WILDCARD
  • Products ▾
    ♠ Protection
    • ♠ 🐝 Domain Security
    • ♠ 🕊️ Email Security
    • ♠ 🐿️ Unified Backups
    • ♠ 🦡 Workstation Defender
    • ♠ 🦉 Identity Monitor
    • ♠ 🦔 Patch Management
    ♠
    F
    ♠
    F
    ♠ CORE Your starting hand for business protection. All six ♠ services.
    One flat rate. FairPlay™.
    Explore →
    ♥ Productivity
    • 🐘 Password Manager
    • 🦚 Email Signatures
    • 🦮 Remote Support
    • 🦜 Business Voice
    ♣ Playbooks
    • 🐟Phishing Training
    • 🎣GoPhish Sessions
    ♦ FairPlay means no minimums, no commitments, and complete transparency. See pricing →
  • Who We Serve
  • Pricing
  • Store
  • About
☎ 888 274 3530 START
**
Where to?
  • 🐝Products♠
  • 🧑‍💼Who We Serve♥
  • 🏷️Pricing♦
  • 📦Store♦
  • 🧯888 274 3530♥
START
Legal

Privacy Policy

v1.0 · Effective 27 September 2026

xFacilitator Inc., operating as WILDCARD * Managed IT Services ("WILDCARD", "we", "us"), provides the products and services offered at teamwildcard.ca and its subdomains. This policy explains what personal information we collect, why we collect it, who we share it with, and the choices you have.

1. Who we are

xFacilitator Inc., operating as WILDCARD * Managed IT Services, is a corporation registered in Alberta, Canada.

  • Address: 10650 113 ST NW, Suite 234, Edmonton, Alberta, T5H 3H6, Canada
  • Privacy questions and requests: [email protected]
  • Phone: +1 888 274 3530

We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and to Alberta's Personal Information Protection Act (PIPA).

2. What this policy covers

This policy applies to teamwildcard.ca and to the WILDCARD services delivered through its subdomains, including quotes.teamwildcard.ca, my.teamwildcard.ca, start.teamwildcard.ca and onboard.teamwildcard.ca. It also applies to the WILDCARD applications that connect to a Microsoft 365 or Google Workspace tenant on your behalf.

Our sister brand wildcardmsp.ca publishes its own privacy policy. Where you engage WILDCARD under a signed Master Services Agreement, that agreement's confidentiality and data handling terms apply to the services it covers, alongside this policy.

3. Information we collect

3.1 Information you give us

  • Contact details: name, business email address, company name, domain name, phone number.
  • Security assessment answers you submit through our online assessments.
  • Order and account details: the products you select, seat counts, billing contact.
  • Anything you send us by email, quote request, support request or web form.

We do not collect or store full payment card numbers. Card payments are processed by Stripe, which receives your card details directly. We receive only a transaction record, the last four digits, the card brand and the expiry date.

3.2 Information we collect automatically

When you visit our sites, we and our service providers collect your IP address, browser and device type, referring page, the pages you view, and timestamps. We use this to keep the service secure, diagnose faults, and understand which pages are useful.

Our public sites currently load three third-party components:

  • Impact (impact.com) affiliate and referral tracking, which sets cookies to attribute a signup to the partner who referred you.
  • SearchAtlas, a search-optimization script served from seo.wildcardmsp.ca.
  • Google Fonts, which receives your IP address in order to serve the typefaces this site uses.

We do not run Google Analytics, advertising pixels or social-network tracking pixels on teamwildcard.ca.

3.3 Information from systems we manage for you

If you are a WILDCARD client, delivering the service requires us to hold technical and administrative information about your environment: user and mailbox lists, licence and seat counts, device inventories, configuration records, security alerts, backup status, and support ticket history. This information may include personal information about your staff. Where it does, your organization is the one accountable for that information, and we handle it on your behalf and under your instructions.

4. Microsoft 365 and Google Workspace administrative access

WILDCARD applications connect to the Microsoft 365 and Google Workspace tenants we administer. This section describes that access specifically.

4.1 What Google user data we access

Our application requests the following Google OAuth scopes, and nothing beyond them:

ScopeWhat it lets us doWhy we need it
admin.directory.userRead the directory of users in the tenant, and create a userReport licensed user counts, and create a documented emergency administrator account where one is required to keep support available
admin.directory.domain.readonlyRead the tenant's verified domainsConfirm we are connected to the correct organization
admin.directory.rolemanagementAssign an administrator roleGive the emergency administrator account the privileges it needs
apps.licensingRead subscription and seat countsBill accurately and identify unused licences
openid, emailIdentify the administrator who authorized the connectionRecord who granted access, and for which domain

We state plainly that two of these scopes can write. Our application is able to create a user account in the tenant and assign it an administrator role. We do this only to establish a documented emergency administrator account, only in tenants we have been engaged to administer, and we record every such account in our documentation system so your organization can see it and revoke it.

We do not request access to Gmail, Google Drive, Google Calendar, Google Photos or Google Chat content. Our application cannot read your messages or your files.

4.2 How we use Google user data

We use it only to provide and improve the administrative and security features you have engaged us for: counting licensed users for billing, confirming tenant identity, maintaining emergency administrative access, and reporting on the environment we manage.

4.3 Limits we commit to

WILDCARD's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not and will not:

  • use Google user data for advertising of any kind, including targeted, personalized, retargeted or interest-based advertising;
  • sell or transfer Google user data to data brokers, information resellers, or any third party for such purposes;
  • use Google user data to assess credit-worthiness or for lending purposes;
  • use Google user data to build or populate a database for resale;
  • use Google Workspace APIs, or any data obtained through them, to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models.

People at WILDCARD read this data only where it is necessary to deliver or support the service, to resolve a fault you have reported, to meet a security or legal obligation, or where you have asked us to.

4.4 How we store and protect it

Access tokens and service-account credentials are held encrypted as platform secrets in our Cloudflare Workers infrastructure and in encrypted key-value storage. They are never written into our source code repositories, never included in logs, and reachable only by our operations service behind an authenticated endpoint. Privileged operations require a second authentication factor.

4.5 Revoking access

A Workspace super administrator can remove our access at any time in the Google Admin console, under Security, then Access and data control, then API controls, then Domain-wide delegation, by deleting our client ID. A user who granted consent directly can revoke it at myaccount.google.com/permissions. Revocation takes effect immediately. Email [email protected] to have the associated tokens deleted from our systems.

Microsoft 365 access is granted through admin consent and Microsoft's delegated administrative privileges. It can be withdrawn in the Microsoft 365 admin center or on the Microsoft Partner relationships page.

5. Why we use your information

  • To provide, maintain, secure and improve the products and services you have asked for.
  • To quote, invoice and collect payment, and to keep the records tax law requires.
  • To answer your questions, quote requests and support requests.
  • To detect, investigate and prevent fraud, abuse and security incidents.
  • To send service and account notices, which are part of the service rather than marketing.
  • To send marketing email where you have consented, which you can withdraw at any time.
  • To meet our legal and regulatory obligations, and to establish or defend legal claims.

We rely on your consent, express or implied by the circumstances, as PIPEDA provides. You may withdraw consent at any time, subject to legal and contractual limits, by writing to [email protected]. Withdrawing consent for information we need in order to deliver the service may mean we can no longer provide it.

We do not sell your personal information.

6. Who we share it with

We share personal information with service providers who process it on our behalf, under contract, and only for the purposes described in this policy. The categories, and the providers we use today:

PurposeProvider
Website and application hosting, security, edge storageCloudflare
Business records, CRM, quotingAirtable
Payments, invoicing, subscriptionsStripe
Transactional email deliveryResend
Our own email, files and collaborationMicrosoft 365
Support ticketing, documentation, monitoring, backupAutotask, IT Glue, Datto RMM, Datto SaaS Protection (Kaseya)
Affiliate and referral attributionImpact.com
Search optimization, web typographySearchAtlas, Google Fonts
Email signature managementXink
Sales research and prospectingApollo.io

We also disclose personal information to our professional advisers, accountants and insurers where necessary; to a purchaser or successor if our business is reorganized, sold or merged, in which case this policy continues to apply to the information transferred; and where the law requires it, including in response to a court order, a subpoena, or a lawful request from a government or law enforcement authority.

Where WILDCARD acts as a Microsoft Cloud Solution Provider or as a reseller for a product you buy through us, we share the details needed to provision and support your licences with that vendor.

6.1 Information held outside Canada

Several of the providers listed above store and process information in the United States and other countries. While information is in another country it is subject to that country's laws, and may be accessible to its courts, law enforcement and national security authorities. We require contractual protections comparable to our own, and we remain accountable for the information throughout. To ask about our practices for a specific provider, write to [email protected].

7. How we protect your information

  • Encryption in transit using TLS, and encryption at rest for the data stores we control.
  • Credentials held as platform secrets, never in source code and never in logs.
  • Multi-factor authentication on administrative accounts, and a second approval factor on privileged operations.
  • Access on a need-to-know basis, limited to the people delivering or supporting your service.
  • Logging and monitoring of administrative activity.

No system is perfectly secure. We cannot guarantee absolute security, and we ask you to keep your own account credentials confidential.

8. How long we keep it

InformationRetention
Billing, invoice and tax records7 years after the transaction, as Canadian tax law requires
Client account and service recordsThe term of the engagement, then 7 years
Security assessment results24 months from submission
Prospect and enquiry contact details where no engagement follows12 months from last contact
Microsoft 365 and Google Workspace access tokensUntil access is revoked or the engagement ends, then deleted
Web and security logsUp to 12 months
Marketing contact recordsUntil you unsubscribe or ask us to delete them

When a retention period ends we delete the information or irreversibly anonymize it. Where we have to keep a record longer to meet a legal obligation or to defend a legal claim, we keep only that record, and only for as long as it is needed.

9. Your rights

You may ask us to:

  • confirm whether we hold personal information about you, and give you access to it;
  • tell you how we have used it and who we have disclosed it to;
  • correct information that is inaccurate or incomplete;
  • delete information we no longer have a legal or business reason to keep;
  • withdraw a consent you previously gave.

Write to [email protected]. We respond within 30 days, and we will tell you if we need more time and why. We may ask you to verify your identity before we act, which protects you against someone else making a request in your name. If we refuse a request we will tell you why, and how to challenge that decision.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to the Office of the Information and Privacy Commissioner of Alberta at oipc.ab.ca.

If you work for an organization that engaged WILDCARD, and your question is about information held in that organization's systems, we will pass your request to that organization, which is accountable for it.

10. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, attribute referrals, and understand how the site is used. You can block or delete cookies in your browser settings. Blocking them may stop parts of the site from working, including sign-in and checkout.

11. Marketing email

Every marketing email we send carries an unsubscribe link, and we act on unsubscribes promptly, as Canada's Anti-Spam Legislation requires. Unsubscribing from marketing does not stop service and account notices, which we need to send you about your account, your billing and your security.

12. Children

Our services are sold to businesses and organizations. They are not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, write to [email protected] and we will delete it.

13. Security incidents

If a breach of our security safeguards involving your personal information creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, keep a record of the breach, and tell you what happened and what to do about it.

14. Changes to this policy

We may update this policy. The version and effective date at the top of this page always show the current version. If we change how we collect, use or share personal information in a way that materially affects you, including any change to how our applications use Google user data, we will post the updated policy here and notify account holders by email before the change takes effect.

15. Contact us

Our Privacy Officer is reachable at [email protected], or by mail at xFacilitator Inc., operating as WILDCARD * Managed IT Services, 10650 113 ST NW, Suite 234, Edmonton, Alberta, T5H 3H6, Canada.

Read our Terms of Service →

* WILDCARD Cybersecurity for small business.
🐝🕊️🐿️🦡🦉🦔🐘🦚🐟🦮🦜
♠ ♥ ♣ ♦
10650 113 ST NW, Edmonton, AB +1 888 274 3530 [email protected] Need it fully managed? wildcardmsp.ca → Privacy Policy · Terms of Service