Cookie preferences

Gather uses essential cookies for sign-in and security. We don't use analytics or marketing cookies.

Read our cookie policy.

Book an event
gatherevents
HOMEABOUT USCONTACT USFAQ
Log inSign up
HOMEABOUT USCONTACT USFAQ

Privacy Policy

Gather Events BK Limited
Website: gatherevents.ca

Effective Date: May 24th, 2026 · Last Updated: 2026-05-24

At Gather Events BK Limited (“Gather”, “we”, “us” or “our”), we are committed to protecting privacy and maintaining a general policy of openness about how we collect, use, disclose and protect personal information.

This Privacy Policy explains how we collect, use, disclose, retain and protect personal information when you visit, interact with or use our website, vendor portal, customer-facing booking and inquiry tools, account features, payment-related workflows, communications and related services available through gatherevents.ca (collectively, the “Site” or “Services”).

For the purposes of this Privacy Policy, “personal information” means information about an identifiable individual, including information that identifies, relates to, describes or could reasonably be associated with an individual.

Gather is based in Ontario, Canada. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and other applicable privacy laws.

This Privacy Policy may be cross-referenced by, and read together with, Gather’s Terms of Use and Vendor Agreement.

This Privacy Policy does not apply to the privacy practices of third-party websites, applications or services that we do not own or control, even if they are linked from or integrated with our Site or Services. Those third parties are responsible for their own privacy practices, and we encourage you to review their privacy policies.

If you have any questions or concerns about this Privacy Policy, please contact us using the contact details provided at the end of this Privacy Policy.

1. What Personal Information We Collect

The personal information we collect depends on how you interact with Gather, including whether you are visiting the Site, creating an account, listing services as a vendor, making an inquiry or booking as a customer, communicating through the Services, or otherwise interacting with us.

Sources of Personal Information

We collect personal information from the following sources:

  • Information you provide directly. We collect personal information when you create an account, build a vendor profile, list offerings, submit an inquiry, make or manage a booking, send messages, upload files or images, connect a calendar, contact us, or otherwise provide information through the Services.
  • Information generated through use of the Services. We collect information created or generated through your use of the Services, including booking records, transaction records, messages, preferences, audit logs, security events, and technical information required to operate and protect the platform.
  • Information collected automatically.When you visit or use the Site or Services, we may automatically collect certain technical and usage information, such as IP address, device information, browser information, log-in activity, session information, pages accessed, links clicked, and similar information. Some of this information may be collected using cookies, browser storage or similar technologies, as described in the “Cookies and Browser Storage” section below.
  • Information from third parties. We may receive personal information from third-party service providers and integrations you choose to use, such as payment processors, calendar providers, email providers, or other services integrated with Gather. We may also receive information from vendors, customers or other users who provide information through the Services.

Categories of Personal Information

The following table describes the categories of personal information we may collect.

CategoryDescriptionSource
Contact InformationName, display name, email address, phone number, mailing address, business contact information and similar details.Directly from you; vendors, customers or other users; service providers.
Account and Administration InformationUsername, account role, account status, password stored in hashed form, authentication information, preferences, notification settings, account identifiers, timestamps and security tokens.Directly from you; generated through use of the Services; automatic collection.
Vendor Business Profile InformationBusiness name or display name, business description, vendor category or type, website address, contact person details, delivery options, delivery radius, delivery fees, logos, profile photos, gallery photos, vendor policy documents and other vendor-uploaded content.Directly from vendors.
Offering and Listing InformationPackages, add-ons, service options, descriptions, pricing, images, availability and other information vendors provide about their goods or services.Directly from vendors.
Customer, Inquiry and Booking InformationCustomer name, contact details, event date, time and location, event type, guest or attendee count, inquiry details, booking details, order contents, amounts, status history, notes, instructions and other information submitted for an inquiry, booking or order.Directly from customers; generated through use of the Services; vendors or other users.
Payment and Transaction InformationTransaction amounts, charge, refund, invoice and payout records, Stripe account, charge, invoice or payout identifiers, payment status, dispute information and related financial records.Directly from you; generated through use of the Services; payment processor.
Calendar Connection InformationOAuth tokens or credentials needed to connect to calendar services, together with busy/free availability information if you choose to connect a calendar, and the booking event details (such as event title or summary, description and location) that Gather writes to your connected calendar.Directly from you; calendar providers; generated through use of the Services.
Messages, Intake Forms and CommunicationsMessages exchanged through the Services, vendor notes, customer intake form responses, support requests, attachments, transactional email content, and records of notices or communications sent through the platform.Directly from you; generated through use of the Services; vendors, customers or other users.
Reviews, Ratings and ReportsRatings, review content, responses to reviews, reports or flags submitted about reviews, and related moderation records.Directly from users; generated through use of the Services.
Security, Audit and Technical InformationIP address, device and browser information, session data, log-in activity, rate-limiting counters, abuse-prevention signals, audit logs, error and diagnostic information, timestamps and technical identifiers.Automatic collection; generated through use of the Services; service providers.
Cookie and Browser Storage InformationSession cookies, CSRF cookies, role or account-state cookies, workflow cookies, cookie-consent choices, session storage and local storage information.Automatic collection.

Gather does not store raw payment card numbers, CVVs or bank account numbers. Payment card and bank account details are handled by our payment processor, Stripe, subject to Stripe’s own privacy and security practices. Stripe is the only payment processor used by Gather, and Gather does not store or otherwise receive raw card, CVV or bank account details.

Where calendar sync is enabled, Gather reads busy/free availability information from your connected calendar. In addition, when real-time write-back is enabled, Gather publishes booking event details back to your connected calendar for each booking, including a branded event title or summary, a description and a location. Gather supports calendar connections with both Google Calendar and Microsoft Outlook. Gather does not read the titles, attendees, descriptions or other content of your existing calendar events; it reads only busy/free availability, and it writes Gather booking events as described above.

2. How We Use Personal Information

We use personal information for the purposes described below. We collect, use and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances.

PurposeExamplesCategories of Personal Information Used
To provide and operate the ServicesCreate, authenticate and manage accounts; operate vendor profiles and listings; enable customer inquiries, bookings, scheduling and orders; enable messaging; display relevant vendor, offering and availability information; write booking events to connected calendars; provide support.Contact Information; Account and Administration Information; Vendor Business Profile Information; Offering and Listing Information; Customer, Inquiry and Booking Information; Calendar Connection Information; Messages, Intake Forms and Communications.
To process payments and transactionsFacilitate payments, payouts, invoices, refunds and disputes; support payment-related onboarding; maintain transaction records; meet tax, accounting and financial obligations.Contact Information; Payment and Transaction Information; Customer, Inquiry and Booking Information; Account and Administration Information.
To communicate with youSend transactional notices, booking confirmations, inquiry updates, reminders, review requests, account notices, security alerts, administrative messages and support responses.Contact Information; Account and Administration Information; Customer, Inquiry and Booking Information; Messages, Intake Forms and Communications.
To personalize, recommend and marketProvide recommendations; rank, sort or feature vendors and offerings; personalize the experience; perform analytics; and, where permitted, send marketing communications. We may use customer information for these purposes.Contact Information; Account and Administration Information; Customer, Inquiry and Booking Information; Offering and Listing Information; Security, Audit and Technical Information.
To manage vendor and customer relationshipsAdminister vendor accounts, customer inquiries, bookings, support issues, disputes and platform-related communications.Contact Information; Account and Administration Information; Vendor Business Profile Information; Customer, Inquiry and Booking Information; Payment and Transaction Information; Messages, Intake Forms and Communications.
To moderate and review contentAccess and review messages, intake form responses, files and attachments submitted through the Services for moderation, support, dispute resolution, safety and quality purposes.Messages, Intake Forms and Communications; Customer, Inquiry and Booking Information; Account and Administration Information; Reviews, Ratings and Reports.
To protect security and prevent misuseAuthenticate users; maintain secure sessions; apply rate limiting; detect, prevent and investigate fraud, abuse, unauthorized access, credential-stuffing, security incidents or other unlawful activity; maintain audit logs.Account and Administration Information; Security, Audit and Technical Information; Payment and Transaction Information; Messages, Intake Forms and Communications where relevant to an investigation.
To improve and maintain the ServicesUnderstand usage, troubleshoot errors, test and improve features, maintain performance, develop enhancements and diagnose technical issues.Security, Audit and Technical Information; Cookie and Browser Storage Information; Account and Administration Information; usage and telemetry information.
To manage reviews, ratings and reportsDisplay reviews and ratings, moderate inappropriate content, respond to reports, and maintain the integrity of review features.Reviews, Ratings and Reports; Contact Information; Account and Administration Information; Vendor Business Profile Information.
To comply with legal obligations and protect legal rightsMaintain legally required records; respond to lawful requests; enforce agreements and policies; establish, exercise or defend legal rights; support corporate, tax, accounting and compliance obligations.Any category of personal information reasonably necessary for the applicable legal, compliance or dispute-related purpose.

If we wish to use personal information for a materially new purpose, we will identify that purpose and, where required by law, obtain consent before doing so.

3. Consent

We collect, use and disclose personal information with consent, except where applicable law permits or requires otherwise.

Consent may be express or implied, depending on the sensitivity of the information and the context. For example, we may rely on:

  • express consent when you create an account, accept applicable terms, connect a calendar, submit information through the Services, or actively choose to use a specific feature; and
  • implied consent where the purpose is obvious from the circumstances, such as when you provide information to make a booking, send a message, request support or complete a transaction.

You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. For example, you may disconnect calendar sync, adjust notification preferences, opt out of non-essential communications or request deletion of your account. Withdrawing consent may limit or prevent our ability to provide some or all of the Services.

If you provide personal information about another individual, you represent that you have authority to do so and that the individual has been informed of the purposes for which the information is being provided.

4. When We Disclose Personal Information

We do not sell personal information. We may disclose personal information as described below.

Platform Users

Certain information is shared between vendors, customers and other platform users as necessary to provide the Services. For example:

  • customer inquiry, booking or order information is shared with the relevant vendor or vendors so they can fulfill, deliver and perform the booked goods or services;
  • vendor profile and offering information may be displayed to customers and Site visitors;
  • messages are shared with the intended recipient;
  • review or rating content may be displayed where review functionality is enabled; and
  • transaction, booking or order status may be visible to the parties involved.

Service Providers and Vendors

We may disclose personal information to third-party service providers and vendors that help us operate, host, secure, maintain and improve the Services, process payments, provide calendar integrations, deliver email communications, store files, support diagnostics, or otherwise provide services on our behalf.

Our service providers are required to use personal information only for the purposes for which it was provided to them and to protect personal information using safeguards appropriate to the nature of the information and services provided. We have data processing agreements in place with our service providers.

Current service providers include:

Service ProviderPurposeInformation Processed
StripePayments, payouts, invoicing and related payment workflows.Transaction identifiers, payment status, amounts, contact details and related payment records. Raw card and bank account details are handled by Stripe, not Gather.
GoogleGoogle Calendar connection: reading busy/free availability and writing Gather booking events.OAuth tokens, busy/free availability information, and booking event details (title or summary, description and location) written to the connected calendar.
MicrosoftOutlook Calendar connection: reading busy/free availability and writing Gather booking events where enabled.OAuth tokens, busy/free availability information, and booking event details (title or summary, description and location) written to the connected calendar.
SMTP2GOTransactional email delivery.Recipient email address, subject line, message body and delivery-related metadata.
Amazon Web ServicesObject storage for uploaded files, including vendor images and message attachments.Uploaded images, documents, attachments and related technical records.
RenderApplication and database hosting, including Render-managed PostgreSQL with point-in-time backups.Platform data needed to host and operate the application and database.

We may update our service providers from time to time as our business and technical infrastructure evolve.

Professional Advisors and Corporate Transactions

We may disclose personal information to auditors, insurers, legal counsel, financial advisors, consultants and other professional advisors where reasonably necessary for legitimate business, legal, compliance, insurance, accounting or advisory purposes.

We may also disclose or transfer personal information in connection with an actual or proposed financing, merger, acquisition, sale, reorganization, transfer or other transaction involving all or part of Gather or its business or assets, provided that personal information is handled in accordance with applicable law.

Legal, Safety and Compliance Reasons

We may disclose personal information where we believe it is reasonably necessary to:

  • comply with applicable law;
  • respond to lawful requests, court orders, subpoenas or legal processes;
  • enforce our agreements, policies or terms;
  • detect, prevent or investigate fraud, abuse, security incidents or unlawful activity;
  • protect the rights, safety, property or security of Gather, users, vendors, customers or others; or
  • establish, exercise or defend legal rights.

5. Transferring and Storing Personal Information

Gather is based in Ontario, Canada. Some of our service providers may store or process personal information outside Ontario or outside Canada, including in the United States or other jurisdictions.

When personal information is processed or stored outside Canada, it may be subject to the laws of the jurisdiction where it is located, including lawful access by courts, law enforcement, regulators or government authorities in that jurisdiction.

Regardless of where personal information is processed, Gather remains responsible for personal information under its custody or control and uses contractual and other measures designed to require service providers to protect personal information appropriately.

You may contact our Privacy Officer for more information about our use of service providers located outside Canada.

6. Cookies and Browser Storage

When you visit or use the Site or Services, we may use cookies, browser storage and similar technologies. A cookie is a small text file stored by your browser. Browser storage may include local storage or session storage maintained by your browser.

We use these technologies to:

  • ensure the Site and Services function properly;
  • authenticate users and maintain sessions;
  • support account and vendor workflows;
  • help protect against cross-site request forgery and other security risks;
  • remember cookie-consent choices or other preferences;
  • support password reset, email verification and similar account flows;
  • temporarily support calendar connection flows; and
  • collect technical information needed to maintain, troubleshoot and improve the Services.

Essential Cookies and Storage

Essential cookies and browser storage are necessary for the Site and Services to function properly. These may include session cookies, CSRF cookies, role or account-state cookies, email verification or password reset cookies, vendor sign-up or login workflow cookies, URL masking or redirection cookies, cookie-consent storage, OAuth state values and similar short-lived technical records.

Most essential cookies are short-lived and expire after a limited period. Based on the current platform configuration, the authentication session cookie has a maximum lifetime of approximately 6 hours, the CSRF cookie approximately 6 hours, administrative one-time-password cookies approximately 10 minutes, and administrative session, role and issued-at cookies approximately 6 hours each. Other workflow cookies, including cookie-consent storage, OAuth state, email verification and password reset cookies, are short-lived in accordance with the retention periods described in this Privacy Policy.

Optional Analytics or Marketing Cookies

Gather only sets essential cookies. We do not currently use optional analytics, advertising, tracking pixel or marketing cookies. If we introduce non-essential analytics, advertising, tracking pixels or marketing cookies in the future, we will update this Privacy Policy and, where required, provide appropriate consent controls.

You may be able to adjust cookie settings through your browser. If you disable certain cookies or browser storage, some features or functionality of the Site or Services may not work properly.

7. How We Protect Personal Information

We use administrative, technical and physical safeguards appropriate to the sensitivity of the personal information we handle.

These safeguards include:

  • encryption in transit using TLS, with HTTP Strict Transport Security (HSTS) enforced in production;
  • encryption at rest for databases and object storage, where AES-256 at-rest encryption is provided by our database and object storage providers;
  • storage of passwords using the scrypt hashing algorithm with per-user salt; passwords are never stored in reversible form;
  • storage of session tokens only as hashed values, with the plaintext token held only in the user’s browser cookie;
  • application-level encryption of sensitive calendar connection tokens, with ciphertext rotation when the encryption key version advances;
  • cross-site request forgery (CSRF) protection using a double-submit cookie pattern, and rate limiting applied across the Services;
  • restricted access to object storage and hosting environments, with access gated by credentials scoped to the production runtime and administrative access protected by single sign-on and multi-factor authentication;
  • role-based access controls distinguishing administrator, vendor and customer roles;
  • audit logging of administrative and security-relevant actions, which records the actor, action, resource and a redacted diff, and does not store card or bank account values;
  • contractual safeguards with service providers;
  • privacy and security procedures for personnel with access to personal information; and
  • incident response processes.

Access to personal information is limited to individuals who require access to perform their duties or provide services to Gather, and who are subject to confidentiality, contractual or other obligations appropriate to their role.

No method of transmission or storage is completely secure. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for using appropriate security precautions when accessing the Site or Services.

8. Retention of Personal Information

We retain personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, to provide the Services, to maintain business records, to comply with legal, tax, accounting and reporting obligations, to resolve disputes, to enforce agreements, and to protect the security and integrity of the Services.

Generally, this means personal information will be retained for the duration of your relationship with us and for a reasonable period thereafter, unless a longer or shorter retention period is required or permitted by law.

Based on the current platform design, retention practices may include:

Type of InformationGeneral Retention Approach
Active account informationRetained while the account remains open.
Password reset tokensShort-lived, generally approximately 60 minutes or as configured.
Email verification tokensShort-lived, generally approximately 24 hours or as configured.
Authentication sessionsShort-lived, generally approximately 6 hours or as configured.
Calendar OAuth state tokensShort-lived, generally approximately 10 minutes or as configured.
Login failure recordsRetained as needed for security and cleared in accordance with account and system rules.
Audit logsEach audit log row expires on a per-row basis according to its own expiry value, after which it is removed by a scheduled cleanup process. Audit logs may be retained longer where required for security, legal or compliance purposes.
Deleted account tombstonesWhen an account is deleted, a tombstone record (which stores the account email only as a hashed value) is created. These records are retained for approximately one year and are then removed by a scheduled cleanup process, except where a longer period is required for fraud prevention, legal, tax, audit or compliance purposes.
Redis rate-limiting countersTransient and generally expire within approximately 60 seconds.
Uploaded files and object storageVendor images, message attachments and other uploaded files are stored in Amazon S3. Under the current lifecycle configuration, objects transition to Amazon S3 Glacier Flexible Retrieval after approximately 30 days and are expired after approximately 365 days, so uploaded files are generally retained for approximately one year.
Tax, accounting and financial recordsRetained as required by applicable Canadian tax, accounting and legal requirements.

When personal information is no longer required, we will delete it, anonymize it or de-identify it. If deletion is not immediately possible, such as where information is stored in backup systems, we will protect the information and restrict further processing until deletion or overwriting is possible. Our database is hosted on Render-managed PostgreSQL, which provides point-in-time backups; where data is deleted from the live database, that deletion is reflected in subsequent backups. If necessary, data may be restored from these backups.

If you delete your account, a tombstone record is created (storing your email only as a hashed value), your user record is marked as deleted, and related data is removed or cascaded in accordance with the platform’s deletion processes. Certain information may be retained where necessary for legal, financial, security, fraud-prevention, dispute-resolution or legitimate business purposes. For example, transaction records may be retained as required for legal or accounting purposes. Messages you have sent remain associated with your deleted user record, which no longer contains personal information. The tombstone record itself is removed by a scheduled cleanup process after approximately one year, except where a longer period is required for fraud-prevention, legal, tax, audit or compliance purposes.

9. Your Privacy Rights and Choices

Depending on your location and subject to applicable law, you may have certain rights regarding the personal information we hold about you.

Individuals in Canada may request access to personal information held by Gather and request correction of inaccurate or incomplete personal information. Subject to legal exceptions, we will inform you of the existence, use and disclosure of your personal information and provide access to that information. If we cannot provide access, we will explain why, subject to any legal restrictions.

You may also:

  • update certain account, profile and preference information through the Services;
  • adjust notification or email preferences where available;
  • disconnect calendar integrations;
  • withdraw consent, subject to legal or contractual restrictions and reasonable notice;
  • request deletion of your account or certain personal information, subject to retention requirements; and
  • make a privacy complaint.

To exercise privacy rights or make a request, please contact our Privacy Officer using the contact details below.

We may need to verify your identity before responding to a request. We will respond to requests within the timeframe required by applicable law. In Canada, PIPEDA generally requires organizations to respond to access requests within 30 days, subject to limited extensions permitted by law.

If you are not satisfied with our response, you may contact us to escalate the matter. You may also contact the Office of the Privacy Commissioner of Canada or another applicable privacy regulator.

10. Marketing Communications

We may send transactional and administrative communications that are necessary to provide the Services, such as account notices, booking confirmations, inquiry updates, security alerts and service updates.

If we send optional marketing communications, we will provide an unsubscribe mechanism or other method to opt out, as required by applicable law. Even if you opt out of marketing communications, we may continue to send transactional or administrative communications related to your account or use of the Services.

11. Children’s Information

The Services are intended for use by businesses and adults. They are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13 without the consent of a parent or guardian.

If you believe a child under 13 has provided us with personal information without appropriate consent, please contact us and we will take reasonable steps to delete the information, subject to legal and technical limitations.

12. Automated Processing

We use limited automated processes to operate and protect the Services, such as authentication, rate limiting, abuse detection, payment routing, scheduling support and account security controls.

We do not use automated processes to make decisions about individuals that produce legal or similarly significant effects without appropriate human involvement.

If you have questions about an automated process affecting your account or use of the Services, please contact us.

13. Breach Response

We maintain processes to identify, investigate, contain and respond to security incidents. If a breach of security safeguards involving personal information creates a real risk of significant harm, we will notify affected individuals and report to the Office of the Privacy Commissioner of Canada as required by PIPEDA. We will also keep records of breaches as required by applicable law.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, Services, technology, legal obligations or other operational reasons. When we update this Privacy Policy, we will revise the “Last Updated” date above.

If we make material changes, we will provide additional notice where appropriate, such as through the Site, Services, email or other reasonable means. Where required by law, we will obtain consent before using personal information for materially new purposes.

15. Contacting Us

If you have questions, concerns or requests about this Privacy Policy or our privacy practices, please contact:

Privacy Officer
Gather Events BK Limited
102 Mildenhall Rd
North York, ON M4N 3H5
Email: privacy@gatherevents.ca

You may also contact the Office of the Privacy Commissioner of Canada if you have concerns about our privacy practices.