KIDO Events

KIDO policy

Privacy Policy

Effective and last updated August 19, 2026 · Version 2026-08-19

This policy explains how KIDO Events collects, uses, shares, protects, and retains personal information. It also explains the choices and privacy rights available to you.

1. Scope

This policy applies to KIDO’s public family site, accounts, saved lists, community features, Ask Do, provider organization tools, feedback, and related communications. Third-party providers and websites linked from KIDO have their own privacy practices.

2. Information we collect

  • Account information: email address, account identifier, display name, sign-in provider, and agreement records.
  • Family-site activity: saved listings and lists, sharing and collaborator choices, followed organizations, likes, comments, ratings, and Ask Do prompts and responses.
  • Organization information: role, membership, invitations, claim activity, listings, organization content, images, edits, approvals, and audit history.
  • Feedback and communications: messages, survey responses, support requests, and email preferences.
  • Device and usage information: page, referrer, timestamps, browser and device details, approximate network information, and random browser or visit identifiers.
  • Session replay: on eligible public pages, KIDO can record page structure, clicks, scrolling, and navigation. Inputs are masked and sensitive surfaces are blocked. KIDO does not intentionally record passwords or payment-card fields.
  • Public-source evidence: provider websites, public listings, source links, correction history, and evidence needed to maintain accurate catalog data.

3. How we use information

We use information to operate accounts and lists, deliver requested features, manage sharing and organization access, personalize results, respond to support, prevent abuse, keep listings accurate, measure and improve the service, maintain security and audit records, comply with law, and communicate service or policy changes.

KIDO’s aggregate usage measurement separates signed-in users from anonymous visitors. Signed-in traffic uses verified account identity, while anonymous traffic uses a separate rotating browser identifier. Both are hashed server-side to count each identity once per day and classify first-seen or returning traffic. Incomplete or pre-identity traffic remains unclassified.

4. Permission and reasonable purposes

We collect and use information with your consent where consent is appropriate, to provide features you request, and for reasonable purposes connected to operating and securing KIDO. You can withdraw optional consent at any time, but that does not affect earlier permitted processing and can make an optional feature unavailable.

5. When information is shared

KIDO does not sell personal information and does not share it for cross-site behavioural advertising. We share only what is reasonably needed with:

  • infrastructure, hosting, storage, authentication, email, security, and support providers working for KIDO;
  • Amazon Bedrock in the United States when you submit content to Ask Do or another clearly identified AI-assisted feature;
  • Google or Meta when you choose their sign-in service;
  • people you invite to a shared list and authorized members of an organization, according to the role and sharing controls shown to you;
  • professional advisers, authorities, or affected parties when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or complete a business reorganization subject to appropriate safeguards.

KIDO primarily uses Google Firebase and related Google Cloud services for account, database, hosting, storage, and application infrastructure.

6. Processing outside Ontario

Service providers can process or store information in Canada and the United States. Information in another country can be subject to that country’s laws and lawful access by its authorities. KIDO uses contractual, access, and technical safeguards appropriate to the service and information involved.

7. Your choices

  • Use KIDO’s persistent Privacy control to opt out of session replay. Replay starts on eligible public pages unless you opt out.
  • Use account and list controls to manage sharing, collaborators, follows, saved content, and community activity.
  • Use the unsubscribe link in optional promotional email. Account, security, invitation, and service messages can still be sent when needed.
  • Choose whether to use Google or Meta sign-in and whether to use Ask Do.
  • Ask us to access, correct, or delete your information as described below.

8. Retention

We retain information only as long as reasonably needed for the purposes above, legal obligations, disputes, and security. Current standard periods are:

  • session replay segments: 30 days;
  • random visit and browser identifiers used for replay and related usage records: up to 400 days;
  • Ask Do content linked to an account: up to 12 months;
  • feedback and survey records: up to 24 months;
  • denied organization-access attempts: 90 days;
  • expired organization claim codes: 30 days after expiry;
  • ordinary application and security logs: up to 12 months;
  • active account data: for the life of the account, then ordinarily deleted or de-identified within 30 days after a completed deletion request;
  • agreement, organization-role, and material audit records: up to 7 years where needed to prove authorization, protect the service, or meet legal obligations;
  • confirmed privacy-breach records: at least 24 months where required.

De-identified aggregate information that no longer identifies a person can be kept longer. Backups and legal holds can delay final deletion for a limited period.

9. Safeguards

KIDO uses access controls, authentication, role checks, server-mediated sharing and uploads, input masking, encrypted network connections, logging, and retention limits designed for the sensitivity of the information. No online service can guarantee perfect security. Please use a unique password and tell us if you suspect unauthorized account use.

10. Access, correction, deletion, and complaints

You can ask what personal information KIDO holds about you, request access or correction, withdraw optional consent, request deletion, or make a privacy complaint by contacting KIDO’s Privacy Lead at ben@kido.events. We may need to verify your identity. We ordinarily respond within 30 days and will explain any lawful limit on access or deletion.

If we cannot resolve a privacy concern, you can contact the Office of the Privacy Commissioner of Canada.

11. Children’s information

KIDO accounts are for people age 18 or older. KIDO is designed for adults finding activities for children, not for children to create profiles. Do not submit a child’s sensitive or identifying information unless it is necessary, lawful, and you have authority to do so. See the Community Guidelines for safe posting rules.

12. Changes and contact

We will post policy updates with a new effective date. If a material change requires renewed consent, we will request it before applying the change to the affected account feature.

KIDO’s Privacy Lead is accountable for this policy. Privacy questions and requests can be sent to ben@kido.events.