Privacy Policy
Last updated: 2026-04-28.
CapeBretonFirst.com (“we,” “us”) is operated by Chants' IT Solutions. We respect your privacy and handle personal information in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Nova Scotia legislation. This policy explains what we collect, why, who we share it with, and your rights.
1. Information we collect
Account information. Name, email address, hashed password, multi-factor authentication preferences. Created when you sign up.
Booking information. First and last name, email, phone number, billing address (where required by Expedia), check-in and check-out dates, and the property booked. Submitted by you at the time of a hotel booking.
Payment information. Card details are sent directly to Moneris for processing. We retain only the last four digits of the card number, the card type (Visa, Mastercard, etc.), the Moneris transaction ID, and the response code — never the full PAN, CVD, or expiry.
Itinerary & activity. Items you save to favorites, day assignments in your trip planner, AI builder inputs (interests, dates, free-text notes), and concierge requests.
Forum and review content. Anything you post publicly — reviews, blog comments, forum questions and answers.
Newsletter subscription. Email address, optional name, source of signup, and your confirmation status. Subject to CASL double-opt-in: we don't send you newsletters until you click the confirmation link.
Technical information. IP address, browser User-Agent, request timestamps. Logged for security, debugging, and abuse prevention.
2. Why we collect it
- To create and authenticate your account
- To process hotel bookings, payments, and refunds
- To send transactional email (booking confirmations, password resets, MFA codes, concierge acknowledgements)
- To send the newsletter, but only after you confirm your subscription
- To suggest itineraries (AI builder) using your stated preferences
- To prevent fraud, abuse, and system misuse
- To improve the Site through aggregate usage analysis
3. Who we share it with
We share personal information only with the third parties that help us deliver the Site:
- Expedia Group Inc. — for hotel search and booking. Receives guest name, email, phone, billing address, and stay dates as required to book a reservation.
- Moneris Solutions Corporation — for payment processing. Receives card details directly from your browser at checkout.
- Anthropic, PBC — for the AI itinerary builder. Receives your stated interests, dates, party size, and free-text notes (no name or contact info) when you trigger the AI builder.
- Cloudflare, Inc. — provides our DNS and tunnel infrastructure; sees request metadata (IP, User-Agent) but not request bodies in clear text.
- Google LLC (Workspace SMTP) — relays our outbound email.
We do not sell your personal information. We do not share it for advertising profiling beyond the analytics described below.
4. Cookies and analytics
We use a session cookie (cbf_session) to keep you logged in. We don't currently run third-party advertising trackers. If we add analytics in the future (e.g., Plausible or a self-hosted alternative), this section will be updated and your continued use of the Site after the update constitutes consent.
5. Retention
- Account & profile: until you request deletion, or 5 years of inactivity.
- Bookings: 7 years from the date of booking, to satisfy Canadian tax record-retention requirements.
- Payment records (masked PAN, transaction IDs): same as bookings.
- Newsletter subscribers: until you unsubscribe.
- Audit logs (booking attempts, payment events): 2 years.
- Forum posts and reviews: indefinitely (they're public content), but you can request takedown of your own submissions.
6. Your rights
Under PIPEDA you have the right to:
- Access the personal information we hold about you
- Correct any inaccuracies
- Request deletion of your account
- Withdraw consent for marketing communications (use the unsubscribe link in any email)
- File a complaint with the Office of the Privacy Commissioner of Canada
To exercise these rights, email [email protected]. We'll respond within 30 days.
7. Security
We use TLS for all traffic, bcrypt for password hashing, JWT for session tokens, and TOTP-based MFA for admin accounts. Card data is processed by Moneris and is not stored on our servers. We log security-relevant events to a tamper-evident audit log. Despite our best efforts, no system is 100% secure; if we discover a breach involving your personal information, we will notify you and the Office of the Privacy Commissioner as required by law.
8. Children
The Site is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please email us and we will delete it.
9. Cross-border transfers
Some of our service providers (Expedia, Moneris, Anthropic, Google, Cloudflare) operate in the United States and other jurisdictions. Your information may be processed outside Canada and may be subject to the laws of those jurisdictions, including lawful access by foreign government authorities. By using the Site you consent to this transfer.
10. Changes to this policy
We may update this policy. Material changes will be communicated by email if you have an account, and the “Last updated” date at the top will reflect the change. Continued use of the Site after a change means you accept the update.
11. Contact
Privacy questions: [email protected]. Or use our contact form.