Privacy
Privacy
Montreal MCM is a small vintage furniture discovery site. Data collection is deliberately limited: enough to run favourites, saved searches, optional notifications, refresh operations, and basic site analytics, without advertising profiles.
Anonymous favourites and saved searches
Anonymous favourites, saved shops, and saved searches use a signed first-party browser cookie. The database stores only a hashed owner key with the IDs of saved items. There are no public user accounts for this feature.
Notifications
Web Push alerts are optional and off by default. If enabled, Montreal MCM stores preferences, the browser push subscription, delivery encryption keys, delivery records, and in-app notification history with the same hashed anonymous key used for favourites. The site does not require an email address or account for notifications.
Shop images and source links
Listings retain provenance and link to the original shop. Many listing images load directly from shop or shop-CDN domains, so those providers receive the browser request normally needed to display the image. Montreal MCM does not send them an advertising profile. Interface JavaScript libraries are served by Montreal MCM, not a third-party CDN.
Maps
Compact maps on the shops page load map tiles from CARTO and show OpenStreetMap attribution. CARTO receives the normal browser request needed to display those tiles. Directions links open Google Maps or Apple Maps only when you select them.
Analytics
Montreal MCM stores aggregate page-view counts by day, page type, path, and language. The app does not store raw IP addresses, user agents, or referrers in this analytics table. Cloudflare also processes requests and logs needed to serve, secure, and measure the site.
Cookies
The site uses first-party cookies for language, the Flask session, and durable anonymous favourite/search/notification identity. Montreal MCM does not load third-party advertising scripts. Because these cookies support site functionality and the site does not sell or share personal information, Montreal MCM does not show a cookie consent banner at this time.
Global Privacy Control
Global Privacy Control signals line up with the current site posture: Montreal MCM does not sell or share personal information, so the app does not change behavior when that signal is present.
Retention
In-app notification history is deleted after 45 days, or 30 days after dismissal. Delivery attempts and detailed job records are retained for 90 days; aggregate daily counters for at most 13 months. After a Push subscription is revoked, its keys and user agent are erased within 7 days and the residual row within 30 days. An active subscription is retained until the user unsubscribes or the Push provider reports that its endpoint is permanently invalid; a quiet subscription is not treated as abandoned. Anonymous favourites, shops, and searches remain until the user deletes them; preferences retain the last selected state, including off. Catalogue data comes from public shop sources and keeps source provenance.