Legal

Privacy Policy

How GoodTap collects, uses, protects, and shares personal information.

Last updated: August 20, 2026

1. Scope and accountability

This policy applies to GoodTap’s websites, customer sign-up and recovery pages, business and staff portals, Wallet pass services, QR and NFC interactions, support, and related business services in Canada.

Goodtap is an Ontario, Canada sole proprietorship operating under the GoodTap brand. A participating business manages its customer relationship, reward offer, and any marketing it sends. GoodTap operates the technology and handles information for the purposes described here. Depending on the activity, GoodTap and the participating business may each be responsible for responding to privacy requests about information under their control.

The Privacy Officer, Goodtap is accountable for GoodTap’s privacy program and can be reached at privacy@goodtap.ca.

2. Information we collect

We limit collection to information reasonably needed for the identified purposes. Depending on how you use GoodTap, this may include:

  • Customer identity: name, email address, Apple private relay address or Google account identifier, and optional phone number.
  • Loyalty activity: participating business, member or pass identifier, Wallet provider, visits, stamps or tokens, rewards, redemptions, and event dates.
  • Consent records: the notice shown, essential service consent, optional marketing choices, when and how consent was given or withdrawn, and unsubscribe activity.
  • Business account information: business and contact details, staff roles, account access, subscription status, support requests, branding, offers, and fulfillment information.
  • Payment information: billing status and transaction identifiers from Stripe. GoodTap does not receive or store complete payment-card numbers.
  • Technical and security information: IP address, browser and device information, session identifiers, login and recovery events, audit logs, QR/NFC validation events, and information needed to detect fraud or misuse.

We receive information directly from you, from a participating business, and from services you choose to use, such as Apple, Google, Stripe, or a digital Wallet provider. Apple may provide a private relay email address instead of your personal email.

3. Why we use information

GoodTap uses personal information to:

  • create, recover, display, and update a loyalty pass;
  • record visits, rewards, and redemptions and show them to the customer and participating business;
  • authenticate users, manage permissions, prevent duplicate or fraudulent activity, and secure QR and NFC interactions;
  • operate business accounts, subscriptions, support, fulfillment, reporting, and service communications;
  • maintain reliability, investigate incidents, enforce agreements, and meet legal, accounting, and tax obligations; and
  • send promotional messages only where the appropriate consent or another lawful basis exists.

For a materially new purpose, we will explain the purpose and obtain new consent where required.

5. Cookies and similar technologies

GoodTap uses essential cookies and local browser storage to keep users signed in, associate a returning device with the correct pass, preserve security state, and remember necessary preferences. Clearing browser data may require account recovery before a visit can be added.

If GoodTap introduces non-essential analytics or advertising technologies, we will provide additional notice and choice where required. Blocking essential cookies may prevent parts of the service from working.

6. When information is shared

GoodTap does not sell personal information for money. We disclose information only as reasonably needed for the purposes in this policy:

  • Participating businesses receive customer and loyalty information connected to their own program, not another business’s information.
  • Service providers help host, store, secure, authenticate, send email, process payments, and provide Wallet services. Current providers may include Vercel, Neon, Stripe, Apple, Google, Microsoft, and Cloudflare.
  • Professional advisers, authorities, or other parties may receive information where required or permitted by law, to protect rights and safety, investigate fraud, respond to an incident, or complete a business reorganization subject to appropriate safeguards.

Providers may process information outside your province or outside Canada, including in the United States, where it may be subject to that jurisdiction’s laws. GoodTap uses contracts and other reasonable measures to require appropriate protection.

7. Retention and deletion

We keep active account and loyalty records while the account or participating business remains active and as reasonably needed to provide the service. After deletion, customer records enter a 30-day recovery period and business records enter a 90-day recovery period before scheduled erasure, unless a legal hold or another lawful need applies.

Security, privileged-administration, and secure-NFC event logs are generally kept for 12 months. Privacy-breach records are kept for at least 24 months from the date GoodTap determines that the breach occurred. Consent, campaign, and unsubscribe evidence is generally kept for six years after the relevant event or the end of reliance on that consent. Minimal billing, tax, and accounting records are generally kept for seven years.

When information is no longer required, it is securely deleted, anonymized, or scheduled for deletion from active and backup systems. A deletion request may not remove records that must be retained by law or for a legitimate security, financial, or dispute-resolution purpose.

8. Safeguards and privacy incidents

GoodTap uses administrative, technical, and physical safeguards appropriate to the sensitivity of the information. Measures include role-based access, authentication controls, encryption where appropriate, audit logging, provider oversight, secure NFC validation, backups, and incident-response procedures. No online service can guarantee absolute security.

We assess suspected privacy incidents, keep required records, and notify affected individuals and regulators as soon as feasible where a breach creates a real risk of significant harm or another law requires notice.

9. Access, correction, deletion, and other rights

Subject to applicable law, you may ask to access personal information under GoodTap’s control, understand how it has been used or disclosed, correct inaccurate information, withdraw consent, or request deletion. Where Québec law applies, you may also have rights relating to computerized information portability and certain automated decisions.

Email privacy@goodtap.ca with enough detail to identify the account and request. We may verify identity before responding and target a response within 30 days, subject to lawful extensions. If the request concerns a participating business’s own marketing list or records, we may direct you to that business or coordinate the response. We will explain any lawful refusal and available complaint route.

10. Children

GoodTap is designed for businesses and their customers and is not directed to children under 13. A participating business must obtain any consent required before enrolling a minor. If you believe a child’s information was collected improperly, contact us so we can investigate.

11. Changes to this policy

We may update this policy as GoodTap, our providers, or legal requirements change. We will publish the updated date and give additional notice or seek new consent where a change is material and the law requires it.

12. Questions and complaints

Contact the Privacy Officer, Goodtap at privacy@goodtap.ca or, where a mailed legal notice is required, at 3-252 Penetanguishene Rd, Barrie, ON L4M 7C2, Canada. We will investigate and respond through our complaint process.

If a concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada. Québec residents may also contact the Commission d’accès à l’information du Québec.

Related document: Terms of Use