Data leak

Tim Hortons App Covert Location Tracking β€” PIPEDA Investigation, Class Action

πŸ“… 2019-01-01 🏒 Tim Hortons mobile loyalty app (Restaurant Brands International)
Primary Source β†—

Incident Details

In June 2022, Canada’s Office of the Privacy Commissioner (OPC), together with privacy commissioners from Alberta, British Columbia, and Quebec, published findings of a joint investigation into the Tim Hortons mobile app. The investigation found that the app had collected continuous geolocation data from users’ phones β€” even when the app was closed β€” through a third-party geofencing service. The app collected location data every few minutes, creating a highly detailed record of users’ daily movements including their home, work, places of worship, health facilities, and other sensitive locations. The app’s collection was far disproportionate to the stated functionality (ordering and rewards). The investigation period covered primarily 2019-2020. Restaurant Brands International (which owns Tim Hortons, Burger King, and Popeyes) was found to have violated Canada’s PIPEDA (Personal Information Protection and Electronic Documents Act). The investigation was triggered by a Globe and Mail investigative report in June 2020 that analysed network traffic from the Tim Hortons app. The OPC ordered Tim Hortons to destroy all the covertly collected data and implement a privacy compliance programme. A class-action lawsuit was filed in Canada and Quebec. The case became a landmark in Canadian mobile app privacy enforcement and highlighted the pervasive but invisible nature of continuous location tracking in consumer apps.

Technical Details

Initial Attack Vector
The Tim Hortons mobile app collected continuous location data from users even when the app was not in use β€” far exceeding what was necessary for the app's stated functionality; the covert tracking persisted between app sessions without adequate consent disclosure
Vendor / Product
Tim Hortons mobile loyalty app (Restaurant Brands International)

Timeline

  1. 2019-01-01 Breach occurred
  2. 2022-06-01 Publicly disclosed
  3. 2022-06-01 Customers notified