Privacy Policy
Last updated: July 2026
1. Introduction
TransPark Technology Inc. ("TransPark," "we," "us," or "our") is committed to protecting the privacy of our clients and website visitors. This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL).
This Policy applies to all personal information collected through our website at transpark.tech, our client portal, our support systems, and any other interactions you have with TransPark.
By using our Services, you consent to the collection, use, and disclosure of your personal information as described in this Policy. If you do not agree with this Policy, please do not use our Services.
2. Information We Collect
We collect the following categories of personal information:
Personal Identification Information: Full name, email address, phone number (optional), company name (optional), mailing address, and any other information you provide during account registration or support interactions.
Billing Information: Billing name, billing address, payment method type, and last four digits of your credit card. Full credit card numbers and sensitive payment data are processed directly by Stripe and are never stored on TransPark servers.
Usage Information: Server access logs, bandwidth usage, storage consumption, login timestamps, IP addresses used to access your account, support ticket history, and service usage patterns.
Technical Information: Browser type and version, operating system, device type, screen resolution, referring URLs, and pages visited on our website.
Cookie Information: Session identifiers, preference settings, and analytics data collected through cookies and similar tracking technologies as described in Section 8 of this Policy.
Communications: Emails, support tickets, live chat transcripts, and any other correspondence between you and TransPark.
3. How We Use Your Information
We use your personal information for the following purposes:
Service Delivery: To provision, maintain, and manage your hosting services, domain registrations, and associated products. This includes server configuration, DNS management, backup operations, and technical maintenance.
Billing and Payments: To process transactions, generate invoices, manage subscriptions, process refunds, and communicate billing-related matters including overdue payment notices.
Technical Support: To respond to support requests, troubleshoot issues, and provide assistance with your services. Support interactions may be logged for quality assurance and training purposes.
Service Communications: To send essential service notifications including maintenance schedules, security alerts, service updates, and account-related communications. These communications are transactional in nature and are not subject to marketing opt-out preferences.
Marketing Communications: With your express consent, to send promotional emails, newsletters, product announcements, and special offers. You may withdraw consent for marketing communications at any time by using the unsubscribe link in any marketing email or by contacting us.
Security and Fraud Prevention: To detect, prevent, and respond to security incidents, fraud, abuse, and violations of our Terms of Service or Acceptable Use Policy.
Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
Service Improvement: To analyze usage patterns, identify trends, and improve our Services, website, and customer experience. Any analytics data used for this purpose is aggregated and de-identified.
4. Legal Basis for Processing
Under PIPEDA, we process your personal information based on the following legal grounds:
Consent: You provide consent when you create an account, submit information through our forms, or opt in to marketing communications. Consent may be express (active opt-in) or implied (reasonable expectations based on our existing relationship).
Contractual Necessity: Processing is necessary for the performance of our contract with you, including service delivery, billing, and support.
Legitimate Interests: Processing is necessary for our legitimate business interests, such as security monitoring, fraud prevention, and service improvement, provided these interests do not override your privacy rights.
Legal Obligation: Processing is required to comply with applicable Canadian laws and regulations, including tax reporting requirements and responses to valid legal orders.
You may withdraw your consent at any time, subject to legal or contractual restrictions, by contacting our Privacy Officer. Withdrawal of consent may affect our ability to provide certain Services to you.
5. Data Storage Location
All personal information collected by TransPark is stored exclusively on servers located in Montreal, Quebec, Canada, within the Amazon Web Services (AWS) ca-central-1 region.
We guarantee that your personal information will not be transferred to, stored in, or processed by servers or personnel located outside of Canada. This commitment applies to all primary data stores, backup systems, and disaster recovery infrastructure.
Our Montreal-based infrastructure provides:
- Physical security through AWS's SOC 2 Type II certified data centres
- Encryption at rest using AES-256 encryption
- Encryption in transit using TLS 1.2 or higher
- Network isolation and firewall protection
- Regular security audits and vulnerability assessments
This Canadian data residency guarantee supports compliance with federal and provincial regulations that require personal information of Canadians to remain within Canadian borders.
6. Data Retention Periods
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our specific retention periods are:
Active Accounts: Personal information associated with active accounts is retained for the duration of the account relationship. We retain this information to provide ongoing services, maintain accurate billing records, and support your account.
Cancelled Accounts: Upon account cancellation, personal information and associated Content is retained for thirty (30) days to allow for account recovery or data retrieval requests. After this period, data is permanently and irreversibly deleted from all primary systems.
Backups: Automated backup copies of account data are retained for seven (7) days on a rolling basis. When account data is deleted from primary systems, it is purged from backup systems within the next backup rotation cycle (maximum 7 days).
Server and Access Logs: Technical logs including IP addresses, access timestamps, and request metadata are retained for ninety (90) days for security monitoring and troubleshooting purposes, after which they are automatically purged.
Billing Records: Transaction records, invoices, and payment history are retained for seven (7) years to comply with Canadian tax reporting requirements under the Income Tax Act and Excise Tax Act.
Support Communications: Support ticket content and correspondence are retained for three (3) years after the last interaction to provide continuity of service and to resolve potential disputes.
7. Third-Party Processors
We share personal information with the following third-party service providers who assist us in delivering the Services. Each provider is bound by a Data Processing Agreement (DPA) that requires them to protect your information in accordance with PIPEDA and this Privacy Policy.
Stripe, Inc. (Payment Processing): Stripe processes all payment transactions on our behalf. Stripe receives your billing name, billing address, and payment card details directly. Stripe is PCI-DSS Level 1 certified and processes data in accordance with its own privacy policy. TransPark does not have access to your full credit card number. Stripe's privacy policy is available at stripe.com/privacy.
Amazon Web Services (AWS) (Infrastructure Provider): AWS provides the cloud computing infrastructure on which our Services operate, including servers, storage, and networking within the ca-central-1 (Montreal) region. AWS acts as a data processor and does not access or use your personal information for its own purposes. AWS maintains SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, and CSA STAR certifications.
NameSilo, LLC (Domain Registration): NameSilo provides domain name registration and DNS management services. When you register a domain through TransPark, your registrant contact information (name, email, address, phone) is shared with NameSilo and may be disclosed to the relevant domain registry (CIRA for .ca domains, ICANN for generic TLDs) as required by registry policies.
We do not sell, rent, or trade your personal information to any third party for marketing or advertising purposes. We do not share your personal information with third parties except as described in this Policy or with your explicit consent.
8. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance your browsing experience and to collect information about how you interact with our site.
Essential Cookies: These cookies are necessary for the website to function and cannot be disabled. They include session cookies that maintain your login state and preference cookies that remember your settings (such as language or theme preferences).
Analytics Cookies: We use analytics tools to understand how visitors interact with our website, including which pages are visited, how long visitors spend on each page, and how they navigate through the site. Analytics data is aggregated and does not identify individual users.
Preference Cookies: These cookies remember your choices and settings to provide a more personalized experience, such as your preferred language, region, or display preferences.
We do not use third-party advertising cookies or cross-site tracking technologies. We do not participate in ad networks or behavioural advertising programs.
You can control cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain features of our website or client portal. Most browsers allow you to refuse cookies, delete existing cookies, or alert you before a cookie is stored.
9. Your Rights Under PIPEDA
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have the following rights regarding your personal information:
Right of Access: You have the right to request access to the personal information we hold about you. Upon receipt of a written request, we will provide you with a copy of your personal information within thirty (30) days. In limited circumstances, we may extend this period by an additional thirty (30) days with notice to you.
Right of Correction: You have the right to request correction of any personal information that is inaccurate, incomplete, or outdated. We will make corrections within thirty (30) days of receiving a validated request and will notify any third parties to whom we disclosed the incorrect information.
Right of Deletion: You have the right to request deletion of your personal information, subject to legal and contractual retention requirements. We will process deletion requests within thirty (30) days and confirm completion in writing.
Right to Withdraw Consent: You may withdraw consent for the collection, use, or disclosure of your personal information at any time, subject to legal or contractual restrictions. We will inform you of the implications of withdrawal, which may include our inability to provide certain Services.
Right to Complain: If you are not satisfied with our response to your privacy request, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca or by calling 1-800-282-1376.
To exercise any of these rights, contact our Privacy Officer at privacy@transpark.tech. We may require verification of your identity before processing your request to protect against unauthorized access to personal information.
10. Data Breach Notification
In the event of a breach of security safeguards involving personal information that creates a real risk of significant harm to individuals, TransPark will:
Notify Affected Individuals: We will notify all affected individuals within seventy-two (72) hours of confirming the breach. Notification will be provided via email to the address on file and will include: a description of the breach, the types of personal information involved, the date or timeframe of the breach, a description of the steps we are taking to address the breach, and steps you can take to mitigate any harm.
Report to the Privacy Commissioner: Where the breach creates a real risk of significant harm, we will report the breach to the Office of the Privacy Commissioner of Canada as required by PIPEDA. The report will include all information required under the Personal Information Protection and Electronic Documents Act and the Breach of Security Safeguards Regulations.
Record Keeping: We maintain records of all breaches of security safeguards, regardless of whether they meet the threshold for notification, for a period of twenty-four (24) months as required by PIPEDA.
Mitigation: Upon discovering a breach, we will immediately take all reasonable steps to contain the breach, assess the scope and impact, and implement measures to prevent recurrence.
11. Children's Privacy
TransPark Services are not directed at children under the age of thirteen (13). We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take immediate steps to delete that information from our systems.
If you are a parent or guardian and believe that your child has provided personal information to TransPark without your consent, please contact our Privacy Officer at privacy@transpark.tech immediately.
Individuals under the age of eighteen (18) must have the consent of a parent or legal guardian to create an account or use our Services.
12. International Transfers
TransPark does not transfer personal information outside of Canada. All data processing, storage, and backup operations occur exclusively within Canadian borders, specifically within the AWS ca-central-1 region located in Montreal, Quebec.
Our third-party processors (Stripe, AWS, NameSilo) may have corporate operations in other countries; however, under our Data Processing Agreements, the processing of TransPark client data is restricted to Canadian infrastructure.
In the event that a transfer of personal information outside of Canada becomes necessary in the future (which is not currently anticipated), we will: (a) notify affected individuals in advance; (b) ensure that the receiving jurisdiction provides an adequate level of protection; and (c) implement appropriate contractual safeguards to protect the information.
13. CASL Compliance
TransPark complies with Canada's Anti-Spam Legislation (CASL) in all electronic communications. We will only send commercial electronic messages (CEMs) with your express or implied consent as defined by CASL.
Express Consent: We obtain express consent through clear opt-in mechanisms when you subscribe to our newsletter, request marketing communications, or indicate your preference during account registration.
Implied Consent: We may send CEMs based on implied consent arising from an existing business relationship (within two years of your last purchase or transaction) or an existing non-business relationship (within six months of your last inquiry).
All commercial electronic messages sent by TransPark include: our identity and contact information, a clear and functioning unsubscribe mechanism, and a physical mailing address. Unsubscribe requests are processed within ten (10) business days as required by CASL.
14. Changes to This Policy
TransPark reserves the right to update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs.
Material changes to this Policy will be communicated to you via email at least thirty (30) days prior to the effective date of the changes. We will also update the "Last updated" date at the top of this Policy.
Non-material changes (clarifications, formatting, or corrections that do not affect your rights) may be made without advance notice.
Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree with the changes, you must discontinue use of the Services before the effective date.
The most current version of this Privacy Policy is always available at transpark.tech/legal/privacy.
15. Privacy Officer Contact
TransPark has designated a Privacy Officer responsible for overseeing compliance with this Policy and with PIPEDA. For any questions, concerns, access requests, or complaints regarding your personal information or this Privacy Policy, please contact:
Privacy Officer
TransPark Technology Inc.
1910 Haiku Street
Ottawa, Ontario K2J 6W8
Canada
Email: privacy@transpark.tech
We will acknowledge receipt of your inquiry within two (2) business days and provide a substantive response within thirty (30) days. If additional time is required, we will notify you of the expected timeline.
This document does not constitute legal advice. Consult a qualified legal professional for guidance specific to your situation.
TransPark Technology Inc. · 1910 Haiku Street, Ottawa, Ontario K2J 6W8, Canada · privacy@transpark.tech