Candyll
NearbyDealsLog In

On this page

  • 1. Who Is Responsible for Your Information
  • 2. What We Collect
  • 2A. Email Addresses
  • 3. How We Collect It
  • 4. Why We Use It (Purposes)
  • 5. Consent
  • 6. What Merchants Can See About You
  • 7. Activity-Data Isolation
  • 8. Service Providers
  • 9. Where Your Information Is Stored (Cross-Border Processing)
  • 10. Other Disclosures
  • 11. Cookies and Similar Technologies
  • 12. Marketing Messages and Push Notifications
  • 13. Location
  • 14. How Long We Keep Information (Retention)
  • 15. Deleting Your Account
  • 16. How We Protect Information (Safeguards)
  • 17. Children
  • 18. Your Rights
  • 19. Automated Decision-Making
  • 20. Privacy Incidents and Data Breaches
  • 21. Complaints
  • 22. Changes to This Policy
  • 23. Contact
← All legal documents

Privacy Policy

Version 2.4 · Last updated: July 24, 2026

Operated by Boryne Labs Ltd. (operating as 'Candyll') · Contact: privacy@candyll.com

These documents are provided in English. If a translation is ever offered, the English version governs.

Privacy requests

Submit an access, correction, deletion, consent-withdrawal, complaint or security-incident request and track its status.

Make a privacy request →

privacy@candyll.com

On this page▾
  • 1. Who Is Responsible for Your Information
  • 2. What We Collect
  • 2A. Email Addresses
  • 3. How We Collect It
  • 4. Why We Use It (Purposes)
  • 5. Consent
  • 6. What Merchants Can See About You
  • 7. Activity-Data Isolation
  • 8. Service Providers
  • 9. Where Your Information Is Stored (Cross-Border Processing)
  • 10. Other Disclosures
  • 11. Cookies and Similar Technologies
  • 12. Marketing Messages and Push Notifications
  • 13. Location
  • 14. How Long We Keep Information (Retention)
  • 15. Deleting Your Account
  • 16. How We Protect Information (Safeguards)
  • 17. Children
  • 18. Your Rights
  • 19. Automated Decision-Making
  • 20. Privacy Incidents and Data Breaches
  • 21. Complaints
  • 22. Changes to This Policy
  • 23. Contact

The key points (a plain-language summary — the numbered sections below are what governs)

  • We collect only what we need to run your account, the Deals you Pledge to, your Deal Passes, and your in-person Redemptions.
  • Candyll processes no customer payments. You pay the Merchant directly, at the store, using the Merchant's own payment methods. We never collect or store your payment-card number, security code, or any card or payment data — there is no card to save, because there is no Candyll checkout and Candyll holds no funds.
  • Your written reviews are not public. Only star ratings are shown publicly, in aggregate. Merchants never see your review text, your review photos, or your identity as a reviewer.
  • Merchants see very little about you. A Merchant sees a per-Deal pseudonymous approval reference (for example, "Group Deal Approval #A79F"). For everyday (non-sensitive) categories a Merchant may also see limited masked contact details — currently your first initial and the last four digits of your phone number. For sensitive categories a Merchant sees the pseudonym only. A Merchant never receives your full legal name, email, full phone number, or review photos. See Section 6.
  • To protect Merchants from abuse, we apply light, automated limits on how many Pledges you can hold and short cooldowns after repeated missed Deal Passes. These are not a public score, and no account is suspended automatically — a person reviews any account restriction first. See Section 19.
  • Marketing messages are opt-in only. Marketing is off by default — you opt in from your account settings — and you can unsubscribe at any time. See the Marketing Communications Policy.
  • Location is optional. It powers nearby deals and distances, and it is never sold. See the Location Services Notice.
  • If you delete your account, we deactivate it, cancel any Pledge or booking still in progress, void any unredeemed Deal Pass, and de-identify your personal information within 30 days, except records that tax, consumer-protection, or other laws require us to keep. See the Data Retention & Account Deletion Policy.
  • Questions or concerns go to our Privacy Officer first. If you are not satisfied, you can complain to the privacy regulators for British Columbia (OIPC) or Canada (OPC) — see Section 21.

1. Who Is Responsible for Your Information

Candyll is operated by Boryne Labs Ltd. (operating as 'Candyll') ("Candyll", "we", "us"), whose mailing address is 604-7769 Park Crescent, Burnaby, BC V3N 0J7, Canada. We operate the candyll.com website and the Candyll mobile app (together, the "Platform"). We are responsible for the personal information in our custody or under our control.

We have designated a Privacy Officer who oversees our compliance with this Policy, with British Columbia's Personal Information Protection Act ("PIPA"), and with the federal Personal Information Protection and Electronic Documents Act ("PIPEDA"), each to the extent it applies. You can reach the Privacy Officer at privacy@candyll.com.

A few defined terms used below carry the same meanings as in the Terms of Service and the Deal Pass Terms, and keep those meanings everywhere they appear:

  • A "Customer" is an individual with a Candyll account who browses, Pledges to, or redeems Deals; a "Merchant" is the business listed on the Platform that sells the goods or services and that the Customer pays directly.
  • A "Deal" is a Merchant's offer on the Platform (a Group Deal or a Slot Booking).
  • A "Pledge" is your free expression of intent to take part in a Group Deal. Pledging is not a payment and not a purchase; no card is saved and no money is taken.
  • "Final Confirmation" is the separate step in which you confirm you still intend to redeem, so that you count toward the group price threshold. Final Confirmation is not a completed purchase and not a guaranteed sale.
  • "Final Locked Price" is the per-participant group price fixed when a Group Deal reaches its threshold; it is the price a Merchant must honour for a valid Deal Pass.
  • A "Deal Pass" is an eligibility credential issued to you after the price locks. It is not money, a payment method, prepaid or stored value, a gift card, store credit, or a coupon balance, and it does not represent any amount Candyll holds.
  • "Redemption" is using a valid Deal Pass in person at the Merchant, where the Platform verifies your eligibility and you then pay the Merchant directly.
  • "pay-at-store" is the model on which the whole Platform operates: the underlying purchase is paid by the Customer directly to the Merchant, normally in person at the store. Candyll processes no payment for any Deal.

This Policy is incorporated into the Terms of Service. On the subject of personal-information handling, this Policy prevails over the Terms of Service. Nothing in this Policy limits any right you have under applicable law that cannot be waived; if anything here conflicts with such a right, the right prevails.

2. What We Collect

We collect only the information reasonably necessary to provide and improve the Platform.

From Customers:

  • Account information — email address, password (held by our authentication provider only in one-way hashed form; we never see it in plain text), display name, optional profile image, phone number (used for account security and, in masked form, for in-store disambiguation — see Section 6), language preference, and account timestamps.
  • Verification data — short-lived one-time email codes and authentication tokens used to sign you in; discarded once used or expired.
  • Deal activity data — your Pledges (joins), your Final Confirmations, the Deals you qualified for, your waitlist entries and claims, your Deal Passes and their status (issued, redeemed, expired, or disputed), Redemption records (whether and when a Deal Pass was redeemed at a Merchant), cart contents, favourites, and followed stores. Candyll does not collect or store customer payment-card data, card security codes, payment tokens, or any purchase, charge, or refund transaction records — because the purchase is paid directly to the Merchant at the store and never passes through Candyll.
  • Deal Pass usage-flow data — records created when you redeem a Deal Pass in person: QR scan events (recorded only where scan logging is enabled — the time of the scan, the store location scanned, and limited device signals), short-lived usage-preparation session records (which expire within minutes if you do not proceed), the record of your deliberate "Use Deal Pass" confirmation, the outcome of any optional in-store verification step (for example, that a staff-PIN check succeeded or failed — never the PIN itself, which belongs to Merchant staff and is held only in one-way hashed form), and any usage-dispute report, review, and reversal/correction record. These records document Deal Pass eligibility and use only; they are never payment records, and Candyll never records that you paid the Merchant.
  • Reliability signals — lightweight counters used to limit abusive Pledging (for example, how many active Pledges you hold, and short cooldowns after repeated missed Deal Passes). These are used only to protect Merchants from abuse; they are not a public score, and any account restriction is reviewed by a person before it takes effect (see Section 19).
  • Reviews and ratings — star ratings, written review text, tags, and any photos you attach. See Section 4 and Section 6 for exactly who can see what.
  • Location data — only if you grant permission, and only as described in the Location Services Notice.
  • Device and usage data — IP address, device type, operating system, app version, browser type, language, crash logs, and security logs needed for reliability, security, and fraud prevention.
  • Push-notification token — only if you enable push notifications.
  • Communications — messages you send to our support, security, or privacy contact addresses.
  • Consent records — when and how you gave each consent and which version of our terms and policies you accepted.

From Merchants and Merchant Staff:

  • Business information (business name, address, contact details, hours, images, and any tax registration numbers the Merchant chooses to provide), the names, email addresses, and roles of staff members the Merchant authorizes, and Merchant activity on the Platform.

What we deliberately do not collect from Customers: government-issued identification, social insurance numbers, payment-card numbers, card security codes, bank-account details, biometric information, health information, or other sensitive categories of personal information. Because Candyll runs no customer checkout, we collect no customer payment or card data of any kind.

2A. Email Addresses

Your email address is the main piece of contact information Candyll holds about you, so this section sets out separately — for Customers, Merchant owners, and Merchant Staff — why we collect it, whether you have to give it, who can see it, and what we do and do not do with it.

Why we collect it. We collect and use an email address as personal information for these operational purposes only:

  1. Account registration and authentication — creating your account and signing you in, including one-time sign-in codes.
  2. Security and account recovery — password resets, sign-in and security alerts, and restoring access to an account you are locked out of.
  3. Customer and Merchant support — receiving, answering, and following up on the questions and problems you send us.
  4. Legal notices — notices about changes to our terms and policies, and other notices we are required or permitted to give you.
  5. Privacy requests — receiving, verifying, tracking, and answering the access, correction, deletion, consent-withdrawal, complaint, and security-incident requests described in Section 18, and contacting you about a privacy incident (Section 20).
  6. Booking or service communications, where necessary — messages about a Deal, Deal Pass, or Slot Booking of yours, where an in-app or push notice is not available or is not enough on its own.
  7. Fraud and abuse prevention — investigating suspicious activity and protecting accounts, Customers, and Merchants.
  8. Merchant onboarding and verification — establishing and verifying a Merchant's legal identity, authorized signatory, and any category licence required before a Deal can be published, and communicating with the Merchant's owner and authorized staff about that account.
  9. Regulatory or legal compliance — meeting Candyll's own legal, tax, and regulatory obligations, and establishing, exercising, or defending legal claims.

Whether it is required. Yes. An email address is required to create and keep a Candyll account: it is how we authenticate you, how we can restore your access, and how we deliver notices the law requires. If you withdraw it or ask us to erase it while your account is open, we can no longer operate the account. A Merchant must also provide a working business email address, and a Merchant Staff member must have one to be granted access.

Who can access it. Inside Candyll, only authorized personnel who need it for one of the purposes above — support, security, privacy, and merchant onboarding — under the least-privilege access controls in Section 16, with access to sensitive identity data recorded in an access log. Outside Candyll, only the service providers named below, on our instructions. A Merchant never receives a Customer's raw email address, and no merchant-facing screen, export, or report exposes it: the pseudonymized Merchant view described in Section 6 is the default and stays the default. A Merchant does see the email addresses of the staff it authorizes on its own account, because it supplies them.

Service providers involved. Your email address is stored with Supabase (authentication and database) and, when we actually send you a message, processed by Resend (outbound email delivery); Cloudflare carries traffic to and from the Platform. Section 8 and Section 9 describe these providers and where they operate. We never sell, rent, trade, or share an email address with an advertising network, a data broker, or another business for that business's own marketing.

Whether it is used for marketing. Marketing is off by default and opt-in only, and you opt in from your account settings — see Section 12 and the Marketing Communications Policy. We do not use an operational email address (an address you gave us to run your account, get support, receive legal notices, make a privacy request, or complete Merchant onboarding) to send you marketing without a valid legal basis and the consent, identification, and unsubscribe requirements of Canada's Anti-Spam Legislation ("CASL"). At launch Candyll operates no automated promotional email program at all: product-generated promotional email is disabled and bulk promotional email is prohibited pending a separate CASL activation review. Operational messages stay operational — we do not add unrelated Deal recommendations, discounts, or promotional taglines to them.

Retention and deletion. We keep your email address for the life of your account. If you delete your account, it is deleted or de-identified within 30 days, along with the rest of your identifying information (Section 15). Consent and acceptance records showing which messages you agreed to receive are kept for 3 years after deletion or withdrawal; support correspondence is kept for 2 years after the matter closes; and an email address that appears inside a record Candyll must keep by law is segregated with restricted access and destroyed when that period ends (Section 14 and the Data Retention & Account Deletion Policy).

Security safeguards. Email addresses are protected by the safeguards in Section 16 — encryption in transit and at rest, least-privilege and row-level access controls, need-to-know staff access, logging, and the masking that keeps full name, email, and full phone out of every merchant-facing surface.

Your access and correction rights. You can view and change the email address on your account in your account settings, and you can ask us what we hold, ask us to correct it, or ask us to delete it under Section 18. Send requests to privacy@candyll.com or file them from the privacy section of your account; we respond within 30 days.

3. How We Collect It

  • Directly from you — when you create an account, Pledge to a Deal, complete Final Confirmation, book a slot, redeem a Deal Pass, write a review, adjust settings, or contact us.
  • Automatically from your device — technical data such as IP address and crash logs when you use the Platform, and location only with your permission.
  • From our service providers — for example, our authentication provider confirms your sign-in. No payment processor reports charges to us, because Candyll runs no customer payments and holds no funds.

We do not buy personal information from data brokers and we do not collect information about you from social networks.

4. Why We Use It (Purposes)

We use personal information only for the following purposes:

  1. Accounts — to create, authenticate, secure, recover, and operate your account.
  2. Showing you Deals — to display Deals, distances, and search results, including nearby results if you enable location.
  3. Pledges, Final Confirmation, and Deal Passes — to record your Pledges and Final Confirmations, count you toward a Group Deal's threshold, notify you when a Deal locks or does not lock, issue your Deal Pass when a group price locks, and send you a durable copy of it.
  4. Redemption — to verify your eligibility in person at the Merchant and to record that a Deal Pass was redeemed. Candyll processes no payment at Redemption; you pay the Merchant directly at the store.
  5. Reviews — to publish star ratings in aggregate and to operate the review system. Your written review text is visible only to you and to Candyll (for moderation); Merchants see anonymized review entries (the star rating, tags, date, and whether written feedback exists — never the text itself) and aggregate statistics — never the review text, never the review photos, and never who wrote it.
  6. Support — to answer your questions and resolve problems, including Deal Pass and Redemption-eligibility questions.
  7. Safety, security, fraud prevention, and reliability limits — to detect and respond to fraud, abuse, security incidents, and violations of the Terms of Service, and to apply the light, automated Pledge caps and cooldowns described in Section 19. These limits are not a public score, and any account restriction is human-reviewed.
  8. Service improvement — internal analytics using aggregated or de-identified data that does not identify you.
  9. Marketing — only with your express opt-in consent, as described in the Marketing Communications Policy.
  10. Legal compliance — to meet tax, accounting, consumer-protection, and other legal obligations that apply to Candyll's own operations, to give you the notices this Policy, the Terms of Service, or the law requires, to receive and answer privacy requests and complaints (Section 18), and to establish or defend legal claims.
  11. Merchant onboarding and verification — to establish and verify a Merchant's legal identity, its authorized signatory, and any category licence required before a Deal can be published, and to communicate with the Merchant's owner and authorized staff about that account.

We will not use your personal information for a new purpose without first obtaining your consent, unless the use is permitted or required by law.

Where any of these purposes involves your email address, Section 2A sets out the specifics — the full list of email purposes, whether email is required, who can access it, retention, and the limits on marketing use.

5. Consent

How we obtain consent depends on the sensitivity and the purpose:

  • Necessary for the service. When you create an account, Pledge to a Deal, or redeem a Deal Pass, you provide the information voluntarily for an obvious purpose; your consent to use it for that purpose is implied by law and by the contract between us (for example, we cannot record your Pledge or issue your Deal Pass without your Deal details).
  • Express consent. We ask for separate, active, opt-in consent for: marketing communications (off by default — you opt in from the notification preferences in your account settings, and nowhere else; see the Marketing Communications Policy), device location (your operating system or browser permission prompt — see the Location Services Notice), and push notifications (your operating system permission).
  • Not bundled. We never bundle marketing consent into acceptance of the Terms of Service, we never ask for it as part of creating your account, and we never make marketing consent a condition of taking part in any Deal.

You may withdraw any consent at any time, subject to legal or contractual limits and reasonable notice, by adjusting your settings or contacting the Privacy Officer. Withdrawing consent that is necessary for the service (for example, consent to process your Pledge or Deal Pass for a Deal in progress) may limit what we can provide. We keep records of the consents you give so we can prove and honour them.

6. What Merchants Can See About You

Candyll is built so that a Merchant learns as little about you as possible. Because you pay the Merchant directly at the store, the Merchant already knows what it needs for the sale itself; from Candyll, a Merchant receives only what it needs to recognize a valid participant and honour the Final Locked Price. Candyll does not provide Merchants with unrestricted access to Customer profiles, cross-Merchant activity, or Customer reliability history.

What a Merchant sees about you through Candyll:

  • a per-Deal pseudonymous approval reference — a short, stable, non-reversible code shown as, for example, "Group Deal Approval #A79F". It identifies you to the Merchant only within that one Deal and cannot be used to look you up elsewhere;
  • your Pledge / order details for that Deal (for example, quantity, and the slot or appointment time for a Slot Booking);
  • Deal Pass Redemption status for that Deal (for example, valid and unredeemed, redeemed, or expired);
  • Deal Pass usage and dispute records for its own store, shown under the same pseudonymous approval reference: when a Merchant views its in-store usage activity (scans, usage sessions, recorded uses) or reviews or reports a usage dispute, it sees your pseudonym only — and for sensitive categories, any free-text detail is suppressed as well.

Additional disambiguation, by category:

  • For everyday (non-sensitive) categories, a Merchant may also see limited masked contact details — currently your first initial and the last four digits of your phone number — so staff can tell two participants apart at the counter.
  • For sensitive categories — beauty, fitness/wellness, and any future hospital, clinic, massage, or adult categories — a Merchant sees the pseudonymous approval reference ONLY. No initial and no phone digits are shown; you disambiguate yourself by presenting your Deal Pass.

What a Merchant never receives: your full legal name, your email address, your full phone number, your password, your device or push token, your precise location, your reliability signals, or your review photos. For reviews, a Merchant sees anonymized review entries (the star rating, tags, date, and whether written feedback exists — never the text itself) and aggregate statistics — average star rating, rating counts, and tag counts — never the review text, never the review photos, and never who wrote it. There is also no payment information for Candyll to share, because Candyll collects and holds none.

7. Activity-Data Isolation

To operate group unlocks, Deal Pass Redemption, and fraud prevention, Candyll records limited activity data — for example, offline-visit and Redemption records, Deal Pass usage-flow records (QR scan events, usage-preparation sessions, recorded uses, and usage-dispute records — see Section 2), and category-level Deal activity (which Deal a Pledge, Final Confirmation, or Redemption relates to).

We handle this activity data under strict limits:

  • Defined internal purposes only. We use activity data solely for (a) operating group unlocks, Deal Passes, and in-store Redemption, (b) preventing and investigating fraud and abuse, and (c) keeping Candyll's own Deal, Deal Pass, and usage records accurate and reconciled — never for any payment, settlement, or referral-reward purpose, because Candyll processes no payments and operates no referral-reward program. We do not use it to build advertising profiles, and we do not sell it.
  • Isolated per Merchant. A Merchant's activity data is separated from every other Merchant's. Access controls (row-level rules) scope each Merchant, its owner, and its authorized staff to that Merchant's own records only.
  • Never shared between Merchants; never public. One Merchant can never see another Merchant's activity data — including participant demand, Redemption counts, or unlock signals — and this data is never exposed publicly.

8. Service Providers

We use a small number of service providers ("processors") to run the Platform. Each processes personal information only on our instructions and under contractual privacy and security obligations:

  • Supabase — authentication, database, and file storage (infrastructure located in the United States and/or Canada).
  • Cloudflare — website hosting, content delivery, DNS, and security protection (global network).
  • Resend — outbound email delivery (United States).
  • Expo, with Apple and Google — push-notification delivery to mobile devices (United States and global).
  • OpenFreeMap — map tile rendering for map views (Europe; receives standard connection data such as IP address; no account information is sent).

Candyll does not use a payment processor for your purchases. Because you pay the Merchant directly and no customer payment passes through Candyll, there is no card handling, saved-card storage, settlement, or payout processor in the loop for your Deals.

If we add or replace a provider that materially changes how your information is handled, we will update this Policy.

9. Where Your Information Is Stored (Cross-Border Processing)

Some of our service providers store or process personal information outside Canada, primarily in the United States. While your information is in another country, it is subject to the laws of that country, and courts, law-enforcement, and national-security authorities there may be able to compel access to it under those laws.

We use providers that commit contractually to protections comparable to those required in Canada, and we use industry-standard encryption in transit and at rest. If you have questions about our cross-border practices, contact the Privacy Officer.

10. Other Disclosures

We may disclose personal information without additional consent only where permitted or required by law, including:

  • to comply with a valid court order, subpoena, warrant, or other lawful demand from a Canadian court or authority with jurisdiction;
  • to detect, investigate, or prevent fraud, security incidents, or threats to any person's safety;
  • to establish, exercise, or defend legal claims;
  • to a prospective or actual buyer or lender in a business transaction (such as a merger, financing, or asset sale), with safeguards, and with notice to you where the law requires it;
  • in aggregated or de-identified form that cannot reasonably be used to identify you.

We do not sell personal information. We do not share it with data brokers or advertising networks, and we do not engage in cross-context behavioural advertising.

Complaints about content, including copyright complaints. Candyll operates a copyright complaint, notice-forwarding, evidence-preservation, and content-restriction process (see the Review & User Content Policy, Section 10). When someone complains that content on the Platform infringes their rights, we may need to tell the person who uploaded it what the complaint says, so that they can respond. We do not give a claimant the uploader's identity, email address, or other personal information without that person's consent, lawful authority, a court order, or another valid legal basis — and we log any such disclosure. Where a complaint requires us to preserve records capable of identifying an uploader, those records are held under restricted access for the period described in the Data Retention & Account Deletion Policy and are used only for that purpose.

11. Cookies and Similar Technologies

The website uses essential cookies only: sign-in and session management, security (for example, protection against request forgery), and remembering your language. We do not use advertising cookies, third-party analytics trackers, or tracking pixels. Because we use only essential cookies, there is no cookie-consent banner to click — but if you block cookies in your browser, signing in may not work.

12. Marketing Messages and Push Notifications

We separate service messages (Deal unlocked / not-unlocked notices, Deal Pass issued notices, Redemption reminders, security and account alerts — sent because they are part of the service you asked for) from marketing messages (promotions and feature news — sent only if you opt in).

The full rules — the settings-only opt-in, sender identification, the unsubscribe promise, and your push-notification controls — are in the Marketing Communications Policy, which forms part of this Policy for personal-information purposes. Marketing stops immediately if you delete your account.

Where marketing stands today. Marketing is off by default and you turn it on only from the notification preferences in your account settings; there is no marketing checkbox anywhere in signing up. At launch Candyll runs no automated promotional email program: product-generated promotional email is disabled, and bulk promotional email is prohibited until a separate CASL activation review is completed. The service messages listed above, together with support, security, privacy, legal, and Merchant-onboarding correspondence, remain operational in nature and carry no promotional content — we do not insert unrelated Deal recommendations, discounts, or promotional taglines into them. If we later begin promotional outreach, it will run on a documented consent or other lawful basis, with sender identification, a working unsubscribe, and a suppression process, as set out in the Marketing Communications Policy.

13. Location

Location is optional and off until you grant permission. If you enable it, we use your device location to show nearby Deals, distances, map views, and directions to a Merchant. We do not track you in the background, we do not build a history of your movements, we do not share your location with Merchants, and we never sell location data. Full details, including how to turn it off and what works without it, are in the Location Services Notice.

14. How Long We Keep Information (Retention)

We keep personal information only as long as reasonably necessary for the purposes above and to meet legal obligations, then we delete or de-identify it. In brief:

  • account information — for the life of your account;
  • your email address — for the life of your account, then deleted or de-identified within 30 days after account deletion; consent and acceptance records for 3 years after deletion or withdrawal; support correspondence for 2 years after the matter closes (see Section 2A);
  • Pledge, Deal Pass, and Redemption records — for as long as reasonably necessary for the purposes in Section 4 and Section 7 (operating Deals and Redemption, dispute handling, and fraud prevention), then deleted or de-identified;
  • booking-contract snapshots (the fixed copy of the terms of a Slot Booking) — kept with the Deal Pass record they belong to; a snapshot is a write-once record that is never edited, and it contains no name, email address, or phone number;
  • records Candyll must keep for its own tax and accounting obligations (for example, records of Candyll's own fees to Merchants, if and when such fees begin — there are none at launch) — approximately 7 years from the end of the year they relate to, the period we apply for Canadian tax and accounting record-keeping;
  • dispute, reliability, and abuse-investigation records (including usage-dispute and reversal/correction records) — at least as long as legal claim periods require;
  • privacy-incident records — at least 24 months, or longer where the law or a legal hold requires (Section 20);
  • copyright and content-complaint records — kept while the complaint is open and then for the conditional statutory period described in the Data Retention & Account Deletion Policy (six months from receipt of a notice, extending to one year where notice of proceedings is received and the statutory condition applies);
  • Deal Pass usage-flow records — usage-preparation sessions expire within minutes; operational QR-scan and verification-attempt logs are kept typically 30–90 days, longer only for an active investigation;
  • security and server logs — typically 30–90 days;
  • information used to make a decision about you — at least one year, so you can ask to see it.

The full schedule by record class, and the criteria we apply, are in the Data Retention & Account Deletion Policy.

15. Deleting Your Account

You can delete your account in your account settings or by writing to the Privacy Officer. Deletion works like this:

  1. your account is deactivated — you can no longer sign in, your profile is no longer visible, push notifications stop, and marketing stops immediately;
  2. your live activity is closed out in the same step — any Pledge or booking still in progress is cancelled (which releases your place, so waitlisted Customers can be offered it), and any Deal Pass you hold that has not been redeemed is voided;
  3. your deletion is recorded as a privacy request — with its own reference, received date, and 30-day response deadline, and tracked as described in Section 18;
  4. your identifying personal information is deleted or de-identified within 30 days — this includes your account details and the written text and photos of your reviews; your star ratings stay in the Merchant's aggregate figures, with nothing left that identifies you;
  5. records we are legally required to keep (for example, records needed for an open dispute or fraud investigation, and any records tied to Candyll's own tax and accounting obligations) are segregated with restricted access and kept only for their required period, then destroyed on schedule.

Deletion of your account is permanent in the sense that it cannot be reversed and your profile cannot be restored; it does not erase the legally retained records described above. Deleting your account does not undo any in-store purchase you already completed with a Merchant — that purchase, its receipt, and any refund or exchange are between you and the Merchant. Full details are in the Data Retention & Account Deletion Policy.

16. How We Protect Information (Safeguards)

We apply administrative, technical, and physical safeguards proportionate to the sensitivity of the information, including:

  • encryption in transit (TLS) and at rest;
  • database access controls enforcing least-privilege, row-level rules — including the per-Merchant isolation described in Section 7 and the masking that keeps full name, email, and full phone out of every merchant-facing surface (Section 6);
  • passwords kept solely in one-way (salted-hash) form;
  • no customer payment-card data in our systems at all — because there is no Candyll checkout, there is no card number or security code for us to store or protect;
  • staff access limited to a need-to-know basis;
  • an access log for sensitive operations — where an authorized administrator needs to see identity information behind a pseudonymous reference (for example, to investigate a dispute or answer a privacy request), the access is recorded first, in an append-only log, with who did it and why;
  • hardened web security controls and authentication checks on sensitive routes;
  • monitoring, logging, and the written incident-response process described in Section 20.

No system is perfectly secure, and we cannot guarantee absolute security — but we are committed to the safeguards above and to the breach-response commitments in Section 20. Guidance on protecting your own account is in the Account Security Policy.

17. Children

You must be at least 19 years old to hold an account. The Platform is not directed at children, we do not knowingly collect personal information from children, and if we learn that we hold a child's personal information we will delete it. If you believe a child has created an account or provided us personal information, contact the Privacy Officer.

18. Your Rights

Subject to limited legal exceptions, you have the right to:

  • Access — ask what personal information we hold about you, how we use it, and to whom it has been disclosed, and receive a copy in an understandable and, where reasonably possible, portable form;
  • Correction — have inaccurate or incomplete information corrected;
  • Withdrawal of consent — as described in Section 5;
  • Deletion — delete your account as described in Section 15;
  • Explanation — ask questions about, and challenge, our compliance with this Policy and applicable privacy law.

Send requests to privacy@candyll.com, or submit them from the privacy section of your account on the Candyll website. We may need to verify your identity before acting on a request — this protects you; a request you submit from inside your signed-in account is already identified to us. We respond within 30 days; if we need longer, we will tell you why and when to expect our response. Where the law permits a minimal fee for an access request, we will give you a written estimate first and proceed only if you agree. If we refuse a request in whole or in part, we will explain the reason and the recourse available to you.

How we handle and track your request. Candyll operates a single privacy-request process for six kinds of request: an access request, a correction request, an account deletion request, a consent withdrawal request, a privacy complaint, and a security incident report. Each request we receive is recorded with:

  • a request reference you can quote to us;
  • who the request is from and that the requester has been verified;
  • the type of request and the date we received it;
  • the Candyll person it is assigned to and its current status (received, in review, waiting for information from you, completed, or refused);
  • a response deadline of 30 days from the day we received it;
  • the record of our response and the date the request was completed; and
  • a history of the steps taken, so the handling of the request can be audited afterwards.

Requests you submit from your account are visible to you there — you can see the reference, the type, the status, the 30-day deadline, and, once it is finished, our recorded response. Deleting your account also files a deletion request automatically, so it is tracked in the same way (Section 15). Our Privacy Officer at Boryne Labs Ltd. (operating as 'Candyll') is responsible for this process; the contact details are in Section 23.

19. Automated Decision-Making

We use limited automated processing to (a) screen activity for fraud and abuse, (b) rank and sort Deals for display, and (c) apply lightweight reliability limits that protect Merchants from abusive Pledging.

The reliability limits work like this: after you miss a Deal Pass (let it expire unused), we may temporarily reduce how many active Pledges you can hold, and after repeated missed Deal Passes in a short period we may apply a short Pledging cooldown before you can make new Pledges. These limits are not a public score or rating, are not shown to Merchants or other Customers, and are not an account suspension. Cancelling before a Deal's deadline never counts against you. The current numbers, and when a limit applies to you, are shown in the app and described in the Terms of Service (Section 26) and the Merchant Terms (Section 15).

We do not use automated systems to suspend or close accounts, or to make other decisions with significant effects on you, without human involvement — any account suspension or restriction is reviewed by a person before it takes effect. You may contact us at any time to ask for a human review of any determination that affects your account.

20. Privacy Incidents and Data Breaches

We maintain a written privacy-incident response process, and we treat more than hacking as an incident — a wrong-recipient message, an access-control error that lets the wrong person see a record, an exposed key, or a failure to delete information on schedule all count.

How we handle an incident. When an incident is reported or detected, we identify and contain it (for example, by disabling the affected function, revoking sessions, rotating credentials, or correcting an access rule, while preserving the evidence), assess it (what happened, when, which systems and people are affected, which categories of information were involved, how sensitive they are, whether the information was actually viewed or copied, and whether any notification duty applies), record it in a restricted internal incident register, notify where required or appropriate, remediate the root cause, and close the incident with a documented review. Named internal roles are responsible for each of these steps — a Privacy Officer, an incident owner, a technical containment owner, and the person who decides on notification — with a documented backup for each. Material changes to an incident record are audit logged.

When we notify you. Notification is not automatic for every incident: it depends on an assessment of the risk. Where PIPEDA applies, if a breach of our security safeguards creates a real risk of significant harm to you, we will notify you and report to the Office of the Privacy Commissioner of Canada as soon as feasible, and we will notify any other organization or authority that can reduce the harm. Where affected individuals are in British Columbia, we will also assess notification to the BC Information and Privacy Commissioner in line with its guidance. Where an assessment concludes that notification is not required, we record the reasons for that conclusion. We will always act as required by applicable law as it stands at the time of the incident.

How we would contact you. We use a method reasonably likely to actually reach you, given the urgency and the contact information we hold — normally a direct in-app notice and an email to the address on your account, and where warranted a push notification, a phone call, or, only where the law permits and it is appropriate, a public notice. We do not rely on push notifications alone, because you may have turned them off or removed the app.

Records we keep. We maintain a record of every breach of our security safeguards, including incidents that fall below any reporting threshold, and we keep each incident record for at least 24 months — longer where a legal hold or another legal requirement applies. Incident records are restricted to authorized personnel; Merchants and ordinary account holders cannot access them. We keep only the affected-person detail the record actually needs.

Reporting something to us. If you believe your information has been exposed or that someone else's information was disclosed to you, tell us at privacy@candyll.com or file a security-incident report from the privacy section of your account — it is tracked like any other privacy request under Section 18.

21. Complaints

If you have a privacy concern, please contact our Privacy Officer first at privacy@candyll.com — most issues can be resolved directly. If you are not satisfied with our response, you may complain to:

  • Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) — oipc.bc.ca;
  • Office of the Privacy Commissioner of Canada (OPC) — priv.gc.ca, 1-800-282-1376.

Which regulator applies depends on the information flow involved; either office can direct you to the right one.

22. Changes to This Policy

We may update this Policy as the law, our technology, or our practices change. We will post the updated version with a new version number and effective date, and for material changes we will give you reasonable advance notice by email or in-app message. Each version applies from its stated effective date.

23. Contact

Privacy Officer Boryne Labs Ltd. (operating as 'Candyll') Mailing address: 604-7769 Park Crescent, Burnaby, BC V3N 0J7, Canada privacy@candyll.com

For account security issues: see the Account Security Policy. For legal notices: admin@candyll.com.