Privacy Policy
Last Updated: May 30, 2026
Introduction
Shift Happens Auto Sales ("we", "us", or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.
This policy complies with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), and applicable provincial privacy legislation in Alberta and across Canada.
This policy also describes how we implement Google Consent Mode v2, the difference between the cookies we run under implied consent and those that require your express opt-in, and how you can manage your cookie and tracking preferences at any time.
Information We Collect
Personal Information You Provide
We collect personal information that you voluntarily provide to us when you:
- Submit a contact form or vehicle inquiry
- Apply for financing
- Request a trade-in valuation
- Sign up for promotional offers
- Contact us via email or phone
The personal information we collect may include:
- Contact Information: Name, email address, phone number, mailing address
- Financial Information: Employment details, income information (for financing applications)
- Vehicle Information: Details about vehicles you own or are interested in purchasing
- Identification Information: Date of birth, driver's license number (if required for financing)
Information Collected Automatically
When you visit our website, certain technical information may be collected automatically. Aggregate analytics (Google Analytics 4) runs under implied consent and can be switched off at any time; session recordings and advertising cookies run only if you expressly opt in. This may include:
- IP address (anonymized where technically possible)
- Browser type and version
- Device type and operating system
- Pages visited, session duration, and referral source (aggregate analytics — implied consent, opt-out available)
- Interaction data such as clicks and scroll depth via session recordings (Microsoft Clarity — express opt-in only)
On-Site Activity Linked to Your Inquiry
If you submit a form on this site (for example, a financing application, trade-in request, or promotional offer), we associate that inquiry with a first-party record of how you used the site during your visit, so our team can respond with relevant context. This record is anonymous: it is tied to a random identifier we generate and store in your browser — not to your name — and it is saved to our records only once you submit a form. It may include:
- The pages you viewed and their titles (for example, a specific vehicle listing)
- The amount of time spent on each page
- The general source that brought you to the site — such as a search engine, an online ad, an AI assistant, or a direct visit — and, where an advertising campaign provides it, the associated keyword
This is a page-by-page trace only. We do not record your keystrokes, capture the contents of forms you did not submit, or make screen or session recordings as part of this feature (optional session replay is handled separately by Microsoft Clarity, on express opt-in only — see the Cookies section). This activity is collected only while Analytics consent is active, is used solely to understand and respond to your inquiry, is forwarded to our internal CRM alongside that inquiry, and is never sold or shared with third parties for their own purposes. You can reset the random identifier at any time by clearing your browser's site data, and you can stop this collection by choosing "Necessary Only" (or switching Analytics off) in our cookie banner.
How We Use Your Information
We use your personal information only for the purposes for which it was collected and with your consent. These purposes include:
- Responding to Inquiries: To answer your questions about vehicles, services, and availability
- Processing Applications: To review and process financing and trade-in applications
- Completing Transactions: To facilitate vehicle sales and related services
- Providing Updates: To inform you about your applications, appointments, or vehicle availability
- Marketing Communications: To send promotional offers and updates (only with your explicit consent under CASL)
- Improving Our Services: To analyze aggregate, anonymized usage and improve our website and customer experience (Google Analytics 4 — implied consent, opt-out available; Microsoft Clarity session replay — express opt-in)
- Ad Measurement: To measure the effectiveness of advertising campaigns (marketing pixels — express opt-in only)
- Legal Compliance: To comply with legal obligations and protect our rights
Consent
Under PIPEDA, the form of consent we rely on is matched to the sensitivity of the information and your reasonable expectations. Consent on this website operates at three levels:
Form Consent (Express)
When you submit a contact form, financing application, trade-in request, or promotional sign-up, you explicitly consent to:
- Collection and use of the personal information in that form
- Opt-in to marketing communications (via separate, explicit checkbox — never pre-checked)
- Processing of your application or inquiry by our team
Aggregate Analytics (Implied Consent)
First-party, anonymized website analytics (Google Analytics 4) run under implied consent — active by default when you visit. We rely on implied consent here because the data is aggregate, non-sensitive, used solely to measure and improve our own website, and within the reasonable expectations of a website visitor. You may opt out at any time using the "Necessary Only" or "Customize" options on the cookie banner, or the "Cookie Preferences" link in our footer.
Cookie & Tracking Consent (Express Opt-In)
On your first visit a cookie consent banner is presented. You may choose "Accept All," "Necessary Only," or "Customize" to set per-category preferences across three categories: Analytics (Google Analytics 4, on by default — opt-out), Session Replay (Microsoft Clarity, off until you turn it on — express opt-in), and Marketing (Meta Pixel, off until you turn it on — express opt-in). Session recordings and advertising cookies never run unless you affirmatively enable them; opening the preferences panel and saving the defaults does not enable them. Your preference is stored in your browser's localStorage and honoured on subsequent visits. See "Cookie Preferences Management" below for full details.
You may withdraw or change your consent at any time via the "Cookie Preferences" link in our site footer, or by contacting us at intake.shifthappensautosales@gmail.com. Opting out of analytics, session replay, or marketing will not affect our ability to respond to an existing inquiry or complete a vehicle transaction.
Canada's Anti-Spam Legislation (CASL)
Commercial electronic messages we send — including financing follow-up emails, promotional offers, and vehicle availability alerts — require your express opt-in consent under Canada's Anti-Spam Legislation (CASL, Section 6).
Consent is collected via a clearly labelled, unticked checkbox at the point of form submission. We do not bundle marketing consent with service consent — you may receive a response to your inquiry without opting into promotional communications.
To withdraw CASL consent at any time:
- Click the unsubscribe link included in any commercial email we send; or
- Email intake.shifthappensautosales@gmail.com with subject "Unsubscribe."
We will honour all unsubscribe requests within 10 business days, as required by CASL Section 11(3).
Cookies and Tracking Technologies
We use cookies, localStorage, and third-party tracking scripts on this website. The following table describes every technology in use, organized by consent category.
Strictly Necessary (Always Active — No Consent Required)
These technologies are required for the website to function. They are not used for advertising or behavioural tracking, and they do not transmit data to third parties.
Session Cookies
- Purpose: Maintain site functionality across page loads (e.g., form state)
- Data captured: Anonymous session identifier only — no personal information
- Retention: Deleted when you close your browser (session-scoped)
- Third-party transmission: None
Cookie Consent Preference (localStorage)
- Purpose: Remember your cookie consent choice so the banner does not re-appear on every visit
- Storage key:
shas_cookie_consent_v1 - Data captured: Your consent selection (e.g., "analytics:true, sessionReplay:false, marketing:false") — no personal information
- Retention: Persists in your browser until you change your preferences or clear your browser's site data
- Third-party transmission: None
Analytics — Google Analytics 4 (Active by Default · Opt-Out)
Google Analytics 4 runs under implied consent and is active by default. It measures aggregate, anonymized site usage to help us improve our services and does not build advertising profiles. You may opt out at any time via the cookie banner ("Necessary Only" or "Customize") or the "Cookie Preferences" link in our footer; opting out switches GA4 to a cookieless, non-identifying mode (see "Google Consent Mode v2" below).
Google Analytics 4 (GA4)
- Purpose: Aggregate site usage analysis — page views, navigation paths, conversion funnels
- Data captured: Page views, session duration, anonymized IP address, device type, browser, referral source
- Retention: 14 months at Google (configurable in GA4 property settings)
- Data location: United States (Google LLC)
- Opt-out options: (1) Update Cookie Preferences in our site footer; (2) Install the Google Analytics Opt-out Browser Add-on
- Google Privacy Policy: policies.google.com/privacy
Session Replay — Microsoft Clarity (Consent Required · Opt-In)
Session recordings and heatmaps are off by default and load only after you expressly enable "Session Replay" in the cookie banner. They are never activated by visiting the site or by saving the default cookie preferences.
Microsoft Clarity
- Purpose: Session recordings and heatmaps to understand how visitors navigate and interact with the site — used solely for UX improvement
- Data captured: Anonymized clicks, scroll depth, page interactions. Clarity's automatic PII masking redacts form field content, email addresses, and phone numbers before transmission
- Retention: 13 months at Microsoft
- Data location: United States / European Union (Microsoft Azure)
- Opt-out options: Update Cookie Preferences in our site footer
- Microsoft Privacy Statement: privacy.microsoft.com/privacystatement
Marketing (Consent Required)
These tools are activated only after you provide Marketing consent. They are used to measure ad campaign effectiveness and, where consent permits, to build anonymized audiences for advertising. You will not receive more ads as a result of visiting our site without Marketing consent.
Meta Pixel (Facebook/Instagram)
- Purpose: Ad conversion tracking and anonymized audience building for Facebook and Instagram advertising campaigns
- Data captured: Standard pixel events (page view, lead form submission); hashed email address or phone number only when you voluntarily submit a form on our site (never transmitted in plain text)
- Retention: Up to 180 days at Meta for ad targeting purposes, subject to Meta's retention policy
- Data location: United States / Ireland (Meta Platforms, Inc.)
- Opt-out options: (1) Update Cookie Preferences in our site footer; (2) Manage ad preferences at facebook.com/adpreferences
- Meta Privacy Policy: facebook.com/privacy/policy
Google Consent Mode v2
Our website implements Google Consent Mode v2. This is a framework that adjusts the behaviour of Google tags (GA4) based on your consent state — it does not disable the scripts entirely, but it changes what data they collect. By default, analytics storage is granted (implied consent) and advertising storage is denied until you opt in.
If you opt out of Analytics (via "Necessary Only," or by switching Analytics off in "Customize"):
- GA4 switches to cookieless, aggregate "ping" signals for statistical modelling only
- No user identifiers, cookies, or persistent IDs are written to your device
- No behavioural tracking or ad personalization takes place
- Your individual journey is not tracked
Each category is governed independently: analytics (GA4) is on by default and can be turned off; session replay (Microsoft Clarity) and marketing (Meta Pixel) remain off until you expressly turn them on. They are not linked to one another.
Cookie Preferences Management
You are in full control of your cookie and tracking preferences at all times. Here is how to manage them:
- On first visit: A cookie consent banner appears at the bottom of the page. Choose "Accept All," "Necessary Only," or "Customize" to set per-category consent (Analytics, Session Replay, and/or Marketing).
- To change your preferences at any time: Scroll to the bottom of any page on our website and click "Cookie Preferences" in the footer. The preference panel will re-open.
- To reset all preferences (force banner to reappear): Clear your browser's localStorage for the domain
shifthappensautosales.ca. The banner will reappear on your next visit. Instructions vary by browser — search "clear localStorage [your browser name]" for guidance.
Your consent preference is stored locally in your browser only. It is not linked to your name or any personal identifier. Clearing your browser data will reset your preference.
How We Share Your Information
We do not sell, rent, or trade your personal information. We may share your information with:
- Service Providers: Third-party companies that help us provide services (e.g., email delivery, error monitoring — see "Service Infrastructure" section below)
- Financial Institutions: For credit applications and financing approvals (with your explicit consent at time of application)
- Legal Authorities: When required by law, court order, or to protect our rights and the safety of others
All third parties are contractually required to keep your information confidential and use it only for the purposes for which we disclose it.
Cross-Border Data Transfers
Some of the third-party services we use — specifically Google Analytics 4, Microsoft Clarity, Meta Pixel, Sentry (error monitoring), and Resend (email delivery) — may transfer and process personal data outside of Canada, including in the United States, Ireland, and European Union member states.
All such third parties are bound by Data Processing Agreements (DPAs) that require PIPEDA-equivalent protections for your personal information. Where regional data residency options are available, we select them (for example, GA4 is configured with the United States as the data processing region — this is the region Google requires for Consent Mode v2 compliance).
You may request a summary of the DPAs in place by contacting our Privacy Officer at intake.shifthappensautosales@gmail.com.
Service Infrastructure
The following backend services touch personal data in the course of operating our website. They are not tracking or advertising technologies — they are operational systems that support site reliability, form delivery, and sales follow-up.
Sentry (Error Monitoring)
- Purpose: Captures crash reports and application error context to help us identify and fix technical issues
- Data handling: Sentry's PII scrubbing is configured to filter breadcrumb data. If a stack trace includes form input data, it is scrubbed before transmission per our Sentry configuration
- Data location: United States / European Union (Functional Software, Inc. d/b/a Sentry)
- Retention: 30 days
Cloudflare R2 (Image Hosting)
- Purpose: Stores and delivers vehicle photos for inventory listings
- Data handling: Vehicle photos only — no user-generated content or personal information is stored here
- Data location: United States (Cloudflare, Inc.)
CRM API (Shift Happens Internal)
- Purpose: Receives and stores form submissions (financing application, contact form, trade-in valuation, promotional sign-up) for sales team follow-up
- Data handling: Your submitted information is forwarded to our internal CRM system. CRM data is retained per the "Data Retention" schedule below
- Data location: Canada — hosted on Neon Postgres (AWS Canada / ca-central-1 region)
Resend (Email Delivery)
- Purpose: Delivers automatic confirmation emails when you submit a form on our website
- Data handling: Your name and email address are passed to Resend to deliver the confirmation. Resend does not use this data for advertising
- Data location: United States (Resend, Inc.)
- Retention: 30 days of delivery logs
Data Security
We implement appropriate technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit (SSL/TLS on all connections)
- Secure database storage with role-based access controls
- Regular security assessments and dependency updates
- Employee training on data protection and privacy practices
- Limited access to personal information on a strict need-to-know basis
- Error monitoring with PII scrubbing configured (see Sentry above)
Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal requirements. Our retention periods are:
- Contact Inquiries: 2 years from last contact
- Financing Applications: 7 years (as required by law)
- Vehicle Purchase Records: 7 years (as required by law)
- Marketing Communications: Until you unsubscribe or withdraw CASL consent
- Cookie Consent Preference (localStorage): Persists until you change your preferences or clear your browser's site data — no automatic expiry
- On-Site Activity Record (visitor journey): The random browser identifier persists in your browser until you clear your site data; the activity record saved with a submitted inquiry is retained with that inquiry per the periods above (e.g., Contact Inquiries: 2 years; Financing Applications: 7 years)
- Analytics Data (GA4, Microsoft Clarity): Per third-party retention policy — GA4: 14 months; Clarity: 13 months
- Marketing Pixel Data (Meta Pixel): Per Meta's retention policy — up to 180 days for ad targeting purposes
- Error Monitoring Logs (Sentry): 30 days
- Email Delivery Logs (Resend): 30 days
After the applicable retention period expires, we securely delete or anonymize your personal information. Third-party retention periods are governed by each provider's own data policies.
Your Privacy Rights
Under PIPEDA, you have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal retention requirements)
- Withdraw Consent: Withdraw your consent for marketing communications or other optional uses at any time
- Data Export: Request a portable copy of the personal information you provided to us
- File a Complaint: Lodge a complaint with the Office of the Privacy Commissioner of Canada (see section below)
See the "Exercising Your Rights — Data Subject Requests" section below for the concrete mechanism to submit any of these requests.
Exercising Your Rights — Data Subject Requests
This section explains exactly how to submit a privacy request. We aim to make this process straightforward and at no cost to you.
How to Submit a Request
Email our Privacy Officer at intake.shifthappensautosales@gmail.com with the subject line:
Privacy Request — [Access | Correction | Deletion | Withdraw Consent | Export]
Choose the type that matches your request.
We will acknowledge your request within 5 business days and complete it within 30 days, as required by PIPEDA Section 8.3. If we require additional time (complex requests), we will notify you before the 30-day period expires.
What to Include
- Your full name
- The email address you used on our forms (so we can locate your records)
- The type of request (Access, Correction, Deletion, Withdraw Consent, or Export)
- A brief description of what you are requesting
Identity Verification
For Access and Deletion requests, we may ask you to verify your identity before releasing or deleting records. This protects you against fraudulent requests from third parties. Acceptable verification: a government-issued photo ID (e.g., driver's license) with sensitive fields redacted (e.g., SIN, full date of birth). Verification documents submitted for this purpose are destroyed within 30 days of the request being closed.
Cost
Standard privacy requests are provided free of charge. In the rare case of excessive or clearly repetitive requests, we may impose a reasonable fee as permitted under PIPEDA Principle 9. We will notify you of any fee before proceeding.
Right to Escalate
If you are not satisfied with our response to a privacy request, you may escalate to the Office of the Privacy Commissioner of Canada — see contact details in the final section of this policy.
Third-Party Links
Our website may contain links to third-party websites, including lenders, vehicle history report providers, and government portals. We are not responsible for the privacy practices of these sites. We encourage you to read their privacy policies before providing any personal information.
Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a person under 18, please contact us immediately at intake.shifthappensautosales@gmail.com and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, third-party tools, or legal requirements. We will notify you of significant changes by posting the updated policy on our website with a new "Last Updated" date. For material changes affecting how we use your personal information, we will provide additional notice (e.g., email notification to users with active consent on file). We encourage you to review this policy periodically.
Contact Us
If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have a privacy concern, please contact our Privacy Officer:
Shift Happens Auto Sales
Privacy Officer
Email: intake.shifthappensautosales@gmail.com
Phone: (825) 736-4438
Address: 59 East Lake Crescent NE, Airdrie, AB T4A 2H5
We will acknowledge your inquiry within 5 business days and respond fully within 30 days as required by PIPEDA.
Office of the Privacy Commissioner
If you are not satisfied with our response to your privacy concern or data subject request, you have the right to contact the Office of the Privacy Commissioner of Canada at no cost:
Office of the Privacy Commissioner of Canada
Website: www.priv.gc.ca
Toll-free: 1-800-282-1376
Email: info@priv.gc.ca
