Legal

FindJobsCanada Privacy Policy

Effective date: August 13, 2026
Last updated: August 13, 2026

1. Who we are

FindJobsCanada is a business name of The Shoppers Hub Canada Inc., a federally incorporated company extra-provincially registered in British Columbia, Canada. In this Policy, “FindJobsCanada,” “we,” “us,” and “our” refer to The Shoppers Hub Canada Inc.

Our Privacy Officer can be contacted at hello@findjobscanada.ca. Please use the subject line Privacy Request.

2. Scope and privacy principles

This Policy explains how we collect, use, disclose, retain, and protect personal information when you visit findjobscanada.ca, use the Career Progression Diagnostic, purchase or participate in a Career Progression Assessment, subscribe to email, contact us, comment on public content, or use another service that links to this Policy.

We aim to collect only information reasonably needed for identified purposes, use it consistently with those purposes, keep it only as long as reasonably required, protect it with safeguards appropriate to its sensitivity, and provide access and correction rights as required by applicable law.

FindJobsCanada operates from British Columbia. British Columbia’s Personal Information Protection Act may govern private-sector personal information handled in British Columbia. The federal Personal Information Protection and Electronic Documents Act may apply to interprovincial or international commercial transactions and other activities within federal scope. Canada’s anti-spam law applies when we send commercial electronic messages. The exact law that applies can depend on the activity and facts.

3. Information we collect

Website and technical information

When you visit the website, our hosting, security, analytics, content-delivery, and performance services may process IP address, device/browser information, referring page, pages viewed, approximate location derived from IP, timestamps, cookie or similar identifiers, security events, and server/application logs. We use this information to deliver, secure, troubleshoot, measure, and improve the website.

Contact and public comments

If you contact us, we collect the information you provide, such as your name, email address, message, attachments, and related correspondence.

If you post a public comment, the comment and display name may be visible to others. WordPress and anti-spam services may also process the email address, IP address, browser details, and other metadata associated with the comment. Do not include sensitive or private contact information in a public comment.

Career Progression Diagnostic

When you complete Diagnostic V2, we collect the 15 answers you select; completion date/time; questionnaire and model versions; resulting archetype or review-required status; result confidence, primary constraint, qualitative Career Constraint Snapshot, answer summary, and randomly generated Diagnostic ID; and limited status/security data needed to operate the service.

You do not need to provide a name or email address to see your result. If you request the Action Brief or email updates, we separately collect your name, email address, consent choice and timestamp, delivery status, and related MailerLite fields, then link that contact record to the Diagnostic ID.

During the transition period, the legacy TryInteract questionnaire and legacy noindexed result pages may remain available. When you use that legacy questionnaire, Interact may process your answers and contact information under its service terms and privacy practices.

Email and MailerLite

If you choose email, MailerLite may process your name, email address, subscription status, consent record, archetype, primary constraint, urgency, search-investment category, Diagnostic date, model version, Diagnostic ID, group membership, delivery data, unsubscribe status, and campaign engagement such as opens or clicks when that tracking is enabled.

Paid Career Progression Assessment and payment

If you buy or participate in a paid Assessment, we may collect your name, contact information, target-role and career information, résumé and LinkedIn materials, questionnaire/intake information, documents or evidence you submit, communications, transaction/reference identifiers, payment status, and the founder’s review notes and deliverables.

Stripe processes payment-card and payment-account details. We do not need to receive or store your full payment-card number. We receive limited transaction, contact, status, refund, dispute, and fraud-prevention information needed to administer the purchase and keep required business records.

Scheduling and meetings

Where Calendly or Zoom is used in the customer journey, those services may process scheduling details, contact information, time zone, meeting link/participation data, device/network data, and communications. We may keep practical meeting notes. We do not record or transcribe a meeting unless we provide notice and obtain any consent required for that specific use.

4. Why we use information

We use personal information to:

  • deliver, secure, maintain, and troubleshoot the website and services;
  • generate, display, preserve, and recover a Diagnostic result;
  • deliver an optional Action Brief and communications you request;
  • administer subscriptions, consent, unsubscribe, support, access, correction, export, and deletion requests;
  • process purchases, refunds, disputes, tax/accounting, and fraud/security matters;
  • deliver and improve the paid Assessment, including founder-reviewed work;
  • measure aggregate website and product behavior and improve the platform using aggregated or de-identified patterns;
  • communicate about a service or transaction and, with appropriate consent or another lawful basis, send promotional messages; and
  • meet legal, regulatory, contractual, recordkeeping, and dispute-resolution obligations.

We do not sell raw Diagnostic responses. We do not send names, email addresses, raw Diagnostic answers, Diagnostic IDs, signed tokens, or score vectors to GA4 or GTM. We do not use raw Diagnostic answers to create third-party advertising audiences.

5. Consent, email choices, and unsubscribe

Where consent is required, we ask for it in a form appropriate to the information and purpose. Diagnostic result access does not require email. A request for an Action Brief or service message does not automatically authorize unrelated ongoing promotional email; the choice presented at collection controls.

Commercial electronic messages identify the sender and include a working unsubscribe mechanism as required. You can unsubscribe through the link in an email or contact us. We use unsubscribe status to stop future messages and to apply the approved Diagnostic identity-link retention rule. Some necessary transactional, security, legal, or privacy-request communications may still be sent when permitted.

Withdrawing consent does not invalidate processing that occurred before withdrawal, and some information may be retained where required or permitted by law.

6. Service providers and cross-border processing

We use service providers to operate the platform. Depending on your interaction, these may include:

  • WordPress.com/Automattic for hosting, platform, backups, security and related services;
  • Jetpack, Akismet, and active website security, performance, image-optimization, and content-delivery providers;
  • TryInteract during the legacy/cutover period;
  • MailerLite for subscriber management and email delivery;
  • Google services for analytics, tag management, forms, documents, spreadsheets, storage, and related Assessment operations;
  • Stripe for payment processing;
  • Calendly and Zoom where scheduling or meetings are used; and
  • professional advisors or other providers needed for support, accounting, legal, security, or business operations.

Some providers process information outside Canada. Information processed in another jurisdiction may be subject to its laws and lawful access by courts, law enforcement, or national-security authorities. We do not promise that information is stored only in Canada. We select and configure providers, limit data where practical, and use contractual, technical, and organizational measures appropriate to our role and the information’s sensitivity. Providers may also have independent obligations for activities they determine, such as payment processing.

We may disclose information if reasonably necessary to comply with law, protect rights or safety, investigate abuse/fraud/security, enforce an agreement, respond to a valid legal process, or complete a business transaction subject to appropriate safeguards. We do not use “never shared” language because service providers necessarily process limited information on our behalf.

7. Diagnostic storage and access

Completed V2 answers and result data are stored in first-party WordPress tables. Optional contact/consent information is kept in a separate linked record. Authorized administrators with a need to know may access identified records for support, privacy requests, security, retention operations, and approved product analysis. Routine analysis should use aggregate or de-identified information wherever practical.

The Diagnostic uses a rule-based model to create a working result from selected answers. It does not make an employment, immigration, licensing, legal, financial, or other high-impact eligibility decision, and it does not guarantee a job, interview, salary, or outcome. A review-required state may ask a user to clarify a result.

8. Retention

We keep information only as long as reasonably needed for the stated purpose, applicable legal requirements, security, disputes, and operational continuity.

Diagnostic V2

  • Anonymous completed Diagnostic: deleted 365 days after the original completion date.
  • Identified link: removed at the earliest of (a) a valid erasure request, subject to a required legal hold; (b) 90 days after unsubscribe or the end of the relevant customer/service relationship; or (c) 24 months after the last qualifying interaction.
  • Qualifying interaction: a new Diagnostic completion, paid Assessment purchase, explicit service request, Assessment/review interaction, or explicit renewed consent where relevant. Email opens, page views, analytics events, and passive browsing do not qualify.
  • After identity is removed, the remaining record follows the anonymous 365-day clock measured from the original completion date and is deleted immediately if already expired.
  • A metadata-only retention ledger records Diagnostic ID, rule/action, timestamp, status, retry count and bounded error code. It does not store name, email, answers, raw payloads, tokens, or provider responses.

The work-status answer inside V2 follows the same Diagnostic retention rule. If we later operate a separate work-eligibility form, its separate notice and retention will be documented before collection.

Other records

We retain Assessment materials, customer communications, payment and business records for the period reasonably necessary to provide the service, manage the customer relationship, meet legal, tax, accounting, security and dispute-resolution obligations, and respond to valid requests. More detailed retention schedules may be maintained internally. Public comments may remain while the associated content is published or as needed for moderation, security, and legal purposes. We may retain a minimal suppression record to honour an unsubscribe.

Backups

Deleted information may remain in protected backups until those backups rotate out under the hosting provider’s normal schedule. We do not use backup copies for ordinary processing of deleted information. If a backup is restored for disaster recovery, valid deletions and unlinks must be replayed before normal processing resumes. We do not promise immediate deletion from every backup.

9. Analytics, cookies, and similar technologies

The site and its providers use necessary cookies or similar technologies for security, preferences, sessions, forms, performance, and platform operation. With the applicable consent/settings, GA4, GTM, Jetpack or similar services may measure page and aggregate event behavior. You can use available consent controls and browser settings, recognizing that blocking necessary technologies can affect function.

V2 analytics events are limited to aggregate workflow milestones such as start, progress, completion, result, clarification, email submit/skip, and Assessment CTA click. Raw answers and directly identifying Diagnostic data are excluded.

10. Security and privacy incidents

We use safeguards appropriate to the sensitivity and context of the information, including access controls, individual administrator accounts, least privilege, validation and request protections, signed short-lived result links/tokens where used, logging that excludes answer/contact payloads, bounded retention jobs, and service-provider controls.

No internet or storage system is completely secure. We do not claim “fully secure” or “100% secure.” We assess suspected incidents and provide notice to affected individuals or regulators when required by applicable law.

11. Your privacy rights

Subject to applicable law and reasonable identity verification, you may ask us to:

  • confirm whether we hold personal information about you;
  • provide access to or an export of identified information;
  • correct inaccurate information;
  • withdraw consent for optional uses;
  • delete or anonymize information where applicable; or
  • explain a refusal, limitation, legal hold, or applicable exception.

An anonymous Diagnostic record contains no name or email. After a browser session ends, we may be unable to locate or verify that a particular anonymous record belongs to you. Identified requests are handled through administrator privacy-export/erase tools. We respond within timelines required by applicable law and will explain if an extension or exception applies.

Contact hello@findjobscanada.ca with subject Privacy Request. You may also contact the Office of the Information and Privacy Commissioner for British Columbia or the Office of the Privacy Commissioner of Canada where their jurisdiction applies.

12. Children and age

FindJobsCanada is designed primarily for adults and working-age career seekers. We do not knowingly collect personal information from children through the Diagnostic. If we learn that information was collected contrary to the applicable rule, we will take reasonable steps to delete it.

13. AI-assisted work

The free Diagnostic is rule-based. For the paid Assessment, technology may assist with organizing evidence or drafting, but the founder reviews the final deliverable. We do not present AI-assisted output as legal, immigration, licensing, tax, or guaranteed career advice. Any external AI provider and the information it receives must be verified and reflected in this Policy before customer evidence is provided to it.

14. Changes to this Policy

We may update this Policy as the platform, providers, or legal requirements change. This Policy shows its effective and last-updated dates. For a material change, we will provide notice in a manner appropriate to the change and our relationship with affected individuals; we do not promise that every website visitor will receive an email.

15. Contact

Privacy Officer
FindJobsCanada / The Shoppers Hub Canada Inc.
Email: hello@findjobscanada.ca
Subject: Privacy Request