1. Who we are and who is accountable
The experience marketplace at feelit.ca is operated by 2828468 ALBERTA INC., a corporation incorporated in Alberta, Canada, carrying on business as FeelIt, at 3-1626 28 Ave SW, Calgary, AB T2T 1J4. That corporation is the organization accountable for the personal information under our control.
Privacy Officer. The person in charge of protecting personal information at 2828468 ALBERTA INC. is the Director of the corporation, whom this policy calls the Privacy Officer. You can reach that person by email at [email protected] — please put “Privacy” in the subject line — or by mail at 2828468 ALBERTA INC., 3-1626 28 Ave SW, Calgary, AB T2T 1J4. If you want the name of the individual who holds that role, ask us and we will tell you. The same person answers questions about how our service providers outside Canada collect, use, disclose or store your personal information. Ask us and we will send you our written information about those providers — by email or by post, whichever you prefer. Sections 6 and 7 explain who they are and where they are.
FEELIT™ is a trademark of 2828468 ALBERTA INC.
2. Which laws apply
We are an Alberta corporation, so Alberta’s Personal Information Protection Act (PIPA) governs the personal information we handle within Alberta, and Canada’s federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs it whenever it crosses a provincial or national border. That happens for every customer, because our servers and some of our service providers are outside Canada. Where the two differ, we apply the stricter one. If you are in Quebec or another province with its own private-sector privacy law, that law applies to you in addition — see section 14.
3. What we collect
If you buy
- Your name and email address, and a phone number if you add one to your account.
- What you bought: the experience, the date and time, how many guests, and any gift message you write.
- Payment is handled by Stripe on its own secure pages — we never see or store your card number. Stripe tells us that the payment succeeded and gives us a reference for it.
- Anything you write to us. Email you send us is kept as a conversation thread under your email address — the message, the formatted copy of it, and the name, size and type of any attachment, but not the attached file itself — so we can see what was asked and what was answered.
If someone sends you a gift
- A gift is a booked visit: the buyer chooses the date at checkout — and the time, where the Experience Provider publishes times — and the certificate shows that booking. If your certificate shows no date, it was sold earlier, under our previous arrangement, and you pick the day yourself. Either way, the buyer gives us your name and email address so we can send you the certificate. We use them to deliver it and to support the visit it is for — never for marketing, and we never add you to a mailing list.
- You did not ask us for any of this, and we know it. If you would rather we did not hold your details, tell us: we will take your name and email off the certificate, stop writing to you about it, and delete what we are not required by law to keep — see section 12.
When a booking is confirmed or moved
- The person confirming the visit — or, where the certificate shows no date, the person booking it — gives a name, an email address and, optionally, a phone number. We pass the Experience Provider what it needs to host the party — section 6 sets out exactly what it receives.
- The code on the certificate is what authorises this: whoever holds it can see the booking and confirm or move it without signing in. That is why we limit how many codes can be tried from one address, and why the code is worth treating like a ticket.
- If the visit is moved, we keep a record of the move: the time it was moved from, the time it was moved to, who moved it, and the reason if one is given. Within 48 hours of the visit the Experience Provider has to agree to a change, so that one goes through us — write to us and we arrange it, and what that adds to your record is your message and the new time.
If you list experiences with us
- Business and contact details, the experiences you publish, and documents you upload — for example your insurance endorsement page.
- What we need in order to pay you and to keep tax records: your payout details and, if you have one, your tax registration number.
- A record of your acceptance of our agreement: the version accepted, the date and time, the IP address it came from, your browser’s user-agent string, and the signature you type or draw. This exists so that what was agreed, and when, can be proved later.
- Messages you send us from the Support page in your dashboard, and any files you attach to them, are kept as one continuous thread for your account, together with our replies. The files stay on our own server.
If you sell for us
- If we invite you to sell for us, we create an account for you — your name and email address — before you have agreed to anything, so that your personal onboarding link works. If you never take it up, tell us and we will delete it.
- Your name and contact details, and the referrals credited to you.
- A record of your acceptance of our sales agreement: the version, the commission share it carried, the date and time, the IP address, your browser’s user-agent string and the signature you type or draw. The yearly statement that you work independently is signed and stored the same way.
- A record of what we have paid you: the amount, the period, the date and the method.
- Messages you send us from the Support page in your dashboard, and any files you attach to them, are kept as one continuous thread for your account, together with our replies. The files stay on our own server.
Everyone who visits the site
- Our servers see the ordinary technical details of a request, including your IP address. We use them to keep the site running and to stop abuse — for example, we limit how many certificate codes can be tried from one address in ten minutes.
- When the site is limited to invited visitors, as it has been at times, entering the access code we gave you adds the address you are connecting from to a list of allowed addresses. That list stays until we clear it — see section 9.
- The photos on our pages are delivered by Cloudinary, so your browser fetches them from Cloudinary directly and Cloudinary sees that request, including your IP address — the same thing that happens on any site whose images come from another company. Sections 6 and 7 say who Cloudinary is and where our providers are.
- First-party analytics, if you leave them on. Section 8 lists exactly what is stored and how to switch it off.
4. Why we use it
- To take orders, issue certificates, confirm and move bookings, and provide support.
- To give the Experience Provider what they need to host you.
- To send transactional email: receipts, certificates, booking confirmations and changes, and answers to what you ask us.
- To prevent fraud and abuse of certificate codes.
- To keep the tax and accounting records the law requires us to keep.
- Marketing email. We do not send any today. If we start, it will be opt-in only — you would have to ask for it separately — and every message will carry a working unsubscribe link, as Canada’s anti-spam law requires. We do not send marketing to gift recipients.
- Business invitations. We invite businesses to list their experiences with us. We write to a business address only where we may lawfully do so — typically an address the business publishes for enquiries of this kind, or one it gave us directly — and we record why we wrote and where the address came from. Every invitation we send to a business about listing its experiences identifies us, gives our mailing address and carries a one-click unsubscribe that needs no account: use it and we will not write again. Some of these invitations are sent by representatives working for us. Their messages identify us as well, and an unsubscribe reaches us the same way — through our own system it takes effect at once, and in every case within ten business days, which is what our agreement with them requires. Inviting someone to represent us is a different thing: that is a message written to one person, and telling us you are not interested ends it. None of this applies to customers or gift recipients.
5. Consent, and how to withdraw it
- We ask for what we need to do the thing you asked for, and we say why at the point we ask.
- Analytics work on an opt-out basis: they are on by default, the banner is the notice, and switching them off takes effect immediately (section 8). An analytics event is stored with no account, no name, no email address and no IP address attached; section 8 lists exactly what an event does carry.
- You can withdraw your consent at any time by writing to us. Some things then stop working: we cannot deliver a certificate without an email address, and we cannot have you hosted without giving the provider a name and a contact.
- Withdrawing consent does not reach records we are required by law to keep — see section 9.
- If we ever want to use information we already hold for a new purpose, we will ask you first. We will not do it by quietly updating this page.
6. Who we share it with
- The Experience Provider hosting your booked experience receives what it needs to host you: the guest’s name, the party size, the booked time and a contact. It is told about the booking as soon as the order is paid for — including when the booking was bought as a gift, because the seats are taken from that moment. When the booking was bought as a gift, it also receives the buyer’s name and contact details and what was entered on the certificate, including the gift message, and then, once the recipient confirms, the name, email address and any phone number that person gives us. Our agreement with them forbids using any of it for their own marketing.
- Service providers that run our infrastructure, each of which we use for one purpose only:
- Stripe — payments and refunds (United States).
- Resend — sending our email and receiving mail sent to us (United States).
- Cloudinary — hosting and delivering the photos on our pages. Your browser loads those photos from Cloudinary itself, so Cloudinary sees the request, including your IP address.
- Our hosting provider — the servers our site and database run on (European Union).
- Authorities, where the law requires it.
- We do not sell personal information. Ever.
7. Where your information is stored
Our servers are in the European Union. Stripe and Resend process data in the United States. Cloudinary delivers our images on its own content-delivery network, which has locations in several countries. If you want to know the exact country a particular provider stores or serves your information from, ask us in writing: we will put the question to that provider and tell you what we are told.
We changed hosting providers in August 2026. Until that change has finished spreading through the internet’s address records, some requests to feelit.ca still reach us through a server at our previous provider, which passes them on to the new one. It is switched off once the change is complete.
We also keep a copy of our database in Canada, on equipment we control in Calgary. That copy is refreshed twice a day.
This means your information may be stored and processed outside Canada, and while it is there it may be accessible to the authorities of those countries under their own laws. Using a provider outside Canada does not reduce our responsibility for your information: we remain accountable for it wherever it is handled.
You can ask us for information about our policies and practices in respect of service providers outside Canada, and we will send it to you in writing — by email or by post, whichever you prefer. The Privacy Officer described in section 1 is the person who answers questions about how those providers collect, use, disclose or store your personal information.
8. Cookies, browser storage and analytics
What we store on your device
- feelit_tokens — keeps you signed in. Browser storage, written when you sign in.
- feelit_cart — what is in your cart. Browser storage. It is created when the site first loads in your browser, is empty until you add something, and is updated as you add or remove items.
- feelit_theme — your light or dark choice. Browser storage, written when you choose a theme.
- feelit_cookie_prefs — your cookie choices. This one is stored twice: as a real cookie, which your browser sends to us with every request to feelit.ca, and as a copy in browser storage. The cookie is set to expire two years after your most recent visit and is refreshed every time you come back; the copy in browser storage stays until you clear it. Each copy restores the other, so clearing both is what brings the banner back.
The Analytics switch in the banner is the one that changes what we collect. The other three are how the site works in your browser: your sign-in token is sent to us when your browser asks us for something on your account, feelit_cookie_prefs travels with every request because that is what a cookie does, and your cart and your theme stay on your device. None of them is used to follow you across other websites.
Analytics
- First-party only. There are no third-party advertising or social trackers on this site — not one. The analytics data goes to us and to nobody else.
- Analytics are on by default. The consent banner appears on your first visit: open Manage Cookies, switch Analytics off and save. It takes effect immediately, without reloading the page. After that the banner does not come back, and the way in is the Cookie preferences link in our footer — at the bottom of this page, of the home page and of every experience page. A few screens, such as the checkout and the certificate page, have no footer; open one that does. Your choice is stored on your device, so we cannot change it for you: change it there, or clear both copies of feelit_cookie_prefs as described above to bring the banner back.
- We record five things: opening a page, opening an experience, adding something to the cart, starting checkout, and a confirmed purchase.
- Stored with each event: the type of event, the address of the page it happened on, the experience it relates to when there is one, small details such as whether a cart item was a gift and how many guests, and the time. No account, no name, no email address and no IP address is attached to an analytics event — not even when you are signed in.
9. How long we keep it
- Orders, bookings and certificates: for as long as the certificate or booking can still be used, and after that as part of the tax and accounting records we keep of our sales. A certificate that does not show a date never expires — that is a promise we make, not a deadline the law sets for us — so for those we hold the order and the certificate until the visit happens, however long that takes.
- Account data: while your account exists.
- Messages you send us: kept as a conversation thread under the email address they came from — and, for messages sent from the Support page in a partner dashboard, with the files attached to them — for as long as we may need them to deal with what was asked and with anything that follows from it.
- Partner and sales-agent records: the agreement and the record of its acceptance (the version, the date and time, the IP address, the browser’s user-agent string and the signature), what we have paid you, and documents you upload such as an insurance endorsement — kept while the agreement is in force, and after that for as long as a claim about it could still be brought and as part of our tax and accounting records.
- Analytics events: kept as site statistics for as long as those statistics are useful to us. They are not attached to an account, a name, an email address or an IP address.
- Server records of requests, including IP addresses: kept on the server only for as long as we need them to run the site, investigate faults and stop abuse. We do not build a profile of you from them.
- Addresses allowed past our access wall: kept until we clear the list.
- Records of security incidents: at least two years — see section 11.
- You can ask us to delete anything we are not required to keep — see section 12.
10. How we protect it
- Traffic between you and the site is encrypted (HTTPS).
- Card details never reach our servers: Stripe’s own hosted page handles them.
- The sign-in links we email can only be used to sign in to a customer account, they stop working after seven days, and changing your password invalidates any link already sent.
- Administrative access to our server needs a key rather than a password, and repeated failed attempts are blocked automatically. Our own administration goes over a private network channel; our automated deployment reaches the server over the public internet, using the same key-only access.
- The database is backed up every night on the server and copied to equipment we control in Canada twice a day, and we test a restore every week.
No system is perfect. Section 11 says what we do when something goes wrong.
11. If there is a breach
If a breach of our security safeguards creates a real risk of significant harm to you, we will report it to the privacy regulators and tell you. Federal law (PIPEDA) requires both. Alberta’s PIPA requires the report to the Alberta Commissioner without unreasonable delay. We will tell you as well. If you are in Quebec, Quebec’s law applies too: where an incident presents a risk of serious injury we would notify the Commission d’accès à l’information and each person affected.
We keep a register of confidentiality and security incidents whether or not an incident has to be reported, and we keep those records for at least two years.
12. Your rights
- Ask what personal information we hold about you, and get a copy of it.
- Ask us to correct it if it is wrong.
- Withdraw your consent, with the consequences described in section 5.
- Ask us to delete information we are not legally required to keep.
- Complain to the Privacy Officer (section 1) at [email protected]. You can also take a complaint to the Office of the Information and Privacy Commissioner of Alberta or to the Privacy Commissioner of Canada. If you are in Quebec, you can go to the Commission d’accès à l’information.
There is no self-service button for any of this yet: write to us at [email protected] or by mail to the address in section 1, and we will handle it.
If you are a gift recipient, these rights are yours too — including asking us to delete your details if you do not want the gift. Tell us and we will take your name and email off the certificate and stop writing to you about it.
13. Children
Purchases on FeelIt are for adults (18+). Minors may take part in experiences only as attendees, under the Experience Provider’s rules and with the consent that provider requires.
14. Quebec and other provinces
If you are in Quebec, or in another province with its own private-sector privacy law, additional rights may apply to you under that law. Contact us and we will honour them. Section 1 publishes the title and contact details of the person in charge of protecting personal information; section 11 names the Quebec regulator.
15. Changes to this policy
We may update this policy. The date at the top tells you when the version you are reading was posted. If a change is material, it takes effect no earlier than 30 days after we post it here. We keep previous versions — ask us for the one that applied to you. As section 5 says, a new use of information we already hold needs your consent: an updated page is not a substitute for asking you.
16. Contact
Director of the corporation (Privacy Officer), 2828468 ALBERTA INC., 3-1626 28 Ave SW, Calgary, AB T2T 1J4 — [email protected]. See also our Terms of Service and Refund Policy.