Privacy
policy.
Discretion is the product. This policy sets out exactly what we hold about you, how long we keep it, and what you can make us do with it.
In effect August 15, 2026
Written to Québec's Act respecting the protection of personal information in the private sector, as amended by Law 25, and to the federal Personal Information Protection and Electronic Documents Act.
Who this covers
Tenebrex Hospitality Inc. — “Tenebrex”, “we” — is a private concierge registered in Québec, Canada. This policy applies to tenebrex.com, to the member area behind it, and to your correspondence with the concierge desk.
It does not govern what a hotel, carrier, restaurant or operator does with your information once we have introduced you to them. Once you are their guest, their own policy applies. See “Partners and providers” below.
Our privacy officer
Law 25 requires us to designate a person responsible for the protection of personal information, and to tell you how to reach them. Write to support@tenebrex.com.
That address is the route for every request described in “Your rights”. We answer within 30 days, which is the deadline the law sets us.
What we collect
Only what a concierge needs to do the work, and only what you give us:
- Account
- Your name, email address, and a password. Passwords are stored solely as a cryptographic hash by our authentication provider — nobody at Tenebrex can read yours, and we cannot recover it for you.
- Profile
- What you choose to add: phone number, province, preferred language, and the preferences that let a concierge act without asking twice — dietary requirements, accessibility needs, seating, and travel preferences.
- Requests and itineraries
- The content of your requests, the itineraries assembled from them, and the messages exchanged with your concierge.
- Membership
- Your member number, tier, eligible spend, and the points ledger behind your rewards balance.
- Technical
- IP address, browser and device type, and the pages requested. Used to keep the service running and to investigate abuse — not to build a profile of you.
Sensitive information
Some of what makes a concierge useful is sensitive by nature. A dietary requirement can disclose a health condition or a religious practice; an accessibility need discloses more still.
We collect it only because you volunteered it for a particular purpose, we pass a provider the minimum required to honour it and nothing else, and you can remove it from your profile at any time.
Why we collect it
Each purpose, and nothing beyond it:
- To run your membership
- Creating and authenticating your account, maintaining your tier, and showing you your itineraries and rewards.
- To arrange what you ask for
- Approaching providers on your behalf and passing them what a booking requires.
- To reach you
- Confirmations, itinerary changes, email verification and password resets. These are operational messages; you cannot unsubscribe from them while your account is open.
- To keep the service secure
- Detecting fraudulent sign-ins and abuse, and protecting other members.
- To meet legal obligations
- Tax and accounting records, and responding to a lawful order.
Consent, and taking it back
We collect personal information with your consent, given when you open an account, complete your profile, or make a request. Consent to anything sensitive is asked for separately and in plain terms.
You may withdraw consent at any time. Be aware of the consequence: if you withdraw it for information a confirmed booking depends on, we may be unable to complete that booking, and a provider's cancellation terms may still apply.
Partners and providers
To arrange anything we must tell a provider enough to deliver it — typically your name, the dates, and any requirement relevant to that service. We do not send them your full profile, your other bookings, or your rewards balance.
We also rely on a small number of suppliers to run the service itself: our database, authentication and file storage provider; our website hosting and content delivery network; and our email delivery provider. Each is bound by contract to process personal information only on our instructions.
We do not sell personal information. We do not trade it, rent it, or disclose it for anyone else's marketing.
Where it is stored
Member data — your account, profile, itineraries, messages and rewards — is held in a database hosted in Canada, in the Montréal region.
Some suppliers operate globally, so limited technical data such as server logs and content-delivery routing may be handled outside Québec, including in the United States. Before entrusting personal information outside the province we assess whether it will receive protection equivalent to what Québec law requires, as Law 25 obliges us to.
How long we keep it
Personal information is destroyed or anonymised once the purpose it was collected for is fulfilled:
- Account and profile
- While your membership is open, and for 24 months after it closes, so that a returning member is recognised and so we can answer a dispute.
- Bookings and financial records
- Seven years, which is the retention period Canadian tax law imposes on us.
- Concierge messages
- 24 months from the close of the request.
- Server logs
- 12 months.
Your rights
Write to support@tenebrex.com to exercise any of these:
- Access
- Obtain a copy of the personal information we hold about you, and be told who it has been disclosed to.
- Correction
- Have anything inaccurate, incomplete or ambiguous put right.
- Deletion
- Have your information deleted where we have no continuing legal reason to hold it.
- Portability
- Receive the information you gave us in a structured, commonly used technological format.
- Withdrawal
- Take back consent, subject to the caveat set out above.
- Complaint
- If our answer does not satisfy you, take it to the Commission d'accès à l'information du Québec, or to the Office of the Privacy Commissioner of Canada.
Cookies
This site sets two kinds of cookie, both strictly necessary:
A session cookie pair from our authentication provider, which is what keeps you signed in to the member area; and a language cookie, tnbx_lang, which remembers whether you chose English or French so you are not re-routed on every visit.
There is no advertising cookie, no analytics package, no third-party tracker and no cross-site pixel anywhere on this site. That is why you are not being asked to dismiss a consent banner — there is nothing to consent to.
Automated decisions
Your tier follows arithmetically from eligible spend. That is a calculation, not a judgement about you, and you can see the thresholds it uses on the membership page.
We do not make decisions producing legal or similarly significant effects about you by automated means alone.
Security
Information is encrypted in transit and at rest. Access to the database is governed by row-level rules, so one member's session cannot read another member's data. Passwords are hashed, never stored in a readable form.
No system is perfect. Should a confidentiality incident occur that presents a risk of serious injury, we will notify the members affected and the Commission d'accès à l'information with diligence, and record it in the register the law requires us to keep.
Minors
Tenebrex membership is for adults. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us information, write to support@tenebrex.com and we will remove it.
Changes
We revise this policy as the service changes. The date at the top always reflects the current version, and we will email members before a material change takes effect rather than relying on you to notice.
Ask, and we will answer.
Any question about this policy, or any request concerning your information, goes to our privacy officer.