Skip to main content

Privacy Policy

Last Updated: January 2025

This policy also covers our use of cookies and tracking technologies. If you previously bookmarked or linked to our separate Cookie Policy page, that page now redirects here.

1. Introduction

Mega Miles Broker ("we", "us", or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at megamilesbroker.com and use our services.

We are governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. This policy is written to meet or exceed the requirements of PIPEDA's ten principles of fair information practice.

2. Scope of This Policy

This policy applies to:

  • All personal information collected through megamilesbroker.com
  • Interactions conducted via email, phone, or any other channel related to our website
  • Cookies, tracking pixels, and other technologies deployed on our site

This policy does not apply to information collected by third parties whose services you access independently, even if you reached those services through a link on our site.

3. Information We Collect

We collect personal information only to the extent necessary for the purposes described in this policy.

3.1 Information You Provide Directly

  • Contact information (name, email address, phone number, mailing address)
  • Loyalty program details (program name, card number where required, approximate point balance)
  • Payment information (processed securely; see Section 7)
  • Messages and communications you send to us
  • Any other information you choose to share when contacting us or using our services

3.2 Information Collected Automatically

When you visit our website, we may automatically collect certain non-personally-identifiable technical data, including:

  • IP address (used for security and basic analytics; not linked to your identity)
  • Browser type and version
  • Device type and operating system
  • Pages visited and time spent on each page
  • Referring URL (the page that linked you to us)
  • General geographic location (city or province level, derived from IP)

This data is collected through cookies and similar tracking technologies. See Section 5 (Cookies & Tracking) for full details.

4. How We Use Your Information

We use personal information only for the purposes for which it was collected, or as otherwise permitted under PIPEDA. Specifically, we use your information to:

  • Process transactions — Complete point-selling transactions and provide accurate valuations and quotes.
  • Respond to inquiries — Answer questions, follow up on service requests, and communicate about your transactions.
  • Improve our services — Analyse aggregated, anonymised usage data to identify areas for improvement on our website and services.
  • Security and fraud prevention — Protect our website and users from unauthorized access, fraudulent activity, or misuse.
  • Legal obligations — Comply with applicable laws, regulations, and court orders.

We do not use your personal information for unsolicited marketing or advertising unless you have given explicit consent to receive such communications.

5. Cookies & Tracking

This section explains what cookies are, which ones we use, and how you can control them. It replaces and supersedes our previously separate Cookie Policy.

5.1 What Are Cookies?

Cookies are small text files that a website places on your device (computer, phone, or tablet) when you visit. They are sent back to the website on subsequent visits, allowing the site to recognise you or remember certain information. Cookies cannot execute code or access personal information on your device beyond what you have shared with the website.

In addition to cookies, we may use similar technologies such as local storage and session storage. For simplicity, this section refers to all such technologies as "cookies".

5.2 Cookies We Use

We categorise our cookies into the following types:

Essential Cookies

These cookies are strictly necessary for the website to function. They enable core features such as page navigation, secure form submissions, and access to site functionality. Because they are required for the site to operate, they are set without your consent. They do not collect any personally identifiable information beyond what is needed for the site to work.

CookiePurposeDuration
__nextNext.js framework internal stateSession
csrf_tokenCross-site request forgery protection on formsSession

Analytics Cookies

We use Google Analytics to understand how visitors interact with our website. This helps us identify which pages are most useful, where users encounter difficulties, and how to improve the overall experience. Google Analytics collects anonymised data only; it does not collect your name, email, or any other directly identifying information.

The data collected through analytics cookies includes:

  • Pages visited and the order in which they were visited
  • Time spent on each page
  • Links and buttons clicked
  • General geographic location (city or province level)
  • Device and browser information
CookieSet ByPurposeDuration
_gaGoogle AnalyticsDistinguishes unique users for aggregate reporting2 years
_ga_*Google AnalyticsStores session and campaign data2 years
_gidGoogle AnalyticsDistinguishes unique users within a 24-hour window24 hours

Google Analytics operates under its own Privacy Policy. You can opt out of Google Analytics tracking entirely by installing the Google Analytics Opt-out Browser Extension.

Functional Cookies

Functional cookies help us provide a better user experience by remembering choices you have made during your visit. They do not track you across sites and are not used for advertising.

CookiePurposeDuration
form_preferencesRetains previously entered form data (e.g. selected loyalty program) to reduce re-entry on return visits30 days
ui_preferencesStores user interface preferences such as display settings1 year

Third-Party Cookies

Some cookies on our site are set by third-party services we integrate with. We do not control how these third-party cookies operate, but we disclose them here for full transparency. Each third party has its own privacy and cookie policy.

Third PartyCookie(s)PurposeTheir Policy
Google (Analytics)_ga, _ga_*, _gidWebsite usage analyticsGoogle Privacy Policy

We review our third-party integrations regularly and update this section whenever we add or remove a service that sets cookies.

5.3 Cookie Consent

Under PIPEDA, we are required to obtain your knowledge and consent before collecting personal information, except in limited circumstances (such as essential cookies required for site functionality).

  • Essential cookies do not require consent because they are necessary for the site to function.
  • Analytics and functional cookies are set only after you have been informed of their use through this policy. By continuing to use our website after reviewing this policy, you indicate your consent to the placement of these cookies.
  • You may withdraw consent at any time by clearing cookies or adjusting your browser settings as described in Section 5.4.

5.4 How to Manage Cookie Preferences

You have full control over the cookies stored on your device. You can manage them in the following ways:

  • Browser settings — Most modern browsers let you view, delete, or block cookies on a per-site basis. Common paths:
    • Chrome: Settings → Privacy and security → Cookies and other site data
    • Firefox: Settings → Privacy & Security → Cookies and Site Data
    • Safari: Preferences → Privacy → Manage Website Data
    • Edge: Settings → Cookies and site data
  • Google Analytics opt-out — Install the Google Analytics Opt-out Browser Extension to prevent Google Analytics from collecting data on any site you visit.
  • Private or incognito mode — Browsing in your browser's private mode prevents cookies from being stored after the session ends.

Please note that blocking or deleting cookies may affect your ability to use certain features on our website, particularly form submission and any functionality that relies on remembering your preferences.

6. Information Sharing & Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  • Service providers — We may share information with companies that help us operate our business (e.g. payment processors, hosting providers). All such providers are bound by confidentiality obligations and may not use your information for their own purposes beyond the services they provide to us.
  • Legal requirements — We may disclose information when required by law, such as in response to a court order or a lawful request by a government authority.
  • Business transfers — If Mega Miles Broker is acquired, merged, or sells substantially all of its assets, your personal information may be transferred to the acquiring entity. We will notify you of any such transfer before it occurs, to the extent practicable.
  • With your consent — We will share your information in any other circumstance only after obtaining your explicit consent.

7. Security of Your Information

We take the security of your personal information seriously and implement measures appropriate to the sensitivity of the information. These include:

  • HTTPS encryption on all pages of our website
  • Secure transmission of payment information via industry-standard protocols
  • Restricted access to personal information, limited to personnel who require it to perform their duties
  • Regular review and updating of our security practices

No method of transmission over the Internet is 100% secure. While we do our best to protect your information, we cannot guarantee absolute security. If you become aware of any potential security issue, please contact us immediately.

8. Retention of Information

We retain personal information only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Specifically:

  • Transaction records are retained for a period consistent with applicable tax and business record-keeping requirements.
  • Communication records are retained for up to 24 months after the last interaction, unless a longer period is required by law.
  • Analytics data is retained in anonymised, aggregated form and is not linked to individual users.

Once the retention period has passed, we securely delete or anonymise your personal information.

9. Your Rights Under PIPEDA

Under PIPEDA, you have the right to:

  • Access — Request access to the personal information we hold about you. We will provide this information within 30 days of your request, or inform you if a longer period is needed.
  • Correct — Challenge the accuracy and completeness of your personal information and have it amended if found to be inaccurate or incomplete.
  • Withdraw consent — Withdraw your consent to the collection or use of your personal information, subject to any legal or contractual restrictions.
  • Complain — File a complaint with the Office of the Privacy Commissioner of Canada if you believe we have violated PIPEDA.

To exercise any of these rights, please contact us using the information provided in Section 11.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. Any changes will be posted on this page with an updated "Last Updated" date at the top.

We encourage you to review this policy periodically. Your continued use of our website after a change is posted constitutes your acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy, our use of cookies, or how we handle your personal information, please contact us:

Email: privacy@megamilesbroker.com

We will respond to your inquiry within 10 business days. If you are not satisfied with our response, you may escalate your complaint to the Office of the Privacy Commissioner of Canada.