Your trust is the foundation of everything we do. MPWH Canada is committed to protecting the privacy of every member, and this policy explains exactly how we handle your information in plain, straightforward language.
1 Who We Are
MPWH Canada Inc. ("MPWH Canada," "we," "us," or "our") operates the website located at mpwh.ca and its associated mobile application (collectively, the "Service"). We are a Canadian corporation registered under the laws of Ontario, dedicated to providing a safe, stigma-free online community for individuals living with HSV (herpes simplex virus) across Canada.
As the operator of this Service, MPWH Canada acts as the "organization" responsible for personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
2 Scope of This Policy
This Privacy Policy applies to all personal information collected, used, or disclosed by MPWH Canada in connection with the Service, regardless of whether you access the Service through a browser, mobile application, or any other means. It applies to:
- Registered members and visitors to mpwh.ca
- Individuals who download or use the MPWH Canada mobile application
- Anyone who communicates with us by email, phone, or contact form
- Job applicants and business partners (limited scope)
This policy does not apply to third-party websites or services that may be linked from our platform. We encourage you to review the privacy policies of any third-party sites you visit.
3 Information We Collect
We collect only the information necessary to provide and improve our Service. The categories of information we may collect include:
3.1 Information You Provide Directly
- Account registration: username, email address, password (stored as a one-way hash), date of birth, province/territory, and gender identity
- Profile information: profile photo, bio, relationship preferences, interests, and any other details you choose to share publicly or privately
- Health-related disclosures: HSV status and any related health information you voluntarily add to your profile. This is treated as sensitive personal health information and receives the highest level of protection.
- Communications: messages sent to other members through our platform, support tickets, and correspondence with our team
- Payment information: billing address and payment card details (processed via our PCI-DSS compliant payment processor; we do not store full card numbers)
- Survey and feedback responses
3.2 Information Collected Automatically
- Device and browser data: IP address, browser type and version, operating system, device identifiers
- Usage data: pages viewed, features used, links clicked, search queries within the platform, session duration
- Location data: general geographic location derived from IP address (city/province level). We do not collect precise GPS coordinates without your explicit consent.
- Cookies and similar technologies (see Section 7 for full details)
3.3 Information From Third Parties
If you choose to register or log in using a social account (e.g., Google or Facebook), we receive your name, email address, and profile picture from that provider. We do not request or store access to your social contacts, posts, or feeds.
A note on sensitive health data: Information about your HSV status is considered sensitive personal health information under PIPEDA. We collect this information only because it is central to the matching purpose of our Service, and we apply the strictest access controls, encryption, and retention limits to it.
4 How We Use Your Information
We use your personal information for the following purposes:
On mobile, swipe horizontally to view the full table.
| Purpose | Description |
|---|---|
| Account management | Creating and maintaining your account, authenticating logins, and enabling account recovery |
| Matching and discovery | Surfacing compatible member profiles based on your stated preferences, location, and activity |
| Messaging | Facilitating private communication between members within our platform |
| Service improvements | Analysing usage patterns to enhance features, fix bugs, and develop new functionality |
| Safety and moderation | Detecting fraud, abuse, spam, and policy violations to protect our community |
| Customer support | Responding to your questions, resolving disputes, and processing account requests |
| Billing | Processing Premium subscription payments and managing subscription status |
| Communications | Sending transactional emails (e.g., match alerts, password resets) and, where you opt in, marketing newsletters |
| Legal compliance | Fulfilling obligations under applicable Canadian law, including responding to lawful requests from authorities |
We do not use your personal information to make fully automated decisions that produce significant legal or similarly significant effects on you without human review.
5 Legal Basis for Processing
Under PIPEDA, we rely on the following legal bases to process your personal information:
- Consent: For most personal information we collect, we rely on your express consent at the time of registration. You may withdraw consent at any time (subject to legal or contractual restrictions), though this may affect your ability to use certain features.
- Contractual necessity: Processing your account details and payment information is necessary to provide the Service you have subscribed to.
- Legitimate interests: We process certain usage and device data to detect fraud, ensure platform security, and improve our Service, where these interests are not overridden by your privacy rights.
- Legal obligation: We may process and retain certain information as required by applicable Canadian law.
For sensitive health information (your HSV status), we rely on your explicit, informed consent, which you provide when completing your profile. You may remove this information from your public profile at any time through your account settings.
6 Sharing Your Information
MPWH Canada does not sell, rent, or trade your personal information to third parties. We do not allow advertisers to access your profile or personal data. We share information only in the following limited circumstances:
6.1 With Other Members
Information you add to your public profile (username, photos, bio, province, interests) is visible to other registered members. Your email address, last name, and full date of birth are never shown to other members. You control the visibility of most profile fields through your privacy settings.
6.2 With Service Providers
We work with carefully vetted service providers who process data on our behalf under written data processing agreements. These include:
- Cloud hosting and infrastructure providers
- Payment processors (PCI-DSS Level 1 certified)
- Email delivery services (transactional and marketing)
- Analytics platforms (data is aggregated and anonymised where feasible)
- Customer support software
All service providers are contractually prohibited from using your data for any purpose other than providing services to MPWH Canada.
6.3 For Legal Reasons
We may disclose personal information if we believe in good faith that disclosure is reasonably necessary to: (a) comply with a law, regulation, legal process, or governmental request; (b) protect the safety of any person from death or serious bodily injury; (c) prevent fraud or abuse; or (d) protect MPWH Canada's legal rights.
6.4 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your personal information may be transferred to the acquiring entity. We will notify you via email or prominent notice on our Service at least 30 days before your information is transferred or becomes subject to a different privacy policy.
6.5 Aggregated or De-Identified Data
We may share aggregated, de-identified statistics about our community (e.g., "MPWH Canada has members in all 13 provinces and territories") that cannot reasonably be used to identify you.
7 Cookies and Tracking Technologies
We use cookies and similar technologies (web beacons, pixel tags, local storage) to provide and improve our Service. Here is how we categorise them:
On mobile, swipe horizontally to view the full table.
| Category | Purpose | Can You Opt Out? |
|---|---|---|
| Strictly Necessary | Essential for login sessions, security tokens, and core functionality | No - required for the Service to work |
| Functional | Remembering your language preference, display settings, and recent searches | Yes, via cookie settings |
| Analytics | Understanding how pages are used to improve performance and layout | Yes, via cookie settings |
| Marketing | We do not serve third-party advertising cookies. Any marketing cookies are first-party and relate only to our own Service. | Yes, via cookie settings |
You can manage your cookie preferences at any time by clicking the "Cookie Settings" link in the footer of our website. You can also control cookies through your browser settings; however, disabling certain cookies may impact your experience.
We do not respond to browser "Do Not Track" signals at this time, as there is no consistent industry standard for how to do so.
8 Data Retention
We retain your personal information for as long as your account remains active or as needed to provide the Service. Specifically:
- Active accounts: Your profile and account data are retained for the duration of your membership.
- Deleted accounts: When you delete your account, your public profile is removed from the platform within 48 hours. Backup and log copies are purged within 90 days, except where retention is required by law.
- Messages: Private messages between members are retained for 12 months after the last message in a conversation, then permanently deleted.
- Billing records: Payment and transaction records are retained for 7 years as required under the Income Tax Act (Canada).
- Safety-related data: Records related to abuse reports, bans, or safety incidents may be retained longer to protect the community and support legal proceedings if required.
Health-related profile data (HSV status) is deleted immediately upon account deletion and is not included in any backup retained beyond 30 days.
9 Security Safeguards
We take the security of your information seriously and implement a range of technical, administrative, and physical safeguards, including:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
- Encryption at rest: Sensitive database fields, including health-related information and hashed passwords, are encrypted at rest using AES-256.
- Access controls: Access to personal data is restricted to MPWH Canada employees and contractors who need it to perform their job duties, and only after completing privacy and security training.
- Infrastructure security: Our platform is hosted in Canadian data centres certified to SOC 2 Type II standards.
- Regular audits: We conduct periodic security assessments and penetration tests.
- Breach notification: In the event of a data breach that creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada (OPC) as required under PIPEDA.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security. We encourage you to use a strong, unique password and enable two-factor authentication on your account.
10 Your Privacy Rights
As a Canadian resident, you have the following rights regarding your personal information. You can exercise most of these rights directly through your account settings or by contacting our Privacy Officer.
Right of Access
Request a copy of the personal information we hold about you, including how it is used and shared.
Right to Correction
Request correction of inaccurate or incomplete personal information we hold about you.
Right to Deletion
Request deletion of your account and associated personal information (subject to legal retention requirements).
Right to Withdraw Consent
Withdraw consent for specific processing activities, such as marketing emails, at any time.
Right to Portability
Request a machine-readable export of the personal data you have provided to us.
Right to Complain
Lodge a complaint with the Office of the Privacy Commissioner of Canada if you believe we have handled your data improperly.
To exercise any of these rights, please contact our Privacy Officer (see Section 14). We will respond to all requests within 30 days. In complex cases, we may extend this by an additional 30 days and will notify you of any extension.
We may need to verify your identity before fulfilling a request. We will not discriminate against you for exercising any of these rights.
To submit a privacy rights request, email us at privacy@mpwh.ca with the subject line "Privacy Rights Request - [Type of Request]."
11 Children's Privacy
Our Service is intended exclusively for adults aged 18 and older. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected information from a person under 18, we will take immediate steps to delete that information and terminate the associated account.
If you are a parent or guardian and believe your child has registered with our Service, please contact us immediately at safety@mpwh.ca.
12 Cross-Border Data Transfers
MPWH Canada primarily stores and processes your personal information in Canada. However, some of our third-party service providers may store or process data outside Canada, including in the United States and the European Union. When this occurs, we ensure appropriate safeguards are in place, such as:
- Contractual clauses requiring the recipient to provide protection equivalent to PIPEDA
- Transfers only to countries with adequacy findings by the Canadian government
- Use of service providers with established binding corporate rules
By using our Service, you acknowledge that your information may be transferred to and processed in countries other than Canada. We will always take steps to ensure your information remains protected in accordance with this Privacy Policy.
13 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Post the updated policy on this page with a revised "Last Updated" date
- Send a notice to your registered email address at least 14 days before the changes take effect
- Display a prominent banner on the platform for 30 days after the update
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you may close your account before the effective date.
We encourage you to review this page periodically to stay informed about how we are protecting your information.
14 Contact Our Privacy Officer
If you have any questions, concerns, or requests related to this Privacy Policy or the handling of your personal information, please contact our designated Privacy Officer:
Privacy Officer - MPWH Canada Inc.
Email: privacy@mpwh.ca
Mailing address:
Privacy Officer
MPWH Canada Inc.
366 Bay Street, Suite 900
Toronto, Ontario M5H 4B2
Canada
Response time: We aim to respond to all privacy inquiries within 5 business days and to fulfil data requests within 30 days.
If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada at 1-800-282-1376.