Privacy policy
Tagnook Privacy Policy
Version: 1.0 · Effective: August 12, 2026 · Last updated: August 12, 2026
Tagnook makes personalized name labels and identification tags for kids' belongings. Some of our tags carry a QR code (and, on some products, a passive NFC chip) that lets a person who finds a lost item reach the owner through us — without the owner's private details ever being printed on the tag. Because our products are used to label children's things, we treat privacy as a core feature, not an afterthought.
Our service is for adults. Tagnook is intended for use by people who are 18 or older, or the age of majority in their province or territory if it is higher. The account holder is the responsible adult — a parent or guardian — who buys and manages the tag. Tagnook is not directed to children, and we do not knowingly collect personal information from a child; any information about a child is provided to us by the responsible adult. The recovery side of our service — everything a finder could ever see — is adult-only: it uses the adult owner's chosen name and contact details. Our service is offered to customers in Canada only.
This policy explains, in plain language, what personal information we collect, why we collect it, who we share it with, how long we keep it, how we protect it, and the rights you have. It applies to our website, our online store, and our lost-and-found recovery service. If there is any conflict between our Terms of Service and this Privacy Policy about how we collect, use, or disclose your personal information, this Privacy Policy governs.
We have written this policy to meet the requirements of Canada's federal privacy law (the Personal Information Protection and Electronic Documents Act, "PIPEDA"), Québec's private-sector privacy law (the Act respecting the protection of personal information in the private sector, as amended by Law 25), and Canada's anti-spam law ("CASL"). Where these laws differ, we aim to meet the stricter standard.
1. Who we are and who is accountable
Tagnook is the business name of 1001064988 Ontario Inc. ("Tagnook", "we", "us", "our"), a corporation incorporated in Ontario, Canada.
We are responsible for the personal information in our custody and control, including personal information we entrust to the service providers who work on our behalf (for example, our hosting, email, and recovery-platform providers). We require those providers to protect that information to a standard comparable to our own.
Our Privacy Officer
We have designated a Privacy Officer who is responsible for our compliance with this policy and with applicable privacy law. You can reach the Privacy Officer about anything in this policy, to exercise your privacy rights, or to raise a concern:
- the Privacy Officer, Tagnook — support@tagnook.com
Registered business address: 226 Kinloch Court, Nepean, Ontario K2J 5S9, Canada Telephone: 1 (613) 262-8136
2. Why we collect personal information (our purposes)
We collect personal information for specific, limited purposes, and we tell you those purposes at or before the time we collect it. We only collect what we genuinely need.
2.1 For running our online store
- To make and fulfil your personalized order — printing the label with the details you provide and preparing your item.
- To ship your order and let the carrier deliver it, and to handle returns, cancellations, reprints, and refunds.
- To take payment for your order, through our store platform (Section 6).
- To provide customer support and answer your questions.
- To keep records for accounting, tax, and reconciliation.
2.2 For the lost-and-found recovery service
The recovery service is adult-only: the information it stores, and anything it can ever surface to a finder, is the adult owner's chosen name and contact details.
- To register a tag to you as its owner and link it to your order.
- To let you set how you want to be reached if your item is found, and to notify you by email when someone reports finding your item.
- To pass messages between a finder and you so the item can come back — without either of you having to reveal private contact details to the other unless you choose to.
- To record a reward against a confirmed return and issue it as store credit (Section 9).
- To keep the service working and safe — for example, limiting how often a page can be hit.
We do not use recovery information to market to you, to build advertising profiles, or for any purpose unrelated to returning lost items. We do not sell personal information to anyone.
2.3 For sending you marketing — only if you ask us to
If you opt in, we use your name and email to send you store news, promotions, and product updates. This is store marketing only. We never use your recovery information — your recovery contact, tag registrations, relayed messages, or anything about a child — for marketing. Section 11 sets out how consent, identification, and unsubscribe work.
2.4 For fraud prevention, abuse investigation, enforcing our Terms, and legal claims
Almost everyone who uses Tagnook does exactly what you would expect: they buy labels, register a tag, and hope a stranger is kind enough to scan it. But a lost-and-found relay puts strangers in contact with each other, and a store takes payments — so a small number of people try to misuse both. Keeping records that let us spot and stop that is what keeps the service safe and free of charge to use. So we also collect and use personal information to:
- verify that a person is who they say they are — for example, confirming that the person activating a tag is the buyer, or that a person asking for their data is the account holder;
- detect, investigate and prevent fraud — fraudulent or fabricated orders, payment fraud, chargeback abuse, and claims made to obtain free duplicate product;
- detect and stop tag and activation fraud — activating or claiming a tag you do not own, bulk-activating tags for resale, or scanning tags to harvest owner contact details;
- investigate misuse of the relay — harassment, threats, extortion ("pay me and I'll return it"), scams, phishing, spam, contact-harvesting, and unlawful content;
- operate and enforce our reward limits — including the caps and frequency limits in Section 9 — and to detect reward farming, collusion, self-returns, and fabricated "found" reports;
- protect the security and integrity of the Service — rate limiting, blocking bots and automated ordering, and detecting scraping, enumeration or probing of tag identifiers;
- enforce our Terms of Service and Recovery & Reward Terms, including refusing or cancelling an order, suspending or closing an account, and deactivating a tag where we reasonably suspect fraud or abuse; and
- establish, exercise or defend legal claims, respond to lawful requests, and meet our legal obligations.
The legal basis. Canadian privacy law expressly permits an organization to collect, use and disclose personal information without consent where it is reasonable for detecting or suppressing fraud, for investigating a breach of an agreement or a contravention of a law, or where the law otherwise requires or permits it. We rely on those provisions for the purposes in this section, and only for these purposes.
What this means for how long we keep records. Where we are investigating suspected fraud or abuse, where a chargeback or dispute is open, where a claim is reasonably in prospect, or where a legal hold applies (litigation, a regulatory request, or a law-enforcement preservation request), we may keep the relevant records beyond the retention periods in Section 7, and the automatic deletion of those records is suspended until the matter is resolved and the hold is lifted. We keep only what is relevant to the matter, and when it ends the normal schedule resumes.
Who we may share those records with. Our payment provider and the card networks, where we are defending a chargeback; our legal advisers and insurers; and police or another authority where the law requires it, where we are responding to a valid legal demand, or where someone's safety is at risk. We do not use fraud or abuse records for marketing or profiling, and we do not sell them.
3. What we collect, and from whom
There are two very different groups of people in our recovery service: the owner (our customer, an adult) and the finder (a member of the public who happens to find a lost item). We collect different information from each, so we describe them separately.
3.1 Information we collect from you, the buyer and owner
| What we collect | Why |
|---|---|
| Your name (the delivery recipient) | To make and ship your order |
| Your shipping address | To deliver your order. We deliberately do not keep your billing address in our production records |
| Your email address | To confirm and fulfil your order, to send order updates, and — if you set it as your recovery contact — to notify you and relay finder messages |
| Your phone number (optional) | Only if you choose to give it: for a fulfilment issue or carrier contact |
| Your order and item-customization details | To produce your personalized item |
| The text you ask us to print on a label, including a child's first name if you choose to print one | Used only to print the physical label. It is not copied into the recovery record, and it is never shown on the finder page or disclosed to a finder (Section 8) |
| A display name and private notes you set for an item (optional) | For your own item management. Notes are never shown to a finder |
| Whether an item belongs to a child | To apply the most protective settings automatically (Section 8) |
| Any reward you choose to offer, and which fields (if any) you allow a finder to see | To reflect your choices. A finder never sees the exact reward amount, and no owner field is shown to a finder unless you switch it on |
| Records of orders, reprints, returns, refunds, disputes, reward activity, and enforcement decisions | To run the store, honour our guarantee, and for the fraud-prevention and enforcement purposes in Section 2.4 |
To keep your data safe, we store your order email both as a working contact and as a one-way scrambled ("hashed") value, so we can confirm it is really you when you claim a tag without keeping a second plain copy lying around as a lookup key.
3.2 Information we collect from a finder
If you find someone's item and use the tag to reach the owner, you do not need an account or an app. You choose what, if anything, to share. We may collect:
| What we collect | Notes |
|---|---|
| A message to the owner (optional) | Only what you type |
| Contact details you choose to include (optional) | Only if you decide to give the owner a way to reach you |
| An email address for a reward (optional) | Only if the owner confirms the return. We store it as a one-way scrambled value, never in plain text |
| A scrambled ("hashed") form of your device's network (IP) address, and basic request details such as the time and which tag was scanned | Derived automatically and kept to limit abuse of the service. We do not keep your raw IP address for this purpose |
What the finder page does not collect. The Service does not include finder location sharing — a finder cannot share a location, and we do not collect location from anyone. The Service does not include photo upload — a finder cannot attach a photo to a found-item report, and an owner cannot upload an item photo.
If you are a finder, please note: by sending a message or contact details through the tag, you are asking us to relay that information to the item's owner so the item can be returned. That is what we do with it, along with keeping the minimal safety record described in Section 2.4.
3.3 How relayed messaging works — please read
Our finder-to-owner messaging is a relay: the owner's private contact details are never shown to a finder, and a finder's details are shown to the owner only if the finder chooses to share them. So that everyone who uses this channel knows exactly how it works, we disclose that relayed messages:
- are recorded and retained — message content is automatically deleted about 90 days after it is sent (Section 7);
- are always visible to the item owner, who receives them as the intended recipient;
- may be read and moderated by us for safety, abuse-prevention, and support purposes; and
- may be preserved and produced in response to a lawful request — for example a court order or a valid law-enforcement request — or where needed to investigate abuse or protect someone's safety.
This messaging is not end-to-end encrypted, and we do not describe it as "zero-knowledge." We can access message content for the limited purposes above. We tell you this up front so your expectations match how the service actually works.
Keeping the relay safe. The relay exists for one thing: arranging the return of a found item. Harassment, threats, extortion, scam or phishing attempts, spam, contact-harvesting, and unlawful content are prohibited. Where we see them, we may block a sender, suspend return access on a tag, retain the relevant records, and report the matter to police. To report abuse, a threat, an extortion attempt, or anything that feels unsafe, email support@tagnook.com with the details and we will investigate.
Where we encounter content that appears seriously unlawful — in particular child sexual abuse material (CSAM), or content that sexually exploits or endangers a child — we may preserve it and report it to the appropriate authorities, including Canada's tip line Cybertip.ca (<https://www.cybertip.ca>) and law enforcement, as our legal obligations require. Nothing in this policy limits that duty.
3.4 What is not on the tag
Our tags carry only a short, non-guessable code — never a name, phone number, address, or any private detail. Those details live in our secure system and are only ever surfaced through the service, on a need-to-know basis, and only to the extent the owner has chosen. This is a deliberate anti-fraud and anti-stalking design, and it is also why we treat any attempt to guess or enumerate tag codes as abuse (Section 2.4).
4. Consent — how we rely on your permission
We collect, use, and disclose personal information with your consent, except where the law allows or requires otherwise — including the fraud-prevention, investigation, and legal-claim purposes in Section 2.4.
- When you place an order, you consent to us using your information to fulfil that order.
- When you register or configure a tag, mark an item as lost, or choose what a finder can see, you consent to those specific uses.
- When you, as a finder, send a message or contact details, you consent to us relaying them to the owner to help return the item.
We ask for consent in clear terms and, where the recovery service is involved, we present that request separately from the general terms of sale rather than burying it in fine print. If we ever want to use your information for a new purpose we did not tell you about, we will ask for your consent again first.
Some recovery information can be sensitive — for example, the fact that an item belongs to a child. Where that is the case we rely on your express consent, and we design the flow so the sensitive details stay protected by default.
You can withdraw your consent at any time, subject to legal and contractual limits — for example, we still need order information to complete a purchase you have already made, to honour our guarantee, and to meet tax and accounting obligations, and Section 2.4 explains when we may keep records despite a withdrawal. To withdraw consent, contact our Privacy Officer. We will explain the effect before we act on it. Note that deleting your account or a tag also deactivates that tag, so a found item could no longer be routed back to you.
5. What the tag is — and what it cannot do
We want to be completely clear about the physical product, because it is easy to assume a tag does more than it does.
A Tagnook tag is a printed QR code and, on some products, a passive NFC chip. It has no battery, no GPS, no beacon and no live location. It does nothing at all until a person chooses to scan it. It cannot be used to track or locate a person, a child, or an item, and neither you nor we can "ping" a tag to find where it is.
- No location, ever. The Service does not include finder location sharing and does not collect location from a finder or an owner.
- A scan is just a web page. Scanning a tag opens a page in the finder's browser. It does not silently install anything, and it does not track the finder across other websites.
- No profiling. We do not use any of this to profile children, and we do not use recovery information for advertising.
Tagnook is not a child-safety device, an emergency service, a tracking device, or a medical device, and we do not guarantee that a lost item will be found or returned. If a child is missing, call 911.
6. Where your information lives, and who helps us process it
6.1 Where your data is stored — Canada, and Shopify's cross-border processing
Our recovery-service data stays in Canada. The personal information in our lost-and-found recovery system — your recovery contact, tag registrations, and relayed messages — is stored and processed in Canada, in Amazon Web Services' Montréal region (ca-central-1), in an isolated environment protected by its own encryption keys.
Our store platform processes order and payment data outside Canada. Shopify runs our online store, checkout and payments, and is our system of record for orders. Shopify stores and processes store, order and customer personal data on cloud infrastructure that it balances dynamically across multiple regions, which may be outside Canada, including the United States, using international data transfers to operate. We cannot pin Shopify's storage to Canada. This means the information you give us to place and pay for an order — such as your name, email, shipping address, and the payment details Shopify handles — may be stored and processed outside Canada by Shopify and its own processors, under Shopify's data-processing and international-transfer commitments. We do not store raw payment-card numbers or security codes ourselves.
In short: we keep our own recovery data in Canada; Shopify's handling of your order and payment data is a cross-border processing that we disclose to you plainly and that relies on Shopify's contractual protections.
6.2 The service providers we rely on
We use a small number of trusted providers to run the business. We share only what each one needs, under written agreements that require them to protect it.
-
CloakTag — our recovery platform (our processor). Our lost-and-found recovery service runs on CloakTag, privacy-first QR/NFC recovery infrastructure operated by 1001064988 Ontario Inc. — the same company behind Tagnook. For the recovery service, Tagnook is the controller and CloakTag acts as our processor: it handles your recovery data only on our behalf, on our instructions, and under a Data Processing Agreement, and stores it in Canada (AWS
ca-central-1). CloakTag does not use your recovery data for its own purposes. - Shopify — our store platform. Processes your order and payment as our system of record, and issues store credit on our behalf. See Sections 6.1 and 6.3.
- Canada Post — our shipping carrier. Every order we ship gives Canada Post the delivery name and address, and, where you have provided one, an email address or phone number for delivery notifications. Canada Post handles that information as an independent organization under its own privacy policy. Where we use another carrier for a particular shipment, the same minimum applies: the delivery name and address only.
- Amazon Web Services (AWS). Hosts our systems, storage, encryption, and databases in Canada.
- Amazon Simple Email Service (SES). Sends our transactional email — order confirmations, sign-in and verification messages, relayed recovery messages, and any breach notice.
- Amazon Cognito. Handles account sign-in.
We do not use an SMS provider. The Service does not send SMS — we notify you by email. The Service does not move money between an owner and a finder, so there is no payment intermediary in the recovery flow (Section 9).
We do not sell your personal information, and we do not share it with anyone for their own marketing.
6.3 Shopify's own use of store data
Shopify does more than host our store for us. To provide, secure and improve its platform, Shopify also processes information about your interactions with our store — combined with data from other merchants and from Shopify — for Shopify's own purposes, for example platform security and fraud prevention, and analytics. For those purposes Shopify acts as an independent controller, responsible for its own processing and for handling the choices you make about it.
- To learn how Shopify uses your personal information and what choices you have, see the Shopify Consumer Privacy Policy (<https://www.shopify.com/legal/privacy/app-users>).
- Depending on where you live, you can exercise choices over Shopify's own processing — including opting out of the "sale" or "sharing" of your information for targeted advertising — through the Shopify Privacy Portal (<https://privacy.shopify.com/en>).
For our part, we do not sell your personal information, we do not use it for cross-site or cross-merchant behavioural advertising, and we have not enabled any personalized-advertising feature. If that ever changes, we will update this policy and give you a working opt-out before we turn it on.
7. How long we keep your information
We keep personal information only as long as we need it for the purpose we collected it, or as long as the law requires, and then we destroy or anonymize it. We maintain a retention schedule that governs this in more detail.
| Information | How long we keep it |
|---|---|
| Relayed message content between a finder and an owner | Automatically deleted about 90 days after it is sent |
| Sign-in links and one-time codes | Single use; they stop working within minutes |
| Order and production processing messages in our fulfilment queue | About 14 days |
| System logs, which do not contain message content | About 30 days |
| Your recovery record — tag registration and recovery contact | For as long as the tag stays registered to you. We operate the recovery service for as long as we operate it and for a minimum of five years from tag activation, so your record is kept at least that long unless you delete the tag or your account |
| Safety, abuse-prevention and access audit records | Kept while we need them to investigate abuse, keep people safe, and enforce our Terms, and deleted when that need ends. They are not kept indefinitely as a matter of routine |
| Your order record — name, delivery address, email, and what you ordered | Held in our store platform for as long as we need it for support, the 30-day return window and the 12-month reprint guarantee, and for the period Canadian tax and accounting law requires (generally six years after the relevant tax year) |
| Production artwork — the file we print from | Kept while we may need it to honour a reprint or resolve a support issue, then deleted from our production systems |
| Marketing consent and unsubscribe records | Kept for at least three years, because CASL requires us to be able to prove consent and to show that an unsubscribe was honoured |
| Confidentiality-incident (privacy-breach) register | 5 years, as Québec law requires |
| Records tied to a verified deletion request | We action the deletion within 30 days of verifying your identity, except for the records described below |
| Records under a legal hold, or needed for a fraud or abuse investigation, a chargeback, or a legal claim | Kept until the matter is resolved and the hold is lifted, then returned to the normal schedule |
Some information is kept longer where the law requires it, or where it is needed to resolve a dispute, defend a claim, or investigate fraud or abuse — see Section 2.4. In those cases a legal hold suspends automatic deletion for the affected records, and we keep only what is relevant to the matter.
8. Children's information
Our products are about children, but our customer is the adult who buys and manages the tag. Tagnook is intended for people 18 or older, or the age of majority in their province or territory if it is higher, and is not directed to children. We do not knowingly let a child create an account or transact with us, and we do not knowingly collect personal information from a child — any information about a child comes to us from the responsible adult.
- We never ask you for a child's name for recovery. The name printed on a label is not copied into the recovery record. You can optionally set a display name for an item; we ask you not to use a child's name, and if you flag an item as a child's, any display name is removed from the finder page automatically.
- Recovery data is adult-only. What the recovery system stores, and anything a finder can ever see, is the adult owner's chosen name and contact details. A finder does not learn a child's identity from our service.
- Parental authority. The account holder must be an adult who owns the item and, where a child's information is involved, is the parent or guardian or otherwise has parental authority. When you tell us an item belongs to a child, you are confirming that, and we record that setting with the item. Under Québec law, using the personal information of a child under 14 generally requires the consent of the person with parental authority unless the use is clearly for the child's benefit; we rely on the parent or guardian's consent.
- Privacy by default. The finder page is minimum-exposure by design. Nothing that could identify a person is shown unless an adult owner deliberately turns it on, and we never expose a child's name, surname, home address, school, or photo to a finder.
- No marketing, no profiling. We do not use a child's information for marketing and we do not profile children for advertising.
If you believe a child has given us personal information without proper parental consent, contact our Privacy Officer at support@tagnook.com and we will delete it.
9. Rewards, and the records behind them
A thank-you to a finder is a nice thing, and we fund one. Here is exactly what that means for information about you.
- Rewards are store credit only. Any reward Tagnook provides is store credit usable only at Tagnook. The Service does not pay cash rewards, does not make any finder payout, and does not hold, route, escrow or take a cut of anyone's money. Store credit never expires, is never redeemable for cash, is not transferable by the holder, and is not refundable.
- A reward follows a confirmed return. A reward is only recorded once an owner confirms an item was actually returned. To issue it, we store the finder's email as a one-way scrambled value, never in plain text.
- The limits we apply, published so you know them. These limits are part of how the reward feature works, and enforcing them is one of the reasons we keep the counters described below:
- Tagnook-funded thank-you credit: maximum CAD $10 per confirmed return.
- One reward per tag in any 180-day period.
- Maximum 5 rewards generated by any one owner's tags in 365 days.
- Maximum 3 rewards to any one finder in 365 days.
- Rewards are issued after a 3-day review period, not instantly.
- Owner-funded reward offers: maximum CAD $500 per offer and CAD $2,000 funded in any 24 hours.
- What we keep to run those limits. To apply the caps we keep simple counters linked to the tag, the owner's account, and the hashed finder email — how many rewards, and when. That is what lets us stop reward farming and collusion without holding anyone's financial details.
- The 3-day review exists for a reason, and a human does it. The vast majority of confirmed returns are exactly what they look like. The short review period is there so that fabricated "found" reports, self-returns, and collusion between an owner and a finder can be caught before credit is issued. We may decline, withhold, reverse or cancel a reward, and suspend the feature for an account, where we reasonably suspect fraud or abuse. Any such decision involves human judgment, not solely automated processing, and if you think we got it wrong you can ask us to review it by emailing support@tagnook.com.
The full reward mechanics are in our Recovery & Reward Terms, which control if there is any inconsistency about how rewards work.
10. Cookies and tracking
We keep this simple, because our site does.
- Strictly necessary cookies only. Our website and store use cookies that are needed to make the site work: keeping your shopping cart and session, completing checkout securely, keeping you signed in, protecting against fraud and cross-site request forgery, and remembering basic preferences such as language. These are essential to deliver the service you asked for.
- No advertising, no cross-site tracking. We do not run advertising pixels, cross-site tracking pixels, social-media trackers, or behavioural-advertising tags on our website or store, and we do not sell or share your personal information for targeted advertising. We do not build advertising profiles, and we never use recovery information for advertising.
- Our finder pages are deliberately bare. A finder page carries no advertising or tracking technology at all, and it is set to "no index" so search engines do not list it.
- You can control cookies in your browser. Every major browser lets you see, block, and delete cookies, and browse privately. Blocking strictly necessary cookies will stop parts of the store — such as your cart and checkout — from working.
Browser privacy signals. Because we run no advertising or cross-site tracking technology, there is nothing on our site for a Global Privacy Control or "Do Not Track" signal to switch off — we do not sell or share your personal information for advertising in the first place, whether or not you send such a signal. For the processing that Shopify controls independently (Section 6.3), you can exercise your choices through the Shopify Privacy Portal (<https://privacy.shopify.com/en>). You can read more about GPC at <https://globalprivacycontrol.org>.
11. Marketing email and Canada's anti-spam law (CASL)
We would rather send you one useful email than five you did not ask for.
- We only send marketing email to people who asked for it. You give consent by subscribing to our newsletter, by ticking a marketing box at checkout, or by asking us directly. We do not use pre-checked boxes, we do not condition your purchase on agreeing to marketing, and we do not buy or rent email lists. Where CASL permits implied consent — for example, for a limited period after you buy from us — we may send you a small number of relevant messages, and each one follows every rule below.
- Every marketing email identifies us. Each message states that it is from Tagnook (1001064988 Ontario Inc.) and gives support@tagnook.com as the way to reach us.
- Every marketing email carries a working unsubscribe. One click, no account, no login, no questions asked. The link stays working for at least 60 days after we send the message. We honour an unsubscribe promptly — in practice almost immediately, and in every case within 10 business days, as CASL requires. You can also unsubscribe by emailing support@tagnook.com.
- We keep proof of consent. We record when and how you gave consent, and when you withdrew it, and we keep that record for at least three years — both because CASL requires us to be able to prove consent and so that an unsubscribe is not accidentally undone.
- Messages about your order are not marketing. Order confirmations, shipping and delivery updates, refund and return notices, security and sign-in emails, lost-item alerts, and notices about changes to a policy or to the service are transactional or service messages. We send them because they are part of the service you bought. Unsubscribing from marketing does not stop them, and it should not — you would otherwise miss the alert that your item was found.
12. How we protect your information
We use security measures appropriate to the sensitivity of the information, and — because our service involves children's things — we hold ourselves to a higher standard. Measures in place include:
- Encryption of your data in transit (TLS 1.2 or higher) and at rest (managed encryption keys) across our storage, databases, and queues.
- A default-private finder page that can only ever show a very short, owner-approved allow-list of fields. Contact details, surnames, serial numbers, addresses, and exact reward amounts can never be shown to a finder.
- A relayed message channel, so a finder and an owner never see each other's private identity unless each chooses to share it.
- Short, non-guessable tag codes, and uniform "not found" responses, so no one can probe our system to discover which tags exist. Attempts to enumerate tag identifiers, scrape the service, or circumvent rate limits are blocked and investigated.
- Escaping of all user-entered text, strict browser security headers, and a search-engine "no index" setting on finder pages.
- Detailed, tamper-evident access logs, and access to personal information limited to the people who need it to do their job.
Plain talk about our encryption claims. We encrypt data in transit and at rest as described above, but we do not claim our service is "zero-knowledge" or "end-to-end encrypted." The Service does not offer an encrypted vault, and no part of the Service is zero-knowledge or end-to-end encrypted. Relayed messaging in particular is not end-to-end encrypted: we can access message content for the limited safety, abuse-prevention, legal-compliance, and support purposes described in Section 3.3.
No system can be guaranteed to be perfectly secure, but we work continuously to protect your information and reduce risk.
13. Your privacy rights — and the limits on them
Subject to the limits allowed by law, you have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Withdraw your consent to a use you previously agreed to (Section 4).
- Delete your information and, where applicable, ask us to stop sharing it or to de-index a link where its continued availability causes you harm or is unlawful.
- Receive a copy of the computerized personal information you gave us, in a structured, commonly used electronic format.
- Opt out of marketing at any time (Section 11).
How to exercise your rights. Email our Privacy Officer at support@tagnook.com. We will respond within 30 days. Exercising these rights is free; if a request involves reasonable transcription or reproduction costs, we will tell you before we incur them. You may authorize someone to make a request on your behalf; we will ask for written proof of that authorization, and we may still verify directly with you. For personal information that Shopify processes as an independent controller (Section 6.3), you can also use the Shopify Privacy Portal (<https://privacy.shopify.com/en>).
We verify who you are before we act. This protects you more than it protects us: the whole point of a privacy request is that nobody else should be able to make it in your name. We verify your identity before disclosing, correcting, or deleting anything — usually with a confirmation to the email address already on the account, and for a higher-risk request with a further check proportionate to the sensitivity of the information. We ask for the least verification that does the job, and we do not keep verification material any longer than we need it.
When we may refuse, and what we do then. We want to say yes to every request, and nearly always we do. But the law recognizes that a small number of requests should not be granted, and we may refuse or partly refuse a request where:
- it is manifestly unfounded, excessive, or repetitive — for example, the same request made repeatedly after we have already answered it in full;
- granting it would reveal another person's personal information — for example, an access request that would hand over a finder's message content, contact details, or identity. Where we can, we will give you the rest with the other person's information redacted;
- it appears to be an attempt to identify a finder, an owner, or any other person, or to obtain someone else's data. We will not let an access request be used as a route around the relay's privacy design;
- the information is subject to solicitor-client privilege, would reveal confidential commercial information, or was generated in the course of a fraud or abuse investigation, a dispute, or the establishment or defence of a legal claim (Section 2.4);
- we are required or permitted by law to keep it — for example, tax and accounting records, the confidentiality-incident register, or records under a legal hold; or
- the law otherwise allows us to refuse.
If we refuse, we will tell you in writing, explain the reasons and the legal basis, tell you which parts of your request we can still complete, and tell you how to escalate. You can take the matter to the Office of the Privacy Commissioner of Canada (<https://www.priv.gc.ca>) or, if you live in Québec, to the Commission d'accès à l'information du Québec (<https://www.cai.gouv.qc.ca>). Section 15 sets out that route in full.
Automated decisions. We do not make decisions about you based solely on automated processing without human involvement. Reward and enforcement decisions in particular involve human judgment (Section 9). If that ever changes, we will tell you and — on request — explain the information used and the main factors, let you have it corrected, and let you submit your views for a review.
One thing to consider before you delete. Deleting your account or a tag also deactivates that tag, so it can no longer route a found item back to you.
14. Keeping your information accurate
We rely on you to give us accurate information and to keep it current — especially your recovery contact details, since an out-of-date email could mean you miss the alert that your item was found. You can update your information at any time through your account or by emailing support@tagnook.com. Providing false information, or using someone else's contact details as your own, is a breach of our Terms of Service.
15. How to raise a concern or make a complaint
If you have a question or concern about your privacy, please contact our Privacy Officer first at support@tagnook.com. We take complaints seriously, we will investigate, and we will respond.
If you are not satisfied with our response, you may contact the relevant regulator:
- Residents of Québec — Commission d'accès à l'information du Québec (CAI), <https://www.cai.gouv.qc.ca>.
- Residents elsewhere in Canada — Office of the Privacy Commissioner of Canada (OPC), <https://www.priv.gc.ca>.
We will cooperate with these authorities as required by law.
16. Privacy breaches
We maintain safeguards to prevent unauthorized access to, use of, or loss of personal information. If a privacy breach (a "confidentiality incident") occurs that presents a risk of serious harm to you, we will notify you and the appropriate regulator — the OPC and, where applicable, the CAI — promptly, telling you what happened, what information was involved, what we are doing about it, and what you can do to protect yourself. We keep a register of confidentiality incidents as required by law. Because our products involve children, we weigh potential harm carefully in every case.
17. Governing law and your consumer rights
This policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable there. Québec's Law 25 and Québec's Consumer Protection Act apply to Québec residents regardless of this choice. Subject to the following paragraph, you and Tagnook agree to the jurisdiction of the courts located in Toronto, Ontario.
Nothing in this section prevents you from bringing proceedings in the courts of the province or territory where you live. If you live in Québec, you may bring proceedings in Québec, and nothing here waives any right you have to participate in a class action or any right you have under Québec's Consumer Protection Act.
Your statutory rights are preserved. Nothing in this policy excludes, restricts, or modifies any right or remedy you have under applicable privacy or consumer-protection law that cannot lawfully be excluded, including under PIPEDA, Québec's Law 25, and Québec's Consumer Protection Act.
18. French-language version
We serve customers across Canada, including Québec. You can request this policy in French, and service and support in French, at support@tagnook.com. Where Québec law requires the French version to govern for a Québec resident, the French version we provide governs to that extent.
19. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top and, for significant changes, provide a more prominent notice. The current version is always available on our website. Please review it periodically.
20. Contact
Privacy questions, access and deletion requests, and complaints: the Privacy Officer, Tagnook — support@tagnook.com
Orders, returns, shipping, product, recovery, and accessibility: support@tagnook.com
Schools, daycares, camps, teams, wholesale and bulk: sales@tagnook.com
Registered business address: 226 Kinloch Court, Nepean, Ontario K2J 5S9, Canada Telephone: 1 (613) 262-8136
