Your Privacy Rights
Under the Privacy Laws, CI is required to collect, use and disclose personal information only by lawful and fair means. To ensure this accountability, we have developed this policy, and trained our staff about our policies and practices.
What is “personal information?”
Personal information is any information that identifies you, or by which your identity could be deduced.
Why do we collect personal information from you?
We collect personal information from you to:
- Create a unique profile within the Services in order to provide relevant and targeted offers to you
- Associate you with your selected loyalty points program and account for the purpose of awarding your earned loyalty points to you
- Better understand your preferences and tailor offers to you based on those preferences
- Better understand our Services’ usage and trends, to improve our Services’ performance, build knowledge and conduct research around user attitudes, motivations, and health behaviours
When will we collect personal information from you?
We will collect information that you provide to us in connection with your use of the Services when you (a) register as a user of the Services; (b) make changes to your user profile information; (c) connect your loyalty points account to the Services; (d) complete offers or surveys through the use of the Services; and (e) send email messages, queries, or other information to us through the Services.
While you are using Carrot Rewards, we may ask for permission to access and collect information from you and/or your mobile device to better enhance your user experience. This information includes, but is not limited to:
- Name: this may be used to personalize your experience and in any external communications you receive from Carrot.
- Email address: we may contact you with additional information about Carrot Rewards.
- Date of birth: this is used to ensure that you are legally permitted to learn and earn with the Carrot Rewards app and to provide you with relevant content.
- Postal code: this is used to identify your location and to provide you with relevant content.
- Gender: this may be used to target specific content so that it is relevant to you and in line with provincial priorities.
- Loyalty card number(s): this is used to connect to your loyalty account.
- Accelerometer and gyroscopes: these are tools on the phone used to identify movement in order to track steps. This is interpreted through a connection with Google Fit (Android) or Health Kit (iOS). Should you wish to disable Carrot’s access to accelerometer/gyroscope data, you may do so by following the directions below for your device type:
- iOS: Open “Settings”, navigate to “Privacy” and then “Health”. Within Health settings, you can restrict Carrot from reading data related to steps.
- Android: Open “Settings” specific to Google Fit and restrict Carrot from reading data related to steps.
- Location Services: this is used to identify your location and to provide you with relevant content. Should you wish to disable Carrot’s access to location services, you may do so by navigating to your device’s settings. Within Carrot’s preferences, you can then change or disable location access within the app.
- Bluetooth: this is used to identify your location and to provide you with relevant content via Bluetooth beacons, where applicable. Should you wish to disable Carrot’s access to Bluetooth services, you may do so by restricting Carrot’s access within your device’s Bluetooth settings.
- Contacts: this is used to make it easier for you to selects friends to send email invitations to. Should you wish to disable Carrot’s access to Contacts, you may do so by navigating to the Carrot Rewards settings within your device’s main “Settings”.
- Phone: this is used to allow you to easily connect with resources that can be accessed via phone.
Wherever possible we collect personal information directly from you, but we may also obtain information about you from other sources: for example, if you register for a Carrot Rewards account, you will be required to provide your name, email address, date of birth, postal code, gender and the collector or account number of any loyalty program that you wish to connect to your Carrot Rewards account. If you register for a Carrot Rewards account via a third party social media network, you authorize Carrot Rewards to collect from the third party network the personal information you provided in your third-party network account so that we may pre-populate the registration and other relevant fields of your Carrot Rewards account. Your use of third-party networks remains subject to the terms and conditions and policies you have agreed to with such third-party network providers.
We may keep this information in order to inform changes and make improvements to the app.
Disclosure of your Personal Information
CI will disclose only the following information to third-party loyalty points partners:
- Your collector or account number associated with the specified loyalty program; and
- The number of points earned by participating in activities related to the Services.
We do not disclose any additional personal information to any third party to enable them to market their products and services. Any information provided to any third party, including the government, will only be provided at the aggregate/de-identified level such that no individual can be uniquely identified or linked to the information.
We may transfer any information we have about you in connection with a merger or sale involving all or part of our business or as part of a corporate reorganization or stock sale or other change in corporate control.
Under certain circumstances, CI will disclose your personal information:
- when we are required our authorized by law to do so, for example if a court issues a subpoena;
- when you have consented to the disclosure;
- when the services we are providing to you require us to give your information to a third party your consent will be implied, unless you tell us otherwise; or
- where it is necessary to establish or collect amounts owed to us.
Transfer to Service Providers
In addition to the disclosures listed above, we transfer information to our service providers for processing and/or storage. We require that our service providers use reasonable safeguards to protection personal information under their control from loss, theft and unauthorized modification and disclosure. Our service providers are only permitted to use your personal information in order to provide services to us in relation to the Services; for example, the following types of information are provided to our service providers for processing and/or storage:
- Information automatically collected through the Services: The information automatically collected about that is provided to our service providers may include, but is not limited to, device ID, device type, browser type and version, geo-location information, computer and connection information, statistics on page views, traffic to and from the App and our Website, ad data, IP address and standard web log information.
- Cookies and Web Beacons: Information about your use of the Services, as evidenced through cookies, locally stored objects, and web beacons may be disclosed to our service providers. Cookies are small bits of information that are transferred to and stored in separate files within your computer or phone’s browser. A cookie may remain on your computer or phone after the session finishes (until the cookie expires or is deleted by you).
Service Providers Outside of Canada
Occasionally we do use service providers located outside of Canada to process and/or store personal information for us. Please note that personal information in the custody of these service providers may be subject to access by the law enforcement authorities of those jurisdictions in which the service providers are located.
Our Privacy Officer, whose contact information is provided below, can provide further information about our policies and practices regarding service providers located outside of Canada and further information about how these service providers, collect, use, disclose or store personal information on CI’s behalf.
Effect of Consent and Withdrawal of Consent
You are free to withdraw your consent to our collection, use and disclosure of your personal information at any time. However, if you choose to do so, the Services will not perform its functions and you will not be able to earn loyalty points on qualifying offers.
Updating Your Information
Since we use your personal information to provide services to you, it is important that the information be accurate and up-to-date.
If any of your information changes, please inform us so that we can make any necessary changes.
Is My Personal Information Secure?
CI takes all reasonable precautions to ensure that your personal information is kept safe from loss, unauthorized access, modification or disclosure. Among the steps taken to protect your information are:
- premises security;
- restricted file access to personal information;
- deploying technological safeguards such as security software and firewalls to prevent hacking or unauthorized computer access; and
- internal password and security policies.
Access to Your Personal Information
You may ask for access to any personal information we hold about you.
Summary information is available on request. More detailed requests which require archive or other retrieval costs may be subject to our normal administrative fees.
If CI holds information about you and if you can establish that it is not accurate, complete and up-to-date, CI will take reasonable steps to correct it.
Can I be Denied Access to My Personal Information?
Your rights to access your personal information are not absolute.
We may deny access when:
- denial of access is required or authorized by law;
- when granting you access would have an unreasonable impact on other people’s privacy, unless the requested information is severable from the personal information of other people; and
- to protect CI’s confidential commercial information.
If we deny your request for access to, or refuse a request to correct information, we shall explain why.
CI does not use your Social Insurance Number or other government issued identification as a way of identifying or organizing the information we hold about you.
How Long do you Keep my Personal Information?
We keep your personal information as long as is reasonably necessary for us to complete our dealings with you, or as may be required by law, whichever is longer. CI will destroy all personal information associated with accounts that are inactive for longer than 1 year.
Communicating with Us
You should be aware that email is not a 100% secure medium, and you should be aware of this when contacting us to send personal or confidential information.
Request for Access
If you have any questions, or wish to access your personal information, please write to our Privacy Officer at:
330 – 20 Richmond St E
If you apply to CI for a job, we need to consider your personal information, as part of our review process. We normally retain information from candidates after a decision has been made, unless you ask us not to retain the information. If we offer you a job, which you accept, the information will be retained with our privacy procedures for employee records.
On our Website, like most other commercial websites, we may monitor traffic patterns, site usage and related site information in order to optimize our web service. We may provide aggregated information to third parties, but these statistics do not include any identifiable personal information.