1. POLICY STATEMENT
1.1 Sport for Life Society is committed to protecting your privacy and the security of information you provide to us. Sport for Life Society will not sell, rent, lease or disclose customer information to third parties unless required by law or unless you provide consent to such a disclosure.
1.2 Sport for Life Society is committed to a safe, welcoming and inclusive environment, and in asking self disclosure questions, will use that information in an anonymous reporting format and will protect from the individual from bias that such disclosure can lead to.
1.3 Privacy of personal information is governed by the Personal Information Protection and Electronics Documents Act ("PIPEDA"). This policy describes the way that Sport for Life Society collects, uses, safeguards, discloses and disposes of personal information, and states Sport for Life Society’s commitment to collecting, using and disclosing personal information responsibly. This policy is based on the standards required by PIPEDA and Sport for Life Society’s interpretation of these responsibilities.
2.1 “Act” – Personal Information Protection and Electronic Documents Act.
2.2 “Personal Information” – any information about an identifiable individual including information that relates to their personal characteristics including, but not limited to, gender, age, income, home address or phone number, ethnic background, family status, health history and health conditions, NCCP number, education, resumes, fitness results, credit card or chequing information, date of birth, athlete history, birth certificate, performance results, certifications, awards, height, weight, uniform size, shoe size, feedback from coaches and trainers, video footage, photographs, banking information, social insurance number, criminal records check, reference checks, beneficiaries, passport numbers, frequent flyer numbers, and discipline results. Personal information, however, does not include business information (e.g. an individuals’ business address and telephone), which is not protected by PIPEDA.
2.3 "Sport for Life Representative" – Any individual employed by, or engaged in activities on behalf of, Sport for Life Society including: employees, contractors, volunteers, researchers, Directors of the Board, Members, committee members, and administrators.
3. COLLECTION AND CONSENT OF PERSONAL INFORMATION
3.1 When you engage in activities on our website, Sport for Life Representative may ask you to provide us with personal information.
By choosing to enter and submit the requested personal information when prompted, you are consenting to Sport for Life Representative’s collection, use, and disclosure of such personal information for the purposes of providing the services to you as outlined herein.
3.3 You have the right to withdraw consent at any time by providing reasonable notice to the Sport for Life Representative at firstname.lastname@example.org. If a request to withdraw consent requires that the Sport for Life delete an individual’s registration information, the Sport for Life will no longer be able to provide the communication for which an individual has subscribed. Cancellation will be subject to the terms and conditions of the registration or services provided, as applicable, and subject to the terms of this Policy.
3.4 The Sport for Life collects only the information that is necessary for the purposes outlined in this Policy.
4.1 Sport for Life Society’s Privacy and Sensitive Information Policy is designed to comply with applicable privacy legislation in Canada. It incorporates the following principles:
ii. Identifying Purpose
iv. Limiting Collection
v. Limiting Use, Disclosure and Retention
vi. Accuracy of Personal Information
vii. Safeguarding Personal Information
ix. Access to Personal Information
x. Challenging Compliance
xi. Prudent Information Retention
4.2 Abiding by this principle also helps Sport for Life Society comply with the fourth principle of Limiting Collectionand prevents it from collecting information that is not required for its intended purposes.
4.3 The principle of Identifying Purposes states that Sport for Life Society must clearly identify the purposes for which personal information is collected, either before or at time of collection. This also helps Sport for Life Society comply with the Openness and Individual Access principles.
4.4 If changes to the Policy are required in the future, those changes will be provided in writing through updates to this Privacy and Sensitive Information Policy and communicated according to Section 11 of this Policy.
4.5 It is Sport for Life Society’s intent that participants will always know what information it collects, how Sport for Life Society uses it and how Sport for Life Society protects it.
4.6 When personal information that has been collected is to be used for a purpose not previously identified, the new purpose will be identified to the specific participant or to the group of which that participant is a member prior to use and consent sought for that use.
5. HOW WE USE YOUR PERSONAL INFORMATION
5.1 Any personal contact information collected will be used only by Sport for Life Representative to communicate with you in the form of newsletters and notices if you give us permission to do so. Sport for Life Representative uses personal information and/or e-mail addresses for internal purposes only and does not sell, lease or rent information to third parties. This policy outlines how Sport for Life Representative will treat your personal information that we gather in accordance with the Act.
5.2 Personal information is shared with external service providers only to the extent required for the provision of such services. Furthermore, Sport for Life Society does not sell personal information to a third-party organization. External service providers are required to keep the information confidential, to use the information only for the purpose requested and to destroy the information when it is no longer required.
5.3 Sport for Life also collects sensitive information for the purposes of tracking trends and reporting to funders. The information that is collected is collated in an anonymous reporting format and individuals are not matched to their identifying information in this reporting. Additionally, Sport for Life will take precautions to protect individuals from bias that such disclosure can lead to. It is important to understand that asking a person to self-declare their cultural, ancestry, gender or ability does not violate any human rights codes, provided it is made clear that the choice to declare is completely voluntary.
6. SPORT FOR LIFE SOCIETY WEBSITE AND E-NEWSLETTERS
6.1 The purpose of this personal information request will be optional and required only to engage in certain activities. Additional personal information that we may ask you to provide when choosing to engage in other activities on our website will enable us to better understand our users and continue to provide improved services.
6.2 The Sport for Life uses Constant Contact ® to communicate relevant information with our subscribers. Sport for Life is in compliance with the Canadian Anti-Spam Legislation (CASL).
i. Our subscribers are encouraged to provide updates to their personal information as changes occur, to enable continued communication from the Sport for Life Society. To update personal information, contact email@example.com.
7. SPORT FOR LIFE SOCIETY ONLINE STORES (SHOPIFY, CAMPUS)
i. Sport for Life Society’s online store is managed and operated by Shopify Inc. and is responsible for adopting its own Privacy and Sensitive Information Policy. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
ii. Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
i. Sport for Life Campus is managed by Momentum IT Group and is responsible for the Sport for Life’s Privacy and Sensitive Information Policy.
ii. Your payment information is managed and operated through Stripe, Inc.
i. If you choose a direct payment gateway to complete your purchase, then Shopify and Stripe, Inc. store your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
ii. All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
i. We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.
8. SECURITY OF YOUR PERSONAL INFORMATION
8.1 Sport for Life Representative takes the protection of the personal information you provide very seriously. Internal data is shared through secured transmissions and maintained in secured databases.
8.2 Sport for Life Society may hire certain outside contractors to perform services or functions on our behalf (such as web development and graphic design). We will only provide those companies your personal information they need to complete the desired service. They are not permitted to use personal information for any other purpose and are obligated to keep your personal information confidential.
9. PRIVACY ISSUES AND CONCERNS & ALTERING OR CORRECTING INFORMATION
9.1 At any time, you may review, alter or remove any personal information, including the permitted uses of your personal information, by contacting us at:
Sport for Life Society
775 Market Street
Victoria, British Columbia, Canada
If you have any questions or concerns regarding our Privacy and Sensitive Information Policy or should you wish to withdraw your consent, contact us at firstname.lastname@example.org.
10. REVIEW AND APPROVAL
10.1 The Sport for Life’s Board of Directors and CEO shall review this Privacy and Sensitive Information Policy every two years at a minimum.
10.2 The Privacy and Sensitive Information Policy and any amendments to it require approval by the Board of Directors prior to its coming into force.
11. COMMUNICATION OF THE POLICY
11.1 The Privacy and Sensitive Information Policy will posted to the public on the Sport for Life Society’s website.
11.2 A copy of the Privacy and Sensitive Information Policy will be distributed to Sport for Life Representatives.
11.3 When the changes are approved in the Policy, Sport for Life will notify to our subscribers via Constant Contact.
Date Approved: June 21, 2018