Skip to content

Privacy policy

Last updated

Compliance review completed September 22, 2026. This document was checked against the site's current operating practices and applicable Canadian and Saskatchewan requirements. It is maintained as the service changes and is general information, not legal advice.

The short version

We collect what we need to run a directory: the contact details you send if you claim a business listing, the listing details themselves, and a count of which pages get viewed. There are no public accounts to create. We don't sell anything to anyone, we don't run third-party advertising or tracking scripts, and we don't store your IP address.

What we collect, and why

  • Claim requests — when someone asks to manage a business listing, we collect their name, email address and phone number, with their consent, so we can verify the claim and reply to it. We keep the record afterwards as evidence of who is responsible for a listing. There is no account and no password; verification is done through the business's own published phone number.
  • Administrator sign-in — the site administrator signs in with an email address and a password stored as a bcrypt hash; we cannot read it, and neither can anyone who obtains the database.
  • Business listings — everything an owner enters about their business, which is published deliberately.
  • Reviews and bookings — writing a review needs an email address, which we confirm by sending a code to it; the address is kept while the review is up (and while it waits for approval) so a disputed review can reach its writer, but it is never published — the listing shows the display name only. Reviews submitted while public accounts were open remain published under their original display names, because quietly deleting them would change businesses' ratings without anyone knowing. A booking request is shared with the business it was sent to, which was the point of sending it.
  • Page views — which listing was viewed, roughly when, a consent-gated random session identifier, and a coarse country or region supplied by our hosting network. Business owners see aggregate results. We do not attach listing views to signed-in accounts, and we do not store the viewer's IP address, browser details or referring page in our analytics records.
  • Payments — handled entirely by Stripe. Card numbers never reach our servers. We keep the amount, date and Stripe's reference so we can show you an invoice.

Cookies and storage

  • Sign-in cookies (fqd_access, fqd_refresh) — strictly necessary, and set only for the site administrator when they sign in. They are httpOnly, so no script on the page can read them.
  • Analytics storage — a random session identifier kept in session storage so one person refreshing a listing is not counted repeatedly. It expires when that browser session ends. It is only written if you agree in the banner, and choosing “No thanks” stops listing-view analytics.
  • Your consent choice — stored in your browser so we don't ask on every page.

We run no third-party advertising, analytics or social tracking scripts. Interactive map tiles are requested directly from the map tile provider by your browser. As with any web request, that provider can receive network metadata such as your IP address, browser headers and the requesting page. Weather requests are made by our server to Open-Meteo, so Open-Meteo does not receive your browser's IP from that request.

Who is accountable

Discover the Qu'Appelle is responsible for personal information under its control. The designated Privacy Contact can answer questions, receive access or correction requests, and handle privacy complaints. Contact the Privacy Contact at jaiscollins2@gmail.com.

How long we keep things

  • Claim requests — kept for as long as the claimant manages the listing, and for two years after, as the record of who was responsible for it.
  • Legacy accounts — public accounts closed on 23 September 2026. Any account not signed into for twelve months is anonymised: the email and name are replaced, and reviews stay up attributed to a removed user rather than being deleted, so the businesses' ratings don't silently change.
  • Raw page-view records — kept for 14 months, then deleted. Aggregate counts remain.
  • Payment records — kept for seven years, because Canadian tax law requires it.

We may keep information longer when reasonably necessary to meet a legal obligation, preserve evidence, resolve a dispute, prevent fraud or enforce an agreement. Deletion from encrypted backups can lag behind deletion from the active system; backup copies remain protected and are overwritten on the normal backup cycle.

Your rights

Subject to lawful exceptions, you may ask to learn whether we hold personal information about you, receive access to it, and have inaccurate or incomplete information corrected. You may also withdraw consent to optional analytics at any time by clearing this site's stored data and choosing “No thanks” when asked again.

Send a written request or complaint to jaiscollins2@gmail.com. We will respond to an access request within 30 days unless PIPEDA permits an extension. If an extension is required, we will tell you within the first 30 days, explain why, and identify your right to complain. We may need to verify your identity before releasing personal information. If our response does not resolve your concern, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

Service providers and international processing

We use service providers for application hosting, database hosting, email delivery, payment processing, maps and weather. They receive only the information needed to provide their service. Stripe receives payment and billing details; our email provider receives message and recipient details; hosting and database providers process application and account data; the map tile provider receives the browser request described above. Providers may process information in Canada, the United States or other countries where they or their subprocessors operate. Information processed abroad can be subject to the laws and lawful access rules of that jurisdiction. We remain accountable for personal information transferred to providers for processing and use contractual and technical safeguards appropriate to the service.

Security

Traffic is encrypted in transit. Passwords are hashed with bcrypt. Sign-in tokens are short-lived and rotate on use, and every stored token is hashed so a database leak yields nothing replayable. Access to administrative functions is restricted and every moderation action is logged. No system is perfectly secure, and we'd rather say that than imply otherwise.

Privacy breaches

We assess any breach of security safeguards involving personal information under our control. Where a breach creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada, notify affected people as soon as feasible, and notify another organization or government institution when doing so may reduce or mitigate the risk. We keep records of all breaches as required by PIPEDA and its regulations.

Changes

If we change what we collect or why, we'll update this page and change the date at the top. See also our terms of service and accessibility statement.