Privacy Policy

Effective Date: July 4, 2025 | Last Updated: October 23, 2025

Quick Summary

Skillful Squirrel Creative Inc. is a Canadian sweepstakes management company. Here's what you need to know:

  • Website visitors: We collect analytics data via Google Analytics and use cookies to improve your experience.
  • Tool users: When you use our free tools, we collect your email (with consent) to send results and marketing communications.
  • Sweepstakes entrants: Entry data is managed by Gleam.io/Sweeperoo.com. We don't retain it.
  • Sweepstakes winners: We collect contact info and store it securely in Canada using encrypted local storage (not cloud). Deleted after 3 years.
  • Your rights: You can access, correct, delete, or export your data anytime. Email info@skillfulsquirrel.com
  • We never sell your data. Third parties only receive winner info for prize fulfillment purposes.

Table of Contents

  1. Information We Collect
  2. Sweepstakes Data
  3. How We Use Your Information
  4. Legal Basis for Processing
  5. Data Storage and Security
  6. Your Rights
  7. California Privacy Rights
  8. Data Retention
  9. Cookies & Tracking
  10. Third-Party Services
  11. Marketing Communications
  12. Contact Information
  13. Children's Privacy
  14. Updates to This Policy

Skillful Squirrel Creative Inc. ("we," "us," or "our") is a Canadian company that runs promotional sweepstakes for clients. This Privacy Policy explains how we collect, use, and protect your personal information when you:

  • Visit our website (skillfulsquirrel.com)
  • Use our free tools (Prize Strategy Optimizer, Campaign Idea Generator, etc.)
  • Download resources or sign up for our mailing list
  • Enter sweepstakes we manage for clients
  • Contact us for services or information

1. Information We Collect

Website Visitors

When you visit our website, we automatically collect:

  • Analytics data: IP address, browser type, device information, pages visited, time spent on pages, referring website
  • Cookies & tracking: Session cookies, analytics cookies, and localStorage data (see Section 9 for details)

Tool Users

When you use our free tools (Prize Strategy Optimizer, Campaign Idea Generator, etc.), we collect:

  • Email address: To send you tool results and marketing communications (with consent)
  • Tool inputs: Campaign preferences, budget information, industry selection, goals, and other data you enter
  • Timestamp: Date and time of tool usage
  • Marketing consent: Whether you agreed to receive marketing emails

Resource Downloads & Newsletter Signups

When you download resources or sign up for our newsletter, we collect:

  • Your email address
  • The date and time of your submission
  • The specific resource you requested
  • Marketing consent status

Contact Form Submissions

When you contact us for services or information, we collect:

  • Name, email address, company name
  • Any information you provide in your message
  • Timestamp of submission

2. Sweepstakes Data (Entrants & Winners)

We run promotional campaigns for clients using third-party platforms. This section explains how we handle personal data from entrants and winners.

Data Collected

Entrants: Name, email, and other entry data via Gleam.io or Sweeperoo.com

Winners: Full name, mailing address, phone number, email, and date of birth — collected directly after winner notification. We may also collect:

  • Identity verification: Government-issued ID, proof of age, or residency documentation
  • Tax compliance: Social Insurance Number (SIN) or Tax ID for prizes valued over applicable tax thresholds
  • Shipping & fulfillment: Delivery preferences, package tracking consent, or customs information for international prizes
  • Other eligibility requirements: Additional information as specified in campaign-specific official rules

We only collect additional data when legally required or necessary to fulfill prize delivery. You will be informed of specific requirements before providing this information.

Purposes & Legal Basis

We process winner and entrant data for the following purposes:

  • Verify eligibility & select winners: Contract (campaign rules)
  • Ship prizes: Contract
  • Maintain records for audits, taxes, disputes: Legitimate Interests (compliance)

Where Your Data Is Stored

Entrant data: Hosted by Gleam.io / Sweeperoo.com (see their privacy policies). We do not retain it.

Winner data: Stored locally in Canada in:

  • Encrypted folders using Windows Encrypting File System (EFS)
  • BitLocker-encrypted drives
  • No cloud storage (e.g., Google Sheets) is used for winner PII

Third-Party Sharing

We may share winner information with trusted third parties solely for prize fulfillment purposes:

  • Prize suppliers & vendors: To manufacture, customize, or source prizes
  • Shipping & logistics providers: To deliver prizes to winners (e.g., courier services, freight forwarders)
  • Campaign clients: The brand or organization sponsoring the campaign may receive winner information for fulfillment and record-keeping
  • Tax & legal compliance: Accountants, tax authorities, or legal advisors when required by law
  • Payment processors: For cash prizes or gift card distribution

Data protection requirements: All third parties are contractually required to:

  • Use winner data only for the specified purpose (prize fulfillment)
  • Implement appropriate security measures
  • Delete or return data after fulfillment is complete
  • Comply with applicable privacy laws (PIPEDA, GDPR)

We do not sell, rent, or share winner data for marketing purposes. Third parties may only use your information to fulfill your prize.

Data Transfers

International data transfers are handled as follows:

  • Within Canada: Winner data remains in Canada whenever possible
  • EU → Canada: Permitted under EU adequacy decision for Canada (PIPEDA)
  • International prizes: Minimal data (name, address) may be shared with international shipping providers or prize suppliers when necessary for delivery. We ensure adequate safeguards are in place.
  • U.S. transfers: Only when required for prize fulfillment (e.g., U.S.-based prize supplier), with appropriate data protection agreements

Retention

We retain sweepstakes data according to the following schedule:

Data Type Retention Period
Entrant data Deleted by platform (Gleam.io/Sweeperoo.com) — we do not retain
Winner data Maximum 3 years from prize delivery date, then permanently deleted
Tax hold (e.g., US 1099-MISC) Extended to 7 years if prize ≥ $600 USD and 1099 issued; documented per winner

This ensures compliance with IRS recordkeeping requirements (7 years for 1099s) while minimizing retention elsewhere.

Security Measures

Winner data is protected using multiple layers of security:

  • Full-disk encryption via BitLocker
  • File/folder encryption via EFS (AES-256 equivalent)
  • Access restricted to authorized personnel
  • EFS certificate backed up on encrypted USB, stored securely offline
  • Secure deletion: files permanently erased from disk

Your Rights (EU Residents – GDPR)

You have the right to:

  • Access: Request a copy of your data
  • Rectification: Correct inaccuracies
  • Erasure: Request deletion of your data (if no legal hold)
  • Object: Object to processing
  • Portability: Receive your data in a portable format

To exercise rights: Email info@skillfulsquirrel.com with subject "GDPR Request – [Campaign Name]". We respond within 30 days.

Complaints: Contact your local EU data protection authority (e.g., Bavarian DPA).

3. How We Use Your Information

Website & Tool Data

We use the information collected from website visitors and tool users to:

  • Provide services: Deliver tool results, resources, and respond to inquiries
  • Improve our website: Analyze visitor behavior to enhance user experience and functionality
  • Marketing (with consent): Send emails about sweepstakes marketing tips, resources, and services
  • Security & fraud prevention: Detect and prevent spam, abuse, and unauthorized access
  • Business development: Understand market needs and improve our service offerings

Email Communications

We use your email address to:

  • Send you the requested resource or tool results
  • Send you marketing emails about sweepstakes marketing tips, resources, and services (only if you consented)
  • Respond to your inquiries and provide customer support
  • Send important updates about our services (rarely, and only if relevant to your usage)

We will never sell your email address or personal information to third parties for their marketing purposes.

4. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

Website & Tool Data

  • Consent: You explicitly agreed to receive marketing communications when using our tools or downloading resources
  • Legitimate Interest: To provide you with the tools, resources, and services you requested, improve our website, and prevent fraud

Sweepstakes Data

  • Contract: Processing is necessary to fulfill our contractual obligations under campaign official rules (verify eligibility, select winners, deliver prizes)
  • Legal Obligation: Tax reporting, record-keeping for audits, and compliance with sweepstakes regulations
  • Legitimate Interest: Fraud prevention and dispute resolution

5. Data Storage and Security

Website & Tool Data

Data collected from our website tools and resource downloads is stored in:

  • Google Sheets: Email addresses, tool inputs, timestamps, and marketing consent status are stored in Google Sheets with restricted access
  • Access controls: Only authorized personnel can access this data
  • Security measures: Google's enterprise-grade security, two-factor authentication, and regular access reviews

Sweepstakes Winner Data

Winner personal information is stored with enhanced security measures:

  • Local storage in Canada: All winner data is stored on encrypted local drives, NOT in cloud services
  • Full-disk encryption: BitLocker encryption on all storage devices
  • File-level encryption: Windows Encrypting File System (EFS) with AES-256 equivalent protection
  • Access restriction: Limited to authorized personnel only
  • Backup security: EFS certificates backed up on encrypted USB drives stored securely offline
  • Secure deletion: Files permanently erased from disk after retention period

See Section 2 for complete details on sweepstakes data handling, retention, and security measures.

6. Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Receive your data in a portable format
  • Object: Object to processing of your data
  • Withdraw Consent: Unsubscribe from marketing emails at any time

7. California Privacy Rights (CCPA)

California residents have additional rights including:

  • The right to know what personal information we collect
  • The right to delete personal information
  • The right to opt-out of the sale of personal information (we do not sell your data)
  • The right to non-discrimination

8. Data Retention

We retain your email address until you request deletion or unsubscribe from our communications.

9. Cookies & Tracking Technologies

We use cookies and similar technologies to improve your experience and analyze website usage:

Types of Cookies We Use

  • Essential cookies: Required for website functionality (session management, security)
  • Analytics cookies: Google Analytics tracks visitor behavior to help us improve our website
  • Functional cookies: Remember your preferences and tool usage (via localStorage)

localStorage Data

We use browser localStorage to:

  • Remember if you've already provided your email (to avoid repeat requests)
  • Rate limit tool submissions (prevent spam/abuse)
  • Store non-sensitive preferences

Managing cookies: You can control cookies through your browser settings. Note that disabling cookies may affect website functionality.

10. Third-Party Services

We use the following third-party services that may collect or process your data:

Website & Marketing Services

  • Google Analytics: Website traffic analysis and visitor behavior tracking (Privacy Policy)
  • Google reCAPTCHA: Spam and bot protection (Privacy Policy)
  • SendGrid: Email delivery service for tool results and marketing emails (Privacy Policy)
  • Google Apps Script: Lead capture and data storage in Google Sheets (Privacy Policy)
  • Vercel: Website hosting and serverless functions (Privacy Policy)

Sweepstakes Platforms

See Section 2 for details on how sweepstakes entrant and winner data is handled.

11. Marketing Communications

You can unsubscribe from marketing emails at any time by:

12. Contact Information

For privacy-related inquiries or to exercise your rights, contact:

Skillful Squirrel Creative Inc.
Email: info@skillfulsquirrel.com
Website: skillfulsquirrel.com

13. Children's Privacy

Our website and services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

14. Updates to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page.