Last updated · 16 May 2026 · Version 1.0 (launch)

Data policy, in plain language.

This is the load-bearing version of CommunATI's privacy and data-handling policy. It's written to be readable, not legalese — but the words still mean what they say. The legal/full-text version follows the same structure and is available on request. Disagreements between the two are resolved in your favour.

The short version

If you only read one section, read this.

We collect the minimum data needed to run the directory and let you save your favourites. We don't sell, broker, syndicate, or rent personal data. We don't track you across other sites, and we don't run third-party advertising trackers. Children don't have accounts — the family-side account is for parents and guardians. Indigenous-led organizations control their own listings under OCAP principles. If you want a copy of your data or want it deleted, write privacy@communati.ca and we'll respond inside 30 days.

What we collect

The full list, by surface.

Family-side account (parents / guardians)

Email address (required, used to send program reminders and account email), display name (optional), region of Manitoba (optional, used to surface nearby programs), preferred language (en or fr), and an opaque user ID generated on signup. Optional: list of orgs you follow, list of saved favourites, notification preferences.

We never store: full birthdate, postal code, phone number, address, payment method, or any data about your kids.

Member-org account

Email address, display name, org name, org public address (the address you publish on the directory), region, optional logo image, optional photos of the program space, billing email. Billing data (card / banking) is held by our payment processor and never touches CommunATI's database; we see only a redacted last-4 and an opaque customer ID.

Public directory listings

Whatever the member org chooses to publish: org name, program names, age bands, schedules, geocoded address (a map pin, derived from the public street address), description, contact email, registration link. This information is intentionally public — that's the point of a directory.

Server logs (everyone)

Standard web-server logs: IP address, user-agent string, requested URL, timestamp, referer (if your browser sent one), response status. Retained 30 days for security and operational debugging, then deleted. Not joined with account data and not used for analytics on individuals.

Analytics (aggregate only)

We track aggregate counts (how many people viewed a page, how many added a program to favourites this week) using server-side counters keyed on the URL — not the user. No third-party analytics scripts, no Google Analytics, no Facebook pixel, no cross-site tracking cookies. We use a single first-party session cookie to keep you signed in.

Form submissions

If you fill out the contact form, the volunteer signup, or a sponsorship inquiry, we store what you submitted plus a timestamp. Used to reply to you, not for marketing. Retained two years from last contact, then deleted unless you become an active sponsor or member org (in which case retention follows that account).

What we don't do

Explicit non-actions.

Where data lives

Hosting, location, and security.

Data is hosted by Supabase in their Canada (Central) region (Toronto). Static site assets are served by Netlify's global CDN; static asset requests are not joined with account data. Backups are encrypted at rest and held in the same region. Card / banking data is held by our payment processor (their own SOC 2 / PCI-DSS environment) and never touches CommunATI's database.

Authentication uses industry-standard hashed credentials (bcrypt-equivalent). All connections to the platform are TLS-encrypted. Access to the production database is limited to two named individuals and is logged.

If a data breach affects personal information, we will notify affected users by email inside 72 hours of confirmation, post a public incident notice on the homepage, and report to the Office of the Privacy Commissioner of Canada as required by PIPEDA.

Your rights under PIPEDA

What you can ask for, and how.

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) you have the right to:

To exercise any of these rights, email privacy@communati.ca from the address on file (or, for account-less requests, give us enough information to find the data). We respond inside 30 days. There is no fee for reasonable requests.

Indigenous data sovereignty

OCAP principles for Indigenous-led STEM listings.

Indigenous-led organizations on CommunATI control their own listings under the OCAP® principles — Ownership, Control, Access, and Possession (First Nations Information Governance Centre). Specifically:

The Indigenous-led STEM page has the broader partnership statement; this section is the data-handling subset of it.

Cookies

What we set, and why.

CommunATI uses a small number of first-party cookies. We do not use third-party advertising or analytics cookies.

There is no cookie-consent banner because we don't set any cookies that require consent under PIPEDA or CRTC anti-spam / electronic-communications rules. If that changes (e.g., if we add a third-party embed), the banner will appear.

Changes to this policy

How this page updates.

Material changes — new data categories collected, new third-party processors, new sharing arrangements — are announced at least 30 days before they take effect, by (a) an email to all account holders and (b) a banner on this page. Non-material changes (wording clarifications, fixing typos, updating contact addresses) are noted in the version history below without notice.

Version 1.0 — 16 May 2026. Launch version. Earlier drafts existed internally but were never live.

Privacy contact.

Bay Tech Ltd. is the organization responsible for personal information collected through CommunATI. Privacy officer: Shawn Brezden. Write privacy@communati.ca for any data-access, correction, or deletion request, or for any question about this policy.

Email privacy@communati.ca General contact