๐Ÿšง   Work in Progress โ€” This policy is a draft and has not yet been reviewed by legal counsel

Overview

Islandview Harbour ("we", "our", or "the marina") operates the website at islandview.club. This Privacy Policy explains what personal information we collect, why we collect it, and how it is used and protected.

By using our website or creating an account, you agree to the practices described in this policy.

TODO: Add governing law clause โ€” confirm Ontario PIPEDA / provincial privacy legislation applicability and effective date once reviewed.

Information We Collect

When you create an account or submit an inquiry, we may collect:

When you sign in using Google or Microsoft, we receive your name and email address from those services. We do not receive or store your password.

TODO: Confirm whether any analytics beyond Google Analytics (GA4) are used. List all third-party services that receive data (Supabase, EmailJS, Cloudflare).

How We Use Your Information

We do not sell your personal information to any third party.

Sign-In and Authentication

Our website uses passwordless authentication. When you sign in, we send a one-time verification code to your email address, or you may sign in using your existing Google or Microsoft account through OAuth 2.0.

Session tokens are stored locally in your browser and expire after a period of inactivity. We do not store your passwords.

TODO: Confirm exact session duration policy with technical team (current implementation: active 7 days, hard expiry 14 days of inactivity).

Cookies and Tracking

We use Google Analytics (GA4) to understand how visitors use our site. This service may set cookies and collect anonymous usage data such as pages visited, session duration, and general location. You can opt out using the Google Analytics Opt-out Browser Add-on.

We use local browser storage (localStorage) to maintain your session. We do not use tracking cookies for advertising purposes.

Data Storage and Security

Your data is stored securely using Supabase, a cloud database platform. Data is encrypted in transit (HTTPS) and at rest. Our website is hosted on Cloudflare Pages.

TODO: Confirm Supabase data residency region. Add details about data retention periods and deletion timelines.

Your Rights

You may request access to, correction of, or deletion of your personal information at any time by contacting us. You can also delete your account directly through the My Account section of the website.

If you are a resident of Ontario or Canada, you have rights under PIPEDA (Personal Information Protection and Electronic Documents Act) regarding your personal data.

TODO: Add formal process for data access requests, including response time commitment and contact method.

Third-Party Services

Our website integrates with the following third-party services, each with their own privacy policies:

Contact

Questions about this policy or your personal data can be directed to: