1. Introduction
TagMe ("we", "us", "our") operates the tagme.ca website and QR-based lost item recovery service. We are committed to protecting your privacy in compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
2. Information We Collect
Account Holders (Tag Owners)
- Email address — for account creation, login, and notifications
- Name — optional, for personalization
- Password — stored as a one-way hash, never in plain text
- Consent timestamp — when you agreed to this policy
Finders (People Who Scan Tags)
- Name — optional, auto-generated anonymous name if not provided
- Contact info — optional phone or email
- Message content — the message sent to the tag owner
- IP address — stored as a SHA-256 hash only, not in plain text
- Approximate location — city/neighborhood level only, never precise GPS without explicit consent
- Browser user agent — for analytics purposes
3. How We Use Your Information
- To facilitate anonymous communication between finders and tag owners
- To send email and push notifications about messages
- To generate and manage QR tags linked to your account
- To prevent abuse through rate limiting
- To improve our service
4. Information We Never Share
- Your email address is never shown to finders
- Your phone number is never shown to finders
- Your real name is never shown to finders
- Finder contact information is only visible to the tag owner
5. Data Retention
- Account data is retained for the duration of your account plus 365 days after deletion request
- Messages are retained as long as the associated tag exists
- IP hashes are retained for abuse prevention
- You may request deletion of your data at any time
6. Data Security
- All data transmitted over HTTPS (TLS encryption)
- Passwords hashed with bcrypt
- IP addresses stored as SHA-256 hashes
- Database hosted on Azure with encryption at rest
- Authentication via secure HTTP-only cookies
7. Your Rights Under PIPEDA
You have the right to:
- Access your personal information
- Request correction of inaccurate information
- Request deletion of your data
- Withdraw consent for data collection
- File a complaint with the Office of the Privacy Commissioner of Canada
8. Cookies
We use a single session cookie for authentication. We do not use tracking cookies or third-party analytics cookies.
9. Third-Party Services
- Resend — for sending email notifications
- Azure — for hosting and database services
These services process data on our behalf under their own privacy policies.
10. Children's Privacy
TagMe is not directed at children under 13. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date.
12. Contact Us
For privacy-related inquiries or to exercise your rights:
Email: privacy@contact.tagme.ca