Data protection

Data Processing Addendum

The privacy and data-handling rules for information processed for a participating business.

Last updated: August 20, 2026

1. Scope and accountability

This Addendum applies when GoodTap handles personal information for a participating business through the loyalty platform. Canadian privacy law does not always use “controller” and “processor” terminology; each party remains accountable for information under its control and for the obligations that apply to it.

The business determines its customer program, offer, supported collection settings, and marketing. GoodTap processes information to provide, secure, support, and improve the contracted service and to meet legal obligations.

2. Documented purposes and instructions

GoodTap will handle business customer data only for the service, documented business settings and requests, security and fraud prevention, support, legal compliance, and other purposes disclosed in the Privacy Policy. GoodTap will not sell the data or use it for unrelated third-party advertising.

If GoodTap believes a requested use is unlawful or outside the agreed service, it may pause that instruction and notify the business.

3. People, information, and duration

Data may concern customers, prospective customers, business administrators, and staff. It may include names, email addresses, optional phone numbers, OAuth identifiers, consent evidence, loyalty activity, rewards, Wallet identifiers, device/session data, support records, roles, audit events, and secure QR/NFC outcomes.

Processing lasts while the service is active and for the retention and deletion periods in the Privacy Policy, including legal holds and security, breach, consent, billing, tax, backup, and dispute records.

4. Safeguards and authorized personnel

GoodTap uses safeguards appropriate to the sensitivity of the information, including role-based access, authentication and MFA controls, encryption where appropriate, environment and secret controls, logging, backups, provider oversight, incident response, and secure NFC validation. Personnel and contractors receive access only where needed and are bound by confidentiality duties.

The business must secure its own accounts, devices, exports, staff access, physical equipment, and any system to which it transfers GoodTap data.

5. Service providers and cross-border handling

GoodTap may use vetted providers for hosting, databases, authentication, email, payments, Wallet delivery, abuse prevention, and support, including providers such as Vercel, Neon, Microsoft, Stripe, Apple, Google, and Cloudflare. Providers receive only the access reasonably needed for their service and are subject to contractual or equivalent safeguards.

Information may be handled outside a customer’s province or outside Canada, including in the United States, and may be available to authorities under the laws of that jurisdiction. GoodTap evaluates providers and uses reasonable contractual and technical protections.

6. Privacy requests and assistance

Each party will promptly forward a request that primarily concerns information controlled by the other. GoodTap will provide reasonable assistance with access, correction, deletion, portability where applicable, consent withdrawal, and information about use or disclosure, subject to identity verification and legal limits.

The business must not direct GoodTap to delete information that must be retained or that belongs to another business or customer.

7. Privacy incidents

GoodTap will investigate suspected unauthorized access, use, disclosure, loss, or alteration involving information under its control, take reasonable containment and mitigation steps, maintain required records, and notify the business without undue delay when an incident materially affects its data.

The parties will cooperate on the real-risk-of-significant-harm assessment and required notices. The party accountable for a required regulator or individual notice remains responsible for making it, with reasonable assistance from the other.

8. Export, deletion, and verification

During the service and for the communicated post-termination window, the business may request a supported export. GoodTap will delete or anonymize data after the applicable retention period unless continued retention is required by law, security, backup integrity, or a documented dispute.

GoodTap will provide reasonable information about its safeguards and compliance program. Any additional audit must be proportionate, protect other customers and confidential systems, occur on reasonable notice, and be at the requesting business’s cost unless a material GoodTap breach is established.

9. Contact and precedence

This Addendum forms part of the Business Terms. It controls if another commercial term conflicts specifically about personal-information handling. Privacy questions and requests may be sent to the Privacy Officer, Goodtap at privacy@goodtap.ca.

Related document: Business Terms