Legal
Privacy Policy
Effective July 15, 2026 · Contact: emil@epasini.com
Effective Date: July 15, 2026 Last Updated: March 20, 2026
1. WHO WE ARE
This Privacy Policy applies to Don't Panic, operated by Don't Panic ("we," "us," "our"). We operate the website at joindontpanic.com and the Don't Panic web application (collectively, the "Platform").
Contact: Email: emil@epasini.com
2. WHAT THIS POLICY COVERS
This policy explains what personal information we collect, why we collect it, how we use it, who we share it with, and your rights over your data. We comply with:
- PIPEDA (Personal Information Protection and Electronic Documents Act: Canada)
- CASL (Canada's Anti-Spam Legislation)
- CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act: USA)
3. WHAT WE COLLECT
We collect only what we need to deliver our services.
What we do NOT collect:
- Health or medical records
- Biometric data
- Social media passwords
- Data from minors (you must be 18+ to use the Platform)
4. HOW WE USE YOUR DATA
We use your information for:
1. Delivering the service, your account, your programs, your content access 2. Processing payments, via Stripe (PCI-compliant, industry standard) 3. Communicating with you, account updates, program emails, support responses 4. Marketing emails, only with your explicit opt-in consent (CASL compliant) 5. Improving the Platform, usage patterns help us make better decisions about features and content 6. Security, detecting fraud, preventing abuse, protecting your account
We do NOT:
- Sell your personal data to anyone. Ever.
- Use your data for targeted advertising on third-party platforms.
- Share your data with data brokers.
5. WHO WE SHARE DATA WITH
We share data only with the services required to run the Platform:
All third-party services are bound by their own privacy policies and data protection obligations. We do not share more than what each service needs.
We may also disclose data if required by law, court order, or to protect the safety of our users.
6. EMAIL COMMUNICATIONS (CASL COMPLIANCE)
We follow Canada's Anti-Spam Legislation:
- You must opt in to receive marketing emails. We never pre-check consent boxes.
- Every email includes an unsubscribe link. One click. No hoops.
- Unsubscribe requests are processed within 10 business days (usually immediate).
- Transactional emails (account confirmations, payment receipts, password resets) are sent without opt-in, these are required for service delivery.
Your email tiers:
- Waitlist, updates on launch and early access
- The Upgrade (free), program emails, clinical content
- The Shift (paid), program emails, full spectrum content
You can change your email preferences or unsubscribe at any time.
7. HOW WE PROTECT YOUR DATA
- All data transmitted to and from the Platform is encrypted via SSL/TLS (HTTPS).
- Payment processing is handled by Stripe, which is PCI DSS Level 1 certified (the highest level of payment security).
- We use secure authentication for account access.
- Access to personal data is limited to those who need it to deliver the service.
- We do not store credit card numbers on our servers.
No system is 100% secure. We take reasonable measures to protect your data, but we cannot guarantee absolute security.
8. HOW LONG WE KEEP YOUR DATA
- Active accounts: Data is retained as long as your account is active.
- Cancelled accounts: We retain your data for up to 12 months after cancellation to handle disputes, refunds, or reactivation. After that, it is deleted or anonymized.
- Email subscribers (non-account): Data is retained until you unsubscribe. After unsubscribe, your email is removed from active lists within 30 days.
- Payment records: Retained as required by tax and financial regulations (typically 7 years for transaction records).
9. YOUR RIGHTS
If You're in Canada (PIPEDA)
You have the right to:
- Access your personal data, request a copy of what we hold
- Correct inaccurate data
- Withdraw consent for marketing communications at any time
- Request deletion of your data (subject to legal retention requirements)
- File a complaint with the Office of the Privacy Commissioner of Canada if you believe your rights have been violated
If You're in California (CCPA/CPRA)
You have the right to:
- Know what personal data we collect and how it's used
- Delete your personal data
- Opt out of the sale of personal data (we don't sell data, but the right is yours)
- Non-discrimination, we won't treat you differently for exercising your rights
For All Users
To exercise any of these rights, email us at emil@epasini.com. We will respond within 30 days.
10. COOKIES & TRACKING
The Platform may use:
- Essential cookies, required for the Platform to function (login sessions, security)
- Analytics cookies, anonymized usage data to understand how the Platform is used
- No third-party advertising cookies, we do not run ads on the Platform
You can disable cookies in your browser settings, though some Platform features may not work properly without essential cookies.
11. CHILDREN'S PRIVACY
The Platform is not intended for anyone under the age of 18. We do not knowingly collect personal data from minors. If we learn that we have collected data from someone under 18, we will delete it immediately.
12. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you via email or a notice on the Platform. Continued use of the Platform after changes constitutes acceptance of the updated policy.
13. CONTACT
For privacy-related questions or requests:
Email: emil@epasini.com Entity: Don't Panic Location: Ontario, Canada
This Privacy Policy is written to be clear and direct. If something doesn't make sense, email us and ask.