Privacy Policy

This Privacy Policy outlines the Yellow Door’s (YD) practices regarding the collection, use, and retention of personal information.

COLLECTION OF PERSONAL INFORMATION

Website Visitors

When you use our website, we collect de-identified statistical data using Google Analytics such as your location and pages you visited. We use this information for statistical purposes and to understand the needs and interests of website visitors.Google Analytics uses cookies to collect information about your activity on our site and the path you took to get here. This information is collected by Google in the United States.The data collected by Google Analytics is generally de-identified.It may be possible for you to prevent your information from being collected by Google Analytics by using an add-on such as Google Analytics Opt-Out or other software. Although the YD does not discourage you from doing so, it takes no responsibility for your use of any such software.

We also use cookies on the site to keep track of your consent to our Privacy Policy. This cookie is created when you accept the privacy notice pop-up. Ourwebsite can also generate a cookie to keep track of your language preference, taking you to the English or French version by default. Those cookies will be deleted when you clear cookies on your browser.

We collect your IP address and the URLs of pages you visit to be able to serve you the webpages you request. This information is collected by our web hosting service in the United States. Your IP address is discarded after a few hours once the system processes the data for usage and access statistics.

Donors

When you donate to us, we collect the following information:

  • First and last names
  • Email address (if provided)
  • Phone number (if provided)
  • Address
  • Name of the organization (if applicable)
  • Amount of donation
  • Payment method for the donation
  • Date of donation
  • Whether you would like to be subscribed to our newsletter
  • Language preference (if provided)
  • IP address

With the exception of your IP address, all data is provided by you through the Zeffy donation form. We use this information to generate charitable tax receipts and send you our newsletters if you wish to receive them. This information is stored on Zeffy. Zeffy stores user information on Amazon’s RDS servers located in Québec, Canada.

Newsletter Subscribers

When you sign up to our newsletter, we collect the following information:

  • Email address
  • First and last names
  • Language preference
  • IP address

With the exception of your IP address, all of the data is provided by you through the sign-up form. We use this information to send you our newsletters.

Our newsletter is distributed through MailChimp, which means that some personal information is shared with this service to facilitate sending and receiving the newsletter.Please note that this external service collects and stores your personal information in the United States.

Volunteers & Individuals Served by the Yellow Door

The YD uses Sumac by Societ as our customer relationship management (CRM) software. The following information is generally stored in our CRM when an individual makes it available to us:

  • First and last name
  • Email address and/or phone number 
  • Information that was shared with us during a member assessment or a volunteer intake form or any follow-up volunteer form

This external service stores your data on Societ’s cloud servers which are hosted on Amazon Web Services (AWS) located in Canada.

Some information, such as the signed confidentiality agreement, volunteer responsibilities agreement, and any other written material relevant to membership or volunteering, might also be stored in our Microsoft SharePoint on a server located in Canada. These files are shared only with relevant staff members who are involved in service delivery.

Partner Organizations or Funders of the Yellow Door

The YD uses Sumac by Societ as our customer relationship management (CRM) software. The following information is generally stored in our CRM when an organization or a funder makes it available to us:

  • First and last name of our main contact at the organization or foundation
  • Email address and/or phone number of this person
  • Job title and organization/foundation of this person
  • Address of the organization/foundation

This external service stores your data on Societ’s cloud servers which are hosted on Amazon Web Services (AWS) located in Canada.

Some information, such as funding agreements, letters of recommendation, and any other written material relevant to a partnership or sponsorship, might also be stored in our Microsoft SharePoint on a server located in Canada. These files are shared only with relevant staff members.

Job Applicants, Employees & Board Members

The YD requires job applicants to send their CVs and letters of motivation to an organizational email address, which means that the following information might be stored on Microsoft Outlook if you apply for a job with us:

  • First and last Name
  • Email address
  • Your CV

Please note that this external service stores data in the United States.

Sensitive employee and board member data, such as financial information, SIN number, and any other HR-related sensitive documents are stored on Dropbox and Quickbooks which both have password protection. Please note that Dropbox stores information on servers in the United States. Quickbooks stores information on its cloud servers which are hosted on Amazon Web Services (AWS) located in Canada. This information is only accessible by the Executive Director, the Board Treasurer, and our bookkeeper. 

Other information, such as ID cards, employment contracts, and salary information, is stored in the YD Microsoft SharePoint on a server located in Canada and is accessible to the Executive Director and the Board of Directors. 

WHO HAS ACCESS AND SECURITY PRACTICES

Access to personal information within the YD is limited to those who need access for the purpose the information was collected. In particular:

  • The Program Coordinators, Assistant, and Interns have access to sensitive personal information provided to us by the individuals we serve.
  • The Executive Director and Communications & Outreach Officer have access to personal information collected through the website, such as newsletter subscribers’ information and information collected through Google Analytics.
  • The Executive Director has access to HR-related documents and information, such as SIN numbers, financial and health information of employees, IDs and addresses of board members.
  • The YD’s Sumac CRM is only accessible to its staff.

The YD hires external contractors in the following fields:

  • Bookkeeper who has access to employee financial information
  • Auditor who does not have access to personal data
  • External facilitators for Wellness Groups who have access to the list of participants and their accessibility needs
  • Graphic designer, who does not have access to personal data
  • External consultants for digital transformation, strategic planning, and other needs who do not have access to personal data

The YD is committed to keeping our security practices up-to-date to safeguard the confidentiality of your personal information. Some of the practices that we have in place to ensure this are: limiting access to sensitive data to a need-to-know basis and limiting downloads of personal information to local computers as much as possible. We are putting in place staff training on cybersecurity and on personal information best practices. 

HOW LONG WE KEEP YOUR INFORMATION

The YD will store job applications for a period of three months, after which point they will be deleted.

If you signed up to our newsletter, your name, email address, and language preference will be stored until you request to be removed from our newsletter.

The YD will continue to store relevant information about the individuals and organizations that we have worked with in our CRM, unless they request that we delete the information.

The YD retains employee records unless the employee has left the YD and requests that their information is removed (legal obligations allowing). The same is true for current and past board members.

When the YD has a legal obligation to retain information for longer periods than those set out in this policy, those obligations will prevail over this policy.

HOW TO ACCESS YOUR INFORMATION, COMPLAIN OR EXERCISE ANOTHER RIGHT

You may at any time:

  • ask to access the personal information that we have regarding yourself;
  • ask the YD to make a correction to personal information it holds about you;
  • withdraw your consent to the retention of your personal information; or
  • make a complaint regarding your privacy.

To exercise any of these rights, please email our Executive Director at director@yellowdoor.org.

If you would like to become a member or a volunteer or in another way work with the YD but would like to opt out of providing any of the information that was mentioned in this policy, don’t hesitate to write to Executive Director at director@yellowdoor.org to explore alternative options.