Gather Events BK Limited
Website: gatherevents.ca
Effective Date: May 24th, 2026 · Last Updated: 2026-05-24
At Gather Events BK Limited (“Gather”, “we”, “us” or “our”), we are committed to protecting privacy and maintaining a general policy of openness about how we collect, use, disclose and protect personal information.
This Privacy Policy explains how we collect, use, disclose, retain and protect personal information when you visit, interact with or use our website, vendor portal, customer-facing booking and inquiry tools, account features, payment-related workflows, communications and related services available through gatherevents.ca (collectively, the “Site” or “Services”).
For the purposes of this Privacy Policy, “personal information” means information about an identifiable individual, including information that identifies, relates to, describes or could reasonably be associated with an individual.
Gather is based in Ontario, Canada. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and other applicable privacy laws.
This Privacy Policy may be cross-referenced by, and read together with, Gather’s Terms of Use and Vendor Agreement.
This Privacy Policy does not apply to the privacy practices of third-party websites, applications or services that we do not own or control, even if they are linked from or integrated with our Site or Services. Those third parties are responsible for their own privacy practices, and we encourage you to review their privacy policies.
If you have any questions or concerns about this Privacy Policy, please contact us using the contact details provided at the end of this Privacy Policy.
The personal information we collect depends on how you interact with Gather, including whether you are visiting the Site, creating an account, listing services as a vendor, making an inquiry or booking as a customer, communicating through the Services, or otherwise interacting with us.
We collect personal information from the following sources:
The following table describes the categories of personal information we may collect.
| Category | Description | Source |
|---|---|---|
| Contact Information | Name, display name, email address, phone number, mailing address, business contact information and similar details. | Directly from you; vendors, customers or other users; service providers. |
| Account and Administration Information | Username, account role, account status, password stored in hashed form, authentication information, preferences, notification settings, account identifiers, timestamps and security tokens. | Directly from you; generated through use of the Services; automatic collection. |
| Vendor Business Profile Information | Business name or display name, business description, vendor category or type, website address, contact person details, delivery options, delivery radius, delivery fees, logos, profile photos, gallery photos, vendor policy documents and other vendor-uploaded content. | Directly from vendors. |
| Offering and Listing Information | Packages, add-ons, service options, descriptions, pricing, images, availability and other information vendors provide about their goods or services. | Directly from vendors. |
| Customer, Inquiry and Booking Information | Customer name, contact details, event date, time and location, event type, guest or attendee count, inquiry details, booking details, order contents, amounts, status history, notes, instructions and other information submitted for an inquiry, booking or order. | Directly from customers; generated through use of the Services; vendors or other users. |
| Payment and Transaction Information | Transaction amounts, charge, refund, invoice and payout records, Stripe account, charge, invoice or payout identifiers, payment status, dispute information and related financial records. | Directly from you; generated through use of the Services; payment processor. |
| Calendar Connection Information | OAuth tokens or credentials needed to connect to calendar services, together with busy/free availability information if you choose to connect a calendar, and the booking event details (such as event title or summary, description and location) that Gather writes to your connected calendar. | Directly from you; calendar providers; generated through use of the Services. |
| Messages, Intake Forms and Communications | Messages exchanged through the Services, vendor notes, customer intake form responses, support requests, attachments, transactional email content, and records of notices or communications sent through the platform. | Directly from you; generated through use of the Services; vendors, customers or other users. |
| Reviews, Ratings and Reports | Ratings, review content, responses to reviews, reports or flags submitted about reviews, and related moderation records. | Directly from users; generated through use of the Services. |
| Security, Audit and Technical Information | IP address, device and browser information, session data, log-in activity, rate-limiting counters, abuse-prevention signals, audit logs, error and diagnostic information, timestamps and technical identifiers. | Automatic collection; generated through use of the Services; service providers. |
| Cookie and Browser Storage Information | Session cookies, CSRF cookies, role or account-state cookies, workflow cookies, cookie-consent choices, session storage and local storage information. | Automatic collection. |
Gather does not store raw payment card numbers, CVVs or bank account numbers. Payment card and bank account details are handled by our payment processor, Stripe, subject to Stripe’s own privacy and security practices. Stripe is the only payment processor used by Gather, and Gather does not store or otherwise receive raw card, CVV or bank account details.
Where calendar sync is enabled, Gather reads busy/free availability information from your connected calendar. In addition, when real-time write-back is enabled, Gather publishes booking event details back to your connected calendar for each booking, including a branded event title or summary, a description and a location. Gather supports calendar connections with both Google Calendar and Microsoft Outlook. Gather does not read the titles, attendees, descriptions or other content of your existing calendar events; it reads only busy/free availability, and it writes Gather booking events as described above.
We use personal information for the purposes described below. We collect, use and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances.
| Purpose | Examples | Categories of Personal Information Used |
|---|---|---|
| To provide and operate the Services | Create, authenticate and manage accounts; operate vendor profiles and listings; enable customer inquiries, bookings, scheduling and orders; enable messaging; display relevant vendor, offering and availability information; write booking events to connected calendars; provide support. | Contact Information; Account and Administration Information; Vendor Business Profile Information; Offering and Listing Information; Customer, Inquiry and Booking Information; Calendar Connection Information; Messages, Intake Forms and Communications. |
| To process payments and transactions | Facilitate payments, payouts, invoices, refunds and disputes; support payment-related onboarding; maintain transaction records; meet tax, accounting and financial obligations. | Contact Information; Payment and Transaction Information; Customer, Inquiry and Booking Information; Account and Administration Information. |
| To communicate with you | Send transactional notices, booking confirmations, inquiry updates, reminders, review requests, account notices, security alerts, administrative messages and support responses. | Contact Information; Account and Administration Information; Customer, Inquiry and Booking Information; Messages, Intake Forms and Communications. |
| To personalize, recommend and market | Provide recommendations; rank, sort or feature vendors and offerings; personalize the experience; perform analytics; and, where permitted, send marketing communications. We may use customer information for these purposes. | Contact Information; Account and Administration Information; Customer, Inquiry and Booking Information; Offering and Listing Information; Security, Audit and Technical Information. |
| To manage vendor and customer relationships | Administer vendor accounts, customer inquiries, bookings, support issues, disputes and platform-related communications. | Contact Information; Account and Administration Information; Vendor Business Profile Information; Customer, Inquiry and Booking Information; Payment and Transaction Information; Messages, Intake Forms and Communications. |
| To moderate and review content | Access and review messages, intake form responses, files and attachments submitted through the Services for moderation, support, dispute resolution, safety and quality purposes. | Messages, Intake Forms and Communications; Customer, Inquiry and Booking Information; Account and Administration Information; Reviews, Ratings and Reports. |
| To protect security and prevent misuse | Authenticate users; maintain secure sessions; apply rate limiting; detect, prevent and investigate fraud, abuse, unauthorized access, credential-stuffing, security incidents or other unlawful activity; maintain audit logs. | Account and Administration Information; Security, Audit and Technical Information; Payment and Transaction Information; Messages, Intake Forms and Communications where relevant to an investigation. |
| To improve and maintain the Services | Understand usage, troubleshoot errors, test and improve features, maintain performance, develop enhancements and diagnose technical issues. | Security, Audit and Technical Information; Cookie and Browser Storage Information; Account and Administration Information; usage and telemetry information. |
| To manage reviews, ratings and reports | Display reviews and ratings, moderate inappropriate content, respond to reports, and maintain the integrity of review features. | Reviews, Ratings and Reports; Contact Information; Account and Administration Information; Vendor Business Profile Information. |
| To comply with legal obligations and protect legal rights | Maintain legally required records; respond to lawful requests; enforce agreements and policies; establish, exercise or defend legal rights; support corporate, tax, accounting and compliance obligations. | Any category of personal information reasonably necessary for the applicable legal, compliance or dispute-related purpose. |
If we wish to use personal information for a materially new purpose, we will identify that purpose and, where required by law, obtain consent before doing so.
We collect, use and disclose personal information with consent, except where applicable law permits or requires otherwise.
Consent may be express or implied, depending on the sensitivity of the information and the context. For example, we may rely on:
You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. For example, you may disconnect calendar sync, adjust notification preferences, opt out of non-essential communications or request deletion of your account. Withdrawing consent may limit or prevent our ability to provide some or all of the Services.
If you provide personal information about another individual, you represent that you have authority to do so and that the individual has been informed of the purposes for which the information is being provided.
We do not sell personal information. We may disclose personal information as described below.
Certain information is shared between vendors, customers and other platform users as necessary to provide the Services. For example:
We may disclose personal information to third-party service providers and vendors that help us operate, host, secure, maintain and improve the Services, process payments, provide calendar integrations, deliver email communications, store files, support diagnostics, or otherwise provide services on our behalf.
Our service providers are required to use personal information only for the purposes for which it was provided to them and to protect personal information using safeguards appropriate to the nature of the information and services provided. We have data processing agreements in place with our service providers.
Current service providers include:
| Service Provider | Purpose | Information Processed |
|---|---|---|
| Stripe | Payments, payouts, invoicing and related payment workflows. | Transaction identifiers, payment status, amounts, contact details and related payment records. Raw card and bank account details are handled by Stripe, not Gather. |
| Google Calendar connection: reading busy/free availability and writing Gather booking events. | OAuth tokens, busy/free availability information, and booking event details (title or summary, description and location) written to the connected calendar. | |
| Microsoft | Outlook Calendar connection: reading busy/free availability and writing Gather booking events where enabled. | OAuth tokens, busy/free availability information, and booking event details (title or summary, description and location) written to the connected calendar. |
| SMTP2GO | Transactional email delivery. | Recipient email address, subject line, message body and delivery-related metadata. |
| Amazon Web Services | Object storage for uploaded files, including vendor images and message attachments. | Uploaded images, documents, attachments and related technical records. |
| Render | Application and database hosting, including Render-managed PostgreSQL with point-in-time backups. | Platform data needed to host and operate the application and database. |
We may update our service providers from time to time as our business and technical infrastructure evolve.
We may disclose personal information to auditors, insurers, legal counsel, financial advisors, consultants and other professional advisors where reasonably necessary for legitimate business, legal, compliance, insurance, accounting or advisory purposes.
We may also disclose or transfer personal information in connection with an actual or proposed financing, merger, acquisition, sale, reorganization, transfer or other transaction involving all or part of Gather or its business or assets, provided that personal information is handled in accordance with applicable law.
We may disclose personal information where we believe it is reasonably necessary to:
Gather is based in Ontario, Canada. Some of our service providers may store or process personal information outside Ontario or outside Canada, including in the United States or other jurisdictions.
When personal information is processed or stored outside Canada, it may be subject to the laws of the jurisdiction where it is located, including lawful access by courts, law enforcement, regulators or government authorities in that jurisdiction.
Regardless of where personal information is processed, Gather remains responsible for personal information under its custody or control and uses contractual and other measures designed to require service providers to protect personal information appropriately.
You may contact our Privacy Officer for more information about our use of service providers located outside Canada.
When you visit or use the Site or Services, we may use cookies, browser storage and similar technologies. A cookie is a small text file stored by your browser. Browser storage may include local storage or session storage maintained by your browser.
We use these technologies to:
Essential cookies and browser storage are necessary for the Site and Services to function properly. These may include session cookies, CSRF cookies, role or account-state cookies, email verification or password reset cookies, vendor sign-up or login workflow cookies, URL masking or redirection cookies, cookie-consent storage, OAuth state values and similar short-lived technical records.
Most essential cookies are short-lived and expire after a limited period. Based on the current platform configuration, the authentication session cookie has a maximum lifetime of approximately 6 hours, the CSRF cookie approximately 6 hours, administrative one-time-password cookies approximately 10 minutes, and administrative session, role and issued-at cookies approximately 6 hours each. Other workflow cookies, including cookie-consent storage, OAuth state, email verification and password reset cookies, are short-lived in accordance with the retention periods described in this Privacy Policy.
Gather only sets essential cookies. We do not currently use optional analytics, advertising, tracking pixel or marketing cookies. If we introduce non-essential analytics, advertising, tracking pixels or marketing cookies in the future, we will update this Privacy Policy and, where required, provide appropriate consent controls.
You may be able to adjust cookie settings through your browser. If you disable certain cookies or browser storage, some features or functionality of the Site or Services may not work properly.
We use administrative, technical and physical safeguards appropriate to the sensitivity of the personal information we handle.
These safeguards include:
Access to personal information is limited to individuals who require access to perform their duties or provide services to Gather, and who are subject to confidentiality, contractual or other obligations appropriate to their role.
No method of transmission or storage is completely secure. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for using appropriate security precautions when accessing the Site or Services.
We retain personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, to provide the Services, to maintain business records, to comply with legal, tax, accounting and reporting obligations, to resolve disputes, to enforce agreements, and to protect the security and integrity of the Services.
Generally, this means personal information will be retained for the duration of your relationship with us and for a reasonable period thereafter, unless a longer or shorter retention period is required or permitted by law.
Based on the current platform design, retention practices may include:
| Type of Information | General Retention Approach |
|---|---|
| Active account information | Retained while the account remains open. |
| Password reset tokens | Short-lived, generally approximately 60 minutes or as configured. |
| Email verification tokens | Short-lived, generally approximately 24 hours or as configured. |
| Authentication sessions | Short-lived, generally approximately 6 hours or as configured. |
| Calendar OAuth state tokens | Short-lived, generally approximately 10 minutes or as configured. |
| Login failure records | Retained as needed for security and cleared in accordance with account and system rules. |
| Audit logs | Each audit log row expires on a per-row basis according to its own expiry value, after which it is removed by a scheduled cleanup process. Audit logs may be retained longer where required for security, legal or compliance purposes. |
| Deleted account tombstones | When an account is deleted, a tombstone record (which stores the account email only as a hashed value) is created. These records are retained for approximately one year and are then removed by a scheduled cleanup process, except where a longer period is required for fraud prevention, legal, tax, audit or compliance purposes. |
| Redis rate-limiting counters | Transient and generally expire within approximately 60 seconds. |
| Uploaded files and object storage | Vendor images, message attachments and other uploaded files are stored in Amazon S3. Under the current lifecycle configuration, objects transition to Amazon S3 Glacier Flexible Retrieval after approximately 30 days and are expired after approximately 365 days, so uploaded files are generally retained for approximately one year. |
| Tax, accounting and financial records | Retained as required by applicable Canadian tax, accounting and legal requirements. |
When personal information is no longer required, we will delete it, anonymize it or de-identify it. If deletion is not immediately possible, such as where information is stored in backup systems, we will protect the information and restrict further processing until deletion or overwriting is possible. Our database is hosted on Render-managed PostgreSQL, which provides point-in-time backups; where data is deleted from the live database, that deletion is reflected in subsequent backups. If necessary, data may be restored from these backups.
If you delete your account, a tombstone record is created (storing your email only as a hashed value), your user record is marked as deleted, and related data is removed or cascaded in accordance with the platform’s deletion processes. Certain information may be retained where necessary for legal, financial, security, fraud-prevention, dispute-resolution or legitimate business purposes. For example, transaction records may be retained as required for legal or accounting purposes. Messages you have sent remain associated with your deleted user record, which no longer contains personal information. The tombstone record itself is removed by a scheduled cleanup process after approximately one year, except where a longer period is required for fraud-prevention, legal, tax, audit or compliance purposes.
Depending on your location and subject to applicable law, you may have certain rights regarding the personal information we hold about you.
Individuals in Canada may request access to personal information held by Gather and request correction of inaccurate or incomplete personal information. Subject to legal exceptions, we will inform you of the existence, use and disclosure of your personal information and provide access to that information. If we cannot provide access, we will explain why, subject to any legal restrictions.
You may also:
To exercise privacy rights or make a request, please contact our Privacy Officer using the contact details below.
We may need to verify your identity before responding to a request. We will respond to requests within the timeframe required by applicable law. In Canada, PIPEDA generally requires organizations to respond to access requests within 30 days, subject to limited extensions permitted by law.
If you are not satisfied with our response, you may contact us to escalate the matter. You may also contact the Office of the Privacy Commissioner of Canada or another applicable privacy regulator.
We may send transactional and administrative communications that are necessary to provide the Services, such as account notices, booking confirmations, inquiry updates, security alerts and service updates.
If we send optional marketing communications, we will provide an unsubscribe mechanism or other method to opt out, as required by applicable law. Even if you opt out of marketing communications, we may continue to send transactional or administrative communications related to your account or use of the Services.
The Services are intended for use by businesses and adults. They are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13 without the consent of a parent or guardian.
If you believe a child under 13 has provided us with personal information without appropriate consent, please contact us and we will take reasonable steps to delete the information, subject to legal and technical limitations.
We use limited automated processes to operate and protect the Services, such as authentication, rate limiting, abuse detection, payment routing, scheduling support and account security controls.
We do not use automated processes to make decisions about individuals that produce legal or similarly significant effects without appropriate human involvement.
If you have questions about an automated process affecting your account or use of the Services, please contact us.
We maintain processes to identify, investigate, contain and respond to security incidents. If a breach of security safeguards involving personal information creates a real risk of significant harm, we will notify affected individuals and report to the Office of the Privacy Commissioner of Canada as required by PIPEDA. We will also keep records of breaches as required by applicable law.
We may update this Privacy Policy from time to time to reflect changes in our practices, Services, technology, legal obligations or other operational reasons. When we update this Privacy Policy, we will revise the “Last Updated” date above.
If we make material changes, we will provide additional notice where appropriate, such as through the Site, Services, email or other reasonable means. Where required by law, we will obtain consent before using personal information for materially new purposes.
If you have questions, concerns or requests about this Privacy Policy or our privacy practices, please contact:
Privacy OfficerYou may also contact the Office of the Privacy Commissioner of Canada if you have concerns about our privacy practices.