Privacy Policy

humanchronicles.ca

Effective Date: April 2026 | Last Updated: July 2026

At Human Chronicles, stories are at the heart of everything we do — including how we handle yours. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and the choices you have. We’ve written it to be readable rather than impenetrable, because that’s how we prefer to communicate.

By using humanchronicles.ca or purchasing a subscription, you consent to the practices described in this Policy.

Human Chronicles is published by SITOSO Digital Publishing, Ajax, Ontario, Canada. This Policy applies to all personal information collected through humanchronicles.ca and related subscription services.

—–

1. Our Legal Basis for Collecting Your Data

We operate in compliance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Ontario privacy legislation. For subscribers located in the European Union or United Kingdom, we also comply with the General Data Protection Regulation (GDPR) and UK GDPR respectively.

We collect personal information only with your consent and only for purposes that a reasonable person would consider appropriate under the circumstances.

We do not collect more information than we need. We are not in the data business. We are in the stories business.

—–

2. What Information We Collect

2a. When You Subscribe or Purchase

When you create an account and subscribe, we collect:

– Your name and email address
– Your mailing address (print subscribers only)
– Payment information — processed and stored securely by Stripe; we do not store your credit card or banking details on our servers
– Your subscription type and history
– Your account preferences

2b. When You Visit the Website

Like most websites, humanchronicles.ca collects some technical information automatically when you browse, including:

– Your IP address and general geographic location
– Browser type and version
– Pages visited and time spent on the site
– Referring URLs (how you found us)

This data is collected through Google Analytics 4 (GA4) and Google Tag Manager. We use it to understand how people engage with the magazine so we can make it better. It is aggregated and anonymized wherever possible.

EU and UK visitors: analytics cookies require your explicit consent before being activated. You will be given that choice when you first visit the site.

2c. When You Leave a Comment

If you post a comment on our website, we collect your name, email address, and the content of your comment, along with your IP address (used for spam detection). If you use a Gravatar, your profile image may be publicly visible alongside your comment.

2d. Cookies

We use cookies — small text files stored on your device — for the following purposes:

Essential cookies: Required for account login, session management, and site functionality. These cannot be disabled without affecting your ability to use the site.

Preference cookies: Remember your display choices and login state (lasting up to two weeks if you select “Remember Me”).

Analytics cookies: Placed by Google Analytics to help us understand site traffic and reader behaviour. These can be declined. EU and UK visitors will be asked for explicit consent before these cookies are set.

Payment cookies: Placed by Stripe during checkout to ensure secure transaction processing.

When you first visit the site, you will be given the option to accept or decline non-essential cookies. You can also manage cookie preferences through your browser settings at any time.

2e. Story Contributors and Interview Subjects

When individuals participate in Human Chronicles as interview subjects, featured storytellers, or story contributors, we collect personal information — including name, biographical details, photographs, and the content of their story — as part of the editorial process. This information is collected under a separate written consent agreement signed before publication. Story subjects may contact us at any time to discuss how their information is used.

—–

3. How We Use Your Information

We use your personal information only for the following purposes:

– To process and fulfill your subscription or single-issue purchase
– To deliver print issues to your mailing address
– To provide access to your digital issues via your account and through FlippingBook
– To send you subscription-related communications (renewal reminders, issue notifications, account updates)
– To send our newsletter and editorial updates, if you have opted in
– To respond to your inquiries and customer service requests
– To improve the website and subscriber experience through aggregated analytics
– To comply with applicable legal obligations

We do not use your personal information for automated decision-making or profiling.

—–

4. Who We Share Your Data With

We do not sell, rent, or trade your personal information. Full stop.

We share data only with trusted third-party service providers who help us operate the magazine, and only to the extent necessary:

– Stripe: Payment processing. Stripe is PCI-DSS compliant. See stripe.com/privacy.
– MemberPress: Subscription and membership management on our WordPress site.
– Kit (formerly ConvertKit): Email marketing and subscriber communications. Kit is GDPR compliant and operates under a Data Processing Agreement that covers EU, UK, Swiss, and Canadian subscribers. See kit.com/privacy.
– FlippingBook: Digital issue delivery. Subscribers accessing their digital edition through FlippingBook are subject to FlippingBook’s privacy practices. See flippingbook.com/privacy.
– Vimeo: Video content embedded on humanchronicles.ca. See vimeo.com/privacy.
– Canada Post: Print issue delivery. Your name and mailing address are shared for fulfillment purposes only.
– Google Analytics / Google Tag Manager: Website analytics. Data is anonymized and aggregated.
– WordPress / Automattic: Website hosting and content management infrastructure.

All third-party providers are required to handle your data in accordance with applicable privacy laws and their own published privacy policies.

We may also disclose your information if required to do so by law or by a valid court order or regulatory authority.

—–

5. How Long We Retain Your Data

We retain your personal information for as long as necessary to fulfill the purposes described in this Policy:

– Active subscriber records are retained for the duration of your subscription and for a reasonable period thereafter for accounting and legal purposes.
– Payment transaction records are retained as required by Canadian tax and financial regulations (typically 7 years).
– Comment data is retained indefinitely to support comment moderation, but can be deleted upon request.
– Analytics data (via Google Analytics) is retained for 26 months, after which it is automatically deleted.
– Story contributor and interview records are retained for the life of the publication, as published editorial content forms part of the permanent archive.

When you close your account or request deletion, we will remove your personal data from our active systems within 30 days, except where retention is required by law or forms part of the published editorial archive.

—–

6. Your Rights

6a. Canadian Subscribers (PIPEDA)

Under PIPEDA and applicable Canadian privacy law, you have the right to:

– Access the personal information we hold about you
– Correct inaccurate or incomplete information
– Withdraw consent for non-essential data uses (such as newsletter communications) at any time
– Request deletion of your personal data, subject to legal retention requirements
– File a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) if you believe your privacy rights have been violated

6b. European and UK Subscribers (GDPR / UK GDPR)

If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights under the GDPR and UK GDPR:

– The right to data portability — you may request a copy of your personal data in a structured, machine-readable format
– The right to object to processing, including for direct marketing purposes
– The right to restrict processing in certain circumstances
– The right to withdraw consent at any time without affecting the lawfulness of processing that occurred before withdrawal
– The right to lodge a complaint with your local data protection supervisory authority (in addition to, or instead of, contacting us directly)

Our lawful basis for processing subscriber data under GDPR is consent. Our lawful basis for processing advertiser and B2B contact data is legitimate interest.

6c. United States Subscribers

Human Chronicles does not sell subscriber personal data to third parties, which exempts our activities from the data sale and sharing provisions of most U.S. state privacy laws. U.S. subscribers who wish to access, correct, or request deletion of their personal data are welcome to contact us directly.

To exercise any of the rights listed above, contact us at hello@humanchronicles.ca. We will respond within 30 days.

—–

7. International Data Transfers

Human Chronicles is based in Canada. If you subscribe from outside Canada, your personal information will be transferred to and processed in Canada. Canada has been recognized by the European Commission as providing adequate data protection under PIPEDA, which means transfers to Canada from the EU are permitted without additional safeguards.

Where we use third-party service providers — such as Kit for email delivery — your data may also be processed in the United States or other jurisdictions. Kit operates under Standard Contractual Clauses approved by the European Commission, and is certified under the EU-U.S. Data Privacy Framework. We take reasonable steps to ensure all international transfers occur under appropriate protections.

—–

8. Data Security

We take reasonable technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These measures include:

– Secure HTTPS encryption on humanchronicles.ca
– Payment processing through Stripe’s PCI-DSS compliant infrastructure
– Password-protected subscriber accounts
– Limited access to personal data on a need-to-know basis

No system is perfectly secure, and we cannot guarantee absolute security. In the unlikely event of a data breach that poses a real risk of significant harm, we will notify affected subscribers and the Office of the Privacy Commissioner of Canada as required by PIPEDA. EU and UK subscribers will also be notified in accordance with GDPR requirements, which include notification within 72 hours of becoming aware of the breach.

—–

9. Children’s Privacy

Human Chronicles is a publication intended for adults. We do not knowingly collect personal information from anyone under the age of 16. If you believe a minor has provided us with personal information, please contact us and we will promptly delete it.

—–

10. Links to Other Websites

Our website may contain links to third-party websites (including social media platforms, our printer’s site, or partner organizations). This Privacy Policy applies only to humanchronicles.ca. We are not responsible for the privacy practices of any external sites and encourage you to review their policies independently.

—–

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

– Post the updated Policy on this page with a revised “Last Updated” date
– Notify active subscribers by email at least 14 days before the changes take effect

Continuing to use humanchronicles.ca or your subscription after the effective date constitutes acceptance of the updated Policy.

—–

12. Contact Us

Privacy questions, data requests, or concerns? We’re a small, human operation and we take this seriously.

Privacy Officer, SITOSO Digital Publishing
hello@humanchronicles.ca
humanchronicles.ca
Ontario, Canada

We will respond to all privacy inquiries within 30 days.

Stories worth preserving.

Sign up for storytelling events.