Legal · medievalttimesiise.com
Privacy Policy
At a glance. The Castle Supper Notebook is an independent dietitian’s food guide, published from Toronto, Ontario. The Castle Supper Notebook is an independent food and dining guide, not affiliated with any dinner theatre or its operator. We do not sell tickets and never process payments. We do not run Google Analytics, Google Ads tags, Meta Pixel, or TikTok Pixel on these pages. The only cookie we may set is a strictly necessary session cookie from the web server. Effective 6 October 2026; last reviewed 6 October 2026. Questions: [email protected], or by post to the P.O. Box below.
1. Who is responsible
Publisher / data controller: The Castle Supper Notebook, an independent editorial project at medievalttimesiise.com, published from Toronto, Ontario.
Editor: Priya Shah, RD
Email: [email protected]
Post: P.O. Box 12248, Postal Station A, Toronto, ON M5W 2A1, Canada
There is no company behind this site. If you are in Canada, the EEA, the United Kingdom, or Switzerland, use the same address for PIPEDA / GDPR / UK GDPR requests. In Ontario we follow the Office of the Privacy Commissioner of Canada’s (OPC) PIPEDA guidance for private-sector editorial projects. This is not the privacy notice of any dinner theatre or its operator.
2. Scope
This Policy covers https://medievalttimesiise.com only — the editorial food pages you are reading now. It does not cover any operator, ticket vendor, payment processor, or any site we merely link to.
3. What we collect
3.1 You send us
If you write to [email protected] or use the contact form, we receive the name, email, and message you send, plus the time it arrived. Do not send card numbers, passport scans, or booking references — if they arrive by mistake we delete them.
3.2 The server records
Each page load typically leaves an ordinary hosting / security log: IP address (including an address forwarded by Cloudflare when the domain is proxied); date and time; URL; referrer; status code; browser / user-agent; approximate country from IP; and the cookie described in the Cookie Policy.
3.3 What we do not ask for here
Payment cards, government identification, precise GPS, account passwords, allergy medical records, or a customer login. We do not sell tickets and we do not collect checkout data on these pages. There is no checkout on this site.
4. Cookies
We may set a strictly necessary first-party session cookie so the server can keep request state. We do not place Google advertising cookies, Google Analytics (_ga, _gid, _gcl_aw), Floodlight, Meta Pixel, TikTok Pixel, Hotjar, Clarity, or similar measurement cookies on these editorial pages. Full table: Cookie Policy.
5. How we use it
- to deliver and secure the Site;
- to answer editorial mail and correct published errors;
- to see, in aggregate, which pages are requested;
- to comply with law;
- to show advertising platforms and regulators who we are and how to reach us.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not operate a ticket desk and we do not forward health or allergy information to anyone.
6. Legal bases (PIPEDA / GDPR)
Canada (PIPEDA) — applicable law for this publication: we collect and use the information above for the reasonable purposes of running an editorial website, answering mail, and protecting the service. The publisher is in Ontario; Ontario does not have a separate private-sector privacy statute, so PIPEDA governs this editorial project across provinces.
GDPR / UK GDPR (if those laws apply to a visitor): legitimate interests (Art. 6(1)(f)) for operating and securing a publication; your request (Art. 6(1)(b)) when you write to us; legal obligation (Art. 6(1)(c)) if a competent authority issues a lawful order. We do not rely on consent for advertising cookies because we do not set them.
California and other US state privacy laws: we do not sell or share personal information as those statutes define those terms. We do not use sensitive personal information for inferring characteristics.
7. Sharing
We share information only with hosting, DNS, TLS, and security providers (a VPS host and, when the domain is proxied, Cloudflare); email infrastructure if we reply; professional advisers or authorities when the law requires it; and a successor if the publication is transferred, under this Policy or a notice posted first. We do not forward your email to any dinner-theatre operator.
8. International transfers
Hosting, DNS, or security providers may process technical data in Canada, the United States, the European Union, or other countries where they operate. Where GDPR applies, those transfers rely on the provider’s appropriate safeguards (for example Standard Contractual Clauses) or an adequacy decision.
9. How long we keep it
- Server and security logs: typically up to 30 days, unless a security investigation needs a longer copy;
- Editorial email: up to 12 months after the last reply, unless you ask us to delete sooner and no legal hold applies;
- Session cookie: until the browser session ends, or shortly after.
10. Children
The Site is written for adults planning a visit. It is not directed at children under 13 (or 16 where that is the relevant digital-consent age). If you believe a child sent us information, write to [email protected] and we will delete it.
11. Your rights
Subject to the law that applies to you, you may ask us to access, correct, delete, or export the personal information we hold, or to restrict or object to certain processing. Send requests to [email protected]. We may need to verify that the request comes from you.
You may complain to the Office of the Privacy Commissioner of Canada (OPC), your EEA supervisory authority, or the UK ICO. We would rather fix the issue first if you write to us.
12. If you came from an advertisement
Occasionally people arrive after seeing an online advertisement that mentioned a Toronto castle tournament, dinner show, or tickets. That advertisement is not ours. We do not advertise this guide and we do not sell tickets. If an ad led you here expecting to buy, leave this page and use the operator’s own official website — nothing here will take a card payment.
- the advertising network (for example Google) is a separate controller for the ad click and any cookies it sets on its own domains;
- we do not operate a Google Ads tag, Floodlight tag, conversion linker, or remarketing tag on these editorial pages;
- we do not upload customer lists to advertising platforms;
- this Policy, the Cookie Policy, the Terms of Use, and the Contact page exist so a reviewer can see who publishes the Site, what we collect, and how to reach us;
- the pages do not sell tickets, show live fares, or process payments.
Google’s own notices: policies.google.com/privacy and policies.google.com/technologies/ads.
13. Security
The public site is served over HTTPS. The origin is access-controlled. No method of transmission is perfectly secure. Do not send secrets to an editorial inbox.
14. Photographs and third-party links
Photographs are from Wikimedia Commons and are credited under each figure with licence and author. Editorial links are context, not endorsements. Those sites have their own policies. This Site does not load Google Fonts or other third-party font CDNs.
15. Changes
If we change this Policy we update the date at the top. If a change is material — for example if we ever introduced analytics cookies — we will post a short notice on the Site as well. There is no mailing list.
16. How to reach us
The Castle Supper Notebook
c/o Priya Shah
P.O. Box 12248, Postal Station A, Toronto, ON M5W 2A1
Canada
[email protected]
https://medievalttimesiise.com/privacy · https://medievalttimesiise.com/cookies · https://medievalttimesiise.com/terms · https://medievalttimesiise.com/contact