MyOutfitters.ca

Privacy policy

Updated August 24, 2026

Your personal information belongs to you. This page explains, without needless jargon, what we collect when you search for an outfitter, send a request or book a stay — and how to take back control in seconds.

We never sell your dataCompliant with Law 25 and PIPEDAEncrypted requests

Who we are and what this policy covers

MyOutfitters.ca operates a Canadian platform for discovering, comparing and booking outfitter stays — hunting, fishing, ice fishing, nature lodging and family experiences. This policy explains what personal information we collect, why, who we share it with and what your rights are.

It applies to the MyOutfitters.ca website, its subdomains and every communication we send you. It is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25) and Canada's Anti-Spam Legislation (CASL).

The outfitters listed on the platform are independent businesses. When you send them a request or book a stay, they become responsible for the information they receive and apply their own privacy practices.

The information we collect

We apply data minimization: we ask only for what is needed to handle your request or your booking.

  • Requests and bookings: name, email address, phone number if you provide one, stay dates, number of guests, activity and species sought, selected package and the content of your message.
  • Payment: when a payment is required, it is processed by a PCI-DSS certified external provider. We never see or store your full card number — only a transaction reference, the last digits and the status.
  • Browsing preferences: province, regions or ZECs, search filters, display currency, favourites and recently viewed outfitters. These are stored locally on your device.
  • Approximate location: we infer your province from your IP address in order to show relevant regions. That inference relies first on our content delivery network's headers and, failing that, on an external IP geolocation service (ipwho.is, then geojs.io) to which your IP address is sent for that sole purpose. If you enter a postal code, it is used to calculate a distance and stays on your device: we do not keep it on our servers.
  • Technical data: IP address, device type, browser, pages viewed and timestamps, for security, fraud prevention and audience measurement.
  • Outfitter accounts: contact name, business contact details and information about the establishment, when an outfitter signs up or claims its listing.
  • Private messaging: the content of messages exchanged with an outfitter, their attachments and delivery metadata (sent, received, delivery failure, held for review).
  • Reviews: if you post a review, your public display name, the rating, the text, any photos and the dates of the stay concerned.

Why we use it

To forward your request to the outfitter you chose, follow up on your booking, prevent fraud and abuse, meet our legal, accounting and tax obligations, improve search and listings, and — only with your consent — send you our marketing communications.

We never sell your personal information. We do not rent or trade it for advertising purposes, and we do no advertising profiling. The only fully automated processing we apply serves the security and integrity of our messaging: masking direct contact details and detecting attempts to bypass the platform. It is described in the "Private messaging and automated filtering" section.

Who we share it with

The outfitter you contact receives your full first name, your last-name initial, the details of the stay you asked about and the text of your message. Your email address and phone number are not revealed to them: they reply through our private messaging. Your full contact details are only exchanged once a booking is confirmed, because the outfitter then genuinely needs to reach you directly.

Our service providers are bound by contract, limited to our instructions and may not use your information for their own purposes:

We may also disclose information where the law requires it, in response to a valid legal request, or to protect our rights and the safety of individuals.

  • Hosting, database and photo storage: Supabase (Amazon Web Services infrastructure).
  • Sending and receiving email, including private messaging: Resend.
  • Scanning message content for hidden contact details: an artificial-intelligence model from Google (Gemini), called at send time through the Lovable AI gateway. The text is analyzed for the duration of the processing only, is not retained by the provider and is not used to train the model.
  • Payments: our internal administration platform and its PCI-DSS certified provider (Stripe). We never receive your full card number.
  • Analytics: Google Analytics 4, loaded only after your consent, with IP anonymization enabled.
  • Public reviews and map tiles: Google (business profile), OpenFreeMap, CARTO and OpenStreetMap. These services receive your IP address when a map or a review is displayed.
  • Approximate IP-based geolocation: ipwho.is and geojs.io.

Private messaging and automated filtering

Every conversation with an outfitter gets a unique, anonymous reply address. Your real address is never passed to the other party: we rewrite each email and leave only your first name and last-name initial.

Before being relayed, every message is analyzed automatically — first by text rules, then by an artificial-intelligence model — in order to mask phone numbers, email addresses, links and third-party messengers, and to spot clear attempts to bypass the platform. A message assessed as high risk is held for human review: our support team then sees its content in the clear, solely to decide whether to deliver it.

This filtering may delay a message or mask part of it. At any time you may request human intervention, be told the reasons for the decision and ask for it to be reviewed by writing to support@myoutfitters.ca.

Hosting and transfers outside Canada

Some of our providers process or store data outside Canada, notably in the United States and the European Union. In those cases, information may be subject to the laws of the host country. We assess each transfer and contractually require protection equivalent to Canadian law, as Law 25 demands.

How long we keep it

Requests, conversations and attachments related to a stay are kept for up to three years after the last contact, so we can handle follow-up or a possible dispute, then deleted or anonymized. Accounting records tied to a payment are kept seven years, as tax law requires. Analytics data is kept for no more than 26 months. One-time sign-in codes and trusted-device tokens expire within minutes or weeks and are then erased automatically. The communications opt-out list is kept indefinitely — that is precisely what guarantees we will not write to you again.

Preferences saved on your device (province, filters, favourites, currency, pre-filled forms) stay with you: they disappear when you clear your browser or withdraw the "Functional" category from your cookie preferences.

Security

Exchanges with the site are encrypted in transit (HTTPS). The content of your requests and of relayed messages — name, email, phone, message text — is encrypted at rest in our database (AES-256-GCM), with keys held outside the database. The information strictly necessary to fulfil a confirmed booking appears in clear text in the booking record, because the outfitter must be able to welcome you. Access to data is restricted to those who need it, governed by row-level security rules and logged.

As no system is infallible, we maintain an incident response plan. In the event of a confidentiality incident presenting a risk of serious injury, we notify the individuals concerned as well as the Commission d'accès à l'information du Québec and, where applicable, the Office of the Privacy Commissioner of Canada, and we keep a register of such incidents.

Your rights

You may request access to your information, its correction, its deletion, the cessation of its dissemination, and its portability in a structured technological format. You may also withdraw your consent or file a complaint.

Write to confidentialite@myoutfitters.ca: we respond within 30 days at most. If our answer does not satisfy you, you may contact the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada.

Cookies and similar technologies

We use four cookie categories: strictly necessary (always on), functional and preferences, performance and measurement, and targeted advertising. Only the first is enabled without your consent, because the site cannot work without it. We use no advertising cookies today.

In concrete terms: your cookie choice is stored locally as "myoutfitter.consent"; the "mo_contact" cookie remembers your name, email and phone number to pre-fill forms — it lasts one year, is set only if you accept the Functional category, and is deleted as soon as you withdraw it; your search preferences, favourites, currency and recently viewed outfitters are stored on your device; and Google Analytics measurement cookies ("_ga") are only set after you consent to the Performance category.

Minors

The platform is intended for people aged 18 and over. We do not knowingly collect information from a child. The number and ages of children entered in a request are used only to prepare your stay and are forwarded to the outfitter.

Changes

Any significant change will be published on this page with a revised update date. If a change materially affects your rights, we will tell you visibly on the site.

Contact us

Our privacy officer answers any question, access request or complaint.

confidentialite@myoutfitters.ca

Opt out of communications

Enter your email address to be removed immediately from all our marketing communications: newsletters, product news and promotional messages. No account or password required.

We keep your address only on a suppression list, so that we never write to you again.