The encyclopedia · Advertising & PR · Marketing decision · 2022
Tim Hortons' app tracked users' every move — privacy findings, class actions
A loyalty app logged users' locations even when closed, for ads it never ran. Two privacy watchdogs found a breach; the data was deleted.
Tim Hortons Inc. · 2022-06
What happened
Tim Hortons' mobile loyalty app asked users for permission to use their location, telling them the data would help target promotions. Instead, the app used a third-party provider, Radar, to record users' movements every few minutes of every day — even when the app was closed and even after a user turned location off. It inferred where users lived and worked and logged every time they entered a competitor, a sports venue or their home.
The company had shelved its plans for targeted advertising but kept collecting the data for about a year afterwards, with no legitimate need. Reporting by the Financial Post first exposed the tracking, and a joint investigation by the federal privacy commissioner with authorities in British Columbia, Quebec and Alberta concluded in June 2022 that the collection violated Canadian privacy law — a 'loss of Users' privacy that was not proportional to the potential benefits' Tim Hortons hoped to gain.
The commissioners found the contract with Radar was so vague that the provider could have sold 'de-identified' location data, which carries a re-identification risk. Tim Hortons agreed to delete all remaining location data, require its providers to do the same, and build a proper privacy management program. Its parent, Restaurant Brands International, also faced nationwide class-action lawsuits over the tracking.
Why it happened
- The app collected far more data than the stated purpose required, and the permission screen misled users about how it would be used
- Tim Hortons kept gathering location data for a year after cancelling the advertising plans it was meant to serve
- The deal with Radar was so vague it could have allowed the data to be sold on, undermining the privacy promise
- The company had no robust privacy management program, so the excess went unnoticed until a journalist exposed it
The lesson
Asking for permission and using data for something else are a breach even when the ads never run. Collecting more than you need is not a hedge — it is the violation.
Aftermath
Tim Hortons deleted the location data and overhauled how its app and future apps handle personal information. The privacy commissioner's June 2022 report made the case a Canadian privacy-lore example of background location tracking. Class-action litigation over the tracking continued after the report, though the federal commissioner had no power to fine under the law at the time.
Sources
- CBC News: Tim Hortons app breached privacy law, watches find
- Office of the Privacy Commissioner of Canada: News release, June 1 2022
spotted an error? The club wants to know.
More like this
RBI squeezed Tim Hortons franchisees — workers lost benefits, the brand took the blame
Tim Hortons tried the US for 40 years — brand awareness was 25 out of 100
A kids' nursery-rhyme app served a splash ad about sharing a mistress schedule
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.