True North Drawson Inc. ("True North Drawson", "we", "us", or "our") operates truenorthdrawson.com, a free social casino platform designed purely for entertainment. No real money is wagered on our platform, no real money can be won, and none of our games offer prizes with monetary value. Even so, we treat the personal information you entrust to us with the same seriousness that a regulated financial institution would. This Privacy Policy explains, in plain language, what information we collect, why we collect it, how we protect it, how long we keep it, and the rights you hold over it under Canadian law, in particular the Personal Information Protection and Electronic Documents Act ("PIPEDA").

This policy applies to every visitor and registered member of truenorthdrawson.com, whether you browse the site casually, create an account, participate in our free-play games, or subscribe to an optional cosmetic membership. By using the platform you acknowledge that you have read and understood this policy. If any part of it is unclear, we genuinely want to hear from you — our contact details appear in Section 13, and we respond to privacy questions with the same priority we give to security incidents.

We review this document at least once per year and whenever our data practices change in a meaningful way. When we make a material change, we will post the updated version on this page, revise the effective date shown above, and — where the change affects registered members — notify you by email before the change takes effect. Continued use of the platform after the effective date of a revised policy constitutes acceptance of the revision, but for any new purpose of collection that PIPEDA treats as requiring fresh consent, we will ask for that consent explicitly rather than assuming it.

1. Information Collection: Our General Approach

Our guiding principle is data minimisation. Because True North Drawson is an entertainment platform rather than a gambling operator, we are not required to perform the extensive identity verification that real-money sites must carry out, and we deliberately choose not to collect anything close to that level of detail. We collect only the information we need to operate the platform, keep it secure, comply with the law, and make the experience genuinely enjoyable.

We collect information through three channels, each described in detail in the sections that follow:

  • Information you give us directly — for example, when you register an account, edit your profile, contact our support team, or subscribe to the newsletter.
  • Information generated automatically — technical and usage data produced by your device and browser as you interact with the site, such as session length and in-game telemetry.
  • Information from a small number of service providers — for example, confirmation from our payment processor that an optional membership payment succeeded, without the card details themselves ever reaching us.

We do not purchase data about you from data brokers, we do not enrich your profile with information scraped from social networks, and we do not combine your account with advertising identifiers. Under PIPEDA's accountability principle, we remain responsible for personal information in our possession or custody, including information transferred to third parties for processing, and we have designated a Privacy Officer who oversees compliance with this policy across the organisation.

Consent matters to us. Where PIPEDA permits implied consent — for example, for the collection of technical data that is plainly necessary to deliver a web page you requested — we rely on it transparently and describe the practice here. Where the law or common sense calls for express consent — for example, before sending you a marketing newsletter — we obtain it through a clear, unticked, affirmative action, and we make withdrawing that consent as easy as giving it.

2. Personal Data You Provide to Us

When you create a True North Drawson account, we ask for the smallest set of details that still lets us run a functional, secure service. The registration form collects the following:

  • Username. A display name you choose yourself. It appears on leaderboards and in community features, so we encourage you to pick something that does not reveal your real identity. You may change it at any time from your account settings.
  • Email address. Used to verify your account, deliver transactional messages such as password resets, and — only if you opt in — send the newsletter described in Section 6. Your email address is never displayed publicly.
  • Password, stored only as a salted hash. We never store your password in readable form. It is processed through a modern, deliberately slow one-way hashing algorithm with a unique salt per account. Not a single member of our staff can view your password, and we will never ask you for it by email or chat.

2.1 Optional profile information

After registration you may, entirely at your discretion, add optional details to your profile: an avatar selected from our built-in gallery, a short biography, your province or territory, and your preferred game categories. These fields exist purely to personalise your experience. Leaving them blank has no effect on your access to any game or feature, and you can edit or erase them whenever you like. We deliberately do not offer photo uploads for avatars, which spares us from processing biometric-adjacent imagery altogether.

2.2 Information you send to support

When you contact our support team by email or through the on-site chat, we receive whatever you choose to include in your message, together with your account identifier if you are signed in. Please share only what is needed to resolve your question. Support correspondence is retained according to the schedule in Section 9 and is accessible only to trained support staff bound by confidentiality obligations.

2.3 Membership billing details

If you choose to purchase an optional cosmetic membership, the payment itself is handled entirely by our external payment processor, as explained in Section 11. We receive and store only the information we need for accounting: the date, the plan you selected, the transaction reference, and the payment status. Full card numbers, CVV codes, and banking credentials never touch our servers in any form.

3. Usage Data Collected Automatically

Like virtually every online service, our servers and applications automatically record certain technical information when you use the platform. This data helps us keep the site fast, stable, and secure, and helps us understand which games and features people actually enjoy. The categories we collect are:

  • Device and browser information — the type of device you use, its operating system and version, your browser name and version, screen resolution class, and preferred language. This lets us serve correctly sized layouts and diagnose rendering problems that affect only certain configurations.
  • Network information — your IP address, truncated for analytical purposes after initial security screening, and the approximate region it resolves to at the province level. We use this to detect suspicious sign-in patterns and to comply with our own policy of operating for a Canadian audience.
  • Session information — sign-in and sign-out timestamps, session length, the pages you visit within the platform, and the order in which you visit them. Session length data feeds our responsible-play features, which can remind long-running sessions to take a break.
  • Game telemetry — which free-play games you launch, how long each round lasts, the virtual (never monetary) coin balances involved, feature usage inside a game, error events, and load-time performance metrics. Telemetry is what tells us that a particular slot animation stutters on older devices, or that a bonus round confuses new players and needs a clearer tutorial.
  • Crash and error reports — when something breaks, our software records a technical snapshot of the failure: the error message, the code path involved, and non-identifying context about the state of the application. These reports are scrubbed of message content and free-text fields before storage.

Usage data is pseudonymised wherever possible: analytical processing is carried out against internal identifiers rather than usernames or email addresses, and raw records are aggregated or deleted according to the retention schedule in Section 9. We do not use usage data to build advertising profiles, and we do not share it with ad networks — there are no ad networks on this platform.

4. Cookies and Similar Technologies

True North Drawson uses a small, carefully limited set of cookies and equivalent browser storage technologies. We divide them into two groups: strictly necessary cookies, which the platform cannot function without, and optional cookies, which are set only after you consent through our cookie banner.

  • Strictly necessary cookies keep you signed in, remember your consent choices, protect forms against cross-site request forgery, and balance load across our servers. These are exempt from consent requirements because the service you have asked for cannot be delivered without them.
  • Preference cookies remember interface choices such as sound settings and your last-played game category, so the platform feels like yours each time you return.
  • Analytics cookies support the privacy-respecting measurement described in Section 5. They are set only if you accept them, and declining them does not restrict any feature of the platform.

You can review the full list of cookies we set, their lifespans, and their exact purposes — and change your consent at any time — on our dedicated Cookie Policy page. You can also delete or block cookies through your browser settings; if you block strictly necessary cookies, parts of the platform such as sign-in will stop working, which is a technical limitation rather than a choice on our part. We honour your consent selections consistently across the site and re-request consent if we introduce a new category of cookie.

5. Analytics

We want to know whether the platform works well — not who you are. Our analytics practice is built around that distinction. We use a privacy-respecting, first-party analytics configuration that measures the platform in aggregate rather than tracking individuals across the web.

Concretely, our analytics setup has the following properties:

  • Aggregated reporting only. The reports our team works with show totals, averages, and distributions — for example, "the average session on mobile lasted eleven minutes this week" — never a named individual's behaviour.
  • No cross-site tracking. Our analytics does not follow you to other websites, does not read third-party cookies, and does not participate in any advertising ecosystem, real-time bidding, or audience marketplace.
  • IP truncation. IP addresses are shortened before analytical storage so that they identify a broad region rather than a household.
  • Short retention. Event-level analytics records are automatically deleted or rolled up into anonymous aggregates on the schedule described in Section 9. Aggregated statistics, which no longer relate to any identifiable individual, may be kept longer for trend analysis.
  • Respect for consent. Analytics cookies fire only after you accept them in the cookie banner. If you decline, we still receive the anonymous server-side minimum needed to count total traffic and defend against abuse, but nothing tied to your browser.

We occasionally run A/B experiments — for example, testing whether a redesigned lobby helps new players find games faster. Participation is determined by a random technical identifier, results are analysed only in aggregate, and no experiment ever varies the fairness or behaviour of game outcomes, which remain governed by the same certified random processes for every player.

6. Communications

We divide the messages we send into two strictly separated streams, because Canadian law — and basic respect — treats them very differently.

6.1 Transactional and service messages

These are messages the service cannot responsibly operate without: email verification when you register, password reset links you request, security alerts when we detect a sign-in from an unfamiliar device, receipts for optional membership payments, responses to your support enquiries, and legally required notices such as material changes to this policy. Because these messages are part of delivering the service you asked for, they are sent to all registered members and cannot be opted out of while your account remains open. We keep them infrequent, factual, and free of promotional content.

6.2 Optional newsletter

Our newsletter covers new game releases, seasonal events, and community highlights. It is strictly opt-in: you receive it only if you ticked the unticked newsletter box at registration or subscribed later from your account settings. In compliance with Canada's Anti-Spam Legislation (CASL) and PIPEDA's consent principle:

  • Every newsletter identifies True North Drawson Inc. as the sender and includes our physical mailing address.
  • Every newsletter contains a one-click unsubscribe link that takes effect immediately — not "within ten business days", but at the moment of the click.
  • You can also toggle the subscription off in your account settings or by emailing us, and we process such requests without asking why.
  • We never make receipt of the newsletter a condition of using any game or feature.

We do not send SMS marketing, we do not make marketing phone calls, and we do not permit third parties to send communications to our member list under any arrangement.

7. Data Security

PIPEDA's safeguards principle requires security protections appropriate to the sensitivity of the information held. Although we intentionally hold little sensitive data, we secure what we do hold to a high standard, using layered technical, administrative, and physical measures.

7.1 Technical safeguards

  • Encryption in transit. All traffic between your browser and our servers is encrypted with modern TLS. We do not operate any unencrypted endpoint, and we use HSTS so that browsers refuse insecure connections to our domain.
  • Encryption at rest. Databases and backups containing personal information are encrypted at the storage layer, with encryption keys managed separately from the data they protect.
  • Credential protection. Passwords exist only as salted hashes produced by an algorithm specifically designed to resist brute-force attacks, as described in Section 2.
  • Hardened infrastructure. Our servers are patched on a defined schedule, protected by firewalls and intrusion detection, and segmented so that a compromise of one component does not expose the whole platform.

7.2 Administrative safeguards

  • Access controls. Staff access to personal information follows the least-privilege principle: each employee can see only the data their role requires, access requires multi-factor authentication, and every access to member records is logged and periodically audited.
  • Training and confidentiality. Everyone who works with member data receives privacy and security training on hiring and annually thereafter, and is bound by contractual confidentiality obligations that survive the end of their employment.
  • Vendor vetting. Service providers listed in Section 11 are assessed for their security posture before engagement and are contractually required to protect personal information to a standard comparable with our own.

7.3 Incident response

We maintain a written incident response plan that is rehearsed, not merely filed away. If we discover a breach of security safeguards involving your personal information, we will assess whether it creates a real risk of significant harm as defined by PIPEDA. Where it does, we will report the breach to the Office of the Privacy Commissioner of Canada, notify affected individuals as soon as feasible with clear guidance on protective steps, notify any other organisation that can reduce the harm, and record the breach in the register we are required to maintain. We follow this process regardless of whether the incident originated inside our systems or at a service provider.

No security programme can promise absolute immunity — anyone who claims otherwise is not being honest with you. What we promise is diligence: proportionate defences, honest and prompt notification if something goes wrong, and continuous improvement of our safeguards as threats evolve.

8. Your Rights Over Your Information

Under PIPEDA you hold meaningful, enforceable rights over your personal information, and we have built account tools and internal processes to honour them. You do not need a lawyer or a formal template to exercise any of these rights — an email to the address in Section 13 is enough.

  • Right of access. You may ask whether we hold personal information about you, what it is, how it has been used, and to whom it has been disclosed. We will respond within thirty days, as PIPEDA requires, and in most cases much sooner. Access is free of charge; if an unusually complex request would involve a modest cost, we will tell you in advance and proceed only with your agreement.
  • Right of correction. If any information we hold about you is inaccurate or incomplete, you may correct most of it yourself in your account settings; for anything else, ask us and we will amend it and, where relevant, notify third parties who received the inaccurate version.
  • Right of deletion. You may close your account at any time from your settings page or by written request. We will delete your personal information, subject only to the narrow legal retention obligations described in Section 9, and confirm to you when the deletion is complete.
  • Right of portability. On request we will provide the personal information you gave us — your profile details and preference settings — in a structured, commonly used, machine-readable format so that you can keep it or take it elsewhere.
  • Right to withdraw consent. Subject to legal and contractual restrictions and reasonable notice, you may withdraw consent to any collection, use, or disclosure at any time. We will explain the consequences of withdrawal honestly; for optional processing such as the newsletter or analytics cookies, there are none beyond losing that feature.
  • Right to complain. You may challenge our compliance with PIPEDA by contacting our Privacy Officer, who will investigate and respond. If you are not satisfied with our answer, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC) at 30 Victoria Street, Gatineau, Quebec K1A 1H3, through the OPC's website, or by telephone. We will never penalise or restrict any member for raising a privacy concern with us or with the OPC.

To protect your information from impostors, we verify identity before acting on access, correction, deletion, or portability requests — usually by confirming control of the email address on the account. We apply the same verification standard to authorised agents acting on your behalf.

9. Data Retention

PIPEDA's limiting retention principle requires that personal information be kept only as long as necessary for the purposes for which it was collected. We apply that principle through a documented retention schedule with automated enforcement — deletion happens because a system runs, not because someone remembers.

  • Account data (username, email address, hashed credentials, optional profile fields) is retained for as long as your account remains open. When you close your account, it is deleted within thirty days, allowing a short grace period in case the closure was accidental.
  • Support correspondence is retained for twenty-four months after the ticket is resolved, so that we can handle follow-up questions and identify recurring problems, then deleted.
  • Event-level usage data and game telemetry tied to an identifiable account is retained for a maximum of fourteen months, after which it is either deleted or irreversibly aggregated into statistics that describe no individual.
  • Server security logs, including untruncated IP records used for abuse prevention, are retained for ninety days unless a specific incident investigation requires a defined longer hold.
  • Membership transaction records are retained for seven years after the transaction, because Canadian tax and accounting legislation requires us to keep financial records for that period. These records contain the minimum described in Section 2.3, never card details.
  • Breach records are retained for the period PIPEDA prescribes, currently a minimum of twenty-four months from the day we determine a breach occurred.

Where litigation, a regulatory investigation, or a lawful demand requires us to preserve specific records beyond these periods, we place a targeted legal hold on only the records concerned and resume normal deletion when the hold ends. Backups are encrypted and cycle out on a fixed schedule, so data deleted from live systems disappears from backups within that cycle rather than lingering indefinitely.

10. International Data Transfers

True North Drawson is a Canadian company serving a Canadian audience, and we have made a deliberate architectural choice to match: our production servers, databases, and primary backups are located in data centres within Canada. For the overwhelming majority of processing, your personal information never leaves the country.

A small number of specialised service providers — identified by category in Section 11 — may process limited data on infrastructure located outside Canada, most commonly in the United States or the European Union. Where that happens, we apply the safeguards PIPEDA expects of an accountable organisation:

  • We enter into written data processing agreements that hold the provider to protection comparable to this policy, restrict processing to our documented instructions, and prohibit any independent use of the data.
  • We transfer the minimum necessary — for example, an email delivery provider receives your email address and the message content, nothing more.
  • We assess each provider's security certifications and breach history before engagement and periodically thereafter.
  • We remain fully accountable to you for the information while it is in a provider's hands; transferring data for processing never transfers our responsibility.

You should be aware that personal information stored or processed in a foreign jurisdiction is subject to the laws of that jurisdiction, and in limited circumstances its courts, law enforcement, or national security authorities may be able to compel disclosure. This is true of every online service that uses any international provider, and we mitigate it by keeping core data in Canada and minimising what crosses the border. If you would like to know which categories of your information, if any, are processed abroad, our Privacy Officer will tell you on request.

11. Third-Party Service Providers

We do not sell personal information. We have never sold personal information. We will never sell, rent, lease, or trade personal information to anyone, for any consideration, monetary or otherwise. That commitment is unconditional and survives any change in management, strategy, or fashion in the advertising industry.

What we do — like every online service — is rely on a small number of carefully selected service providers who process limited data strictly on our behalf and under contract. The categories are:

  • Hosting and infrastructure provider. Operates the Canadian data centres where the platform runs. Processes all platform data as a technical necessity but is contractually barred from accessing or using it for any purpose other than providing the infrastructure.
  • Email delivery provider. Sends transactional messages and, for subscribers, the newsletter. Receives your email address and the content of the messages we ask it to deliver, and may not use that address for anything else.
  • Payment processor. Handles all optional membership payments. Your card or banking details go directly from your browser to the processor over an encrypted connection; we receive only a confirmation, a transaction reference, and the status of the payment. The processor is independently certified to the payment card industry's data security standards and acts as a separate accountable organisation for the payment data it collects.
  • Privacy-respecting analytics tooling. Provides the aggregated measurement described in Section 5, configured to our minimisation settings.

Every provider is bound by a written agreement covering confidentiality, security safeguards, breach notification to us without undue delay, deletion or return of data at the end of the engagement, and a prohibition on engaging sub-processors without equivalent obligations. We review this roster periodically and remove providers whose practices no longer meet our standard.

Beyond service providers, we disclose personal information only where the law compels or clearly permits it: in response to a valid Canadian court order, warrant, or statutory demand; to detect, suppress, or prevent fraud against the platform; to protect the safety of an individual where urgency demands it; or, in the event of a merger or sale of the business, to a successor bound to honour this policy, with notice to you before any new practice takes effect. We scrutinise every legal demand for validity and scope, and we disclose the narrowest set of records that satisfies a valid demand.

12. Children's Privacy

True North Drawson is an adults-only platform. Although no real money is involved, our games simulate casino-style entertainment, and we hold the firm view that such content is not appropriate for minors. Access is therefore restricted to individuals who are at least 18 years of age, or the age of majority in their province or territory of residence if it is higher — 19 in British Columbia, New Brunswick, Newfoundland and Labrador, Northwest Territories, Nova Scotia, Nunavut, and Yukon.

We put that policy into practice as follows:

  • Registration requires an affirmative declaration that you meet the age requirement, and our Terms of Service make providing a false declaration a ground for immediate account closure.
  • We do not knowingly collect, use, or disclose personal information from anyone under the age of majority. We do not design features, run promotions, or choose visual themes intended to appeal to children.
  • If we learn that an account belongs to a minor — through our own review, a parent or guardian's report, or any other credible source — we will close the account and delete the associated personal information promptly, applying the same deletion process described in Section 9 without the thirty-day grace period.
  • Parents and guardians who believe a minor has created an account can write to us at the address in Section 13; we treat such reports with urgency and will confirm the outcome once the matter is resolved.

The Office of the Privacy Commissioner of Canada has consistently taken the position that the personal information of minors is particularly sensitive and that meaningful consent from young people is difficult to establish. We agree, and our answer is not to attempt clever consent mechanisms for young users, but simply not to serve them at all.

13. Contact Details

Questions, concerns, access requests, correction requests, deletion requests, complaints, and compliments about this Privacy Policy or our data practices all go to the same place, and a human being — not an unattended mailbox — reads them:

  • Privacy Officer, True North Drawson Inc.
  • Email: support@truenorthdrawson.com (subject line "Privacy Request" helps us route your message fastest)
  • Mail: True North Drawson Inc., 482 Wellington St W, Toronto, ON M5V 1E3, Canada

We acknowledge privacy correspondence within two business days and provide a substantive response within thirty days, the maximum period PIPEDA allows. If a request is unusually complex and we need to extend that period in the narrow circumstances the Act permits, we will tell you before the original deadline expires, explain why, and give you the new date.

If, after working with our Privacy Officer, you believe your concern has not been resolved, you may contact the Office of the Privacy Commissioner of Canada, which oversees compliance with PIPEDA and provides a free, independent complaint process. Nothing in this policy limits any right you hold under the laws of Canada or of your province or territory, and where provincial private-sector privacy legislation declared substantially similar to PIPEDA applies to you, we honour whichever standard gives you the stronger protection.

Thank you for taking the time to read this policy. Privacy documents are usually written to be skimmed; we wrote this one to be understood, because informed players are exactly the kind of community we want at True North Drawson.