we collect for the following purposes:
- Fulfilling and managing your orders and subscription, including processing payments, arranging shipment, and managing renewals, pauses, and cancellations
- Recommending the appropriate formulation based on your Assessment responses
- Communicating with you about your account, orders, subscription status, and product updates
- Sending marketing communications where you have provided consent or where applicable law permits
- Delivering SMS communications where you have opted in
- Analyzing Site usage and funnel performance to improve the Site and our products
- Serving and measuring targeted advertising campaigns on third-party platforms using hashed or anonymized identifiers where technically feasible
- Personalizing your experience on the Site
- Detecting, investigating, and preventing fraudulent transactions and unauthorized access
- Complying with legal obligations and enforcing our terms of service
We will not use your Assessment information for any purpose other than product matching and account personalization without your explicit consent.
Who We Share Your Information With
Service Providers
We share information with third-party vendors who perform functions on our behalf. All service providers are contractually prohibited from using your information for purposes other than performing services for us.
| Provider Category |
What They Do |
| E-commerce platform |
Hosts the Site and processes storefront transactions |
| Payment processors |
Process payment card and financial transactions securely |
| Email and SMS providers |
Send transactional and marketing communications on our behalf |
| Subscription management |
Manage billing cycles, pause and cancellation workflows |
| Product assessment platform |
Hosts and routes questionnaire responses to our matching systems |
| Customer support platform |
Manages support ticket intake, routing, and resolution |
| Analytics and performance |
Measures Site usage, session behavior, and conversion performance |
| Attribution and advertising |
Measures paid marketing effectiveness and assists with audience targeting |
| Cloud infrastructure |
Stores and processes operational data securely |
Aggregated Data
We do not sell or rent your personal information to third-party marketers. We may share aggregated, de-identified information with partners for research and analytics purposes, provided such information cannot reasonably be used to identify you.
Legal Disclosures
We may disclose your information if required by law or in good faith belief that disclosure is necessary to:
- Comply with a legal obligation, court order, or governmental request
- Protect and defend the rights or property of Project: Life
- Prevent or investigate possible wrongdoing in connection with the Site
- Protect the personal safety of users or the public
Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you if such a transfer occurs and your information becomes subject to a materially different privacy policy.
Your Choices
Marketing Emails
You may opt out of marketing emails by clicking the unsubscribe link in any marketing email or by contacting support@getprojectlife.com. You will continue to receive transactional messages related to your account and orders.
SMS Messages
You may opt out of SMS communications at any time by replying STOP to any message. You will receive a confirmation and no further SMS unless you re-enroll. For help, reply HELP or contact support@getprojectlife.com. Standard message and data rates may apply. Consent to receive SMS is not a condition of purchase.
Cookies and Tracking
Most browsers allow you to manage cookie preferences through settings. You can refuse cookies or set alerts when cookies are sent. Disabling cookies may affect some Site features. We honor the Global Privacy Control (GPC) browser signal as an opt-out of the sale and sharing of personal information.
Do Not Sell or Share My Personal Information
We do not sell your personal information for monetary consideration. However, we may share information — including identifiers and browsing activity — with advertising and analytics partners for cross-context behavioral advertising, which constitutes “sharing” under CCPA/CPRA.
You may opt out of this sharing at any time by:
- Clicking the “Do Not Sell or Share My Personal Information” link in the Site footer
- Emailing support@getprojectlife.com with the subject line “Do Not Sell or Share”
- Enabling the Global Privacy Control (GPC) signal in your browser
Targeted Advertising
You may request removal of your information from custom audiences on third-party platforms by contacting support@getprojectlife.com. Removal from a custom audience does not guarantee you will stop seeing our ads — it means your information will no longer be used to build or match that audience.
Accessing and Correcting Your Information
You have the right to know what personal information we hold about you and to request corrections to inaccurate or incomplete information.
You may submit an access or correction request by:
- Emailing support@getprojectlife.com with the subject line “Access Request” or “Correction Request”
We will verify your identity before processing your request by matching identifying information you provide against our records. We will respond within 45 days. If additional time is needed (up to 90 days total), we will notify you within the initial 45-day window.
Account holders may also review and update certain information by logging into their account on the Site.
Your California Privacy Rights
This section applies to California residents and supplements the rest of this Privacy Policy. It is provided in accordance with the California Consumer Privacy Act of 2018 and the California Privacy Rights Act of 2020 (together, “CCPA/CPRA”).
Categories of Personal Information Collected
In the twelve months prior to the Last Modified date above, we have collected the following categories of personal information:
| CCPA Category |
Examples |
Collected |
| Identifiers |
Name, email, phone, IP address, account username, device identifiers |
Yes |
| Personal information (Cal. Civ. Code § 1798.80(e)) |
Name, address, telephone, payment card information (partial, via processor) |
Yes |
| Commercial information |
Products purchased, subscription history, order amounts, transaction records |
Yes |
| Internet or electronic network activity |
Browsing history on the Site, search queries, ad interaction, session data |
Yes |
| Sensitive personal information |
Wellness assessment responses including cycle details and lifestyle information |
Yes |
| Inferences |
Formulation recommendations from Assessment responses; marketing segmentation |
Yes |
| Geolocation (general) |
Country and state derived from IP address; shipping address |
Yes |
Your Rights Under CCPA/CPRA
-
Right to Know. You have the right to request that we disclose the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties to whom we disclosed it.
-
Right to Delete. You have the right to request deletion of personal information we hold, subject to certain exceptions (e.g., legal obligations, security purposes).
-
Right to Correct. You have the right to request correction of inaccurate personal information.
-
Right to Opt Out of Sale/Sharing. You have the right to opt out of the sale and sharing of your personal information for cross-context behavioral advertising. See the Your Choices section above.
-
Right to Limit Use of SPI. You have the right to limit our use of sensitive personal information to uses necessary to provide the services you requested. We use SPI only for product matching and service delivery.
How to Submit a Request
You may submit a verifiable consumer request by emailing support@getprojectlife.com.
You may submit a request on your own behalf or through an authorized agent with written proof of authorization. We will verify your identity before processing and respond within 45 days (extendable to 90 days with notice).
Non-Discrimination
We will not discriminate against you for exercising your CCPA/CPRA rights. We will not deny goods or services, charge different prices, or provide a different level of service quality because you exercised a privacy right.
Shine the Light
California Civil Code Section 1798.83 permits California residents to request information about personal information disclosed to third parties for direct marketing purposes. To make such a request, email support@getprojectlife.com with the subject line “Shine the Light Request.”
Nevada Residents
Nevada Senate Bill 220 provides certain consumers the right to opt out of the sale of covered information. We do not currently sell covered information as defined under Nevada law. Questions: support@getprojectlife.com.
Data Security
We implement technical, administrative, and physical safeguards to protect your information from unauthorized access, use, alteration, or disclosure:
- SSL/TLS encryption for all data transmitted between your browser and the Site
- Encrypted storage of personal information on secure servers
- Role-based access controls limiting access to authorized personnel
- Regular security reviews and assessments
- Payment card data handled by PCI-DSS-compliant processors — we do not store full card numbers
No method of internet transmission or electronic storage is 100% secure. While we use commercially reasonable means to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify you and relevant authorities as required by law.
You are responsible for maintaining the confidentiality of any account password. Please notify us immediately at support@getprojectlife.com if you suspect unauthorized access to your account.
Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
| Data Category |
Retention Period |
| Active account information |
Duration of active account + 24 months after closure |
| Transaction and order records |
As required by law — typically 7 years for financial records |
| Assessment responses |
24 months from last interaction, then anonymized or deleted |
| Marketing profiles |
Suppressed 36 months after last engagement, then deleted or anonymized |
| Support correspondence |
24 months after resolution |
| Aggregated and anonymized data |
Retained indefinitely (cannot identify individuals) |
| Server logs and security data |
90 days rolling, unless retained for security investigation |
When personal information is no longer required, we delete or anonymize it. Where deletion is not immediately practicable (e.g., backup archives), we securely isolate the data until deletion is possible.
Changes to This Policy
We may update this Privacy Policy from time to time. The Last Modified date at the top indicates when it was last revised.
If we make material changes — meaning changes that significantly affect how we handle your personal information — we will notify you by:
- Posting a prominent notice on the Site homepage
- Sending an email to the address associated with your account
- Displaying a banner on the Site when you next visit
We will not retroactively change how we use information collected under a prior version of this policy in ways that are materially adverse to you without providing clear notice and, where required by law, obtaining your consent.
Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or our privacy practices, please contact us:
Project: Life
82 Laird Dr., PO Box 313
Toronto, ON M4G 3V1, Canada
Email: support@getprojectlife.com
Website: www.getprojectlife.com
For privacy requests from California residents, please email support@getprojectlife.com. We will acknowledge receipt within 10 business days.
© 2026 Project: Life. All rights reserved. This policy was last modified on March 25, 2026.
Effective Date: March 25, 2026 | Canada · PIPEDA · Quebec Law 25 · CASL
1. Introduction
This Privacy Policy describes how Project: Life ("we," "us," or "our"), collects, uses, discloses, and protects personal information in connection with our website at www.getprojectlife.com and our subscription products and services (collectively, the "Services").
We are committed to protecting your privacy and handling your personal information in a transparent and accountable manner consistent with our obligations under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act Respecting the Protection of Personal Information in the Private Sector (commonly referred to as "Law 25" or "Bill 64"), Canada's Anti-Spam Legislation (CASL), and other applicable Canadian privacy laws.
This Policy applies to all personal information we collect from individuals who visit our website, create an account, complete our product matching questionnaire, purchase or subscribe to our products, contact us for support, or otherwise interact with our Services. It does not apply to our employees or contractors in their employment capacity, or to information that has been rendered anonymous or aggregated such that it cannot reasonably identify an individual.
By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described here, please discontinue use of our Services.
2. Privacy Officer
In accordance with PIPEDA Principle 1 (Accountability) and the requirements of Quebec's Law 25, we have designated a Privacy Officer who is responsible for overseeing our compliance with applicable Canadian privacy laws, managing privacy inquiries and requests, and maintaining our privacy program.
You may contact our Privacy Officer at:
Privacy Officer
Project: Life
82 Laird Dr., PO Box 313
Toronto, ON M4G 3V1
Email: support@getprojectlife.com
For general support inquiries that do not involve a privacy matter, you may also reach us at support@getprojectlife.com.
3. Information We Collect
We collect personal information only for purposes that a reasonable person would consider appropriate given the circumstances and our stated purposes. The categories of personal information we may collect are described below.
3.1 Information You Provide Directly
When you interact with our Services, you may provide us with:
-
Account and contact information: Full name, email address, phone number, shipping and billing address, and account credentials when you create an account or place an order.
-
Product matching questionnaire responses: Information you submit through our product matching questionnaire, including wellness goals, cycle and lifestyle details, and personal profile information used to recommend a suitable formulation. See Section 4 for a dedicated description of this data.
-
Order and transaction information: Payment method details, billing information, and transaction history. Full payment card numbers are processed directly by our payment processor and are not stored on our systems.
-
Correspondence and support communications: Messages, emails, and other communications you send through our support channels, including the nature of your inquiry and our responses.
-
Surveys and feedback: Responses to satisfaction surveys, feedback requests, check-in questionnaires, and optional review submissions.
-
Referrals and promotions: Information provided when you refer a friend, participate in a promotional program, or otherwise engage with optional features of our Services.
3.2 Information Collected Automatically
When you visit our website or interact with our emails, we and our service providers may automatically collect certain technical and usage information, including:
-
Device and technical information: IP address, browser type and version, operating system, device type, screen resolution, and general geographic location (city and country level).
-
Browsing and interaction data: Pages visited, duration and time of visit, links clicked, products viewed, and the referring URL that brought you to our website.
-
Cookies and tracking technologies: Information collected via cookies, pixel tags, web beacons, and similar technologies. See Section 9 for a full description of our cookie practices.
-
Email engagement data: Whether you opened an email we sent, which links you clicked within it, and the time of those interactions.
3.3 Information from Third Parties
We may receive personal information about you from third parties in limited circumstances, including:
-
Business partners: Information from business partners when you engage with co-promotional activities or referral programs involving Project: Life.
-
Advertising and attribution platforms: Advertising and attribution platforms may share aggregated or pseudonymous signals to help us understand how you came to learn about Project: Life.
-
Social media platforms: If you interact with our content on social media platforms or choose to connect your social media account to our Services, we may receive information from those platforms.
We do not purchase personal information from data brokers or list vendors.
4. Product Matching Questionnaire
To recommend an appropriate formulation, we ask you to complete a product matching questionnaire (the "assessment"). This assessment collects information about your wellness goals, lifestyle, and personal profile to help us match you to a suitable formulation from the Project: Life lineup.
The assessment is designed and informed by the clinical practice of Dr. Ye, a TCM practitioner with over 40 years of experience. The assessment asks questions in areas such as your wellness priorities, cycle patterns, lifestyle factors, and personal profile details relevant to selecting a formulation.
Completion of the assessment is voluntary; however, without it, we cannot provide a formulation recommendation and you will not be able to proceed with a subscription purchase. This information is collected with your express consent and is used solely for product recommendation purposes and to improve our formulation matching over time.
We do not use assessment responses to generate medical diagnoses, provide medical advice, or create medical records. The assessment is a product recommendation tool, not a medical or clinical assessment.
Responses to the assessment are retained for 24 months from your last interaction with us, after which they are anonymized or securely deleted. See Section 10 for full retention details.
5. Purposes for Collection, Use, and Disclosure
In accordance with PIPEDA Principle 2 (Identifying Purposes), we collect, use, and disclose personal information only for the purposes identified at or before the time of collection, or as permitted or required by law. Our purposes include:
-
Providing and fulfilling our Services: To process your order, fulfill your subscription, ship your formulation, manage your account, and provide client support.
-
Product matching and formulation recommendation: To review your assessment responses and recommend a Project: Life formulation suited to your wellness profile and goals.
-
Payment processing: To process payments, manage billing and renewals, handle refunds, and maintain transaction records as required by law.
-
Account management: To create and maintain your account, authenticate your identity, and enable you to manage your subscription, preferences, and personal information.
-
Client communications: To send transactional messages related to your account, including order confirmations, shipping notifications, subscription renewal notices, billing alerts, and support responses.
-
Check-in and wellness engagement: To contact you through scheduled check-in calls and follow-up communications to support your experience with your formulation and gather feedback on your progress.
-
Marketing and commercial communications: With your express consent, to send promotional emails, product updates, offers, and other commercial electronic messages. You may withdraw this consent at any time. See Section 14.
-
Analytics and service improvement: To analyze how clients use our Services, understand product performance, identify improvement areas, and develop new offerings. Where possible, we use aggregated or de-identified data for this purpose.
-
Advertising and attribution: To measure the effectiveness of our advertising campaigns, understand how new clients find us, and optimize our marketing investments across platforms.
-
Fraud prevention and security: To detect, prevent, and investigate fraudulent transactions, unauthorized access, and other potentially illegal or harmful activities.
-
Legal compliance: To comply with applicable laws and regulations, respond to lawful requests from regulatory or law enforcement authorities, and enforce our Terms of Service.
-
Dispute resolution: To investigate and resolve complaints, disputes, and legal claims involving Project: Life.
We will not use your personal information for purposes materially different from those listed above without first seeking your consent, or as otherwise permitted by law.
6. Consent
In accordance with PIPEDA Principle 3 (Consent), we rely on your knowledge and consent for the collection, use, and disclosure of your personal information, except where the law permits or requires collection without consent.
6.1 Types of Consent We Rely On
-
Express consent: We obtain express (opt-in) consent before collecting and using your product matching questionnaire responses and before sending commercial electronic messages (marketing emails and SMS). Express consent is obtained through a checkbox, a signed form, or another clear affirmative action, and is recorded with a timestamp.
-
Implied consent: Where you provide personal information voluntarily to complete a transaction or receive a service you have requested — such as entering your shipping address to receive an order — we rely on implied consent. By using our website, you also provide implied consent to the collection of technical information described in Section 3.2.
6.2 Consent for Cross-Border Transfers
By providing your personal information and using our Services, you consent to the transfer of your information to service providers located outside Canada, including in the United States, as described in Section 8 of this Policy.
6.3 Withdrawing Consent
You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by contacting our Privacy Officer at support@getprojectlife.com.
Please be aware that withdrawing consent for certain core purposes — such as our use of your product matching questionnaire responses — may mean we are unable to provide formulation recommendations or continue your subscription. We will inform you of the consequences of withdrawal before you make your decision.
Withdrawing consent for commercial electronic messages will not affect our ability to send transactional messages related to your account or subscription.
7. Disclosure to Third Parties
We do not sell your personal information. We may disclose your personal information to third-party service providers who assist us in operating our business and delivering our Services. These service providers are contractually obligated to protect your information, use it only for the purposes for which it was disclosed, and comply with applicable privacy laws.
The categories of service providers we engage include:
-
E-commerce platform providers: To host our online store, manage product listings, and process orders.
-
Email and communication service providers: To deliver transactional emails, marketing communications, and automated messaging flows.
-
Payment processors: To securely process payment card transactions and manage subscription billing.
-
Analytics and performance measurement tools: To collect and analyze website traffic, conversion data, and user behavior.
-
Attribution and advertising technology providers: To measure advertising performance and manage our marketing campaigns across platforms.
-
Customer support platforms: To manage support tickets, client correspondence, and care advisor communications.
-
Subscription management providers: To manage subscription contracts, pauses, cancellations, and renewals.
-
Product assessment and questionnaire platforms: To host and process our product matching questionnaire.
-
Cloud infrastructure providers: To store data, host applications, and provide computing resources.
-
Business intelligence and data analysis service providers: To assist with reporting, analytics, and performance insights.
In addition to the above, we may disclose your personal information in the following circumstances:
-
Business transfers: In the event of a merger, acquisition, sale of assets, or other business reorganization, your personal information may be transferred to the successor entity, subject to equivalent privacy protections.
-
Legal requirements: When required or permitted by applicable law, court order, or regulatory authority, including responses to lawful requests from law enforcement.
-
Protection of rights and safety: When we believe disclosure is necessary to protect the rights, property, or safety of Project: Life, our clients, or the public.
-
With your consent: For any other purpose with your express consent.
8. Cross-Border Transfers
Project: Life is headquartered in Toronto, Ontario, Canada. To deliver our Services, we engage service providers that may store, process, or access your personal information outside Canada, including in the United States.
Specifically, you should be aware of the following:
-
Transfer to the United States: Your personal information may be transferred to, stored in, and processed in the United States by our service providers. The United States has different privacy laws than Canada and, in some circumstances, US law may permit government authorities to access personal information held in the United States.
-
Contractual safeguards: All service providers outside Canada are bound by contractual obligations to protect your personal information using standards substantially equivalent to those required under Canadian law, and to use your information only for the purposes we have specified.
-
Government access: Information stored or processed outside Canada may be accessible to law enforcement and government authorities in those jurisdictions in accordance with the laws of those jurisdictions. We cannot guarantee the same level of protection that exists under Canadian law once your information is transferred outside Canada.
-
Further information: You may contact our Privacy Officer at support@getprojectlife.com for information about our policies and practices regarding service providers outside Canada, including the countries where your information may be processed.
Quebec residents are specifically informed, as required by Law 25, that their personal information may be communicated outside Quebec. Before authorizing such communication, we conduct a privacy impact assessment where required by law and we ensure that the information will receive a level of protection equivalent to that afforded under Quebec law.
9. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to operate the website, understand how visitors use it, and deliver relevant advertising.
9.1 What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They allow the site to recognize your browser, remember preferences, and gather information about your visit. We also use pixel tags (web beacons) — small images embedded in web pages or emails that signal when a page or email has been opened.
9.2 Types of Cookies We Use
-
Strictly necessary cookies: Essential for our website to function. They enable core features such as shopping cart functionality, account authentication, and checkout processing. These cannot be disabled without impairing website functionality.
-
Functional cookies: These cookies remember your preferences and enable personalized features to improve your experience.
-
Analytics cookies: These collect information about how visitors use our website — such as most-visited pages, traffic sources, and navigation paths — in aggregate form to help us improve our site. We use third-party analytics service providers for this purpose.
-
Advertising and attribution cookies: Used to measure the effectiveness of our advertising campaigns on third-party platforms, to understand which marketing channels drive new clients to our website, and in some cases to show relevant advertising on other platforms. These may collect your IP address and browsing behavior across websites.
-
Email tracking pixels: Our email communications may include a pixel tag that tells us whether you opened an email and clicked links within it. This helps us understand engagement with our communications.
9.3 Managing Your Cookie Preferences
You can manage cookies in the following ways:
-
Browser settings: Most web browsers allow you to view, manage, and delete cookies through browser settings. Please refer to your browser's help documentation for instructions.
-
Cookie preference center: Where we offer a cookie preference center on our website, you can use it to accept or decline non-essential cookies.
-
Advertising opt-out tools: You can opt out of interest-based advertising through the Digital Advertising Alliance of Canada (DAAC) at youradchoices.ca, or through the Network Advertising Initiative at optout.networkadvertising.org.
Please note that disabling certain cookies may affect the functionality of our website and your ability to complete a purchase or access your account.
10. Data Retention and Disposal
In accordance with PIPEDA Principle 5 (Limiting Use, Disclosure, and Retention), we retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required or permitted by law. When personal information is no longer needed, it is securely destroyed, deleted, or rendered anonymous.
Our standard retention periods by category are as follows:
-
Active account and profile data: Retained for the duration of your active relationship with Project: Life (including any pause period), plus 24 months after the end of that relationship.
-
Transaction and billing records: Retained for 7 years from the date of transaction, in accordance with tax, accounting, and legal record-keeping requirements under applicable Canadian law.
-
Product matching questionnaire responses: Retained for 24 months from your last interaction with Project: Life, after which responses are anonymized or securely deleted. Anonymized data is no longer personal information and may be retained for product research purposes.
-
Marketing and communication profiles: Where you have unsubscribed or disengaged from our communications, your suppression record is retained for 36 months after your last engagement, to ensure we do not contact you again.
-
Support correspondence: Retained for 24 months after resolution of the relevant inquiry or ticket.
-
Aggregated and anonymized data: Data that has been rendered truly anonymous (from which no individual can reasonably be identified) is no longer personal information and may be retained indefinitely for research, analytics, and product development purposes.
Retention periods may be extended where personal information is relevant to an ongoing legal proceeding, regulatory investigation, or dispute, or where we are required to retain information for a longer period by applicable law.
11. Safeguards
In accordance with PIPEDA Principle 7 (Safeguards), we use physical, administrative, and technical measures appropriate to the sensitivity of your personal information to protect it against loss, theft, unauthorized access, disclosure, copying, use, or modification.
Our safeguards include, but are not limited to:
-
Encryption: Personal information transmitted to and from our website is protected using industry-standard Transport Layer Security (TLS) encryption.
-
Access controls: Access to personal information is restricted to team members and service providers who have a legitimate business need, protected by role-based permissions and authentication requirements.
-
Payment security: We do not store full payment card numbers. Payment processing is handled by our payment processor in compliance with Payment Card Industry Data Security Standard (PCI DSS) requirements.
-
Service provider agreements: All third-party service providers are bound by data processing agreements that require them to maintain appropriate security measures and comply with applicable law.
-
Employee training: Our team members who handle personal information are trained on our privacy policies and obligations.
-
Incident response: We maintain documented procedures to identify, contain, and respond to privacy breaches. See Section 13 for our breach notification obligations.
No method of data transmission over the internet or electronic storage is completely secure. While we implement commercially reasonable safeguards, we cannot guarantee absolute security. If you have reason to believe your personal information has been compromised, please contact us immediately at support@getprojectlife.com.
12. Your Rights
Depending on your province of residence, you have a number of rights with respect to your personal information. We are committed to honoring those rights in accordance with PIPEDA (Principles 8, 9, and 10) and, for Quebec residents, the requirements of Law 25.
12.1 Right to Access
You have the right to request access to the personal information we hold about you, including information about the purposes for which it has been collected, the categories of third parties to which it has been disclosed, and the source of the information where reasonably determinable.
We will respond to access requests within 30 calendar days of receipt. Where we require additional time to fulfill a complex or voluminous request, we may extend this period by an additional 30 days (for a total of 60 days), and we will notify you of the extension and the reason for it within the initial 30-day period.
We may charge a reasonable fee to fulfill an access request in certain circumstances. If a fee applies, we will notify you in advance of the estimated cost.
12.2 Right to Correction
If the personal information we hold about you is inaccurate, incomplete, or outdated, you have the right to request that we correct it. You may update certain account information directly through your account settings, or by contacting us at support@getprojectlife.com.
12.3 Right to Deletion
You may request that we delete your personal information. We will fulfill deletion requests to the extent permitted by law. In some cases we may be required or entitled to retain certain information — for example, transaction records required for tax purposes, or information necessary to resolve an outstanding dispute. We will inform you if we are unable to fulfill a deletion request and explain the reason.
12.4 Right to Data Portability (Quebec Residents)
If you are a resident of Quebec, you have the right under Law 25 to receive the personal information you have provided to us in a structured, commonly used, technological format, to the extent technically feasible. You also have the right to request that we communicate that information directly to another organization where the technology is compatible.
To submit a data portability request, please contact our Privacy Officer at support@getprojectlife.com with the subject line "Data Portability Request."
12.5 Right to Withdraw Consent
You may withdraw consent to our processing of your personal information at any time, subject to legal or contractual restrictions and reasonable notice. See Section 6.3 for details on how to withdraw consent and the consequences of doing so.
12.6 Right to Be Informed of Automated Decision-Making
We use automated systems to generate formulation recommendations based on your assessment responses. You have the right to be informed that such automated processing is taking place and, upon request, to receive an explanation of how the recommendation was generated. Our automated recommendation system does not produce legal or similarly significant effects about you. For questions about how your recommendation was determined, please contact us at support@getprojectlife.com.
12.7 How to Exercise Your Rights
To exercise any of the rights described above, please submit a written request to our Privacy Officer at support@getprojectlife.com. We may ask you to verify your identity before processing your request in order to protect your information from unauthorized access.
12.8 Right to File a Complaint with a Supervisory Authority
If you are not satisfied with our response to a privacy inquiry or request, or believe we have not handled your personal information in accordance with applicable law, you have the right to file a complaint with the relevant supervisory authority:
-
Office of the Privacy Commissioner of Canada (OPC): All Canadian residents may file a complaint with the Office of the Privacy Commissioner of Canada (OPC): www.priv.gc.ca | 1-800-282-1376 | 30 Victoria Street, Gatineau, QC K1A 1H3
-
Commission d'accès à l'information du Québec (CAI) — Quebec residents: Residents of Quebec may also file a complaint with the Commission d'accès à l'information du Québec (CAI): www.cai.gouv.qc.ca | 1-888-528-7741
We encourage you to contact us directly before filing a complaint so that we have an opportunity to address your concern.
13. Breach Notification
We maintain documented procedures to identify, contain, and respond to privacy breaches involving personal information in our custody or control. Our breach response program includes investigation, containment, notification, and remediation steps.
13.1 Federal Requirements (PIPEDA)
Under PIPEDA's Breach of Security Safeguards Regulations, where a breach of security safeguards involving personal information creates a real risk of significant harm to an individual, we are required to:
- Notify affected individuals as soon as feasible, in plain language, of the breach and the steps they can take to protect themselves;
- Report the breach to the Office of the Privacy Commissioner of Canada (OPC);
- Notify any other organizations that may be able to reduce the risk of harm to affected individuals; and
- Maintain a record of all breaches, regardless of whether they create a real risk of significant harm.
"Real risk of significant harm" is assessed by considering factors such as the sensitivity of the information, the probability that the information has been or will be misused, and the potential for financial, reputational, physical, or other harm to affected individuals.
13.2 Quebec Requirements (Law 25)
For Quebec residents, in addition to our federal obligations, we comply with the breach notification requirements under Quebec's Law 25:
- We will notify the Commission d'accès à l'information du Québec (CAI) as soon as reasonably possible after becoming aware of a confidentiality incident involving personal information that presents a risk of serious injury to the persons concerned.
- We will also notify affected individuals and any other persons or organizations identified by regulation, within the timeframes required by Law 25.
- We maintain a confidentiality incident register as required by Law 25.
If you believe your personal information may have been compromised, please contact us immediately at support@getprojectlife.com.
14. Commercial Electronic Messages (CASL)
Canada's Anti-Spam Legislation (CASL) governs the sending of commercial electronic messages (CEMs), including promotional emails and text messages, to recipients in Canada. We are committed to complying with CASL.
14.1 Consent for Commercial Electronic Messages
We send commercial electronic messages based on one of the following grounds:
-
Express consent: We obtain express consent when you actively opt in to receive marketing emails or SMS messages — for example, by checking an opt-in box at checkout or completing a consent form. Your consent is recorded with a timestamp and the method by which it was obtained.
-
Implied consent (time-limited): Under CASL, we may rely on implied consent to send commercial electronic messages for up to 24 months following a purchase or other transaction with Project: Life, or for up to 6 months following a product inquiry, unless you opt out sooner.
Transactional messages — including order confirmations, shipping notifications, subscription renewal reminders, billing alerts, account security notifications, and responses to your direct inquiries — are not commercial electronic messages under CASL and do not require your express consent.
14.2 Unsubscribing from Commercial Electronic Messages
Every commercial electronic message we send includes a clear, functional, and free-of-charge unsubscribe mechanism. To unsubscribe from our marketing emails, click the "Unsubscribe" link at the bottom of any such email, or contact us at support@getprojectlife.com. We will honor your request within 10 business days, as required by CASL.
Unsubscribing from marketing communications will not affect your receipt of transactional messages related to your account or active subscription.
15. SMS and Text Messages
We may, with your consent, send you text messages (SMS/MMS) for marketing, order updates, and engagement purposes.
-
Consent: You must actively opt in to receive marketing text messages from Project: Life. We do not send unsolicited marketing texts.
-
Confirmation: You will receive a confirmation message once you have opted in, along with information about message frequency. Message and data rates from your mobile carrier may apply.
-
STOP: To stop receiving text messages from us at any time, reply STOP to any message we send. You will receive a confirmation of your opt-out.
-
HELP: To receive help or information about our text message program, reply HELP to any message we send, or contact us at support@getprojectlife.com.
-
Not required for purchase: Consent to receive text messages is not a condition of purchasing any product or service from Project: Life. You may decline to provide your mobile number or opt out of texts at any time without affecting your subscription or services.
For SMS messaging involving recipients in the United States, our practices also comply with the Telephone Consumer Protection Act (TCPA) and applicable US state laws.
16. Children
Our Services are not directed to persons under the age of 18 and we do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and you believe that a person under 18 has provided personal information to us without your consent, please contact us at support@getprojectlife.com and we will promptly delete such information from our records.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other business reasons. The updated Policy will always be posted at www.getprojectlife.com with a revised effective date at the top.
For non-material changes — such as clarifications, grammatical corrections, or updates to contact information — we will update the Policy and revise the effective date without additional proactive notice.
For material changes — meaning changes that significantly affect your rights or the way we handle your personal information — we will provide active notice, such as a prominent notice on our website or an email to the address associated with your account, prior to the change taking effect. Where required by law, we will seek your renewed consent before applying material changes.
We encourage you to review this Policy periodically. Your continued use of our Services after a material change takes effect constitutes your acceptance of the updated Policy, to the extent permitted by applicable law.
18. Contact Us
If you have any questions, concerns, or requests related to this Privacy Policy or the handling of your personal information, we want to hear from you.
Privacy Officer (privacy inquiries, access requests, complaints)
Project: Life
82 Laird Dr., PO Box 313
Toronto, ON M4G 3V1
Email: support@getprojectlife.com
General support:
Email: support@getprojectlife.com
Website: www.getprojectlife.com
If you remain unsatisfied after contacting us, you may escalate your complaint to:
-
For all Canadian residents: Office of the Privacy Commissioner of Canada (OPC)
www.priv.gc.ca | 1-800-282-1376 | 30 Victoria Street, Gatineau, QC K1A 1H3
-
For Quebec residents (Law 25): Commission d'accès à l'information du Québec (CAI)
www.cai.gouv.qc.ca | 1-888-528-7741
Project: Life | 82 Laird Dr., PO Box 313, Toronto, ON M4G 3V1
support@getprojectlife.com | www.getprojectlife.com | Effective: March 25, 2026