Privacy Policy

Effective date: 15.01.2025

Entity: Gifto Canada, Inc. ("Gifto", "we", "us", "our") — Alberta, Canada.

1. Introduction

Gifto helps people give and enjoy experiences through our website Gifto.ca.

This Privacy Policy explains how we collect, use, and protect your personal information when you:

  • Visit our website,
  • Purchase or receive a gift experience certificate,
  • Activate or book an experience, or
  • Partner with us as an Experience Provider.

We follow Alberta's Personal Information Protection Act (PIPA) and, where applicable, Canada's federal privacy laws (PIPEDA) and Canada's Anti-Spam Legislation (CASL).

By using our Services, you agree to this Policy.

2. Scope and Responsibility

Gifto acts as the "organization" (controller) under PIPA for the information we collect about customers, recipients, and experience providers.

Experience Providers are independent businesses.

When you attend their experience or fill out their forms or waivers, they become responsible for their own privacy practices.

3. What We Collect

We collect only the information we need to deliver your experience safely and effectively.

From customers and recipients

  • Name, email, phone, and delivery address (for gift boxes)
  • Gift message and recipient details
  • Certificate number, activation, and booking details
  • Chosen date/time for the experience
  • Communications with our support team

From experience providers

  • Business name, contact details, email/phone
  • Experience descriptions, photos, logos, licences/insurance details
  • Banking or payout information (processed securely)
  • Communications with Gifto

Automatically

  • Browser, device, and IP information
  • Pages visited, session data, performance analytics
  • Cookies or local storage to keep your wishlist and improve performance

We never collect unnecessary data.

4. How We Use Information

We use your information to:

  • Deliver and manage your gift or booking
  • Communicate with you about activation, confirmation, or support
  • Pay Experience Providers after experiences are completed
  • Improve website performance and security
  • Meet our legal obligations (tax, recordkeeping, anti-fraud)
  • Send marketing offers only if you consent

We do not sell your personal information.

5. How We Share Information

We share information only when necessary:

  • With Experience Providers — your name, contact info, and certificate or code to deliver your experience.
  • With trusted service providers — payment processing (e.g., Stripe), hosting, email/SMS delivery, analytics, and fraud prevention.
  • For legal or safety reasons — if required by law or to protect our rights or users.
  • In business transfers — if Gifto merges, finances, or sells its business, we ensure privacy protection continues.

Once you deal directly with a Provider, your information is governed by that provider's own privacy practices.

6. Cookies and Online Tracking

We use cookies and similar tools to:

  • Remember your favourites and filters,
  • Keep your session active,
  • Measure website use and performance.

You can block cookies in your browser settings, but some features may not work properly. We don't sell cookie data or track users for advertising.

7. Marketing & Communications

We send service messages (order confirmations, booking updates) without additional consent. Promotional messages are sent only with your explicit permission under CASL, and you can unsubscribe anytime.

8. Security

We use secure connections (HTTPS), access controls, and reliable vendors like Stripe to protect your data.

While no system is 100% secure, we take reasonable steps to safeguard all information in our care.

9. Data Breaches

If a security breach creates a real risk of significant harm, we will:

  • Notify the Office of the Information and Privacy Commissioner of Alberta (OIPC), and
  • Contact affected individuals as soon as feasible.

We keep breach records for at least two years.

10. Retention

We keep information only as long as needed for our business and legal purposes, then securely delete or de-identify it.

Typical timeframes:

  • Orders, activations, bookings — up to 7 years (for accounting)
  • Support requests — up to 24 months
  • Provider records — contract term + 7 years
  • Marketing contacts — until you unsubscribe or 24 months of inactivity

11. Your Rights

You have the right to:

  • Access and receive a copy of your personal information
  • Correct inaccurate information
  • Withdraw consent for non-essential uses
  • Complain to us or to the OIPC if you believe your privacy rights were violated

We'll respond within 15 business days and may verify your identity first.

12. Children's Privacy

Gifto is not directed to children under 13.

All purchases must be made by adults.

Some experiences are suitable for children but must be booked by a parent or guardian.

13. Reviews & User Content

If you leave a review, photo, or comment:

  • Make sure it's accurate and lawful.
  • We may display your first name or initials publicly.
  • We may remove or edit content that violates our terms.

14. Third-Party Links

We may link to other websites (e.g., providers, social media).

We are not responsible for their privacy practices — please review their own policies.

15. Contact Us

If you have any questions or requests about this Policy, contact:

Privacy Officer — Gifto Canada, Inc. (Gifto)
support@gifto.ca