Canadian Salary Index The Peak

Privacy policy

Last updated: July 20, 2026 · Effective: July 20, 2026

1. Who we are and who is accountable

The Canadian Salary Index is operated by the Business News Company of Toronto Inc. (DBA The Peak) ("we", "us"), 68 Claremont Ave., Toronto, ON.

We have designated a Privacy Officer who is accountable for our compliance with this policy and with Canadian privacy law: Brett Chang ([email protected])

You can contact them with any question, access request, correction request, or complaint. We respond to access requests within 30 days.

2. The two kinds of information we hold

This is the most important section of this policy. Please read it before submitting.

2a. Salary submissions (anonymous by default)

When you submit compensation information, we collect only what you enter: job title or role, employer, industry, province and city, work arrangement, years of experience and years at your employer, your compensation figures, and optional details (vacation days, pension match, education, union membership, gender, age band).

We do not ask for your name, and we do not ask for your email on this form. By default, a submission is stored with no connection to any email address or account. There is no shared identifier, key, or join path between our salary records and our email records. We cannot look up your salary, and neither can anyone who compels or breaches us.

To make this hold in practice:

  • The time we received your submission is deliberately randomised by up to ±72 hours before it is stored, so a submission cannot be matched to a sign-in or any other event by timing.
  • Site analytics never record a submission, an account, or an email address.
  • The only handle on an anonymous submission is a one-time removal code shown to you once when you submit. We never email it, because emailing it would create exactly the connection this design exists to prevent.

The consequence you should understand: if you lose that removal code, your entry cannot be found again — including by us. We cannot retrieve it, correct it, or delete it on your behalf, because we have no way to tell which entry is yours.

2b. Salary submissions if you choose to connect to your account

If you have verified an email address, you may explicitly choose to connect a submission to your account so that you can correct or delete it yourself. This is off by default and never happens unless you tick the box.

If you connect an entry, the protection described in 2a no longer applies to that entry. We can see that the entry is yours. So could anyone who lawfully compels us to disclose it, and so could an attacker who obtained our database. We record only the fact that you consented, the time you consented, and the index year — never anything more.

You can disconnect a connected entry at any time. Disconnecting permanently returns it to being anonymous: the connection record is deleted, the entry itself is not modified, and it becomes indistinguishable from an entry that was never connected. Because of that, disconnecting cannot be undone — afterwards we can no longer identify the entry as yours.

Connecting is not required to contribute, and it is not required to see the results.

2c. Your email address and profile

Separately from any salary data, we collect your email address to verify that you are a real person rather than an automated scraper, and to give you access to the dataset from any device. We use a one-time sign-in link; we do not store a password.

Optionally, you may tell us your industry and job function. This is a coarse professional profile — it never includes a compensation figure.

2d. Website analytics

We record first-party usage events (for example: a page was viewed, a form step was completed) against a random per-visit identifier stored in a cookie. These records contain no email address, no account identifier, and no submission identifier, and cannot be linked to a salary entry or a person. We do not use third-party advertising. We use cookies to keep you logged in after you sign in with a magic link.

3. Why we collect it (purposes)

What Why
Salary submission fields To build and publish aggregate compensation statistics for Canada
Email address To verify you are a real person; to give you access to the dataset; to notify you when results publish
Industry / function profile To send you relevant content, if you consent to marketing
Connection between an entry and your account Only so you can correct, delete, or disconnect your own entry
Usage analytics To understand and improve how the site performs
Anti-bot check, rate limiting, security logs To protect the dataset from automated abuse

We do not sell personal information collected on this website or share your information with third-parties. We share aggregated and anonymized data with third-parties, including other users of the website.

We rely on your express consent, obtained at the point of collection:

  • Submitting a salary is itself your consent to include it in the published aggregate statistics.
  • Connecting an entry to your account requires a separate, explicit, unticked opt-in.
  • Marketing email requires a separate opt-in, which you may withdraw at any time using the unsubscribe link in any message or by contacting our Privacy Officer.

You may withdraw consent at any time, subject to legal and contractual limits. For an anonymous entry, the removal code is the mechanism. For a connected entry, disconnecting or deleting it in your account is the mechanism. Withdrawing consent to marketing does not remove your submission, and removing your submission does not cancel your newsletter subscription — they are separate.

5. What we publish, and how we protect you in the published data

Everything published is aggregated or generalised. Regardless of whether you connected your entry:

  • Statistics are suppressed entirely for any group with fewer than 5 submissions.
  • Compensation figures shown per row are rounded to the nearest $1,000.
  • Years of experience are shown as a band, never an exact number.
  • Dates are shown to the month only.
  • Your city and your employer are hidden until at least 10 similar entries exist, unless you have chosen to waive that protection.
  • We never publish your name, email address, exact submission date, or free-text answers that we have identified as identifying without your explicit consent.

We do not publish, and will not publish, which entries are connected to an account.

6. Who we share it with

We do not sell or rent personal information. We share it only with service providers who process it on our behalf under contract, and only the minimum each needs, including our website host and email service provider.

We may also disclose personal information where required by law, such as in response to a valid court order, warrant, or other lawful demand.

Storage outside Canada

Our hosting and service providers may store and process data in the United States. While it is there, it is subject to the laws of that jurisdiction, and may be accessible to U.S. courts, law enforcement, and national security authorities under those laws. By using the service, you acknowledge this transfer.

7. How long we keep it

What Retention
Anonymous salary submissions Indefinitely
Connected submissions Until you delete them, or after account closure
Email address and profile Until you ask us to delete it
Connection records Until you disconnect, delete the entry, or delete your account
Usage analytics Indefinitely
Breach records As required by law

When you delete your email account, any connections to salary entries are deleted with it. The salary entries themselves survive as anonymous records with nothing pointing back to you, because they form part of a published statistical dataset.

8. Your rights

You may:

  • Access the personal information we hold about you, and be told how it is used and to whom it has been disclosed;
  • Correct it if it is inaccurate or incomplete;
  • Withdraw consent, including disconnecting an entry or unsubscribing from marketing;
  • Delete your account, a connected entry, or (with your removal code) an anonymous entry;
  • Complain — see section 11.

For an anonymous submission we cannot verify that a given entry is yours, and we will not guess. We will not accept a description of a submission's contents as proof of ownership, because doing so would let anyone probe the private dataset by guessing at a colleague's pay. If you hold the removal code, you can delete that entry; if you do not, we cannot act on it. We consider a submission with no connection to any individual to fall outside the scope of an access request, since it is not information about an identifiable individual.

9. How we protect it

We use safeguards appropriate to the sensitivity of compensation information, including encryption in transit, encryption at rest for credentials, one-time sign-in links instead of stored passwords, rate limiting, automated bot protection, and filtering of salary figures, email addresses, and tokens out of our application logs. Access to production data is limited to staff who need it.

No system is perfectly secure, and we do not claim otherwise.

10. If there is a breach

If a breach of our security safeguards creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and notify you as soon as feasible, describing what happened, what information was involved, and what you can do. We keep records of all security breaches for 24 months, whether or not notification is required.

11. Questions and complaints

Contact our Privacy Officer first (section 1). If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376), or to your provincial regulator — including the Commission d'accès à l'information du Québec for Quebec residents.

12. Changes

We will post any change here and update the date above. If a change materially affects how we use information you have already given us, we will seek your consent again rather than apply it retroactively — including, specifically, that we will never connect an existing anonymous submission to an account.