Back to the archive

The encyclopedia · Advertising & PR · Marketing decision · 2022

Tim Hortons' app tracked users' every move — privacy findings, class actions

A loyalty app logged users' locations even when closed, for ads it never ran. Two privacy watchdogs found a breach; the data was deleted.

Tim Hortons Inc. · 2022-06

What happened

Tim Hortons' mobile loyalty app asked users for permission to use their location, telling them the data would help target promotions. Instead, the app used a third-party provider, Radar, to record users' movements every few minutes of every day — even when the app was closed and even after a user turned location off. It inferred where users lived and worked and logged every time they entered a competitor, a sports venue or their home.

The company had shelved its plans for targeted advertising but kept collecting the data for about a year afterwards, with no legitimate need. Reporting by the Financial Post first exposed the tracking, and a joint investigation by the federal privacy commissioner with authorities in British Columbia, Quebec and Alberta concluded in June 2022 that the collection violated Canadian privacy law — a 'loss of Users' privacy that was not proportional to the potential benefits' Tim Hortons hoped to gain.

The commissioners found the contract with Radar was so vague that the provider could have sold 'de-identified' location data, which carries a re-identification risk. Tim Hortons agreed to delete all remaining location data, require its providers to do the same, and build a proper privacy management program. Its parent, Restaurant Brands International, also faced nationwide class-action lawsuits over the tracking.

Why it happened

  • The app collected far more data than the stated purpose required, and the permission screen misled users about how it would be used
  • Tim Hortons kept gathering location data for a year after cancelling the advertising plans it was meant to serve
  • The deal with Radar was so vague it could have allowed the data to be sold on, undermining the privacy promise
  • The company had no robust privacy management program, so the excess went unnoticed until a journalist exposed it
What it costPIPEDA-violation findings, forced deletion, class actionscostly

The lesson

Asking for permission and using data for something else are a breach even when the ads never run. Collecting more than you need is not a hedge — it is the violation.

Aftermath

Tim Hortons deleted the location data and overhauled how its app and future apps handle personal information. The privacy commissioner's June 2022 report made the case a Canadian privacy-lore example of background location tracking. Class-action litigation over the tracking continued after the report, though the federal commissioner had no power to fine under the law at the time.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →