1. Our approach
In plain terms: We collect the minimum we need to run a hosting company, and we do not sell any of it.
Polar Host Inc. is the organisation responsible for the personal information described here. We handle it in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy law.
Two commitments underpin everything below: we collect the least information we can while still running the service properly, and we never sell, rent, or trade your personal information or your customers’.
2. Information we collect
In plain terms: Account details, billing details, support conversations, and server logs.
Account information. Your name, business name, email address, phone number, mailing address, and the credentials for your account.
Billing information. Invoices, payment history, tax province, and the last four digits and expiry of your card. Full card numbers are handled by our PCI-DSS compliant payment processor and never touch our servers.
Support information. The messages you send us and our replies, so we have the history when you come back.
Technical information. Server, web, and mail logs including IP addresses, timestamps, requested resources, and user agents. These are what let us diagnose problems, detect abuse, and produce the uptime figures on our status page.
Website analytics. Aggregate, cookie-free page counts for polarhost.ca. We do not use third-party advertising or tracking scripts on this site.
3. Customer content
In plain terms: The data inside your sites and mailboxes is yours; we are just the custodian.
Anything you host with us — website files, databases, email, backups — is your content. If it contains personal information about other people, you are the organisation responsible for it and we act as your service provider.
We do not read, scan, mine, or analyse the contents of your sites, databases, or mailboxes for any purpose beyond operating the service. Automated malware and spam scanning look for known signatures; they do not build profiles and nobody reviews the output unless something is flagged.
Our staff access your content only when you ask us to help, or when it is genuinely necessary to keep the platform running or secure. That access is logged.
4. Why we use it
In plain terms: To provide the service, bill you, support you, keep the platform secure, and meet legal obligations.
- To create and administer your account and provide the services you ordered.
- To bill you and to keep the financial records tax law requires.
- To answer your support requests and follow up on them.
- To detect, investigate, and stop abuse, fraud, and attacks on our network.
- To send service messages: invoices, renewal notices, security advisories, and planned maintenance.
- To meet legal and regulatory obligations that apply to us in Canada.
We send marketing email only if you opt in, and every marketing message has a one-click unsubscribe. Service messages are not marketing and you cannot unsubscribe from them while you have an active account.
5. Where your data lives
In plain terms: In Canada. All of it. Including backups.
Your account data, your hosted content, your email, and your backups are stored in Canadian data centres in Toronto, Montréal, and Vancouver, operated by Canadian companies.
We do not replicate customer data outside Canada. If that ever needs to change, we will tell every affected customer in advance and explain what it means.
A small number of vendors necessarily process limited data — a payment processor for card transactions, an email relay for transactional mail. We keep that list short, we hold each vendor to written privacy commitments, and we choose Canadian providers where a workable one exists.
6. How long we keep it
In plain terms: As long as your account is open, plus a short tail for records the law requires.
- Account and hosted content: for the life of your account, then 30 days after cancellation, then permanent deletion.
- Backups: 7 to 90 days depending on plan, then overwritten.
- Server and access logs: 90 days, except logs retained longer for a specific abuse or security investigation.
- Support conversations: three years, so we have context if you come back.
- Invoices and financial records: seven years, as Canadian tax law requires.
7. Your rights
In plain terms: You can see it, correct it, take it with you, or ask us to delete it.
You may ask us to give you a copy of the personal information we hold about you, correct anything inaccurate, export your data in a portable format, or delete your information where we are not required to keep it.
You may also withdraw consent for anything optional, such as marketing email, at any time. Withdrawing consent for something essential to the service means we can no longer provide it.
Write to privacy@polarhost.ca or use the contact page. We reply within 30 days, and we will ask you to verify your identity first so nobody else can make a request in your name. There is no charge.
8. Government and legal requests
In plain terms: We require lawful process, we push back on fishing expeditions, and we tell you unless we are forbidden to.
We disclose customer information to law enforcement or a government agency only when we are compelled by valid Canadian legal process, such as a warrant, production order, or court order.
We review every request, we refuse or challenge ones that are overbroad or improper, and we disclose only the narrow set of data the order actually requires.
Unless a court order or the law forbids it, we notify the affected customer before disclosing anything, so you have the chance to respond.
Because your data is held in Canada by a Canadian company, foreign agencies must go through Canadian legal channels — they cannot compel us directly.
9. Security
In plain terms: Encryption in transit and at rest, least-privilege access, and we tell you fast if something goes wrong.
Traffic to our services is encrypted in transit with current TLS. Backups and stored volumes are encrypted at rest. Administrative access requires two-factor authentication, follows least privilege, and is logged.
No system is perfect. If a breach happens that creates a real risk of significant harm, we will notify affected customers and the Office of the Privacy Commissioner of Canada as PIPEDA requires, and we will tell you what happened rather than what our lawyers would prefer we said.
11. Children
In plain terms: Our services are not aimed at children.
Our services are intended for people aged 18 and over, or for younger people with a parent or guardian’s consent and on the guardian’s account. We do not knowingly collect personal information directly from children.
12. Changes and how to complain
In plain terms: We post changes here; if we cannot resolve a complaint, the federal Privacy Commissioner can review it.
We will update this page when our practices change and revise the date at the top. Material changes are emailed to account holders at least 30 days in advance.
If you have a privacy concern, write to privacy@polarhost.ca first — most things are settled quickly. If you are not satisfied with our response, you may bring a complaint to the Office of the Privacy Commissioner of Canada at priv.gc.ca.