{"id":124842,"date":"2022-06-16T21:56:42","date_gmt":"2022-06-17T01:56:42","guid":{"rendered":"https:\/\/rbach.net\/?p=124842"},"modified":"2022-06-16T21:57:09","modified_gmt":"2022-06-17T01:57:09","slug":"tim-hortons-caught-collecting-private-data","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/tim-hortons-caught-collecting-private-data\/","title":{"rendered":"Tim Horton&#8217;s Caught Collecting Private Data"},"content":{"rendered":"\r\n<p><a href=\"https:\/\/www.macleans.ca\/economy\/business\/the-tim-hortons-brand-is-badly-broken-heres-how-to-fix-it\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-124846\" title=\"Tim Horton's Caught Collecting Private Data\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/spilling_tims.jpg?resize=129%2C71&#038;ssl=1\" alt=\"Tim Horton's Caught Collecting Private Data\" width=\"129\" height=\"71\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/spilling_tims.jpg?resize=150%2C82&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/spilling_tims.jpg?resize=75%2C41&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/spilling_tims.jpg?resize=768%2C422&amp;ssl=1 768w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/spilling_tims.jpg?w=810&amp;ssl=1 810w\" sizes=\"auto, (max-width: 129px) 100vw, 129px\" \/><\/a>The mobile app from coffee shop <strong><a href=\"https:\/\/www.timhortons.com\" target=\"_blank\" rel=\"nofollow noopener\">Tim Horton&#8217;s<\/a> <\/strong>has been collecting vast amounts of users <strong>private dat<\/strong>a without consent. The Canadian federal privacy commission <a href=\"https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/investigations\/investigations-into-businesses\/2022\/pipeda-2022-001\/#fn1\" target=\"_blank\" rel=\"nofollow noopener\">investigation<\/a> began two years ago after the <a href=\"https:\/\/financialpost.com\/\" target=\"_blank\" rel=\"nofollow noopener\"><em>Financial Post<\/em><\/a> <a href=\"https:\/\/financialpost.com\/technology\/tim-hortons-app-tracking-customers-intimate-data\" target=\"_blank\" rel=\"nofollow noopener\">reported<\/a> on Tim\u2019s contract with <a href=\"https:\/\/radar.com\/\" target=\"_blank\" rel=\"nofollow noopener\"><strong>Radar Labs<\/strong><\/a><strong> Inc. <\/strong>Radar Labs is a third-party U.S. firm that provided enhanced <a href=\"https:\/\/www.bobology.com\/public\/What-is-Location-Tracking.cfm\" target=\"_blank\" rel=\"nofollow noopener\">location tracking services<\/a> for the app.<\/p>\r\n<h3>What Private Data Did Tim Horton&#8217;s Collect?<\/h3>\r\n<p><a href=\"https:\/\/www.trulioo.com\/blog\/geolocation-identity-verification\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-124862\" title=\"Tim Horton's app collected users' geolocation without their knowledge.\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/TimsTracking.jpg?resize=77%2C80&#038;ssl=1\" alt=\"Tim Horton's app collected users' geolocation without their knowledge.\" width=\"77\" height=\"80\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/TimsTracking.jpg?resize=145%2C150&amp;ssl=1 145w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/TimsTracking.jpg?resize=73%2C75&amp;ssl=1 73w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/TimsTracking.jpg?w=274&amp;ssl=1 274w\" sizes=\"auto, (max-width: 77px) 100vw, 77px\" \/><\/a>Between May 2019 and August 2020 the Tim Horton&#8217;s app, which has four million users, <strong>collected users&#8217; <a href=\"https:\/\/www.investopedia.com\/terms\/g\/geolocation.asp\" target=\"_blank\" rel=\"nofollow noopener\">geolocation<\/a> without their knowledge. <\/strong>The app collected personal data from users even when the apps was not being used. People who downloaded the Tim Horton&#8217;s app had their movements tracked and recorded every few minutes of every day, even when their app was not open.<\/p>\r\n<p>Radar was able to use the information it collected in the app to identify personal location data. The app could identify a <strong>user\u2019s home, place of work<\/strong> and when they visited a competitor of Tim Horton&#8217;s. <a href=\"https:\/\/bobsullivan.net\/cybercrime\/tim-hortons-tracked-when-customers-went-to-starbucks-and-much-more-lessons-for-u-s-privacy-law\/\" target=\"_blank\" rel=\"nofollow noopener\">Reports<\/a> are the app noted when users entered a Starbucks, Second Cup, McDonald\u2019s, Pizza Pizza, A&amp;W, KFC or Subway. The Tim Horton&#8217;s app was even able to figure out if users had been traveling. The app generated an \u201cevent\u201d every time users entered or left a Tim Horton\u2019s competitor, a major sports venue, or their home or workplace. <a href=\"https:\/\/www.priv.gc.ca\/en\/\" target=\"_blank\" rel=\"nofollow noopener\">Canadian Privacy Commissioner<\/a> Daniel Therrien said in a statement<\/p>\r\n<p style=\"padding-left: 40px;\"><em>Tim Horton&#8217;s clearly crossed the line by amassing a huge amount of highly sensitive information about its customers<\/em><\/p>\r\n<h3>What Happened to Tim&#8217;s?<\/h3>\r\n<p><a href=\"https:\/\/www.rxbenefits.com\/blogs\/what-you-need-to-know-about-the-drug-pricing-blame-game\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-124864\" title=\"delete the granular data it collected, and any further data derived from it\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ficklefingrtfate.png?resize=80%2C80&#038;ssl=1\" alt=\"delete the granular data it collected, and any further data derived from it\" width=\"80\" height=\"80\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ficklefingrtfate.png?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ficklefingrtfate.png?resize=75%2C75&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ficklefingrtfate.png?resize=768%2C768&amp;ssl=1 768w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ficklefingrtfate.png?w=800&amp;ssl=1 800w\" sizes=\"auto, (max-width: 80px) 100vw, 80px\" \/><\/a>According to the report, Tim Horton&#8217;s collected granular location data for the purpose of targeted advertising and product promotions. Even though <strong>Tim&#8217;s never used the information for those purposes<\/strong>. The investigation also found that there were inadequate contractual protections for users&#8217; personal data. Commissioner Therrien commented,<\/p>\r\n<p style=\"padding-left: 40px;\"><em>T<\/em><em>he location tracking ecosystem, where details of our daily lives are treated as a commodity to be exploited to sell us products and services such as a cup of coffee, heightens the risk of mass surveillance<\/em><\/p>\r\n<p>Based on its findings, the OPC ordered Tim Horton\u2019s to delete the granular data it collected, and any further data derived from it and to order all third-party providers to do the same. Tim Horton&#8217;s has since complied. Additionally, the company agreed to create a privacy management program for the app and all future apps to prevent another privacy violation. The Office of the Privacy Commissioner <a href=\"https:\/\/arstechnica.com\/tech-policy\/2022\/06\/tim-hortons-coffee-app-broke-law-by-constantly-recording-users-movements\/\" target=\"_blank\" rel=\"nofollow noopener\">noted<\/a>, there &#8220;<em>is a real risk that de-identified geolocation data could be re-identified.<\/em>&#8220;<\/p>\r\n<p>Tim Horton&#8217;s has more than 5,100 stores in 13 countries. Most are in Canada, but there are more than 600 in the US, mostly in New York, Michigan, and Ohio.<br \/><br \/><strong><em>rb-<\/em><\/strong><\/p>\r\n<p><em>Tim Horton&#8217;s was caught collecting illegitimate data via its app. It is a safe bet that many more apps are doing much the same with dubious consent. It is essential to always read through a user agreement before consenting. Both Apple and Android offer options on their phones to restrict how their apps track them. A step in the right direction.<\/em><\/p>\r\n<p style=\"text-align: center;\"><em><strong><a href=\"https:\/\/www.obama.org\/updates\/help-ukraine\/\" target=\"_blank\" rel=\"nofollow noopener\">How you can help Ukraine!<\/a><\/strong><\/em><\/p>\r\n<p><strong>Related article<\/strong><\/p>\r\n<ul>\r\n<li><a title=\"All Those How Secure Are Food Delivery Apps? Which Apps Are Safe?Pushing Crypto Are Not So Vocal Now\" href=\"https:\/\/vpnoverview.com\/privacy\/apps\/food-delivery-apps\/\" target=\"_blank\" rel=\"nofollow noopener\">How Secure Are Food Delivery Apps? Which Apps Are Safe?<\/a>\u00a0(<a title=\"VPN Overview\" href=\"https:\/\/vpnoverview.com\/\" target=\"_blank\" rel=\"nofollow noopener\">VPN Overview<\/a>)<\/li>\r\n<\/ul>\r\n<p>&nbsp;<\/p>\r\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a>\u00a0about IT, careers, and anything else that catches his attention since 2005. You can follow him on\u00a0<a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>Coffee shop Tim Horton&#8217;s app has been gathering users private data without their OK like their home &#038; work addresses and when they visited a Tim&#8217;s competitor<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3627,1693,431,951,185,3306],"class_list":["post-124842","post","type-post","status-publish","format-standard","hentry","category-security","tag-3627","tag-coffee","tag-mobile","tag-pii","tag-privacy","tag-tim-hortons"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/124842","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=124842"}],"version-history":[{"count":15,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/124842\/revisions"}],"predecessor-version":[{"id":124871,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/124842\/revisions\/124871"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=124842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=124842"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=124842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}