Canadian regulators discovered that Tim Hortons, a popular fast food and coffee chain, made some changes to mobile app in 2019 to track and collect sensitive data about its customers.

The finding comes after an investigation led by Canada's privacy commissioner found that Tim Hortons was able to collect data on customers' locations "as frequently as every few minutes." It appears that another US-based company called Radar.
Dor also: Ransomware attacks: It takes 4 days to encrypt systems
Regulators found that the data, described as “continuous and massive,” ultimately served no legitimate purpose and was “not proportionate to the benefits Tim Hortons hoped to derive from better-targeted promotion of its coffee and other products.”
Canada's Privacy Commissioner, Daniel Therrien, stressed that the company "overstepped its bounds by collecting a vast amount of highly sensitive information about its customers. Tracking people's movements every few minutes, every day, was clearly an inappropriate form of surveillance."
How did it all start?
According to the records, the government investigation into Tim Hortons began in 2020, when a reporter for the Financial Post alleged that the company's mobile app had recorded his GPS coordinates more than 2,700 times over five months. According to the reporter, the tracking was happening even when he was not using the app.
The Tim Hortons app requested permission to access the mobile device's geolocation features, but misled many users into believing that the information would only be accessible when the app was in use. In reality, the app was tracking users while the device was on, continuously collecting their location data.
See also: SideWinder hackers install fake Android VPN app on Google Play Store
The app used location data to infer where users lived, worked, and traveled. It created an “event” every time users entered or left a Tim Hortons competitor, a major sports venue, or their home or workplace.

In a statement, Tim Hortons stressed that the privacy commissioners' report does not recommend changes to its current app. Following the story with the reporter, the company "preemptively removed geolocation technology," it said.
“The very limited use of this data was done on an aggregated basis, without access to identifiable information, to study trends in our business – and the results did not contain any personal information from any visitors,” the company said.
However, stopping tracking does not mean that there is no longer any risk and concern for user privacy.
See also: Costa Rica: Public health service hit by Hive ransomware
“This research sends a strong message to organizations that you can’t spy on your customers just because it fits your marketing strategy,” said Michael McEvoy, British Columbia’s information and privacy commissioner. “This type of information collection is not only a violation of the law, but a complete violation of customer trust.”
Phone makers have taken some steps to prevent app developers from accessing location. In April 2021, Apple allowed its users to block apps from tracking their locations and sharing that information with third parties. The world seems to have embraced the new feature. About two-thirds of iPhone users opted out of tracking when given the option, according to a report from analytics firm AppsFlyer.
Source: gizmodo.com
