Privacy policy
Flashbook — Privacy Policy
Last updated: August 27, 2026 Effective: August 27, 2026
1. Who we are
Flashbook Tattoos Inc. ("Flashbook", "the Company", "we", "us"), a
corporation incorporated federally under the Canada Business Corporations Act, operates
flashbook.ca and the Flashbook progressive web app (the "Platform"). We are the
organization accountable for the personal information described here.
We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and with the Act respecting the protection of personal information in the private sector (Quebec, as amended by Law 25), Alberta's PIPA, and British Columbia's PIPA, where those apply to you.
Privacy Officer: [privacy@flashbook.ca], 1839 Commercial Dr, Vancouver, BC V5N 4A6. We will give you their name on request.
2. The short version
| Customers have no account. | We identify your booking by a cookie and your email. |
| We collect what a booking needs. | Name, email, phone, and a description of the tattoo you want, including where on your body it goes. |
| The artist sees your request. | That is the point of it. They see your name, contact details, tattoo description, reference images, budget, and how far away you are and how you're travelling. Once you accept, they also see when you'll arrive. |
| Artists' exact locations are hidden. | Public map markers are deliberately offset by 150–300 metres. The real address is revealed to you only after an artist accepts your request. |
| We don't see your card. | Payments go to Stripe. We store only a reference. |
| We don't sell your information. | Not to anyone, for any purpose, ever. |
| We don't advertise to you. | No ad networks, no tracking pixels, no profile of you. We count page views without cookies, and the count cannot be traced back to you (§8). |
3. What we collect
3.1 If you book a walk-in (Customer)
You do not create an account. When you place a Walk-in Request we collect:
Contact information — your name, email address, and phone number.
Tattoo request details — your description of the design, its size in inches, whether it's black-and-grey or colour, where on your body it will go, your maximum budget if you name one, and any reference images you upload.
Booking and payment records — the artist you chose, timestamps for when you booked, when the artist responded, and when the booking ended; the outcome (accepted, declined, expired, cancelled, completed, no-show); who cancelled and any note they left; the $5.00 booking fee, whether it was charged or refunded, and a Stripe payment reference. We never receive or store your card number, CVC, or expiry date.
Travel information — when you book, we ask how you are getting here, and if you have granted location permission we use your device's location to work out roughly how far you are from the artist's public map marker. We store the travel mode and that distance, and we show both to the artist so they can decide whether to accept. After they accept, we use your location again to calculate a live arrival estimate, and we store the estimated minutes. We do not store your coordinates at any point, and we do not track your position as you travel.
Technical information — the strictly necessary and functional cookies listed in §8, your IP address, standard server logs, and the de-identified page view and portfolio view measurements described in §8.
3.2 If you enter a contest
Entering a contest is separate from booking, and neither one requires the other. When you enter we collect:
Contact information: your name, and either an email address or a phone number. This is a fresh copy that you give for the contest. We do not take it from a booking, and we do not use your booking details to enter you.
How you entered: whether the entry came from a booking confirmation screen or from the free entry form, and the date and time you ticked the box. Where the entry came from a booking, we record which booking, so we can tell at the draw whether the entry is eligible under the contest rules.
Marketing consent, if you gave it: a separate, optional box. Ticking it is never a condition of entering, of booking, or of anything else. If you tick it we record that you did, and when, and we send you one message with a confirmation link. Nothing is sent to you as marketing unless you tap it, and a request you never confirm is deleted after seven days.
3.3 If you ask to be notified
If you sign up for "notify me when this artist is available," we collect your phone number and store it against that artist, with a record of when we last messaged you.
3.4 If you are an Artist
Account — your email address and a password you choose. Our authentication provider (Supabase) stores the password only as a salted cryptographic hash. Neither we nor they keep it in a form anyone can read, it never appears in our logs, and a reset is a signed, expiring link sent to your own email.
Booking alerts — a request expires ten minutes after a client places it, so we tell you one has arrived. Email goes to your account address unless you turn it off in your settings. Text messages are off until you ask for them and give us a mobile number, which we store only while they are switched on.
Identity, which is private — your legal name, required to set up an account and to go available. We hold it for verification, safety, and payment disputes. It is never shown to customers, never appears on your public profile, and is readable only by Flashbook staff. We do not ask for or store government identification.
Instagram handle — the account we verify to confirm you are who you say you are. Your handle is public on your profile; the verification is a person at Flashbook confirming you can respond from that account.
Blood Borne Pathogens certificate, if you choose to upload one — the certificate document itself and its expiry date. This is optional: you can take walk-ins without it. The document is stored in a private bucket that no customer and no other artist can read; staff open it only to confirm it names you and has not expired. What the public sees is a badge, never the document. Deleted when you close your account (§11).
Profile, which is public — display name, pronouns, bio, profile photo, portfolio images, tattoo styles, hourly rate if you choose to show it, your rating, and your working hours.
Location — the exact latitude and longitude you pin during onboarding, your studio's street address, and, if you choose to add them, your own street address and a short note on how to find you (a buzzer, a floor, which door). Both address fields are optional, and neither replaces the pin. See §5 for exactly who can see this and when.
Activity — your availability status, the requests you receive, whether you accepted, declined, or ignored them, your decline reasons, your cancellations, and your no-shows. This drives the warning system in §12 of the Terms of Service.
3.5 What we do not collect
From customers, we do not collect health information, government identification, or age verification documents. Your artist checks your ID and asks about your medical history in person. That conversation is between you and them; it does not pass through the Platform and we never see it. Please do not put medical information into the tattoo description field.
The one document we ever hold is an artist's own Blood Borne Pathogens certificate, and only if they choose to upload it (§3.4). It is a training credential about the artist, not health information about anybody, and it is never collected from customers.
We do not use advertising cookies, tracking pixels, or session recording, and we do not build a browser fingerprint to identify or follow you across sites. We do measure how the Platform is used, in aggregate and without cookies; §8 sets out exactly what that records, and what it cannot do. The only device identifier we set is the first-party, abuse-prevention cookie described in §8, which exists solely to rate-limit form submissions; for the same purpose we compare a one-way hash of your IP address, which we do not store in the clear. We do not buy personal information from data brokers, and we do not enrich what you give us from outside sources.
4. Why we use it, and on what basis
Under PIPEDA we rely on your consent, which you give expressly by submitting a booking form or a phone number, or which is implied by the obvious purpose of the information you provide. We collect only what a reasonable person would consider appropriate in the circumstances.
| We use | To |
|---|---|
| Name, email, phone | Identify your booking to the artist; tell you when it is accepted, declined, or expired; contact you about a refund |
| Tattoo description, size, colour, placement, budget, reference images | Let the artist decide whether they can and want to do the work, and be ready when you arrive |
| Your device location | Calculate travel time to the artist. Processed in the moment; coordinates not stored |
| Travel mode and distance at booking | Show the artist how far away you are and how you are travelling, so they can decide whether to accept before they commit a chair |
| Travel mode and ETA | Tell the artist when to expect you |
| Booking outcome and timestamps | Charge, release, or refund the $5.00 fee; enforce the artist warning system; resolve disputes |
| Phone number (notify list) | Send one SMS when that artist becomes available |
| Name, email or phone (contest entry) | Enter you in the launch draw, and contact you if you win |
| Email or phone (marketing) | Send you news about Flashbook, only if you ticked the separate box asking for it |
| Name and mobile number (event queue) | Hold your place in the line at an event, and text you when the artist is ready for you |
| Contact details on an event listing | Invite that artist to claim the listing, so the profile on the floor plan becomes theirs |
| Artist email | Sign you in; tell you a client has requested a booking, unless you turn that off |
| Artist mobile number (booking alerts) | Text you that a client has requested a booking, if you asked us to |
| Artist location | Place a fuzzed marker on the public map; give the real address to a customer whose request you accepted |
| Artist legal name | Confirm who an artist is before they take walk-ins; resolve payment disputes and safety reports. Never published |
| Artist Instagram handle | Verify the account is theirs before they appear on the map; link the profile customers see |
| Artist Blood Borne Pathogens certificate | Confirm the document names that artist and is current, so their profile can show the badge |
| IP address, server logs | Keep the Platform secure, prevent abuse, debug faults |
| Anonymous page view measurements (§8) | See which parts of the Platform are actually used, and find pages that are slow or broken |
We do not use your information to profile you, score you, or make any decision about you by automated means, other than the automatic expiry of a booking after ten minutes.
Warnings, throttling, and suspensions applied to Artists are informed by automated counts of cancellations and no-shows, but the decision to suspend is reviewed by a person, and every decision can be appealed to a human under §12 of the Terms.
5. Location, in detail
Location is the most sensitive thing on this Platform, in both directions. Here is exactly how it works.
An artist's exact coordinates are never public. When an artist saves their location, a database trigger generates a separate, deliberately inaccurate marker, offset by a random 150–300 metres at a random bearing. The public map, and anyone browsing without a booking, sees only that offset marker. The real coordinates live in a table that anonymous visitors cannot read at all.
The real address is revealed only on acceptance. When an artist accepts your Walk-in Request, and only then, the Platform gives you their street address and exact coordinates so you can travel there. This is gated on two independent checks: your browser must hold the cookie proving the request is yours, and the request must actually be in the accepted state.
Your location is not stored. If you have granted location permission, we use it twice: once at booking, to work out roughly how far you are from the artist's public map marker, and again after they accept, to calculate a live arrival estimate. We keep only the distance in metres, the travel mode you picked, and the resulting estimate in minutes. We do not store your coordinates at any point, there is no location history, and there is no live tracking.
Artists: what your customer sees. Your street address, your note on how to find you, and your exact pin, once you accept. Consider this before pinning a home studio, and before writing a door code into the note.
6. Reference images
Reference images you upload with a booking are stored in a private storage bucket that anonymous visitors cannot read at all. Your artist views them through a short-lived, signed link that is generated only when they open your request and expires on its own. There is no public URL, and the stored file is never served without a fresh signature.
Images are deleted with the booking record under the schedule in §11.
7. Payments
Payment card details are collected and processed by Stripe on their own infrastructure, under Stripe's privacy policy. Flashbook stores only a payment reference identifier, the fee amount, and whether it was captured or refunded.
We never receive your full card number, security code, or expiry date, and cannot charge your card outside the $5.00 booking fee described in the Terms.
8. Cookies and measurement
Every cookie we set is first-party and either strictly necessary or functional. None are for advertising, none are read by a third party for its own purposes, and none track you across other websites. The measurement described at the end of this section sets no cookie at all. That is why the Platform shows no consent banner. This is the complete list.
Set for anyone who books:
| Name | Purpose | Flags | Lifetime |
|---|---|---|---|
fb_request | Proves a live Walk-in Request belongs to your browser, so only you can see the artist's address once they accept | httpOnly, SameSite=Lax | 6 hours |
fb_intent | Lets us release the payment hold your browser placed if you leave without completing the booking | httpOnly, SameSite=Lax | 1 hour |
fb_device | A random identifier used only to rate-limit form submissions and block automated abuse. It is not tied to your name, booking, or any profile, and it is never used to track you | httpOnly, SameSite=Lax | 12 months |
Set only for Artists, and only after sign-in: an authentication session cookie
(sb-…, set by our authentication provider Supabase) that keeps you signed in. If you
arrived on an invitation or "set up your profile" link, a short-lived cookie (fb_invite
or fb_waitlist, roughly 14 days) also carries the invitation token through signup, so a
pre-approved artist is not asked to be re-checked.
The Platform also uses your browser's local storage to remember interface preferences on your device; that never reaches our servers.
Blocking fb_request will prevent you from receiving an artist's address after they accept
your booking. Blocking the others will interfere with placing a booking or, for artists,
staying signed in.
Measurement
We use Vercel Web Analytics to count page views and to measure how quickly pages load. Vercel already hosts the Platform (§10), and this feature uses no cookies and no local storage.
Each page view records the page path, the site you arrived from, the country, region and city your request came from, your browser, operating system and device type, and the time. It does not record your name, your email address, your phone number, or anything about your booking, and it is not joined to any of them.
Query strings are removed before anything is sent. A link that carries an unsubscribe,
invitation, or review token in the address bar reaches us as the bare page path, with the
token stripped in your browser. Pages whose address contains a token as part of the path
are recorded as the pattern (for example /claim/[token]) and never as the token itself.
To count you once rather than once per page, Vercel derives a one-way hash from your incoming request. Your IP address is used to work out the city and to compute that hash, and is not stored with the measurement. The hash is discarded every 24 hours, cannot be reversed, is not shared with anyone, and does not follow you to any other website. There is no profile, no session recording, and no way for us to look up what any one person did.
Portfolio view counts. When you open an artist's card on the map or visit their public profile page, we record which artist you looked at, the time, and a one-way code derived from your network address using a server-side secret. We use this for exactly one thing: telling that artist how many different people looked at their portfolio while they were not taking walk-ins ("3 people checked out your portfolio"). The artist only ever sees the number. The code cannot be reversed into your address without the secret, which never leaves our servers; it is not joined to your name, email, phone number, booking, or account, and it does not follow you off the Platform. Each record is deleted after 90 days. Artists viewing their own card are not counted, and this measurement, like the one above, sets no cookie.
These are the only measurements of their kind on the Platform. If we ever add one that sets a cookie, identifies you, or follows you off the Platform, that is a material change, and §16 says how you will hear about it.
9. Who we share it with
Your artist. Everything in your Walk-in Request: your name, email, phone number, tattoo description, placement, budget, reference images, your travel mode, and your distance from them, all shown before they decide whether to accept. Once they accept, they also see your estimated arrival. They need it to do the work. They are independent contractors and become responsible for what they do with it once they have it.
Other customers. Nothing. Your booking is never visible to another customer.
Service providers. Listed in §10. Each is bound by contract to use the information only to provide the service to us.
Law enforcement and legal process. Where we are legally required to, or where we reasonably believe disclosure is necessary to investigate suspected fraud, to protect our rights, or to prevent imminent harm to any person. We will notify you of a demand for your information unless legally prohibited from doing so.
A successor. If Flashbook is acquired or merges, personal information may transfer as part of the transaction. The recipient will remain bound by this policy, and we will notify you before your information becomes subject to a different one.
We never sell your personal information, and we never disclose it to advertisers, data brokers, or list vendors.
One thing we deliberately do not share. When an artist declines your booking, they must select a reason from a fixed list — including "not my style" and "not comfortable." You never see the raw reason. You see a softened message. We retain the raw category to operate the warning system, and it is never shown to you or to any other customer.
10. Service providers and where your information goes
These providers process personal information on our instructions, to operate Flashbook. They are not permitted to use it for their own purposes. This is not a sale, and it is not disclosure to advertisers or data brokers — see §9.
The table below lists the providers we use today. We may replace a provider with another performing the same function. If we do, the purposes in §4 do not change, and we will update this table. If a replacement introduces a new category of recipient or sends personal information to a new country, that is a material change and we will tell you before it takes effect (see §16).
| Provider | What they do | Handles | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Everything in §3 | Canada (ca-central-1) |
| Vercel | Web hosting, CDN, and the anonymous page view measurement in §8 | IP addresses, request logs, and the measurements listed in §8 | United States |
| Sentry | Error and crash monitoring, to find and fix faults | IP address, the page or action that failed, and technical error diagnostics | United States |
| Stripe | Payment processing | Card details, payment references | Canada / United States |
| Resend | Transactional email | Email addresses, message content | United States |
| Twilio | Availability notifications (SMS) | Phone numbers | United States |
| OpenFreeMap | Map tiles | Your IP address when your browser requests tiles | European Union |
Sentry receives an error report only when something on the Platform breaks. It records what failed and the technical context needed to fix it, and it does not record your screen or session. Neither Sentry nor the measurement in §8 is used for advertising, and neither is used to build a profile of you or to follow you off the Platform.
Cross-border transfer. Some of these providers store or process personal information outside Canada, principally in the United States. While it is there, it is subject to the laws of that country, and may be accessible to foreign courts, law enforcement, and national security authorities under those laws — including where Canadian law would not permit it. This is disclosed to you so that your consent is meaningful. We use providers that offer contractual protections comparable to those required under Canadian law, but we cannot override foreign legal process.
If you are in Quebec, we have assessed these transfers as required by Law 25 before making them.
11. How long we keep it
| Information | Retention |
|---|---|
| Walk-in Request that expired, was declined, or was cancelled before acceptance | 90 days, then deleted |
| Completed, forfeited, or no-show Walk-in Request | 7 years, as a financial record required by tax and consumer-protection law |
| Reference images | Deleted when the booking record is deleted, or when its contact details are stripped, whichever comes first — 90 days at the outside. A nightly sweep then deletes the underlying file from storage |
| Messages you exchange with your artist (in-app or by SMS) | 30 days after the booking ends |
| Customer name, email, phone | Deleted with an unfulfilled request; on a record we must keep for tax reasons, stripped after 90 days so only the payment record remains |
| Notify-list phone number | Until you unsubscribe, or 12 months of inactivity. If you never confirm the opt-in, 7 days |
| Contest entry (your name, contact, and which booking it came from) | 90 days after the draw date, then deleted |
| Marketing consent | Marketing stops the moment you unsubscribe, and we keep the record that you consented, and when, as our proof of the consent you gave. If you never confirm the opt-in, 7 days |
| Event queue entry (your name and mobile number) | 90 days after you join the line, then deleted. Holding a place in a line takes no deposit and moves no money, so there is no financial record to keep and nothing survives the 90 days |
| Contact details on an event listing, used to invite an artist to claim it | 90 days after the event ends. The address, the number, and the claim link are all removed together, whether or not the listing was ever claimed |
| Artist mobile number (booking alerts) | Until you turn text alerts off, which deletes it, or you close your account |
| Artist account and profile | While the account is open. On closure you come off the map at once; 30 days later your profile, photos, and login are deleted and the account is de-identified. We keep a skeletal, nameless record only where a past booking requires it as a financial record |
| Artist legal name | While the account is open. Removed by the same 30-day de-identification on closure |
| Artist Blood Borne Pathogens certificate | The document itself is deleted the moment staff approve it. They need to read it once, to check the name and the expiry date; after that the approval and that expiry date are the entire record, and the certificate is not kept. One still waiting on review, or one that was turned down, keeps its document until it is replaced, so that a refusal can be looked at again. It is a health-and-safety credential, so it is never kept as part of the 7-year financial record, and closing your account clears the approval and the expiry along with everything else |
| Artist cancellations and no-shows | Recorded on the booking itself, and kept for as long as that booking is: 90 days where it was cancelled before an Artist accepted it, 7 years where it had been accepted and is a financial record |
| A confirmed artist no-show | Kept with that booking for 7 years. It is deliberately not removed by the 90-day strip above, because it is the evidence behind a suspension decision under §12 of the Terms, and evidence that expires cannot support one |
| A suspension or a verification decision, and the staff note explaining it | While the Artist account is open, and kept on the closed, de-identified record after that as our record of the decision |
| A review you leave | Indefinitely, as the Artist's public record. A review carries no name, email, or phone — only your rating, whatever you typed, and a one-way code we use to stop the same person reviewing the same job twice. It is not deleted when the booking behind it is, because by then it identifies nobody |
| Server and security logs | No longer than 90 days |
| Anonymous page view measurements (§8) | Held by Vercel as aggregate statistics for up to 12 months. The 24-hour visitor hash behind them is discarded daily, and nothing in them identifies you, so there is nothing in this row to delete on request |
| Backups | Our database is backed up daily. A backup is kept 7 days and then overwritten, so a deletion made in the live system disappears from backups within a week |
Deletion means deletion, not de-identification, except where we are required to keep a financial record — in which case we keep the minimum needed for that record and nothing else. The windows for your booking, message, contact, and account data are enforced automatically by a job that runs every night, not by hand.
12. Your rights
Whoever you are and wherever you live, you may:
- Access the personal information we hold about you, and be told how it has been used and to whom it has been disclosed;
- Correct anything inaccurate or incomplete;
- Withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent for a live booking will cancel it, and §7 of the Terms decides what happens to the fee;
- Delete your information, except what we must keep as a financial record;
- Complain to us, and then to a regulator, if you think we've got it wrong.
If you are in Quebec, you may additionally request that we cease disseminating information about you, request de-indexing, receive your information in a structured, commonly used technological format (portability), and be informed of the reasoning behind any decision based exclusively on automated processing.
How to exercise these rights. Write to [privacy@flashbook.ca].
Because Customers hold no account, we will ask you to confirm control of the email address used for the booking before we disclose or delete anything. This protects you: it prevents someone else obtaining your booking history by knowing your name. We will not ask for identity documents. We respond within 30 days and will tell you if we need longer and why. Access is free unless a request is manifestly unfounded or repetitive.
13. Email and SMS (CASL)
We send transactional messages about a booking you placed — acceptance, decline, expiry, refund. Depending on the contact details you gave when booking, these arrive by email or by text message to that number. They are not marketing, and you cannot unsubscribe from them while a booking is live, because they are how the booking works.
We send a separate availability SMS only if you explicitly asked to be notified when a specific artist becomes available. That request is your express consent under Canada's Anti-Spam Legislation. Every such message identifies Flashbook and tells you how to stop: reply STOP at any time, at no cost, and it takes effect immediately. We keep a record of when and how you gave that consent.
If you are an artist, we email you when a client requests a booking, and we text you as well if you switched that on and gave us a number. Both are transactional: they are how a booking reaches you. Turning either off is a switch in your artist settings, and every text also stops on STOP.
We send marketing email only to people who ticked a separate box asking for it, which today means the optional box on a contest entry, and who then confirmed by tapping the confirmation link we send them. A box somebody else could have ticked is not consent, so nothing markets to an address that never tapped, and an unconfirmed request is deleted after seven days. The box is never ticked for you, and it is never a condition of entering a contest, of booking, or of anything else. We keep a record of when you ticked and when you confirmed. Every marketing message identifies Flashbook and carries an unsubscribe link that works in one click and takes effect immediately.
If you enter a contest, we send you one message confirming the entry, except we skip it for an email address that has already opted out of Flashbook email. We contact you again only if you win. Those are about the contest you entered, not marketing, and they go to the address or number on your entry.
We will not treat a booking as consent to be marketed to.
14. Security
We protect personal information with safeguards appropriate to its sensitivity:
- Row-level security in the database, so that a query can only return rows the caller is entitled to. Anonymous visitors cannot read artists' exact locations at all.
- Ownership of an anonymous booking is proved by an
httpOnlycookie that JavaScript cannot read, and address disclosure is additionally gated on the booking being accepted. - Encryption in transit (TLS) and at rest.
- Artist passwords are stored only as salted hashes by our authentication provider; we never see or store the plaintext, and a reset is a signed, expiring link to your own email.
- Access to production data limited to personnel who need it.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, as PIPEDA requires, and the Commission d'accès à l'information if you are in Quebec.
Tell us immediately at [security@flashbook.ca] if you find a vulnerability. We will not pursue legal action against anyone who reports one in good faith and gives us reasonable time to fix it.
15. Children
The Platform is for adults. Tattooing a minor through Flashbook is prohibited without exception. We do not knowingly collect personal information from anyone under 18. If we learn we have, we delete it. If you believe a child has given us information, write to [privacy@flashbook.ca].
16. Changes to this policy
We may update this policy, and an update takes effect when we post it. We are early enough that how we handle information is still changing, and a fixed notice period would be a timetable we could not always keep.
What we already hold does not move on posting alone. Where an update would mean using information we have already collected for a new purpose, disclosing it to a new category of recipient, or sending it somewhere new, we ask for your consent before doing that. Posting a new policy is not how we get it, and the new terms do not reach backwards over information you gave us under the old ones.
We tell you rather than leave you to notice. A material change (a new purpose, a new category of recipient, a new cross-border transfer, a longer retention period) is posted prominently on the Platform. Artists are asked to read the updated policy and agree to it on their dashboard, and cannot go available until they do.
We keep prior versions, each one dated, and will provide any of them on request. The Last updated line at the top of this document tells you which one you are reading.
17. Contact and complaints
Privacy Officer Flashbook Tattoos Inc. 1839 Commercial Dr, Vancouver, BC V5N 4A6 [privacy@flashbook.ca]
We will give you the Privacy Officer's name on request.
Please come to us first — we would rather fix a problem than argue about it. We acknowledge every complaint within 10 business days and investigate all of them.
If you are not satisfied with our response, you may complain to:
Office of the Privacy Commissioner of Canada 30 Victoria Street, Gatineau, Quebec K1A 1H3 · 1-800-282-1376 · priv.gc.ca
Residents of Quebec, Alberta, and British Columbia may instead complain to their provincial commissioner:
- Quebec — Commission d'accès à l'information · cai.gouv.qc.ca
- Alberta — Office of the Information and Privacy Commissioner · oipc.ab.ca
- British Columbia — Office of the Information and Privacy Commissioner · oipc.bc.ca