Our Core Privacy Commitments
We do not sell your personal information. We do not share your data with advertisers. We collect the minimum data necessary. You have the right to access, correct, or delete your data at any time. We comply with Canada's PIPEDA and CASL.
📋 Table of Contents
- Who We Are
- Information We Collect
- How We Use Your Information
- Cookies & Tracking Technologies
- Email & CASL Compliance
- Information Sharing & Disclosure
- Third-Party Links
- Data Retention
- Data Security
- Children's Privacy
- Your Rights Under PIPEDA
- Complaints & Disputes
- Changes to This Policy
- Contact Our Privacy Officer
1. 🏛️ Who We Are
Midland Community Hub ("we," "us," "our") is a community information service dedicated to helping residents, visitors, and newcomers of Midland, Ontario, Canada find local services, government programs, and community resources.
We operate the website located at midlandcommunity.ca (the "Site"). Our primary purpose is to provide a free, comprehensive, and easy-to-navigate directory of public and community services for the Town of Midland and surrounding Georgian Bay area.
We are not a government entity. We are not affiliated with the Town of Midland, the Province of Ontario, or the Government of Canada, unless explicitly stated. Service listings are provided for informational purposes only.
Governing Law: This Privacy Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, including the Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5, and Canada's Anti-Spam Legislation (CASL), S.C. 2010, c. 23.
2. 📥 Information We Collect
We collect only the minimum information necessary to provide our services. We collect information in three ways: information you provide directly, information collected automatically, and information from third parties.
2.1 Information You Provide Directly
| Data Type | When Collected | Purpose | Required? |
|---|---|---|---|
| Email address | Newsletter signup | Send community newsletter | Yes (for newsletter) |
| Newsletter consent timestamp | Newsletter signup | CASL compliance record | Yes (for newsletter) |
| Service/event suggestion text | Suggest a Service form | Review and potentially list the service | Yes (for submission) |
| Contact information (optional) | Suggest a Service form | Follow-up on your suggestion | No |
| Advertiser business details | Advertising inquiries | Process advertising requests | For advertisers only |
2.2 Information Collected Automatically
When you visit our Site, certain technical information may be collected automatically by our web server or analytics tools:
- IP address (anonymized where possible)
- Browser type and version
- Operating system
- Pages visited and time spent
- Referring URL (the page you came from)
- Date and time of visit
This information is collected to understand how our Site is used, improve user experience, and maintain security. It is not used to identify you personally.
2.3 Local Browser Storage
Our Site uses your browser's localStorage to store your saved/bookmarked services and cookie consent preferences. This data is stored entirely on your device and is never transmitted to our servers. You can clear this data at any time through your browser settings.
2.4 Information We Do NOT Collect
We Never Collect
We do not collect Social Insurance Numbers, health card numbers, banking or financial information, government ID numbers, precise geolocation, biometric data, or any sensitive personal information as defined under PIPEDA Schedule 2.
3. 🎯 How We Use Your Information
We use personal information only for the specific purposes for which it was collected, consistent with your reasonable expectations and applicable law. Specifically:
| Purpose | Legal Basis (PIPEDA) | Data Used |
|---|---|---|
| Delivering the community newsletter you subscribed to | Express consent (CASL) | Email address |
| Reviewing and publishing community service suggestions | Implied consent / legitimate purpose | Submission text, optional contact |
| Responding to advertiser inquiries | Contractual necessity | Business contact details |
| Analyzing Site usage to improve the directory | Legitimate purpose | Anonymized analytics data |
| Maintaining Site security and preventing abuse | Legitimate purpose | IP addresses (temporary) |
| Legal compliance and record-keeping | Legal obligation | Consent records |
We will never use your information for automated profiling, targeted advertising, sale to third parties, or any purpose incompatible with the original reason you provided it.
4. 🍪 Cookies & Tracking Technologies
Cookies are small text files stored on your device when you visit a website. We use cookies minimally and transparently.
4.1 Essential Cookies (Always Active)
These cookies are strictly necessary for the Site to function. They do not require your consent under PIPEDA as they are essential to service delivery:
| Cookie Name | Purpose | Duration |
|---|---|---|
| mcg-cookie | Stores your cookie consent preference so we don't ask again | 1 year |
| mcg-saved (localStorage) | Stores your bookmarked services on your device only | Until you clear browser data |
4.2 Analytics Cookies (Optional — Requires Consent)
If you consent to optional cookies, we may use privacy-respecting analytics (such as anonymized Google Analytics or self-hosted Matomo) to understand how visitors use the Site. This helps us improve the directory. You may decline optional cookies by selecting "Decline Optional" on our cookie banner.
4.3 How to Manage Cookies
You can control cookies through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, or receive a warning before a cookie is placed. Note that disabling essential cookies may affect Site functionality. Visit allaboutcookies.org for guidance.
4.4 Do Not Track
We respect browser "Do Not Track" (DNT) signals. When DNT is enabled, we will not load optional analytics scripts.
5. 📧 Email Communications & CASL Compliance
Canada's Anti-Spam Legislation (CASL) Compliance
All commercial electronic messages (CEMs) we send comply with CASL, S.C. 2010, c. 23. We only send emails to individuals who have given express consent with a clear description of what they are consenting to receive.
5.1 Express Consent
We collect express consent for our newsletter by requiring you to:
- Actively check a consent checkbox (pre-ticked boxes are not used)
- Read a clear description of what you will receive
- Be informed of your right to unsubscribe at any time
- Be informed that your email will not be shared
5.2 Consent Records
We maintain records of each subscription including the date and time consent was given, the specific consent text displayed, and the IP address (anonymized) at time of signup. These records are retained as required by CASL.
5.3 Every Email We Send Contains
- Our full business name and mailing address
- A clear, functioning one-click unsubscribe mechanism
- A statement of why you are receiving the email
5.4 Unsubscribing
You may unsubscribe at any time by clicking the unsubscribe link in any email we send, or by emailing us at [email protected] with the subject "Unsubscribe." We will process your request within 10 business days as required by CASL.
6. 🤝 Information Sharing & Disclosure
We do not sell, rent, trade, or share your personal information with third parties for their commercial purposes. Period.
6.1 We May Share Information With
- Service providers: Trusted third-party providers who help operate our Site (e.g., web hosting, email delivery platforms) under strict data processing agreements. They may not use your data for their own purposes.
- Legal authorities: If required by law, court order, or to protect the safety of any person, we may disclose information to law enforcement or regulatory authorities.
- Business transfers: In the unlikely event of a sale or transfer of this project, user data may be part of the transferred assets. We will notify you before your data is subject to a different privacy policy.
6.2 Advertising Disclosures
Paid "Featured" business listings are clearly labelled with a "⭐ Featured" badge. Sponsored content is clearly identified. We do not allow advertisers to access user data, and advertising relationships do not influence our community service listings.
7. 🔗 Third-Party Links
Our directory contains links to external websites operated by government agencies, community organizations, businesses, and charities. These links are provided for your convenience.
Important Notice About Third-Party Sites
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party website. We encourage you to review the privacy policy of every website you visit. The inclusion of a link does not imply our endorsement of the linked site.
8. 🗂️ Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Email newsletter subscriptions | Until unsubscribed + 3 years | CASL requires consent records to be kept 3 years after the relationship ends |
| CASL consent records | 3 years after consent withdrawn | Legal obligation under CASL s. 13 |
| Service/event suggestions | 90 days after review | Operational necessity |
| Advertising correspondence | Duration of contract + 7 years | Canadian tax/business record requirements |
| Server logs (IP addresses) | 30 days, then deleted | Security monitoring only |
| Cookie consent records | 1 year | Compliance documentation |
When personal information is no longer required for its stated purpose and retention period has expired, it is securely deleted or anonymized.
9. 🔐 Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These measures include:
- HTTPS/TLS encryption for all data in transit
- Access controls limiting who can access personal data
- Regular security reviews of our systems and practices
- Minimal data collection (we only keep what we need)
- Reputable hosting providers with strong security practices
No Absolute Security
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. In the event of a data breach affecting your rights and freedoms, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required by PIPEDA.
10. 👧 Children's Privacy
Our Site is intended for use by members of the general public aged 18 years and older, or by minors with parental/guardian supervision. We do not knowingly collect personal information from children under the age of 13 without verifiable parental consent.
If you are a parent or guardian and believe your child under 13 has provided us with personal information without your consent, please contact us immediately at [email protected] and we will promptly delete such information.
Some services listed in our directory (such as Kids Help Phone and youth programs) are specifically designed for minors. When linking to such services, we direct users to those organizations' own privacy policies.
11. ⚖️ Your Rights Under PIPEDA
Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) gives you the following rights regarding your personal information:
Right to Access
Request a copy of the personal information we hold about you.
Right to Correction
Request correction of inaccurate or incomplete personal information.
Right to Deletion
Request deletion of your personal information (subject to legal retention requirements).
Right to Withdraw Consent
Withdraw consent for collection or use of your information at any time.
Right to Know
Know what personal information we hold and how it is being used.
Right to Complain
Lodge a complaint with the Office of the Privacy Commissioner of Canada.
Exercising Your Rights
To exercise any of the above rights, submit a written request to our Privacy Officer at [email protected]. We will respond within 30 days as required by PIPEDA. We may ask you to verify your identity before processing your request.
There is no charge for making an access request, though we may charge a reasonable fee for large or complex requests after informing you in advance.
12. 🏛️ Complaints & Disputes
If you have a concern about how we handle your personal information, we encourage you to contact us first. We take privacy complaints seriously and will investigate promptly.
If you are not satisfied with our response, you have the right to file a complaint with the federal privacy regulator:
Office of the Privacy Commissioner of Canada
Phone: 1-800-282-1376 (toll-free)
Website: www.priv.gc.ca
Address: 30 Victoria Street, Gatineau, QC K1A 1H3
Online Complaints: Available at priv.gc.ca
For Ontario-specific privacy concerns related to provincial public bodies, you may also contact the Information and Privacy Commissioner of Ontario at www.ipc.on.ca or 1-800-387-0073.
13. 🔄 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Post a prominent notice on our Site homepage for at least 30 days
- Where required by law, seek renewed consent
- Notify newsletter subscribers by email of material changes
Your continued use of the Site after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree with the changes, you should stop using the Site and request deletion of any personal information we hold about you.
Previous versions of this policy are available upon request.
14. 📬 Contact Our Privacy Officer
Privacy Officer — Midland Community Hub
When contacting us regarding a privacy matter, please include your name, contact information, and a clear description of your request or concern. If requesting access to your personal information, we may require identity verification.