{"id":19253,"date":"2022-06-04T10:45:23","date_gmt":"2022-06-04T18:45:23","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/06\/04\/news-12986\/"},"modified":"2022-06-04T10:45:23","modified_gmt":"2022-06-04T18:45:23","slug":"news-12986","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/06\/04\/news-12986\/","title":{"rendered":"Your Tim Hortons Coffee App Knew Where You Were at All Times"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/629a78308a06d69f5e44b3b0\/master\/pass\/timhorton_ars_GettyImages-903432692.jpg\"\/><\/p>\n<p><strong>Credit to Author: Jon Brodkin, Ars Technica| Date: Sat, 04 Jun 2022 12:00:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/jon-brodkin-ars-technica\">Jon Brodkin, Ars Technica<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">Canadian investigators determined<\/span> that users of the Tim Hortons coffee chain&#x27;s mobile app &quot;had their movements tracked and recorded every few minutes of every day,&quot; even when the app wasn&#x27;t open, in violation of the country&#x27;s privacy laws.<\/p>\n<p class=\"paywall\">This story originally appeared on <a data-offer-url=\"https:\/\/arstechnica.com\/tech-policy\/2022\/06\/tim-hortons-coffee-app-broke-law-by-constantly-recording-users-movements\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/arstechnica.com\/tech-policy\/2022\/06\/tim-hortons-coffee-app-broke-law-by-constantly-recording-users-movements\/&quot;}\" href=\"https:\/\/arstechnica.com\/tech-policy\/2022\/06\/tim-hortons-coffee-app-broke-law-by-constantly-recording-users-movements\/\" rel=\"nofollow noopener\" target=\"_blank\">Ars Technica<\/a>, a trusted source for technology news, tech policy analysis, reviews, and more. Ars is owned by WIRED&#x27;s parent company, Cond\u00e9 Nast.<\/p>\n<p class=\"paywall\">&quot;The Tim Hortons app asked for permission to access the mobile device&#x27;s geolocation functions but misled many users to believe information would only be accessed when the app was in use. In reality, the app tracked users as long as the device was on, continually collecting their location data,&quot; according to an <a data-offer-url=\"https:\/\/www.priv.gc.ca\/en\/opc-news\/news-and-announcements\/2022\/nr-c_220601\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.priv.gc.ca\/en\/opc-news\/news-and-announcements\/2022\/nr-c_220601\/&quot;}\" href=\"https:\/\/www.priv.gc.ca\/en\/opc-news\/news-and-announcements\/2022\/nr-c_220601\/\" rel=\"nofollow noopener\" target=\"_blank\">announcement Wednesday<\/a> by Canada&#x27;s Office of the Privacy Commissioner. The federal office collaborated with provincial authorities in Quebec, British Columbia, and Alberta in the investigation of Tim Hortons.<\/p>\n<p class=\"paywall\">&quot;The app also used location data to infer where users lived, where they worked, and whether they were traveling,&quot; the Office of the Privacy Commissioner said. &quot;It generated an &#x27;event&#x27; every time users entered or left a Tim Hortons competitor, a major sports venue, or their home or workplace.&quot;<\/p>\n<p class=\"paywall\">Tim Hortons scrapped plans to use the app for targeted advertising but &quot;continued to collect vast amounts of location data&quot; for another year &quot;even though it had no legitimate need to do so,&quot; the Office of the Privacy Commissioner said. Tim Hortons said it used aggregated location data &quot;to analyze user trends\u2014for example, whether users switched to other coffee chains and how users&#x27; movements changed as the pandemic took hold,&quot; the federal office said.<\/p>\n<p class=\"paywall\">\u201cTim Hortons clearly crossed the line by amassing a huge amount of highly sensitive information about its customers,\u201d Canada Privacy Commissioner Daniel Therrien said. \u201cFollowing people&#x27;s movements every few minutes of every day was clearly an inappropriate form of surveillance.&quot;<\/p>\n<p class=\"paywall\">Tim Hortons has <a data-offer-url=\"https:\/\/www.rbi.com\/English\/news\/news-details\/2022\/Tim-Hortons-Accelerating-Global-Growth-with-Plans-to-Launch-in-India-in-2022\/default.aspx\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.rbi.com\/English\/news\/news-details\/2022\/Tim-Hortons-Accelerating-Global-Growth-with-Plans-to-Launch-in-India-in-2022\/default.aspx&quot;}\" href=\"https:\/\/www.rbi.com\/English\/news\/news-details\/2022\/Tim-Hortons-Accelerating-Global-Growth-with-Plans-to-Launch-in-India-in-2022\/default.aspx\" rel=\"nofollow noopener\" target=\"_blank\">more than 5,100 stores<\/a> in 13 countries. Most are in Canada, but there are more than <a data-offer-url=\"https:\/\/locations.timhortons.com\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/locations.timhortons.com\/&quot;}\" href=\"https:\/\/locations.timhortons.com\/\" rel=\"nofollow noopener\" target=\"_blank\">600 in the US<\/a>, mostly in New York, Michigan, and Ohio.<\/p>\n<p class=\"paywall\">Tim Hortons halted the continual tracking of users&#x27; locations in 2020 after the government began investigating. But that &quot;did not eliminate the risk of surveillance&quot; because &quot;Tim Hortons&#x27; contract with an American third-party location services supplier contained language so vague and permissive that it would have allowed the company to sell &#x27;de-identified&#x27; location data for its own purposes,&quot;\u00a0the Office of the Privacy Commissioner said. As the office noted, there &quot;is a real risk that de-identified geolocation data could be re-identified.&quot;<\/p>\n<p class=\"paywall\">Tim Hortons agreed to implement the agencies&#x27; recommendations but apparently will not face any punishment. The <a data-offer-url=\"https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/investigations\/investigations-into-businesses\/2022\/pipeda-2022-001\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/investigations\/investigations-into-businesses\/2022\/pipeda-2022-001\/&quot;}\" href=\"https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/investigations\/investigations-into-businesses\/2022\/pipeda-2022-001\/\" rel=\"nofollow noopener\" target=\"_blank\">investigative report<\/a> said that Tim Hortons&#x27; commitments &quot;will bring the company into compliance&quot; with Canadian law and that &quot;we therefore find this matter to be well-founded and conditionally resolved.&quot; That&#x27;s the <a data-offer-url=\"https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/investigations\/def-cf\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/investigations\/def-cf\/&quot;}\" href=\"https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/investigations\/def-cf\/\" rel=\"nofollow noopener\" target=\"_blank\">language used<\/a> when an organization violates Canadian privacy laws but has &quot;committed to implementing satisfactory corrective actions.&quot;<\/p>\n<p class=\"paywall\">The announcement said Tim Hortons agreed to &quot;delete any remaining location data and direct third-party service providers to do the same,&quot; implement a privacy program that &quot;includes privacy impact assessments for the app and any other apps it launches,&quot; implement &quot;a process to ensure information collection is necessary and proportional to the privacy impacts identified,&quot; and ensure &quot;that privacy communications are consistent with, and adequately explain, app-related practices.&quot; Tim Hortons also agreed to report back to the government with details on its compliance.<\/p>\n<p class=\"paywall\">The investigation began after a June 2020 Financial Post <a data-offer-url=\"https:\/\/financialpost.com\/technology\/tim-hortons-app-tracking-customers-intimate-data\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/financialpost.com\/technology\/tim-hortons-app-tracking-customers-intimate-data&quot;}\" href=\"https:\/\/financialpost.com\/technology\/tim-hortons-app-tracking-customers-intimate-data\" rel=\"nofollow noopener\" target=\"_blank\">report<\/a> titled &quot;Double-double tracking: How Tim Hortons knows where you sleep, work, and vacation.&quot; Reporter James McLeod found that &quot;Tim Hortons had recorded my longitude and latitude coordinates more than 2,700 times in less than five months, and not just when I was using the app,&quot; even though the app &quot;told customers that it tracks location &#x27;only when you have the app open.&#x27;&quot;<\/p>\n<p class=\"paywall\">Tim Hortons&#x27; statement said, &quot;In June 2020, we took immediate steps to improve how we communicate with guests about the data they share with us and began reviewing our privacy practices with external experts. Shortly thereafter, we proactively removed the geolocation technology outlined in the report from the Tims app. Data from this geolocation technology was never used for personalized marketing for individual guests. The very limited use of this data was on an aggregated, de-identified basis to study trends in our business\u2014and the results did not contain personal information from any guests.&quot;<\/p>\n<p class=\"paywall\">Alberta Information and Privacy Commissioner Jill Clayton said the investigation provides &quot;yet another example where an organization has not effectively notified customers about its practices. Tim Hortons&#x27; customers did not have adequate information to consent to the location tracking that was actually occurring.&quot;<\/p>\n<p class=\"paywall\"><em>This story originally appeared on<\/em> <a data-offer-url=\"https:\/\/arstechnica.com\/tech-policy\/2022\/06\/tim-hortons-coffee-app-broke-law-by-constantly-recording-users-movements\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/arstechnica.com\/tech-policy\/2022\/06\/tim-hortons-coffee-app-broke-law-by-constantly-recording-users-movements\/&quot;}\" href=\"https:\/\/arstechnica.com\/tech-policy\/2022\/06\/tim-hortons-coffee-app-broke-law-by-constantly-recording-users-movements\/\" rel=\"nofollow noopener\" target=\"_blank\"><em>Ars Technica<\/em><\/a><em>.<\/em><\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/tim-hortons-coffee-app-location-data-tracking\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/629a78308a06d69f5e44b3b0\/master\/pass\/timhorton_ars_GettyImages-903432692.jpg\"\/><\/p>\n<p><strong>Credit to Author: Jon Brodkin, Ars Technica| Date: Sat, 04 Jun 2022 12:00:00 +0000<\/strong><\/p>\n<p>The Canada-based company illegally collected \u201cvast amounts of location data,\u201d such as every time a person entered or left their home, workplace, or another coffee shop.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21382],"class_list":["post-19253","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-privacy"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19253"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19253\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}