top of page

Privacy Policy

THE MUNRO COLLECTION · EST. 2026

 

 

 

 

 

 

 

 

 

PRIVACY POLICY

Considered Care for Personal Information

 

Version 1  · Prepared July 2026 · Effective July

00 · PRIVACY AT A GLANCE

The Munro Collection uses personal information to understand a journey, create and administer travel arrangements, communicate with clients, protect transactions, and meet legal obligations. We seek to collect only what is reasonably needed, use it for identified purposes, disclose it carefully, and remove it when it is no longer required.

Your Experience, Our Experience

 

Principle

TMC standard

Purpose first

We identify why information is needed before collecting it.

Minimum necessary

We avoid requesting sensitive details until the service or Supplier requires them.

Secure channel

Passports, payments, and sensitive travel information are processed only through the approved secure method.

Human accountability

A responsible TMC representative remains accountable for decisions and client communication.

Client choice

Marketing is optional and separate from the information required to provide travel services.

Last updated: July 2026

01 · SCOPE AND ACCOUNTABILITY

1. Who we are

 

This Privacy Policy describes how The Munro Collection (“TMC,” “we,” “us,” or “our”) handles personal information in connection with our website, inquiries, planning services, proposals, forms, payments, bookings, client support, marketing, and business administration.

Contracting name: The Munro Collection.

Business location: Airdrie, Alberta, Canada. Email: concierge@themunrocollection.ca.

Telephone: 403-369-4411.

Complete mailing address: 105 Railway Ave, Airdrie, AB, Canada, T4B 3E0

2. Privacy Officer

 

TMC designates a Privacy Officer with authority to oversee this Policy, privacy requests, service-provider controls, retention, training, complaints, and incident response.

Privacy Officer: Chief Executive Officer

Privacy email: concierge@themunrocollection.ca]

Questions, access or correction requests, consent withdrawals, and privacy complaints may be directed to the Privacy Officer using the contact information above.

3. What is covered

 

This Policy applies to personal information of identifiable clients, travellers, prospective clients, website visitors, payers, authorized decision-makers, and other individuals whose information is provided to TMC for commercial purposes.

It does not govern the independent privacy practices of hotels, airlines, cruise lines, tour operators, insurers, payment processors, border authorities, or other third parties. Those organizations may provide their own notices and terms.

02 · INFORMATION AND PURPOSE

4. Information we may collect

  • Identity and contact — name, preferred name, address, email, telephone, language, and authorized decision-maker details.

  • Traveller profile — date of birth, citizenship or residency where relevant, passport or identity-document details submitted through an approved secure channel, and loyalty-program information.

  • Journey preferences — destinations, dates, budget, travel style, room or seating preferences, celebrations, interests, dining preferences, and service expectations.

  • Sensitive support information — accessibility, dietary, allergy, medical-support, safety, or other information a Traveller chooses to provide because it is reasonably needed for an arrangement.

  • Commercial records — selected scope, proposals, approvals, invoices, payments, refunds, credits, Supplier terms, booking confirmations, change or cancellation instructions, complaints, and correspondence.

  • Payment and authorization metadata — processor, transaction reference, amount, currency, status, authorized Supplier/categories/cap, platform authorization reference, and permitted masked card information. TMC does not place full card numbers or security codes in ordinary business records.

  • Website and device — IP address, device/browser information, pages and links used, referral source, cookie choices, and analytics information to the extent enabled.

  • Marketing choices — consent source, wording, date, preferences, unsubscribe or withdrawal history, and campaign engagement where lawfully collected.

  • Security and compliance — fraud indicators, access logs, incident records, sanctions or identity checks when reasonably required, and evidence needed for a complaint, dispute, chargeback, audit, or legal obligation.

5. How we obtain information

 

We may receive information directly from you; from another Traveller or authorized organizer acting for you; through Wix, TravelJoy, payment providers, email, telephone, meetings, or approved forms; from Suppliers and licensed service providers; and from public or official sources when reasonably necessary to verify travel information or legal requirements.

 

If you provide information about another person, you represent that you are authorized to do so and will ensure they receive the relevant privacy information. TMC may request direct confirmation from that person when the information is sensitive or the authority is unclear.

6. Why we use personal information

  • Inquiry and relationship — respond, qualify fit, schedule consultations, establish the Client brief, and provide requested information.

  • Planning and curation — research, design, refine, price, present, and document a journey within the accepted scope.

  • Booking and support — request availability, reserve services, transmit required Traveller information, manage payments and deadlines, issue confirmations, support authorized changes, and prepare the final TMC itinerary or brochure.

  • Personalization and continuity — remember relevant preferences, prior decisions, service history, and care details for current or future engagements, subject to consent and retention limits.

  • Safety and accessibility — communicate reasonable support needs and respond to identified travel, health, security, or disruption concerns within TMC’s role.

  • Business and legal — accounting, reconciliation, quality assurance, security, fraud prevention, insurance, complaints, disputes, chargebacks, audits, recordkeeping, and compliance.

  • Marketing — send inspiration, collection releases or offers only where TMC has a lawful basis and honours the recipient’s choices.

  • Improvement — measure and improve services, forms, workflows, website performance, and client experience using information that is aggregated or minimized where reasonably possible.

03 · CONSENT AND CLIENT CHOICE

7. Consent and other lawful authority

 

TMC seeks meaningful consent where required and limits collection, use, and disclosure to purposes that a reasonable person would consider appropriate in the circumstances. The form of consent may be express or implied depending on sensitivity, reasonable expectations, and applicable law. Sensitive identity, health-support, accessibility, and travel-document information should receive a clear collection notice and secure handling.

 

Some information is necessary to answer an inquiry, enter an agreement, make a booking, process a payment, protect a transaction, or meet a legal obligation. If required information is not provided, TMC may be unable to perform the affected service. Optional personalization and marketing choices will be identified separately.

8. Withdrawal and correction of choices

 

You may withdraw consent for a future use or disclosure by contacting the Privacy Officer, subject to reasonable notice and legal or contractual restrictions. Withdrawal does not invalidate handling that was lawful before the withdrawal and may make an active service impossible to continue.

Promotional consent may be withdrawn without affecting planning, booking, payment, safety, confirmation, or other service messages. TMC will record and action a valid unsubscribe request within the period required by law.

9. Children and other Travellers

 

TMC does not knowingly contract for planning services with a person who lacks legal capacity. Travel for a minor must be arranged by a parent, guardian, or authorized adult. TMC collects a minor’s information only as reasonably necessary for the arrangement and through the responsible adult or another authorized source.

The primary Client must not provide another Traveller’s information without authority. TMC may communicate directly with adult Travellers about their own sensitive information, choices, documents, or rights where appropriate.

04 · DISCLOSURE AND INTERNATIONAL PROCESSING

10. Who may receive information

 

TMC may disclose only the information reasonably needed to hotels, resorts, airlines, cruise lines, tour operators, transportation and activity providers, destination partners, licensed insurance sources, TravelJoy, Wix, Google Workspace, payment processors, communications and document providers, professional advisers, insurers, regulators, law enforcement, and other authorized service providers.

A Supplier may require information to decide whether to accept a request, complete a reservation, provide accessibility or dietary support, process a payment, respond to a disruption, or investigate a guest charge. Once a third party independently controls the information, its own policy and the law applicable to it may govern.

11. Outside-Canada providers and destinations

 

Because TMC serves international travel and uses global technology and Suppliers, personal information may be accessed, processed, or stored in Canada, the United States, the destination country, and other jurisdictions in which an approved provider or Supplier operates. It may therefore be subject to lawful access by courts, governments, or authorities in those jurisdictions.

TMC remains accountable for personal information transferred to a service provider acting on its behalf and uses contractual, access, configuration, and due-diligence controls appropriate to the information and service. You may contact the Privacy Officer for information about TMC’s current outside-Canada service-provider practices and the position responsible for questions about them.

12. Payment information

 

Planning fees and travel payments may be processed by e-transfer, TravelJoy, a payment processor, TMC, or a Supplier as identified in the transaction. Full card details must be entered only into the secure payment or authorization method TMC identifies. Do not email, text, upload to a general form, or place full card details, card images, security codes, banking credentials, or passwords in ordinary files or messages.

 

TMC may retain payment status, amount, currency, processor or merchant, transaction reference, last four digits where permitted, authorization scope, and reconciliation information. Card security codes are not retained after authorization.

13. Assisted technology and human review

 

TMC may use approved productivity, search, document, automation, or AI-assisted tools to help organize information, draft content, check consistency, or improve operations. TMC is responsible for selecting authorized tools, minimizing the information used, configuring access appropriately, and applying human review before a material client decision or deliverable.

TMC does not intentionally place full payment card numbers, security codes, online-banking credentials, passwords, or unnecessary passport, identity, health, or accessibility details into general AI prompts or unapproved systems. Technology does not replace TMC’s responsibility for professional care, privacy, security, or the accuracy of client-facing work.

05 · WEBSITE, SECURITY AND RETENTION

14. Cookies and website analytics

 

The website may use essential cookies needed for security and operation and, where enabled, preference, analytics, or marketing technologies. The active cookie banner or settings panel should identify available choices. Non-essential technologies will be managed according to applicable consent requirements and the configured provider settings.

Browser controls may block or remove cookies, although parts of the website may not function as intended. TMC will not describe a technology as active in this Policy unless it is actually configured and included in the approved provider inventory.

15. Safeguards

 

TMC uses administrative, technical, and physical safeguards proportionate to the sensitivity and volume of information. Controls may include role-based access, multi-factor authentication, approved secure forms, restricted sharing, device protection, backups, incident procedures, provider review, retention rules, and workforce confidentiality and training.

 

No method of transmission or storage is completely risk-free. If you believe information has been sent to the wrong person, exposed, or accessed without authority, contact TMC promptly and do not resend sensitive information through the same channel until instructed.

16. Accuracy and retention

 

TMC takes reasonable steps to keep information accurate and complete for its intended use. Clients and Travellers must promptly review legal names, dates, passport details, contact information, preferences, invoices, authorizations, and confirmations and report an error.

TMC retains personal information only as long as reasonably required for the identified purpose, an active client relationship, transaction records, tax or accounting obligations, security, complaint or dispute management, legal limitation periods, or another lawful requirement. Retention varies by category. When information is no longer required, TMC will securely delete, anonymize, or destroy it, subject to a documented legal hold.

06 · RIGHTS, COMPLAINTS AND CHANGE

17. Access and correction

 

You may ask for access to your personal information or request correction of information that is inaccurate or incomplete, subject to identity verification and exceptions permitted by law. TMC may ask for enough detail to locate the record and respond securely.

If TMC cannot provide access or make a requested correction, it will explain the reason where required and identify any available complaint route. A request about information independently controlled by a Supplier may need to be directed to that Supplier.

18. Privacy questions and complaints

 

Send a written privacy question or complaint to the Privacy Officer with your name, contact information, the relevant journey or interaction, the information or event at issue, and the resolution requested. TMC will acknowledge, investigate, document, and respond within a reasonable period and any period required by law.

You may also contact the Office of the Information and Privacy Commissioner of Alberta or another competent privacy regulator. TMC asks for an opportunity to understand and address the concern first but does not restrict a lawful complaint right.

19. Privacy incidents

 

TMC maintains a process to contain, assess, investigate, document, and remediate suspected privacy or security incidents. Where applicable law requires notice to a regulator or affected individual, TMC will follow that requirement and provide available information needed to reduce harm.

20. Marketing communications

 

TMC separates promotional consent from service acceptance and keeps evidence of the wording, source, date, method, and withdrawal. Commercial electronic messages will identify the sender, provide current contact information, and include a usable unsubscribe method where required. Transactional or service messages may still be sent when necessary to administer an inquiry, agreement, payment, booking, safety issue, or legal obligation.

21. Policy changes and governing rights

 

TMC may update this Policy to reflect changes in services, technology, providers, law, or operations. The current version and effective date will be published. I

 

f a change materially alters how existing information will be used, TMC will provide additional notice or seek consent where required.

 

This Policy does not limit any privacy right that applicable law prohibits from being waived. The law applicable to a specific individual,

 

transaction, processing activity, or regulator may differ by jurisdiction.

 

PUBLICATION GATE · INTERNAL NOTE

 

Required confirmation

Publication field

 

Complete legal/mailing address

105 Railway Ave, Airdrie, AB, Canada T4B 3E0

 

Privacy Officer name or position

CEO

 

Privacy contact email

concierge@themunrocollection.ca

 

Actual providers and processing locations

Wix, TravelJoy, Google Workspace, processors, analytics, email, AI-assisted tools and Suppliers verified

 

Cookie configuration

Essential / analytics / marketing categories and consent banner verified

 

Retention schedule

Counsel, accountant and Privacy Officer approved

Incident and request procedures

Owner, response route and evidence location tested

The Munro Collection
THE MUNRO COLLECTION · EST. 2026
bottom of page