Privacy policy
Privacy Policy
Pilot Coffee Roasters
Effective Date: January 1, 2026 | Last Reviewed: April 21, 2026
1. Who We Are and How to Contact Us
Pilot Coffee Corp. (operating as “Pilot Coffee Roasters” or “Pilot”) is a specialty coffee company headquartered at 50 Wagstaff Drive, Toronto, Ontario. We roast, sell, and deliver specialty coffee and related products through our e-commerce store, mobile app, retail café locations, and loyalty program.
We are committed to protecting the personal information of our customers and website visitors. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with:
- The Act Respecting the Protection of Personal Information in the Private Sector (Quebec Law 25 / Loi 25), fully in force as of September 22, 2024;
- The Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s federal private-sector privacy law; and
- Applicable provincial privacy legislation across Canada.
Privacy Officer
Pilot has designated a Privacy Officer responsible for overseeing compliance with this Policy and applicable privacy laws. You may contact our Privacy Officer at:
Rita Mistry, Head of People, Culture & Diversity
Email: privacy@pilotcoffeeroasters.com
Mailing Address: Pilot Coffee Corp., 50 Wagstaff Drive, Toronto, Ontario
Phone: 416 546 4006
If you are a Quebec resident, you may also direct complaints or inquiries to the Commission d’accès à l’information (CAI) at www.cai.gouv.qc.ca.
2. Scope of This Policy
This Policy applies to all personal information collected, used, or disclosed by Pilot Coffee Corp. in connection with commercial activities, including:
- Purchases made through our online store at pilotcoffeeroasters.com;
- Account registration and use of our mobile app;
- Enrollment and participation in the Pilot Coffee Club loyalty program;
- Email and SMS marketing communications;
- In-café transactions and loyalty enrollment at Pilot retail locations; and
- General use of our website, mobile app, and other digital properties.
This Policy applies to all customers and website visitors, including residents of Quebec. Quebec residents have additional rights under Law 25, which are described throughout this Policy and summarized in Section 8.
3. Personal Information We Collect
We collect personal information only for the purposes described in this Policy and only to the extent necessary for those purposes. The following table describes the categories of personal information we collect, the source, and the purpose:
| Category | Source | Purpose |
|---|---|---|
|
Identity & Contact Information Name, email address, phone number, shipping/billing address |
Provided by you at account creation, checkout, loyalty enrollment, or contact form | Order fulfilment, account management, customer service, loyalty program administration, marketing communications (with consent) |
|
Transaction & Order Data Order history, products purchased, order value, fulfilment records |
Generated through your purchases on our online store or in-café purchases | Order processing, loyalty rewards calculation, product recommendations, service improvement |
|
Loyalty Account Data Points balance, redemption history, membership tier, account preferences |
Generated through participation in loyalty programs (99minds, Square Loyalty) | Loyalty program administration, personalized offers, communications |
|
Marketing Preferences Email/SMS opt-in status, communication preferences, unsubscribe records |
Provided by you when signing up for communications or updating preferences | Sending marketing emails and SMS messages with your consent; honouring opt-outs |
|
Behavioural & Usage Data Website browsing patterns, pages visited, session duration, click data, IP address, device type |
Collected automatically through cookies, Google Analytics, Meta Pixel, and TikTok Pixel when you visit our website or use our app | Website analytics, performance improvement, targeted advertising (with your consent — see Section 6) |
|
Payment Information (Passthrough only — not stored by Pilot) |
Collected at checkout by our payment processors (Shopify Payments and Square) | Payment processing. Pilot does not store, access, or retain raw card data. See Section 7. |
We do not knowingly collect personal information from individuals under the age of 14 without the consent of a parent or legal guardian. If you believe a minor’s information has been collected without appropriate consent, please contact our Privacy Officer immediately.
4. How We Use Your Personal Information
We use your personal information only for the purposes for which it was collected or for purposes that are consistent with those purposes and permitted by law. Specifically, we use personal information to:
- Process and fulfil your orders, including coordinating delivery and managing returns;
- Create and manage your online account or mobile app account;
- Administer your Pilot Coffee Club membership, calculate loyalty points, and communicate rewards;
- Respond to your customer service inquiries and support requests;
- Send you transactional communications (order confirmations, shipping notifications);
- Send you marketing emails or SMS messages about our products, promotions, and events, where you have provided consent;
- Analyze website and app usage to improve our digital properties and customer experience;
- Measure the performance of our marketing campaigns (Google Analytics, Meta Pixel, TikTok Pixel) where you have consented to such tracking;
- Comply with our legal obligations, including applicable privacy and tax laws;
- Prevent fraud, unauthorized access, and other security incidents; and
- Operate and improve our in-café services and POS systems.
We will not use your personal information for any new purpose without first notifying you and, where required by law, obtaining your consent.
5. Third Parties Who Receive Your Personal Information
Pilot does not sell, rent, or trade your personal information. We share your personal information only in the following circumstances and only with the parties described below.
5.1 Service Providers
We share personal information with trusted third-party service providers who process it on our behalf to help us operate our business. Each provider is subject to contractual obligations limiting how they may use your data. Our current service providers and the data they receive are:
| Provider | Service | Data Shared | Location |
|---|---|---|---|
| Shopify | E-commerce platform & payment processing | Name, address, email, order data, payment info (tokenized) | Canada / United States (Shopify Inc., Ottawa, ON) |
| Square | In-café POS & payment processing | Transaction records, payment card data (encrypted/tokenized) | United States (Block, Inc.) |
| Klaviyo | Email marketing platform | Email, name, purchase history, engagement data | United States (Klaviyo, Inc.) |
| 99minds | Loyalty program platform & online gift card platform | Name, email, phone, loyalty points, purchase history | United States |
| Square Loyalty | In-café loyalty enrollment | Email, phone, loyalty activity, transaction history | United States (Block, Inc.) |
| Oracle NetSuite | Customer relationship management | Contact info, interaction records, account data | United States (NetSuite, Inc.) |
| Google Analytics | Website & app analytics | Browsing data, session info, IP address, device data (with consent) | United States (Google LLC) |
| Meta (Facebook) Pixel | Advertising measurement & retargeting | Browsing behaviour, conversion events (with consent) | United States (Meta Platforms, Inc.) |
| TikTok | Advertising measurement & retargeting | Browsing behaviour, conversion events (with consent) | United States (TikTok USDS Joint Venture LLC) |
5.2 Gift Card Processing (Square & 99minds)
Pilot gift cards are processed through Square and 99minds, which work together to allow gift cards to be used both in-store and online. As a result, gift card data is stored in both systems.
- In-store purchases: Gift cards are created in Square and synced to 99minds for online use.
- Online purchases: Gift cards are created in 99minds and synced to Square for in-store use.
To enable this functionality, Square and 99minds exchange:
- Gift card number;
- Gift card balance;
- Purchase and redemption history; and
- Customer contact information (if provided).
This syncing ensures a unified gift card experience across all Pilot sales channels.
5.3 Cross-Border Transfers
As indicated above, several of our service providers are located in the United States. When your personal information is transferred outside Canada, including to the United States, it may be subject to the laws of that jurisdiction, which may differ from Canadian privacy laws.
We have implemented contractual safeguards (Data Processing Agreements) to protect your personal information when it is transferred internationally.
For Quebec residents: Transfers of your personal information outside Quebec are subject to the requirements of Law 25. You may contact our Privacy Officer to request information about the protections in place for cross-border transfers of your data.
5.4 Legal Disclosure
We may disclose personal information to government authorities, law enforcement, or regulators where required by law, court order, or to protect our legal rights or the safety of others.
5.5 Business Transactions
In the event of a merger, acquisition, or sale of all or part of our business, your personal information may be transferred to the acquiring entity, subject to equivalent privacy protections.
6. Cookies and Behavioural Tracking
6.1 What Are Cookies?
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work efficiently, to remember your preferences, and to provide analytical and advertising information to site owners.
6.2 Types of Cookies We Use
| Cookie Type | Purpose | Provider | Consent Required |
|---|---|---|---|
| Essential / Functional | Required for the website and checkout to function (shopping cart, session management, account login) | Shopify | No — always active |
| Analytics | Measures how visitors use our website to help us improve it (pages visited, session duration, traffic sources) | Google Analytics | Yes — opt-in required for QC |
| Marketing / Advertising | Tracks conversions and enables retargeting of ads on Meta (Facebook/Instagram) and TikTok based on your browsing behaviour | Meta Pixel, TikTok Pixel | Yes — opt-in required for QC |
| Preference | Remembers your language, currency, and other site preferences | Shopify | No — functional |
6.3 Your Cookie Choices
When you visit our website, you will be presented with a cookie consent banner. You can choose to:
- Accept all cookies (including analytics and advertising cookies);
- Accept only essential cookies; or
- Customize your preferences by category.
You can change or withdraw your consent at any time by clicking the “Cookie Preferences” link in the footer of our website. Note that disabling non-essential cookies will not affect your ability to browse or purchase from our store.
You may also control cookies through your browser settings. For more information, visit www.allaboutcookies.org.
6.4 Mobile App
Our mobile app does not use browser cookies. Instead, it may use similar technologies such as mobile software development kits (SDKs), device identifiers, and local storage to provide app functionality, remember your preferences, deliver push notifications (where you have enabled them), and measure analytics and advertising performance. Where required by law, including for Quebec residents, we will obtain your consent before activating analytics or advertising technologies in the app, and you can manage these technologies through your device settings and the app’s in-app privacy controls.
6.5 Quebec Residents
If you are a Quebec resident, we will not activate analytics or advertising tracking technologies (Google Analytics, Meta Pixel, TikTok Pixel) until you have given your express, informed consent through our cookie consent tool. This applies to both our website and mobile app.
7. Payment Information and PCI DSS
Pilot Coffee Roasters does not store, process, or access your raw payment card information. All payment transactions are handled by our certified payment processors:
- Online purchases are processed by Shopify Payments (PCI DSS Level 1 certified).
- In-café purchases are processed by Square (PCI DSS Level 1 certified).
Your card data is encrypted at the point of entry and tokenized before any information is transmitted. Pilot receives only a transaction confirmation and the last four digits of your card for record-keeping purposes.
8. Your Privacy Rights
8.1 Rights Available to All Customers
Subject to applicable law, you have the right to:
- Right of Access — Request a copy of the personal information we hold about you, and information about how it is used.
- Right of Rectification — Request that inaccurate or incomplete personal information be corrected.
- Right of Erasure — Request deletion of your personal information, subject to legal retention obligations.
- Right to Withdraw Consent — Withdraw consent for marketing communications at any time (via unsubscribe links or by contacting us).
8.2 Additional Rights for Quebec Residents (Law 25)
If you are a resident of Quebec, you have the following additional rights under Law 25:
- Right to Data Portability — Request your personal information in a structured, machine-readable format (e.g., CSV or JSON), and request that it be transferred directly to another organization. We will respond to portability requests within 30 days.
- Right to De-indexation — Request that we cease disseminating or de-index any link associated with your name that contains personal information about you, where dissemination causes you harm.
- Right to Object to Automated Decision-Making — Where we use automated processing to make decisions that significantly affect you, you have the right to request human review and to contest the outcome.
- Right to File a Complaint — File a complaint with the Commission d’accès à l’information (CAI) at cai.gouv.qc.ca if you believe your privacy rights have been violated.
8.3 How to Submit a Request
To exercise any of the above rights, please contact our Privacy Officer:
Email: privacy@pilotcoffeeroasters.com
Mail: Privacy Officer, Pilot Coffee Corp., 50 Wagstaff Drive, Toronto, Ontario
We will acknowledge your request within 5 business days and respond within 30 days. In complex cases, we may extend this period by up to 30 additional days, with notice to you. We may need to verify your identity before processing your request.
9. How Long We Keep Your Information
We retain personal information only as long as necessary for the purposes for which it was collected and to comply with legal obligations. Our general retention guidelines are:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account & Contact Information | Duration of account + 2 years after last activity | Customer service, legal compliance |
| Order & Transaction Records | 7 years from transaction date | Financial records, tax compliance |
| Loyalty Program Data | Duration of membership + 1 year after inactivity | Loyalty administration |
| Marketing Preferences | Until you withdraw consent or unsubscribe | Honouring opt-in/opt-out choices |
| Behavioural / Cookie Data | Up to 13 months or as set in cookie consent tool | Analytics and advertising measurement |
When personal information is no longer required, we securely destroy it or anonymize it so that it can no longer be associated with you.
10. How We Protect Your Information
We implement technical and organizational security measures appropriate to the sensitivity of the personal information we hold. These measures include:
- SSL/TLS encryption for all data transmitted between your browser and our website;
- PCI DSS-compliant payment processing through Shopify and Square (neither of whom share raw card data with Pilot);
- Access controls limiting personal information to employees and contractors with a legitimate business need;
- Data Processing Agreements (DPAs) with all third-party service providers; and
- Ongoing monitoring for unauthorized access or security incidents.
No system is completely secure. In the event of a privacy or security incident that poses a risk of serious injury to your interests, we will notify the Commission d’accès à l’information (for Quebec residents) and affected individuals as required by Law 25, and take all reasonable steps to mitigate harm.
11. Children’s Privacy
Our services are not directed at individuals under the age of 14. We do not knowingly collect personal information from children under 14 without obtaining consent from a parent or legal guardian, as required by Law 25. If we discover that we have inadvertently collected information from a child under 14 without appropriate consent, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make material changes, we will:
- Update the “Last Reviewed” date at the top of this Policy;
- Post a notice on our website; and
- Where required by law or where changes are significant, notify you by email.
We encourage you to review this Policy periodically. Continued use of our services after changes take effect constitutes your acceptance of the updated Policy, to the extent permitted by law.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact our Privacy Officer:
Rita Mistry, Head of People, Culture & Diversity
Email: privacy@pilotcoffeeroasters.com
Mail: Pilot Coffee Corp., 50 Wagstaff Drive, Toronto, Ontario
Phone: 416 546 4006
Quebec residents who are unsatisfied with our response may lodge a complaint with the Commission d’accès à l’information (CAI):
Website: www.cai.gouv.qc.ca
Phone: 1 888 528-7741

