top of page

Privacy Policy

Effective Date: July 8, 2026
Last Updated: July 8, 2026

Busy Blooming (operated as a sole proprietorship by Tessa Barclay in Ontario, Canada) respects your privacy. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over it, when you use our website at https://busyblooming.ca, the Busy Blooming HQ members area at https://hq.busyblooming.ca, our mobile applications (including the Busy Blooming iOS app), and any related services (together, the "Services").

This policy is designed to comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.

1. Information We Collect

1.1 Information you give us directly

•    Account information: name, email address, member ID, subscription status, and passwordless sign-in (magic-link) records. We do not use account passwords.

•    Billing information: billing name, email, country, postal code, card details (card number, CVC, expiry). Full card details are submitted directly to our payment processor, Stripe, and are never stored on our servers.

•    Member-created content: agenda or to-do items, content drafts and versions you create in HQ tools, preference and orientation settings, and questions you submit for support.

•    AI tool inputs (optional): text you choose to submit to AI drafting tools, such as a brand message you paste into the pitch drafter. See Section 4 for how this is processed.

•    Communications: any messages you send us by email, reply, or form submission, including support requests and feedback.

1.2 Information collected automatically

•    Device, app, and usage data: IP address, browser or device type, operating system, app version, device and install identifiers, pages or screens viewed, links tapped, episodes played and watch progress, saved or tried idea status, feature-use events, news-read status, and session timestamps. For website and email analytics, our providers may also derive approximate location (city/region) from IP address.

•    Crash and performance data: crash reports and app performance measurements from the mobile app, with our error-reporting tool configured not to collect personal details by default and to scrub common personal information before sending (see Section 4, Sentry).

•    Cookies and similar technologies: small data files stored in your browser to keep you logged in, remember preferences, and measure aggregate usage. See Section 5.

•    Push-notification tokens (if you opt in): a device or browser push token used only to deliver notifications you have requested.

1.3 Information from third parties

•    Payment processor (Stripe): the last four digits of your card, card brand, expiry month/year, billing country, subscription status, invoice history, and in some cases tax status. We do not receive your full card number.

•    Email providers: delivery and related logs for emails we send you, including open and click events where available for website, newsletter, and membership emails sent through Ghost/Mailgun. App sign-in emails are delivered through Microsoft 365, which provides delivery status only.

2. How We Use Your Information

We use your information only for the purposes for which it was provided, and for closely related purposes that a reasonable person would expect:

•    To create and maintain your account.

•    To process payments, send invoices, and manage subscriptions.

•    To deliver the HQ content, audio, video, and notifications you have signed up for.

•    To operate member tools in the app and on the site, including saving your progress, saved items, preferences, agenda items, and drafts across your devices.

•    To provide optional AI drafting tools when you choose to use them, including sending the text you submit to our AI service provider to generate a response.

•    To send transactional messages about your account, security, billing, and changes to the Services.

•    To send membership updates and content announcements to current members (unless you have unsubscribed).

•    To respond to your questions, support requests, and feedback.

•    To operate, protect, debug, and improve the Services, including defending against fraud, abuse, account sharing, and security incidents.

•    To calculate and remit applicable sales or value-added taxes.

•    To comply with applicable law, court orders, and lawful requests from public authorities.

We do not sell your personal information, rent it out, or share it with advertisers for targeted advertising.

3. Legal Bases for Processing

Where applicable under PIPEDA or equivalent law, we rely on one or more of the following bases:

•    Performance of a contract with you (delivering the Services you signed up for).

•    Your consent (for optional items like push notifications, AI tools, non-transactional email marketing, or any cookies that require opt-in).

•    Our legitimate interests in operating, improving, and protecting the Services, provided these do not override your rights.

•    Legal obligation (for example, tax record-keeping).

4. Who We Share Information With

We share personal information with trusted service providers who help us operate the Services, and in the limited additional circumstances described below. We share or make available only what is reasonably necessary for them to provide those services. Current providers include:

Provider    What they do    Where data lives

Ghost Pro    Membership platform, member records, content management, member emails    United States / European Union

Stripe, Inc.    Payment processing, billing, tax calculation, invoicing    United States

Cloudflare, Inc.    Application services and security for HQ, including our app API, rate limiting, sign-in link records, and member app data (progress, saved items, preferences, agenda items, drafts, feature-use events, push tokens, and deletion records)    Global edge network; member app data is stored in North America

Anthropic    AI draft generation for optional tools (such as the pitch drafter and idea sketches), only when you choose to use them    United States

Sentry    App crash reporting and performance monitoring, with personal details scrubbed before sending    United States

Microsoft    Email delivery for app sign-in links (Microsoft 365)    Canada / United States / global Microsoft infrastructure

Mailgun (via Ghost)    Website, newsletter, and membership email delivery    United States / European Union

Bunny.net    Video and audio streaming for HQ content    Global CDN (primary: EU)

Apple and browser push services    Push-notification delivery, only if you enable notifications    Global

Wix    Hosting and security for busyblooming.ca    United States / Global CDN

Each provider is bound by their own terms and privacy policy, and we choose providers that commit to reasonable safeguards through their terms, policies, or data-processing agreements.

AI processing: when you use an optional AI tool (such as the pitch drafter), the text you submit is sent to Anthropic, our AI service provider in the United States, to generate a draft response. Busy Blooming does not intentionally store the text you submit on our own servers after your draft is generated; our servers are designed to log metadata only (request identifiers, timestamps, token counts, and request status), not the content itself. Anthropic processes the submitted text under its API terms and does not use API inputs or outputs to train its models. Please do not submit sensitive information, or personal information about someone else, unless you have the right to share it.

Embedded third-party content: when you view content embedded from other platforms (for example TikTok, Instagram, or YouTube posts, Canva reports, or live-session video and polls from YouTube and AhaSlides), your device connects to that platform directly, and the platform may receive your IP address, device and browser information, and cookie identifiers, governed by its own privacy policy. The same applies if you choose to open off-platform spaces we link to, such as our Instagram group chat.

We may also disclose information:

•    To comply with a valid legal process (subpoena, court order, CRA request).

•    To protect the rights, safety, or property of Busy Blooming, members of HQ, or the public.

•    In connection with a sale, merger, or reorganization of the business (with notice to affected users).

5. Cookies and Similar Technologies

We use cookies and similar technologies to:

•    Keep you signed in to HQ (essential).

•    Remember your preferences (essential).

•    Measure aggregate usage so we can improve the Services (analytics).

•    Detect abuse and fraud (security).

Embedded third-party content (for example TikTok, Instagram, YouTube, Canva, or AhaSlides embeds) may set its own cookies or similar identifiers, governed by those platforms' privacy policies; we do not control these.

You can control cookies through your browser settings. Disabling essential cookies may break sign-in and paid-content access.

6. International Transfers

Because some of our providers operate outside Canada (mainly in the United States and European Union), your information may be transferred to, stored, and processed in those jurisdictions. Where required, we rely on contractual safeguards to ensure your information receives a comparable level of protection. By using the Services you acknowledge this transfer.

7. How Long We Keep Information

•    Account and app data: kept while your account is active. If you delete your account (available in the app, or by emailing us), access is revoked immediately and the account enters a 7-day recovery period. If you do not restore it during that period, we permanently delete your member record and your app data (progress, saved items, preferences, agenda items, drafts, feature-use events, read status, and push tokens), except limited records we must keep for legal, tax, security, dispute, or fraud-prevention reasons.

•    Billing and tax records: retained by us and/or Stripe for as long as required by Canadian tax law (currently 6 years from the end of the fiscal year to which they relate) and for legitimate dispute, chargeback, and accounting needs.

•    Transactional emails and logs: typically up to 12 months.

•    Push subscriptions: until you turn off notifications, we detect the subscription has expired, or your account is deleted.

•    Support messages: up to 24 months after the support issue closes. If a question you submitted has been edited, anonymized, and published as HQ content, the published version may remain after account deletion.

When personal information is no longer needed, we delete or anonymize it. Copies of deleted data may persist for a limited time in provider-managed backups, which expire on their normal schedules and are not used to restore deleted accounts except in a disaster-recovery scenario.

8. Your Rights

Under PIPEDA and similar laws, you have the right to:

•    Access the personal information we hold about you.

•    Correct any information that is inaccurate or incomplete.

•    Withdraw consent for optional processing (such as marketing emails, push notifications, or AI tools) at any time.

•    Request deletion of your account and personal information — available self-serve in the app, or by emailing us — subject to the 7-day recovery period and any legal obligation we have to retain certain records (for example, tax records).

•    Request a copy of your information in a portable format.

•    Make a complaint to us (hello@busyblooming.ca) or to the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca.

To exercise any of these rights, email hello@busyblooming.ca from the address associated with your account. We respond within 30 days.

9. Security

We take reasonable administrative, technical, and physical safeguards to protect your information:

•    Passwordless magic-link authentication (no password reuse risk).

•    Payment card details handled exclusively by Stripe (PCI DSS Level 1 certified).

•    HTTPS on all services that handle personal data.

•    Principle-of-least-privilege access to production systems.

•    Routine backups and monitoring.

No system is 100% secure. If we discover a breach that creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as soon as feasible, as required by law.

10. Children

The Services are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us so we can delete it.

11. Do Not Track and Similar Signals

Because there is no common standard, our website does not currently respond to "Do Not Track" signals, but we honour all opt-outs listed in Section 8.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and, where required, notify paid members by email or in-product notification. Continued use of the Services after the effective date of an updated version means the updated policy applies to your future use. Where required by law, we will request fresh consent for material new uses or disclosures of personal information.

13. Contact Us

Privacy questions or requests:

Email: hello@busyblooming.ca

Our person in charge of the protection of personal information (privacy officer) is Tessa Barclay, reachable at the email address above.

Office of the Privacy Commissioner of Canada:

https://www.priv.gc.ca — 1-800-282-1376
bottom of page