Privacy

Privacy policy

What we collect when you visit an experience, what stays in the room, and what you can ask us to remove.

Last updated · September 12, 2026

Who this policy covers

Studio Rabaska Inc. is a Montreal company and a subsidiary of iLLOGIKA. We create location-based virtual reality experiences, and we make Portage, the software that venues use to check visitors in and run the room.

This policy covers what Studio Rabaska does with your information as the maker of that platform. It does not cover the venue you visit. The venue decides what to ask you at check-in, writes its own waiver, holds its own customer file and sends its own marketing. If you want to know what your venue does, ask the venue — it publishes its own policy.

Where we and the venue each decide part of what happens, both of us are responsible for our part. Nothing here reduces what the venue owes you.

What you give us at check-in

To take part you sign a waiver, on a kiosk, a phone, or at the counter. That signature records your first and last name, your email address, your date of birth, the handwritten signature you draw, and your answers to whatever the venue asks.

It also records the complete text you were shown, in the language you read it in, along with the time, your IP address and your browser. That is what makes the waiver hold up: without it we could not show what you actually agreed to. It is the reason this record exists, and the reason it is kept.

The venue may also hold your phone number and notes its staff typed about your booking. That file belongs to the venue.

If you are under eighteen

A minor does not sign. A guardian who is physically present signs instead, and their signature is tied to the minor’s record. Our server re-checks that link rather than trusting the screen: same venue, same operating day, guardian not a minor themselves, signature actually present.

A minor’s record carries no email address. We ask for a full date of birth because the platform has to know whether a guardian is required; age brackets used for attendance statistics are worked out when the numbers are read, never stored against you.

What happens while you are playing

Your headset reports where your head and your hands are, about twenty times a second, so the experience can show you the other players and stop you walking into them. This runs on a computer inside the room. It is never sent to us, and it is not recorded — there is no history of where you walked.

We do not collect eye tracking, voice, heart rate, height, or any other measurement of your body. There is no biometric identification of any kind.

What does reach us is what happened in the story: which scene you entered, how long it lasted, which choices were made. Those events are attached to a headset, not to a name. An operator can see a live overhead view of the room while you play; it is not recorded.

No photographs, no payment cards

Studio Rabaska takes no photograph or video of you, and stores none. The only image tied to a person is the handwritten signature on the waiver. The headsets are not granted camera access at all, so they could not photograph you even if something asked them to.

The character who represents you in the story is one you choose yourself, from a fixed list of figures modelled by hand, plus a colour. Two numbers travel across the room network — which figure, which colour. Nothing is derived from how you actually look.

We never see your card. When a venue records that you paid, it keeps the amount and a reference from its payment provider — never a card number.

This website

This site is a set of static files. It has no accounts, no database of ours, and it sets no cookie of its own.

It loads Google Analytics only if you accept the banner. Nothing is requested from Google before you do, and declining means no Google script is ever fetched. If you accept, Google receives your IP address and the pages you read; we have turned off advertising features and asked for IP anonymisation. You can change your mind by clearing this site’s storage in your browser.

If you subscribe to the newsletter, your email address goes to Mailchimp, and only then. Every newsletter carries an unsubscribe link.

Who else receives your information

XROAM, the platform the headsets run on, receives your name, your email address, your age in whole years, your gender if you gave one, the fact that a guardian consented, and the language you chose. It receives your age, not your date of birth. We never tell XROAM that you agreed to marketing.

XROAM is run by Univrse Core, S.L., in Spain, and publishes its own privacy policy — the one you are asked to accept before you play, alongside ours. It names further companies involved in running experiences on that platform. What XROAM does with what it holds is set out there, not here, and it is worth the two minutes.

Our host is OVH. Daily encrypted backups of the whole database are kept in cloud storage. Newsletters and booking emails go through an email relay.

Nobody else. We do not sell anything, we run no third-party analytics on the platform, and nothing about you is used to train any model.

Where your information is kept

Today, on servers in the European Union. That means information about visitors in Quebec is held outside Quebec, and we assess that transfer as Quebec law requires before it happens.

We are moving this to a Quebec data centre. When that is done, this paragraph and the date at the top of this page change with it.

How long we keep it

Every week we review what has passed its retention period, and an authorised person confirms each removal. It is not automatic, and that is deliberate: a mistake in date arithmetic would quietly destroy years of records on a Sunday morning, and nobody would find out until they needed them.

The periods are these. A signed waiver is kept for three years after the visit, which is the limitation period for a civil claim in Quebec. A minor’s waiver is kept until they turn twenty-one — their majority plus those same three years, because that period does not run against a child. A customer file is kept for thirty-six months without activity, counted from the last visit or booking and not from the day it was created, so that someone who comes back every year is not anonymised between visits.

A waiver is deleted; a customer file is anonymised. Those are two different acts, not two words for one, and they are never merged into a single button.

Two things already expire on their own: the contents of messages sent to other systems, after thirty days, and our internal audit log, after thirteen months.

Your venue keeps your signed waiver so that you do not have to sign again on a later visit. That reuse is limited to one year.

Asking us to remove you, and what that actually does

Ask, and we will run it. Be aware that it cannot be undone and that it is not instant — a person on our team performs it.

What is emptied: your customer file, your record as a member of a household, your bookings, everywhere you appear as a contact of a venue, every marketing list you are on, and your visit history. Your name, your email address and your phone number go from all of them. What is left is counters, amounts and dates — that a sale happened, for how many places, at what price, on what day.

What is cut: every link between you and what you did in the room. The name copied onto your visit and onto your headset assignment, the links back to your booking, the link to your household record, and the name we had sent to XROAM. What is left of the gameplay is a headset and a series of scenes, attached to nobody.

What stays, and you should know it before you ask: your signed waiver, kept whole but no longer connected to anything else. It becomes the only place your name still appears anywhere. Your date of birth goes with the rest — you drop out of our attendance figures entirely, which is the honest consequence of cutting the link.

Why we keep the waiver

Because it is the only proof of what you were told and what you agreed to, including that you were fit to take part. If we destroyed it on request, we would be destroying the record that protects both of us, and we would have no way to answer a claim months later.

It is kept with your name on it, on purpose. It is not used for marketing, it is not read for statistics, and after an anonymisation request it points at nothing else.

Your rights

You can ask what we hold about you and get a copy. You can have it corrected if it is wrong. You can ask us to stop sending you anything, and unsubscribing from a newsletter takes one click. You can ask for the removal described above.

You never have to give a reason. Write to us and we will come back to you — and if you are not satisfied, you can complain to the Commission d’accès à l’information du Québec, or to your own supervisory authority if you are in Europe.

Marketing is opt-in: the default is off, and it stays off unless you say otherwise. Being imported from a file cannot subscribe you, and coming back to the site never re-subscribes someone who has unsubscribed.

Changes

If this policy changes materially, the date above changes with it. This page keeps no version history; if you need to know what it said on a given date, ask us.

Contact

hello@studiorabaska.com

Person responsible for the protection of personal information

David Fugère-Lamarre · President

hello@studiorabaska.com