1. Introduction
Lost & Found Birds ("we", "us", "our") is operated by Bird Sitting Toronto. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at lost-found.birdsittingtoronto.ca (the "Portal"). We are committed to complying with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
2. Information We Collect
Information You Provide
- Post submissions: Name, phone number (optional), email (optional), location, bird description, and photos.
- Alert subscriptions: Email address, bird type preference, location preference.
- Contact form: Name, email, subject, and message.
- Sighting reports: Name, email (optional), message, location, and date.
- Success stories: Title, story text, and optional photo.
Automatically Collected Information
- IP address: Used solely for rate limiting to prevent abuse. Not stored permanently.
- Analytics: We use Vercel Analytics to collect anonymous usage data (page views, performance). No personal data is tracked.
3. How We Use Your Information
- To display your lost/found bird listing on the Portal.
- To send email alerts when matching birds are posted (if you subscribed).
- To notify you of updates to posts you are watching.
- To respond to contact form inquiries.
- To send you a management link for your post.
- To prevent spam and abuse through rate limiting.
- To geocode locations for map display (using OpenStreetMap Nominatim).
4. Third-Party Services
We use the following third-party services:
- Supabase: Database hosting and file storage (servers in US/Canada).
- Vercel: Website hosting and analytics.
- Gmail SMTP: Email delivery for alerts, notifications, and contact form messages.
- OpenStreetMap Nominatim: Location geocoding (only location text is sent, no personal data).
5. Data Retention
- Post data: Retained until you delete it via your management token, or until we remove inactive listings.
- Alert subscriptions: Retained until you unsubscribe via the link in any alert email.
- Contact form messages: Delivered via email and not stored on the Portal.
- Rate limit data: Automatically purged every 5 minutes.
6. Your Rights
Under PIPEDA, you have the right to:
- Access: Request a copy of your personal information.
- Correction: Update or correct your information via your management link.
- Deletion: Delete your post via your management link, or unsubscribe from alerts at any time.
- Withdraw consent: Stop receiving alerts by unsubscribing.
To exercise any of these rights, contact us at postthisad@gmail.com.
7. Security
We implement reasonable security measures including encrypted connections (HTTPS), secure authentication for admin access, rate limiting, and honeypot spam detection. However, no method of transmission over the Internet is 100% secure.
8. Children's Privacy
The Portal is not directed at children under 13. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date.