Introduction
The Bad Alibi Inc. respects the privacy of every guest, visitor, supplier and website user. This Privacy Policy describes the personal information we handle, the reasons we handle it, the choices available to you and the safeguards we apply. It applies to our public house, our private event venue, our booking process and the website published at www.badalibi.autos. The policy was prepared under the supervision of our developer, Bad Alibiy, who oversees the technical operation of this website and the systems that support it.
We operate in Ottawa, Canada, and we design our practices to align with Canadian privacy law, including the Personal Information Protection and Electronic Documents Act, together with applicable provincial rules. Where other laws offer stronger protection to a particular guest, we aim to honour the spirit of those laws as well. This document is written in plain language on purpose, because a privacy notice should be readable by the people it protects.
By visiting our premises, using our website or contacting us to plan an event, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, you may choose not to use our services or our website, and you may contact us with your questions before deciding.
Who We Are
The data controller responsible for your personal information is The Bad Alibi Inc., a company operating a public house and private event venue. Our registered and operating address is 2326 Bois Vert Place, Ottawa - K4A 4T8, Canada (CA). You may reach us by email at bookings@badalibi.autos or by telephone at +18287604216. Our website is published at www.badalibi.autos.
References in this policy to we, us and our mean The Bad Alibi Inc. References to you mean any individual whose personal information we handle, including guests, event organisers, suppliers, applicants and website visitors. When we refer to personal information, we mean information about an identifiable individual, as that concept is understood under Canadian privacy law.
We are supported by a small team and a number of trusted service providers. Some of those providers process information on our behalf, and we require them to protect it and to use it only for the purposes we set. The developer named above maintains the technical environment, but business decisions about guest information remain with The Bad Alibi Inc.
Information We Collect
We collect several categories of personal information, and we try to keep each category to the minimum that our work genuinely requires. The categories are described below so that you can see, at a glance, what we hold and why it exists.
- Identity information such as your name, the name of your organisation and your role within it.
- Contact information such as your email address, telephone number and mailing address.
- Booking information such as event dates, guest counts, room layouts and menu preferences.
- Payment information such as deposit records, invoice references and transaction confirmations.
- Communication records such as emails, enquiry forms and notes taken during planning calls.
- Technical information such as browser type, device category and general region of access.
- Preference information such as dietary needs, accessibility requests and seating wishes.
- Feedback information such as comments you send us about an evening at the house.
We do not ask for sensitive information such as health records or government identifiers unless a specific legal duty or a clear operational reason makes it necessary. When a guest shares a dietary or accessibility need, we treat that detail with extra care and share it only with the staff who must act on it.
How We Collect Information
Most of the personal information we hold comes directly from you. You give it to us when you complete the contact form on this website, send us an email, telephone the house, reserve a table, sign an event agreement or pay a deposit. In each case you choose what to share, and we encourage you to share only what is needed for the matter at hand.
We also collect a limited amount of information automatically when you browse our website. This includes technical details that help the site load correctly and remain secure, such as the type of browser you use and the pages you visit. We keep this information aggregated wherever possible so that it does not identify you personally.
Finally, we may receive information from third parties in narrow circumstances. A corporate client might give us the names of guests attending a function, a supplier might confirm a delivery contact, and a booking platform might pass along the details of a reservation. When we receive information this way, we handle it under this policy and ask that the sender had a right to share it.
Why We Use Information
We use personal information to run a public house and an event venue well. In practical terms, that means confirming bookings, preparing rooms, planning menus, keeping the bar stocked, sending confirmations and answering questions. It also means handling payments, keeping accurate accounts and meeting our tax and licensing duties.
We use information to improve what we offer. Feedback about an evening, a dish or a drink helps us adjust the menu, the seating or the service. Aggregated website data tells us which pages are useful and which need work. We use contact details to keep in touch about events you have asked to hear about, and we always give you a straightforward way to stop receiving those messages.
We also use information to protect our guests, our team and our premises. That can include checking booking details for accuracy, preventing misuse of our website and cooperating with authorities when the law requires it. We do not use your information for purposes that are unrelated to these aims.
Legal Bases for Processing
Privacy law expects an organisation to have a lawful reason for handling personal information. In our case, the main reasons are the performance of a contract, the pursuit of legitimate interests, compliance with legal obligations and, in selected situations, your consent.
When you book an event or buy a drink, we process your details because we need them to provide the service you requested. When we secure our website or improve our menu, we rely on legitimate interests that are balanced against your rights. When we keep financial records for a set period, we do so because tax and licensing rules require it. When we send a newsletter, we rely on the consent you gave and which you can withdraw at any time.
Where consent is the basis, you may withdraw it without affecting the lawfulness of processing that took place before the withdrawal. We will explain the consequences of withdrawal if it means we can no longer provide a service you have asked for.
Bookings and Event Records
Private event bookings generate the most detailed records we keep. To plan an evening, we need to know who is organising it, how many guests will attend, what the room should look like and what the kitchen should prepare. We record these details in a booking file so that any member of our team can pick up the plan and help without asking you to repeat yourself.
A booking file may include correspondence, a run sheet, a menu selection, a seating plan, a deposit record and any special instructions. We keep these files because they let us deliver the evening you agreed to and because they help us resolve any question that arises afterwards. When a booking involves a third party planner or supplier, we share only the details that party needs to perform its own role.
Guest lists supplied by an organiser are treated as confidential to that event. We use them to manage entry, seating and safety, and we do not repurpose them for unrelated marketing without a separate lawful basis.
Payments and Financial Data
Payments for bookings, drinks and food create financial records. We keep deposit confirmations, invoice references and transaction totals so that our accounts are accurate and so that we can answer any billing question. These records are retained for the period required by tax and accounting rules and are then securely destroyed.
We do not store full payment card numbers on our own systems. Card payments are handled by regulated payment processors that operate under their own security standards, and we receive only the confirmation and summary details needed to reconcile the sale. If you pay by bank transfer or cheque, we record the reference and amount rather than any account credentials.
Where a refund or credit is due, we use the same payment details to return the funds and keep a record of the adjustment. Financial information is accessible only to the team members who manage accounts and to our professional advisers when they need it for a specific task.
Cookies and Similar Technologies
Our website uses a small number of cookies and similar technologies. These are tiny text files stored by your browser that help the site function, remember a simple choice and measure general traffic. We keep the set as small as we reasonably can, because we prefer a website that respects the visitor rather than one that follows the visitor around.
Essential cookies keep the site secure and load pages correctly. Analytics cookies help us understand which pages are read and which are overlooked, using aggregated numbers rather than individual profiles. If we introduce a cookie that is not essential, we will ask for your agreement first and explain what it does.
You can control cookies through your browser settings. Most browsers allow you to block or delete them, and you can usually set a preference to be told when a cookie is offered. Blocking essential cookies may affect how the site works, but you remain free to do so, and the rest of our services will still be available to you in person.
Marketing and Communications
We send marketing messages only when we have a lawful basis to do so. If you ask to hear about live music nights, seasonal menus or room offers, we add you to the relevant list and we keep the content useful and infrequent. Every message includes a clear way to unsubscribe, and we act on unsubscribe requests promptly.
Service messages are different. When you have a booking, we will send confirmations, timing reminders and practical updates because those messages are part of the service you requested. We may also contact you about a change that affects your event, such as a shift in hours or a supply issue in the kitchen.
We do not sell contact lists, and we do not rent your email address to others. If a partner ever wishes to send a message to our guests, we will either send it ourselves on their behalf or ask for your explicit agreement before any direct contact is made.
Sharing and Disclosure
We share personal information only when there is a clear reason to do so. The most common reason is to deliver a service you requested, such as passing a menu selection to the kitchen or an event time to a musician you hired. We also share information with professional advisers, such as accountants and legal counsel, when their expertise is needed.
We may disclose information when the law requires it. That includes responding to a valid court order, a lawful request from a regulator or a request from emergency services during an incident. In those cases we provide only the information that is genuinely required and, where possible, we tell you that a request has been made.
If our business were ever reorganised, sold or merged, guest information could form part of the transferred assets. In that situation we would require the receiving organisation to honour this policy or to give you a clear notice of any change before your information is used for a new purpose.
Service Providers and Processors
Like most organisations, we rely on service providers for tasks such as website hosting, email delivery, payment processing and accounting. These providers process personal information on our instructions and are not permitted to use it for their own independent purposes. We choose providers with care and review their safeguards before we engage them.
Our agreements with providers require them to protect information, to limit access to staff who need it and to notify us if anything goes wrong. Where a provider operates in another country, we consider the legal environment it works within and we use contractual measures to keep protection at an appropriate level.
The developer named at the start of this policy maintains the technical environment and may access system logs as part of that work. That access is limited to what is needed to keep the website secure and running, and it is governed by the same confidentiality expectations that apply to our own team.
International Transfers
Some of our service providers store data outside Canada, most commonly in the United States or the European Union. When information leaves Canada, it may be subject to the laws of the country where it is held, and authorities there may be able to access it under their own rules.
We take steps to keep protection consistent wherever information travels. These steps include selecting providers with strong security records, using contractual clauses that impose privacy duties and keeping the amount of transferred information to the minimum necessary for the task.
If you would like to know more about where a particular category of information is held, you may contact us using the details at the end of this policy and we will explain what we can within the limits of our own security obligations.
Data Retention
We keep personal information only as long as we need it. The retention period depends on the purpose and on any legal duty that applies. A booking file is usually kept for a period after the event so that we can answer questions and manage accounts, while financial records are kept for the length required by tax law.
Marketing preferences are kept until you withdraw your consent or until we have had no contact with you for a long period, after which we remove your details from the list. Website analytics are kept in aggregate form and are not linked to you as an individual for longer than is necessary to produce useful reports.
When a retention period ends, we delete or anonymise the information. Deletion is done in a way that prevents recovery, and anonymisation is done so that the remaining data can no longer be linked to a person. We review our retention schedule from time to time to make sure it stays reasonable.
How We Protect Information
We protect personal information with a combination of technical, physical and organisational measures. Our website uses encryption in transit, our accounts use strong authentication and our records are kept in systems that limit access to authorised team members. Paper records, where they exist, are stored securely on the premises.
Our team receives guidance on handling personal information and on what to do if something goes wrong. We limit access on a need to know basis, which means a staff member sees only the information required for the task in front of them. We review our measures as our operations and the threats we face evolve.
No method of storage or transmission is completely secure. If a privacy breach occurs that creates a real risk of significant harm, we will notify affected individuals and the relevant authorities as required by law, and we will explain what happened and what we are doing about it.
Privacy for Children
Our public house serves adults, and our website is intended for adults who wish to learn about our venue, menus and events. We do not knowingly collect personal information from children. If a family event brings younger guests to the house, we handle their details only as part of the booking and only as far as safety and catering require.
If you believe that a child has provided personal information to us without appropriate consent, please contact us and we will investigate promptly. If we learn that we hold information about a child without a proper basis, we will delete it without unnecessary delay.
Parents and guardians who are planning a family celebration may contact us to discuss what information we need. We will explain the scope clearly so that families can make an informed choice about what to share.
Your Privacy Rights
You have rights over the personal information we hold about you. These include the right to know what we hold, the right to ask for a copy, the right to correct errors and the right to ask us to delete information in appropriate circumstances. You also have the right to object to certain processing and to withdraw a consent you previously gave.
To exercise a right, contact us using the details at the end of this policy. We may ask you to confirm your identity before we act, because we must not disclose information to the wrong person. We will respond within the time allowed by law and we will explain any reason why a request cannot be fully met.
If you are not satisfied with our response, you may raise the matter with the Office of the Privacy Commissioner of Canada or with the privacy regulator in your own jurisdiction. We would prefer the chance to resolve your concern directly first, and we take every complaint seriously.
Access and Correction Requests
An access request asks us to confirm what personal information we hold about you and to provide a copy. We will describe the information, explain how it is used and list the parties to whom it has been disclosed, where that is possible and appropriate. A correction request asks us to fix information that is inaccurate or incomplete.
When you make a request, please be as specific as you can about the information and the timeframe involved. That helps us locate the right records quickly. If we cannot find the information you describe, we will tell you what searches we carried out and invite you to add any detail that might help.
In rare cases the law allows us to refuse part of a request, for example where disclosure would reveal another person private information or would breach a legal privilege. If we refuse, we will give you a clear reason and explain how you can challenge the decision.
Deletion and Restriction Requests
You may ask us to delete personal information or to restrict how we use it. We will consider the request against our legal duties and our legitimate needs. For example, we cannot delete a financial record that tax law requires us to keep, but we can restrict its use so that it is held only for that legal purpose.
Where we agree to delete information, we will remove it from active systems and from backups as those backups are cycled. We will also ask any service provider that holds the information for us to delete its copy. We will confirm the action we have taken in writing.
Restriction means we keep the information but stop using it for general purposes while a question is resolved. This is often the right answer when the accuracy of a record is in dispute and both parties need the record to remain available.
Automated Decisions and Profiling
We do not make decisions about you using automated processing that produces legal or similarly significant effects. We do not build behavioural profiles for advertising, and we do not use your booking history to target you with offers through automated systems.
Our website analytics describe activity in aggregate, such as how many people opened a page in a week. That information helps us improve the site, but it does not drive decisions about any individual guest or customer. Any decision that affects you personally is made by a member of our team.
If we ever introduce a tool that makes an automated decision, we will update this policy, explain the logic involved in plain language and provide a way for you to request human review before the decision takes effect.
Third Party Links
Our website may link to other sites, such as a ticketing service, a map provider or a musician page. Those sites are operated by other organisations and have their own privacy policies. We are not responsible for their practices, and a link from our site does not mean that we endorse everything they do.
We encourage you to read the privacy notice of any site you visit, especially before you enter personal information or make a payment. If you follow a link from our site and have a concern about what you find, please tell us so that we can review whether the link still belongs on our pages.
The same principle applies to social media. When you interact with us on a social platform, the platform handles your information under its own terms, and our relationship with you there is governed by both this policy and the platform rules.
Changes to This Policy
We review this policy from time to time and update it when our practices, our technology or the law changes. When we make a material change, we will update the date at the foot of the page and, where the change is significant, we will give a clearer notice on the website or by email.
The current version always governs how we handle personal information. We keep earlier versions on file so that we can show what applied at a given time. If you continue to use our services after an update, you accept the revised policy, and if you do not accept it you may contact us to discuss your options.
We will never use information collected under an earlier policy for a new purpose without first giving you the notice and the choice that the change requires. Our commitment to that principle does not change with the wording of any particular version.
How to Contact Us
If you have a question about this policy, a request about your information or a concern about how we have handled a matter, please contact The Bad Alibi Inc. Our team will route your message to the person best placed to help and will respond as quickly as we reasonably can.
You may write to us at The Bad Alibi Inc., 2326 Bois Vert Place, Ottawa - K4A 4T8, Canada (CA). You may email bookings@badalibi.autos or telephone +18287604216. If you prefer, you can use the contact form on our website and we will come back to you by email.
Your trust matters to us. A public house is built on good company, and good company depends on respect. We will treat your privacy with the same care that we bring to every pour and every plate at the house.