Skip to content
Hands On Exotics

Legal

Privacy Policy

Last updated: March 2026. Your privacy matters to us — this policy explains how we handle your data.

Privacy questions? Contact us

1. Information We Collect

When you interact with Hands On Exotics — whether browsing our website, submitting an inquiry, or completing a booking — we may collect the following categories of personal information:

Contact & Identity Information

Your full name, email address, phone number, and mailing address. This information is collected when you submit a booking inquiry, contact form, or subscribe to our communications.

Event & Booking Details

Event date, time, venue address, event type, expected guest count, package selections, add-on choices, and any special requests or accessibility requirements you provide during the booking process.

Payment Information

Credit card details and billing address are collected and processed securely by our payment processor, Stripe. Hands On Exotics does not store your full credit card number on our servers. We retain only the last four digits and card brand for transaction reference purposes.

Technical & Usage Data

When you visit our website, we automatically collect certain technical information including your IP address, browser type and version, device type, operating system, referring URL, pages visited, time spent on pages, and general geographic location (city/region level). This data is collected through cookies and similar technologies as described in Section 3 below.

2. How We Use Your Information

We use the personal information we collect for the following purposes:

  • Fulfilling bookings — processing inquiries, generating quotes, confirming reservations, coordinating event logistics with handlers, and delivering animal experience services
  • Processing payments — charging deposits, collecting balance payments, issuing refunds, and generating invoices
  • Communicating with you — sending booking confirmations, event reminders, balance due notices, post-event follow-ups, and responding to your inquiries
  • Marketing communications — with your consent, sending newsletters, seasonal promotions, and updates about new services or animals. You can unsubscribe at any time
  • Improving our services — analyzing website usage patterns to enhance the user experience, optimizing our booking process, and improving our event offerings
  • Legal compliance — meeting our obligations under applicable Canadian laws, responding to legal requests, and protecting our rights

3. Cookies & Tracking

Our website uses cookies and similar tracking technologies to provide a better browsing experience and to understand how visitors use our site.

Essential Cookies

These are required for the website to function properly. They enable core features such as session management, authentication for our handler portal, and security protections. Essential cookies cannot be disabled without affecting site functionality.

Analytics Cookies

We use analytics tools to understand how visitors navigate our website, which pages are most popular, and where users encounter difficulties. This data is aggregated and anonymized. Analytics cookies help us improve our website and the booking experience.

Managing Cookies

Most web browsers allow you to control cookies through their settings. You can choose to block or delete cookies, though doing so may affect certain features of our website. For more information on managing cookies, visit your browser's help documentation.

4. Third-Party Services

We use the following third-party services to operate our business. Each service processes certain data on our behalf and is subject to its own privacy policy:

Supabase (Database & Authentication)

Our application data — including booking records, customer contact information, event details, and handler accounts — is stored securely in Supabase, a cloud database platform. Supabase employs encryption at rest and in transit, row-level security policies, and SOC 2 Type II compliance. Data is hosted in secure data centres with geographic redundancy.

Stripe (Payment Processing)

All payment transactions are processed by Stripe, a PCI DSS Level 1 certified payment processor. When you enter your credit card information, it is transmitted directly to Stripe's secure servers. Hands On Exotics does not have access to your full card number. Stripe may collect additional fraud prevention data such as device fingerprints and IP addresses. For details, refer to Stripe's Privacy Policy.

Resend (Transactional Email)

We use Resend to send transactional emails including booking confirmations, payment receipts, event reminders, and balance due notices. Resend processes your name and email address to deliver these communications. For details, refer to Resend's Privacy Policy.

Google Maps (Geocoding & Map Views)

We use Google Maps Platform services for address geocoding (converting venue addresses to coordinates for travel distance calculations) and displaying map views during the booking process. Google may collect usage data, IP addresses, and location information through these services. For details, refer to Google's Privacy Policy.

5. Data Retention

We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected or as required by applicable law. The following retention periods apply:

  • Booking and event records: retained for a minimum of seven (7) years from the date of the event for tax, insurance, and legal compliance purposes
  • Payment records: retained for seven (7) years as required by Canadian tax law. Stripe independently retains payment data per its own retention policies
  • Marketing contact information: retained until you unsubscribe or request deletion, whichever occurs first
  • Website analytics data: retained in aggregated, anonymized form and not subject to individual deletion requests
  • Inquiry and contact form submissions: retained for two (2) years from the date of submission

When your data is no longer required, it is securely deleted or anonymized so that it can no longer be associated with you.

6. Your Rights Under PIPEDA

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have the following rights regarding your personal information:

  • Right of access: you may request a copy of the personal information we hold about you
  • Right to correction: you may request that inaccurate or incomplete personal information be corrected
  • Right to withdraw consent: where we rely on your consent to process personal information (such as marketing emails), you may withdraw that consent at any time
  • Right to challenge compliance: you may file a complaint with the Office of the Privacy Commissioner of Canada if you believe we have not handled your personal information in accordance with PIPEDA

To exercise any of these rights, please contact us using the details provided in Section 10. We will respond to your request within thirty (30) days, as required by PIPEDA. There is no fee for submitting a request, though we may charge a reasonable fee for requests that are manifestly unfounded or excessive.

7. Children's Privacy

Hands On Exotics does not knowingly collect personal information directly from children under the age of 13. Our booking process is intended for use by adults (parents, guardians, or event organizers) who are arranging animal experiences on behalf of attendees, which may include children.

When a booking includes children — such as birthday parties or school presentations — we collect the parent or guardian's contact and billing information only. We do not collect names, email addresses, or other personal information from child attendees. If you believe we have inadvertently collected personal information from a child under 13, please contact us immediately and we will promptly delete the information.

8. Data Security

We take the security of your personal information seriously and implement a range of technical and organizational measures to protect it against unauthorized access, disclosure, alteration, or destruction. These measures include:

  • All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security)
  • Database access is restricted through row-level security policies, ensuring users can only access data they are authorized to view
  • Administrative access to our systems is protected by multi-factor authentication and role-based access controls
  • Payment information is handled exclusively by PCI DSS Level 1 certified processors and never stored on our servers
  • We conduct regular reviews of our security practices and update them as necessary to address emerging threats

While we strive to protect your personal information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to taking all reasonable steps to safeguard your data.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable legal requirements. When we make changes, we will revise the “Last updated” date at the top of this page.

For material changes that significantly affect how we collect, use, or share your personal information, we will make reasonable efforts to notify you via the email address associated with your most recent booking at least fourteen (14) days before the changes take effect. Your continued use of our website or services after the updated policy is posted constitutes your acceptance of the revised terms.

10. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please contact us:

Hands On Exotics
Email: privacy@handsonexotics.com
Website: handsonexotics.com/contact

If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.