xFacilitator Inc., operating as WILDCARD * Managed IT Services ("WILDCARD", "we", "us"), provides the products and services offered at teamwildcard.ca and its subdomains. This policy explains what personal information we collect, why we collect it, who we share it with, and the choices you have.
xFacilitator Inc., operating as WILDCARD * Managed IT Services, is a corporation registered in Alberta, Canada.
We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and to Alberta's Personal Information Protection Act (PIPA).
This policy applies to teamwildcard.ca and to the WILDCARD services delivered through its subdomains, including quotes.teamwildcard.ca, my.teamwildcard.ca, start.teamwildcard.ca and onboard.teamwildcard.ca. It also applies to the WILDCARD applications that connect to a Microsoft 365 or Google Workspace tenant on your behalf.
Our sister brand wildcardmsp.ca publishes its own privacy policy. Where you engage WILDCARD under a signed Master Services Agreement, that agreement's confidentiality and data handling terms apply to the services it covers, alongside this policy.
We do not collect or store full payment card numbers. Card payments are processed by Stripe, which receives your card details directly. We receive only a transaction record, the last four digits, the card brand and the expiry date.
When you visit our sites, we and our service providers collect your IP address, browser and device type, referring page, the pages you view, and timestamps. We use this to keep the service secure, diagnose faults, and understand which pages are useful.
Our public sites currently load three third-party components:
We do not run Google Analytics, advertising pixels or social-network tracking pixels on teamwildcard.ca.
If you are a WILDCARD client, delivering the service requires us to hold technical and administrative information about your environment: user and mailbox lists, licence and seat counts, device inventories, configuration records, security alerts, backup status, and support ticket history. This information may include personal information about your staff. Where it does, your organization is the one accountable for that information, and we handle it on your behalf and under your instructions.
WILDCARD applications connect to the Microsoft 365 and Google Workspace tenants we administer. This section describes that access specifically.
Our application requests the following Google OAuth scopes, and nothing beyond them:
| Scope | What it lets us do | Why we need it |
|---|---|---|
| admin.directory.user | Read the directory of users in the tenant, and create a user | Report licensed user counts, and create a documented emergency administrator account where one is required to keep support available |
| admin.directory.domain.readonly | Read the tenant's verified domains | Confirm we are connected to the correct organization |
| admin.directory.rolemanagement | Assign an administrator role | Give the emergency administrator account the privileges it needs |
| apps.licensing | Read subscription and seat counts | Bill accurately and identify unused licences |
| openid, email | Identify the administrator who authorized the connection | Record who granted access, and for which domain |
We state plainly that two of these scopes can write. Our application is able to create a user account in the tenant and assign it an administrator role. We do this only to establish a documented emergency administrator account, only in tenants we have been engaged to administer, and we record every such account in our documentation system so your organization can see it and revoke it.
We do not request access to Gmail, Google Drive, Google Calendar, Google Photos or Google Chat content. Our application cannot read your messages or your files.
We use it only to provide and improve the administrative and security features you have engaged us for: counting licensed users for billing, confirming tenant identity, maintaining emergency administrative access, and reporting on the environment we manage.
WILDCARD's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not and will not:
People at WILDCARD read this data only where it is necessary to deliver or support the service, to resolve a fault you have reported, to meet a security or legal obligation, or where you have asked us to.
Access tokens and service-account credentials are held encrypted as platform secrets in our Cloudflare Workers infrastructure and in encrypted key-value storage. They are never written into our source code repositories, never included in logs, and reachable only by our operations service behind an authenticated endpoint. Privileged operations require a second authentication factor.
A Workspace super administrator can remove our access at any time in the Google Admin console, under Security, then Access and data control, then API controls, then Domain-wide delegation, by deleting our client ID. A user who granted consent directly can revoke it at myaccount.google.com/permissions. Revocation takes effect immediately. Email [email protected] to have the associated tokens deleted from our systems.
Microsoft 365 access is granted through admin consent and Microsoft's delegated administrative privileges. It can be withdrawn in the Microsoft 365 admin center or on the Microsoft Partner relationships page.
We rely on your consent, express or implied by the circumstances, as PIPEDA provides. You may withdraw consent at any time, subject to legal and contractual limits, by writing to [email protected]. Withdrawing consent for information we need in order to deliver the service may mean we can no longer provide it.
We do not sell your personal information.
We share personal information with service providers who process it on our behalf, under contract, and only for the purposes described in this policy. The categories, and the providers we use today:
| Purpose | Provider |
|---|---|
| Website and application hosting, security, edge storage | Cloudflare |
| Business records, CRM, quoting | Airtable |
| Payments, invoicing, subscriptions | Stripe |
| Transactional email delivery | Resend |
| Our own email, files and collaboration | Microsoft 365 |
| Support ticketing, documentation, monitoring, backup | Autotask, IT Glue, Datto RMM, Datto SaaS Protection (Kaseya) |
| Affiliate and referral attribution | Impact.com |
| Search optimization, web typography | SearchAtlas, Google Fonts |
| Email signature management | Xink |
| Sales research and prospecting | Apollo.io |
We also disclose personal information to our professional advisers, accountants and insurers where necessary; to a purchaser or successor if our business is reorganized, sold or merged, in which case this policy continues to apply to the information transferred; and where the law requires it, including in response to a court order, a subpoena, or a lawful request from a government or law enforcement authority.
Where WILDCARD acts as a Microsoft Cloud Solution Provider or as a reseller for a product you buy through us, we share the details needed to provision and support your licences with that vendor.
Several of the providers listed above store and process information in the United States and other countries. While information is in another country it is subject to that country's laws, and may be accessible to its courts, law enforcement and national security authorities. We require contractual protections comparable to our own, and we remain accountable for the information throughout. To ask about our practices for a specific provider, write to [email protected].
No system is perfectly secure. We cannot guarantee absolute security, and we ask you to keep your own account credentials confidential.
| Information | Retention |
|---|---|
| Billing, invoice and tax records | 7 years after the transaction, as Canadian tax law requires |
| Client account and service records | The term of the engagement, then 7 years |
| Security assessment results | 24 months from submission |
| Prospect and enquiry contact details where no engagement follows | 12 months from last contact |
| Microsoft 365 and Google Workspace access tokens | Until access is revoked or the engagement ends, then deleted |
| Web and security logs | Up to 12 months |
| Marketing contact records | Until you unsubscribe or ask us to delete them |
When a retention period ends we delete the information or irreversibly anonymize it. Where we have to keep a record longer to meet a legal obligation or to defend a legal claim, we keep only that record, and only for as long as it is needed.
You may ask us to:
Write to [email protected]. We respond within 30 days, and we will tell you if we need more time and why. We may ask you to verify your identity before we act, which protects you against someone else making a request in your name. If we refuse a request we will tell you why, and how to challenge that decision.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to the Office of the Information and Privacy Commissioner of Alberta at oipc.ab.ca.
If you work for an organization that engaged WILDCARD, and your question is about information held in that organization's systems, we will pass your request to that organization, which is accountable for it.
We use cookies and similar technologies to keep you signed in, remember your preferences, attribute referrals, and understand how the site is used. You can block or delete cookies in your browser settings. Blocking them may stop parts of the site from working, including sign-in and checkout.
Every marketing email we send carries an unsubscribe link, and we act on unsubscribes promptly, as Canada's Anti-Spam Legislation requires. Unsubscribing from marketing does not stop service and account notices, which we need to send you about your account, your billing and your security.
Our services are sold to businesses and organizations. They are not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, write to [email protected] and we will delete it.
If a breach of our security safeguards involving your personal information creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, keep a record of the breach, and tell you what happened and what to do about it.
We may update this policy. The version and effective date at the top of this page always show the current version. If we change how we collect, use or share personal information in a way that materially affects you, including any change to how our applications use Google user data, we will post the updated policy here and notify account holders by email before the change takes effect.
Our Privacy Officer is reachable at [email protected], or by mail at xFacilitator Inc., operating as WILDCARD * Managed IT Services, 10650 113 ST NW, Suite 234, Edmonton, Alberta, T5H 3H6, Canada.