Privacy Policy for 2604927 Ontario Inc. (o/a Gray Line Toronto & Gray Line Niagara Falls Canada) and VIP Tours Corporation (o/a Gray Line Niagara Falls US)
Last Updated: May 10, 2025
1. Introduction
Welcome to Gray Line Toronto, Gray Line Niagara Falls Canada and Gray Line Niagara Falls US (the "Brands"), operated by 2604927 Ontario Inc. and VIP Tours Corporation ("we," "us," "our," "Company"). We are a licensed franchisee of Gray Line Worldwide. We are committed to protecting the privacy and security of the personal information of our customers and website users ("you," "your").
This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you visit our websites graylinetoronto.com and graylineniagarafalls.com (the "Website"), book our tours, use our services, or otherwise interact with us. It also outlines your rights regarding your personal information.
This policy is designed to comply with Canadian federal and provincial privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA), and to align with best practices, including principles of the General Data Protection Regulation (GDPR) for any users to whom it may apply.
2. Information We Collect
We collect personal information in various ways, including when you provide it to us directly, when you use our services, and when you visit our website or interact with our online platforms.
a. Information You Provide Directly:
Booking Information: When you book a tour through our booking platform, CheckFront, we collect information such as your full name, email address, phone number, billing address, number of participants, names of participants (if required), tour preferences, pick-up/drop-off locations, and any special requests or accessibility needs you provide.
Payment Information: When you make a booking, payment is processed by our third-party payment processor, Stripe, often via our booking platform, CheckFront. Stripe will collect your payment card details (credit/debit card number, expiry date, CVV), billing address, and other information necessary to process the transaction securely. We do not directly collect or store your full payment card details on our servers. We receive confirmation of payment, transaction details, and potentially the last four digits of your card for identification and record-keeping purposes from Stripe or CheckFront.
Communication Information:
- When you contact us via email, phone, or our website contact forms, we collect your name, email address, phone number (if provided), and the content of your communications.
- If you communicate with us using our chat solution (tawk.io), we collect your name, email address (if provided), IP address, chat transcripts, and browser/OS information provided via tawk.io.
- If you communicate with us via Meta Platforms such as WhatsApp, Facebook Messenger, or Instagram Direct Messages, we collect your account identifier (e.g., phone number for WhatsApp, profile ID for Facebook/Instagram), the content of your communications, and any media shared.
Account Information: If you create an account on our booking platform (CheckFront), we collect information related to your account, such as your username and password.
b. Information Collected Automatically:
Website Usage Information: When you visit our website, we use Google Marketing Platform tools (Google Analytics, Google Tag Manager) and other technologies to automatically collect information about your device and Browse activity. This may include your IP address, browser type, operating system, device identifiers, pages viewed, links clicked, the date and time of your visit, referring URL, and general location information (e.g., city based on IP address).
Cookies and Similar Technologies (including Meta Pixel): We use cookies, web beacons, pixels (such as the Meta Pixel), and similar tracking technologies to collect website usage information, remember your preferences, and for advertising and analytics purposes. For more information, see Section 6 ("Cookies and Tracking Technologies").
Google Ads: If you interact with our advertisements through Google Ads, Google may collect information related to your interaction with those ads and subsequent activity on our website for conversion tracking and remarketing purposes.
Meta (Facebook & Instagram) Advertising and Page Interactions:
- When you interact with our advertisements on Facebook or Instagram, Meta may collect information about your interaction for ad performance tracking and targeting.
- If you visit our website after interacting with our Meta ads, the Meta Pixel may collect information about your activities on our site (e.g., pages visited, tours viewed, bookings initiated or completed) to help us measure ad effectiveness, create custom audiences for future ads, and deliver more relevant advertising to you on Meta platforms.
- If you interact with our business pages or profiles on Facebook or Instagram (e.g., by liking, commenting, sharing, or following), Meta provides us with aggregated analytics and insights about user engagement and demographics, but we do not typically receive personal information about specific individuals from these general interactions unless you directly message us or provide it in a public comment.
c. Information from Third Parties:
- Gray Line Worldwide: As a franchisee, we may receive booking information or customer referrals from Gray Line Worldwide.
- Booking Platforms (CheckFront): Our booking platform, CheckFront, processes bookings and provides us with your booking details and customer information. You can review CheckFront's privacy policy here: https://www.checkfront.com/terms/privacy/
- Payment Processors (Stripe): Our payment processor, Stripe, provides us with confirmation of your payment transactions. Stripe's privacy policy can be found here: https://stripe.com/en-ca/privacy
- Social Media Platforms (Meta): Meta may provide us with information related to the performance of our advertising campaigns and engagement with our content on Facebook and Instagram, often in an aggregated or anonymized form. Meta's data practices are governed by their privacy policy: https://www.facebook.com/privacy/policy/ (for WhatsApp, also see https://www.whatsapp.com/legal/privacy-policy).
- Google: Google may provide us with information related to the performance of our advertising campaigns and website analytics. Google's privacy policy can be found here: https://policies.google.com/privacy
3. How We Use Your Information
We use your personal information for the following purposes:
To Provide and Manage Our Services:
- Process and confirm your tour bookings (facilitated by CheckFront and Stripe).
- Communicate with you about your bookings, services, and inquiries (including via email, phone, tawk.io chat, and Meta messaging platforms like WhatsApp, Facebook Messenger, or Instagram Direct Messages if you initiate contact or consent to communication through these channels).
- Provide customer support.
- Manage your account (if applicable via CheckFront).
- Facilitate tour operations, including logistics and coordination.
To Improve Our Services and Website:
- Analyze website traffic and user behavior (using Google Analytics and data from the Meta Pixel) to understand how our website and services are used.
- Improve website functionality, user experience, and our tour offerings.
- Conduct internal research and development.
For Marketing and Advertising (with your consent where required):
- Send you promotional emails, newsletters, and special offers about our tours and services, in compliance with Canada's Anti-Spam Legislation (CASL). You can opt-out at any time.
- Deliver targeted advertising through platforms like Google Ads and Meta (Facebook and Instagram) Ads based on your interests, interactions with our website (e.g., via the Meta Pixel and Google's tracking technologies), and demographic information.
- Create custom audiences for advertising on Meta platforms and Google.
- Measure the effectiveness of our advertising campaigns on Google and Meta platforms.
- Engage with our audience and respond to comments and messages on our Meta social media pages (Facebook, Instagram).
For Legal and Security Purposes:
- Comply with applicable laws, regulations, and legal processes.
- Protect our rights, property, and safety, and the rights, property, and safety of our users and others.
- Prevent and detect fraud, security breaches, and other prohibited or illegal activities (including through fraud prevention tools used by our payment processor, Stripe).
- Enforce our Terms and Conditions.
4. Legal Basis for Processing (for GDPR purposes)
If you are in the European Economic Area (EEA), our legal basis for collecting and using your personal information as described above will depend on the personal information concerned and the specific context in which we collect it.
- Contract: We process your personal information to fulfill our contractual obligations to you (e.g., to process your tour booking and payment).
- Consent: We will obtain your consent for certain processing activities (e.g., for sending marketing communications, or for using certain cookies). You can withdraw your consent at any time.
- Legitimate Interests: We may process your personal information based on our legitimate interests, provided these interests are not overridden by your data protection rights (e.g., for website analytics, fraud prevention, improving our services).
- Legal Obligation: We may process your personal information to comply with our legal obligations (e.g., financial record-keeping).
5. Sharing and Disclosure of Your Information
We do not sell your personal information. We may share your personal information with third parties in the following circumstances:
Service Providers: We share information with third-party service providers who perform services on our behalf, such as:
- CheckFront: Our booking engine provider, for processing bookings and managing customer data related to bookings. (Privacy Policy: https://www.checkfront.com/terms/privacy/)
- Stripe: Our payment processing provider, for securely handling financial transactions when you book a tour. (Privacy Policy: https://stripe.com/en-ca/privacy). They are also typically required to maintain standards such as PCI DSS compliance for payment processing.
- tawk.io: Our live chat provider, for customer support communications. (Privacy Policy: https://www.tawk.to/privacy-policy/)
- Google Marketing Platform (Google LLC): For website analytics, tag management, and advertising services. (Privacy Policy: https://policies.google.com/privacy)
- Meta Platforms, Inc.: For advertising on Facebook and Instagram (including through the Meta Pixel), managing our social media presence, and for communications via WhatsApp, Facebook Messenger, or Instagram Direct Messages. Data shared with Meta is subject to their Data Policy: https://www.facebook.com/privacy/policy/ (and supplemental WhatsApp policy: https://www.whatsapp.com/legal/privacy-policy).
- Email Marketing Providers: To send newsletters and marketing communications (with your consent). These service providers are contractually obligated to protect your information and are restricted from using it for any other purpose beyond providing services to us.
Gray Line Worldwide: As a franchisee, we may be required to share certain booking information or operational data with Gray Line Worldwide for brand compliance, reporting, or central reservation system purposes.
Legal Requirements: We may disclose your information if required by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
With Your Consent: We may share your information with other third parties with your explicit consent.
6. Cookies and Tracking Technologies
We use cookies and similar technologies (e.g., web beacons, pixels) on our website.
What are Cookies: Cookies are small text files placed on your device when you visit a website. They help us recognize your device, remember your preferences, analyze website traffic, and for advertising purposes.
Types of Cookies We Use:
- Essential Cookies: Necessary for the website to function properly (e.g., for booking processes via CheckFront and facilitating payment via Stripe).
- Performance/Analytics Cookies (e.g., Google Analytics): Collect information about how you use our website, such as which pages you visit and if you experience any errors. This helps us improve our website. Google's use of this data is governed by its privacy policy.
- Functionality Cookies: Allow the website to remember choices you make (e.g., language preferences) and provide enhanced features. For example, tawk.io may use cookies to remember your chat session.
- Advertising/Targeting Cookies (e.g., Google Ads, Meta Pixel): Used to deliver advertisements more relevant to you and your interests, both on our website and on third-party sites (like Facebook, Instagram, and Google partner sites).
The Meta Pixel allows Meta to collect information about your visit to our website, which can be used to show you targeted ads on Facebook and Instagram, create custom audiences, and measure ad conversions. You can learn more about Meta's ads and manage your preferences through your Facebook and Instagram settings.
Google Ads cookies enable Google and its partners to serve ads to you based on your visit to our site and/or other sites on the Internet. You can manage your Google ad preferences through Google's Ad Settings.
Your Choices:
- Most web browsers allow you to control cookies through their settings. You can usually set your browser to refuse cookies or to alert you when cookies are being sent. However, if you disable cookies, some parts of our website may not function properly.
- You can opt-out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
- You can manage your advertising preferences for Google here: https://adssettings.google.com
- You can manage your advertising preferences for Meta (Facebook and Instagram) within your account settings on those platforms. More information on Meta's ad controls can typically be found in their Help Center or Privacy sections.
For more information about cookies and how to manage them, you can visit www.allaboutcookies.org.
7. International Data Transfers
Your personal information may be processed and stored in countries outside of your country of residence, including Canada and the United States, where our service providers (e.g., Google, Meta, CheckFront, tawk.io, Stripe) may have servers.
These countries may have data protection laws that are different from the laws of your country. When we transfer your information outside of Canada or the EEA, we will take appropriate steps to ensure that your personal information is protected in accordance with this Privacy Policy and applicable laws. This may include using Standard Contractual Clauses approved by the European Commission or ensuring the recipient is in a country deemed to provide an adequate level of data protection.
You acknowledge that by using our services, your information may be processed by these third parties in other jurisdictions, subject to their respective privacy policies (linked above).
8. Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your personal information from unauthorized access, use, disclosure, alteration, or destruction. These measures include encrypted connections via HTTPS, access controls, and regular security assessments.
When it comes to payment information, we rely on our PCI DSS compliant payment processor, Stripe, to handle sensitive payment card details securely. We do not store your full credit card number on our servers.
However, no method of transmission over the Internet or electronic storage is 100% secure. Therefore, while we strive to protect your personal information, we cannot guarantee its absolute security.
9. Data Retention
We will retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. For example, transaction data (including some personal information) may be kept for several years to comply with financial and tax regulations.
The criteria used to determine our retention periods include:
- The length of time we have an ongoing relationship with you and provide services to you.
- Whether there is a legal obligation to which we are subject (e.g., tax or accounting requirements).
- Whether retention is advisable in light of our legal position (e.g., in regard to applicable statutes of limitations, litigation, or regulatory investigations).
When your personal information is no longer needed, we will securely destroy or anonymize it.
10. Your Privacy Rights
Depending on your jurisdiction (e.g., under PIPEDA or GDPR), you may have certain rights regarding your personal information. These may include:
- Right to Access: You have the right to request access to the personal information we hold about you.
- Right to Rectification: You have the right to request correction of inaccurate or incomplete personal information.
- Right to Erasure (Right to be Forgotten): You have the right to request the deletion of your personal information under certain conditions (this may be limited by legal or contractual retention obligations, particularly for transaction data).
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal information under certain conditions.
- Right to Data Portability: You have the right to request a copy of your personal information in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller, under certain conditions.
- Right to Object: You have the right to object to the processing of your personal information under certain conditions, particularly for direct marketing purposes or processing based on legitimate interests.
- Right to Withdraw Consent: If we are processing your personal information based on your consent, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority, such as the Office of the Privacy Commissioner of Canada or your local data protection authority in the EEA.
To exercise any of these rights, please contact us using the details provided in Section 14 ("Contact Us"). We will respond to your request in accordance with applicable laws. We may need to verify your identity before processing your request.
Please note that for data processed primarily by our third-party service providers (like payment details held by Stripe or interactions solely within Meta platforms), you may also need to contact those providers directly to exercise some of your rights.
11. Children's Privacy
Our services are not directed to children under the age of 16 (or a lower age if stipulated by applicable law in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child without parental consent, we will take steps to delete such information. If you believe we might have any information from or about a child, please contact us.
12. Third-Party Links
Our website may contain links to other websites or services operated by third parties (e.g., local attractions, partners), including the platforms of our service providers like Google, Meta, CheckFront, tawk.io, and Stripe. This Privacy Policy does not apply to such third-party websites or services once you leave our website. We encourage you to review the privacy policies of those third parties (links provided where applicable in this policy) before providing them with your personal information or interacting with their services.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. We will post any changes on this page and update the "Last Updated" date at the top. If we make material changes, we will provide more prominent notice (e.g., by email or a notice on our website) prior to the change becoming effective. We encourage you to review this Privacy Policy periodically.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
2604927 Ontario Inc.
88 Queens Quay W Suite 2500, Toronto,
ON M5J 0B8