Privacy
Last updated: September 2026
1. How this policy fits with our main privacy policy
app.modelpie.ca (the "Portal") is operated by Brighton Shores Summer Estates Ltd., operating as Timber House Resort, using the ModelPie software platform.
Our main privacy policy — the Privacy Policy of Brighton Shores Summer Estates Ltd., published at timberhouse.net/policies/privacy-policy and posted at the resort office — explains why we collect personal information from occupants, guests, partners, contractors and the public, how long we keep it, how you can see and correct it, and how to complain. That policy applies to the Portal. This policy supplements it with the details that are specific to running a web application: exactly what data the Portal holds, which cloud services process it, how it is secured, and how you manage consents and connected accounts. Where the two overlap, this policy is more specific and governs the Portal.
Both policies are made under the Personal Information Protection and Electronic Documents Act (PIPEDA).
2. Who we are and who can see what
We are a small, owner-operated Ontario business. The Portal is private: there is no public sign-up, and accounts are created by us during onboarding.
The Portal is built to serve more than one property. Each property's data — sites, occupants, partners, contracts, notices, tickets and billing — is isolated using database row-level security, so people connected to one property cannot see another property's data. At present the only property publicly served through the Portal is Timber House Resort. If other properties or operating entities are added, this section will name them and the entity responsible for each.
Within a property, what you can see depends on your role:
RoleCan see
Customer (site or trailer owner, occupant)Own profile, own contracts and notices, own billing explainer, own fractional sharing group
Event partner / data-room partnerOwn agreements; data-room content after accepting the NDA
Property Manager / AdministratorAll records for the properties they manage
InternRead-only view for the educational program; no ability to change records
3. Personal information the Portal holds
Account and sign-in. Email address (your identifier), a hashed password (we cannot read it), Google sign-in tokens if you use Google, your role, and session tokens.
Onboarding. Before your account exists, if you express interest through our onboarding flow: name, email address, what you are interested in (seasonal site, purchase, visitor, event partnership), and which onboarding stage you have reached.
Profile. Legal name, email, phone, whether you are an individual or an organization, and which property you belong to. For seasonal and residential occupants: mailing address; a secondary contact (for example a spouse or partner) with name, email and phone; an emergency contact with name, phone and relationship; trailer or park-model insurer name and policy number (we do not store policy documents); and your consent selections (Section 5).
Contracts and notices. Contract type, dates, rent or licence fee, security deposit, the parties, secondary occupants, generated PDF files and their status, and notices issued to you.
Fractional sharing. If you share your trailer with others during the season, the Portal records the sharing group you set up: who is in it, the periods each member uses the site, and the resulting allocation of charges. You control who is in your group. Group members can see the group's schedule and their own allocation, not each other's personal contact details beyond what you share with them.
Utility billing. Which site you occupied and when, the service type, your pro-rated share of hydro, water-testing and administrative charges, and the totals we reconcile against our accounting system. The Portal holds aggregate reconciliation totals from QuickBooks, not individual bank or payment transactions.
Events and tickets. Attendee name, email address, ticket code, QR code, event, and purchase amount. Square payment processing is currently in test mode; purchase records in the Portal are test data. [Remove the italic sentence when Square goes live.] Card details are never held by the Portal (Section 6).
Data room. Your NDA acceptance (who, when), a log of which data-room pages you visited and when, and scenario calculations you save.
Property map. The public property map shows each lot's occupancy status (occupied, available, and similar). It does not show occupant names or any other personal information.
Technical. The Portal's hosting provider records standard server logs (IP address, browser, pages requested, timestamps) to run and secure the service.
4. How the Portal collects information
-
From us, when we create your account and enter your site, contract and billing details from the documents you have signed with us.
-
From you, when you complete onboarding, fill in or update your profile, accept an NDA, or save a scenario.
-
Automatically, when the Portal calculates billing allocations from the records above.
-
From timberhouse.net, when you buy an event ticket on our Shopify store: Shopify sends the order (attendee name, email, items) to the Portal so it can issue your ticket.
-
From Square, when you buy a ticket directly through the Portal: Square tells the Portal the payment succeeded and the amount, but not your card details.
-
From Google, if you sign in with Google: your email address and name from your Google profile.
5. Consent and how to manage it
When you complete your profile, the Portal asks for two required consents — to receive email communication about your site and the resort, and to our collection of the personal information described here — and offers optional acknowledgments confirming you have read the Property Rules and the hydro, property-tax, monthly-rent, right-of-first-refusal and water-testing explainers. Required consents are necessary for us to manage your site or agreement and keep you informed; if you do not give them, we cannot set up your Portal account, though your signed agreement with us still stands. Optional acknowledgments do not change your agreement; they record that you read the document.
You can review and change your selections in your profile at any time. Withdrawing a required consent means we will manage your relationship with us outside the Portal, using the methods in your agreement.
Data-room access requires its own explicit authorization (Section 8).
6. Third-party services that process Portal data
We use these providers to run the Portal. Each has access only to what it needs, is bound by its own privacy commitments, and processes data on our instructions.
ProviderWhat it does for the PortalWhat it receives
Supabase(supabase.com)Database, authentication, file storageAll Portal data described in Section 3, sign-in credentials (passwords hashed), generated PDFs
Vercel(vercel.com)Hosts and runs the applicationServer logs and request metadata
Make.com(make.com)Generates contract PDFs and sends the Portal's email through our Gmail accountContract details, the names and email addresses of the parties, and the content of each email it sends
Google Workspace (Gmail) via Make.comSends the Portal's transactional email — onboarding, verification, notices, contract delivery and ticket confirmations — from our Timber House Resort Gmail account through a Make.com connectorRecipient email address and the content of the message; sent messages are retained in our mailbox like any other business email
Square(squareup.com)Processes ticket payments made in the PortalCard details (entered on Square, never stored by us), amount, attendee name and email. Currently test mode; no live payment data.[Remove italic when live.]
Shopify(shopify.com)Sends ticket orders placed on timberhouse.net to the PortalOrder line items and attendee names/emails (Shopify's own policy governs the store)
Google(google.com)Optional sign-in providerEmail and name from your Google profile
QuickBooks Online (Intuit)Accounting reconciliationAggregate billing totals only; no individual profiles
MapLibre / ArcGISDraws the property mapMap tiles only; no personal data
Most of these providers store data in the United States, and the Portal's database is hosted by Supabase on cloud infrastructure that may be located outside Canada. Personal information stored outside Canada is subject to the laws of that country and may be accessible to its authorities. We choose providers with strong security practices and contractual privacy commitments, but we cannot remove that possibility.
We do not sell personal information, and we do not share Portal data with anyone for advertising.
7. Cookies and local storage
The Portal sets a session cookie containing an authentication token so you stay logged in. It sets no advertising, analytics or tracking cookies. Your browser may store small amounts of data locally for the Portal to work (for example your preferred map view). Clearing cookies logs you out.
8. Data room
If you are invited to the partner data room, you must accept a non-disclosure agreement in the Portal before you can view it. We record your acceptance, and we keep an audit log of the data-room pages you visit and when, so we can meet our obligations to other stakeholders. Scenario calculations you save are stored with your account.
9. Where data is stored and how it is protected
-
Application data is stored in Supabase's managed PostgreSQL database and file storage; the application runs on Vercel.
-
All connections to the Portal use HTTPS. Data is encrypted in transit and at rest.
-
Sign-in uses email/password (passwords hashed, never stored in plain text) or Google sign-in. Sessions use short-lived signed tokens.
-
Row-level security policies in the database enforce that each user can read only the records their role and property allow, even if the application has a bug.
-
Administrative access is limited to a small number of named staff.
-
Generated documents are stored in access-controlled storage and served only to the parties to the document.
We are a small operator and do not claim perfect security. If we become aware of a breach of security safeguards that creates a real risk of significant harm to you, we will notify you and report to the Privacy Commissioner of Canada as PIPEDA requires.
10. How long we keep Portal data
Retention follows our main privacy policy. In short:
-
Account and profile data — for as long as your account is active, then for the retention period that applies to your occupancy or partnership records (at least five years after your relationship with the property ends).
-
Contracts, notices and billing explainers — at least five years; financial records for the period the Canada Revenue Agency requires.
-
Onboarding leads that never become accounts — approximately twelve months.
-
Ticket records — with our accounting records for the events.
-
Server logs — as retained by our hosting provider, typically a matter of weeks.
-
Data-room audit logs — for the life of the NDA and the period it specifies afterward.
11. Seeing, correcting and exporting your information
You can view and update your profile, contacts, insurance details and consents in the Portal at any time, and view your contracts, notices, and billing explainers. For anything you cannot change yourself, or to request a copy of all the personal information the Portal holds about you, contact the Information Officer (Section 14). The access and correction process, the 30-day response time, and the exceptions are set out in the main privacy policy.
12. Children
The Portal is not intended for anyone under 18. Occupancy agreements and event partnerships are available only to adults. If we learn we have collected personal information from a minor without a parent's or guardian's consent, we will delete it.
13. Changes to this policy
We may update this policy as the Portal changes — for example when Square live payments are activated or when another property is added. The date at the top shows the latest revision. For material changes we will notify you by email or in the Portal.
14. Questions and complaints
Information Officer: Jordan Johnston Brighton Shores Summer Estates Ltd. (Timber House Resort) 116 Cedardale Road, PO Box 903 Brighton, ON K0K 1H0 jjohnston@timberhouse.net
The Information Officer will try to answer your questions. Formal complaints should be made in writing; we will acknowledge them, investigate promptly, and give you a written decision with reasons.
If you are not satisfied, you may contact the Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec K1A 1H3, toll-free 1-800-282-1376, www.priv.gc.ca.
Questions about the open-source ModelPie software itself, as opposed to this Portal and your data in it, can be sent to info@modelpie.ca.