Privacy Policy
Last Updated: April 1, 2026
TireSync Inc. ("TireSync," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy describes how we collect, use, disclose, and otherwise handle your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), provincial privacy legislation, and other applicable Canadian privacy laws.
This Privacy Policy applies to all individuals who access or use our Platform at tiresync.ca (the "Platform"), including customers, tire shop partners, and other users.
1. Collection of Personal Information
1.1 Types of Information We Collect
We collect personal information that you voluntarily provide to us, as well as information collected automatically through your use of the Platform.
1.2 Information You Provide
- Account Information: name, email address, password, phone number, physical address, province/territory of residence, and profile picture.
- Booking Information: appointment dates, times, selected services, vehicle information (make, model, year), and tire specifications.
- Payment Information: credit card number, expiration date, and CVV (processed securely through our PCI-DSS compliant payment processor and not stored on our servers).
- Communication Records: messages, support tickets, reviews, ratings, and feedback you provide through the Platform.
- Shop Information (for Partner Shops): business name, contact information, inventory data, pricing, hours of operation, insurance details, and tax identification numbers.
1.3 Information Collected Automatically
- Device Information: device type, operating system, browser type, IP address, and unique device identifiers.
- Usage Data: pages visited, links clicked, time spent on pages, searches performed, and interaction patterns.
- Location Data: approximate geographic location derived from IP address (not precise GPS unless you grant permission).
- Cookies and Similar Technologies: see our <a href="/legal/cookies" className="text-accent hover:underline">Cookie Policy</a> for details.
2. Use of Personal Information
We use the personal information we collect for the following purposes:
- Account Management: creating and maintaining your account, authenticating your identity, and managing account security.
- Service Delivery: processing bookings, managing appointments, facilitating payments, and providing customer support.
- AI-Powered Features: powering tire recommendations, Q&A features, and personalized search results through our AI service provider (Google Gemini).
- Communication: sending transactional emails (booking confirmations, receipts, support responses), operational notices, and with your consent, marketing communications.
- Marketplace Operations: verifying Partner Shop compliance with our Acceptable Use Policy, monitoring for fraudulent activity, and maintaining marketplace integrity.
- Performance Analytics: analyzing platform performance, understanding user behavior, improving functionality, and optimizing the user experience.
- Legal Compliance: complying with applicable laws, regulations, and legal obligations, and responding to lawful government requests.
- Fraud Prevention: detecting, preventing, and investigating fraudulent transactions and unauthorized access.
- Safety: protecting the security and integrity of the Platform and protecting against harm to users.
3. Disclosure and Sharing of Personal Information
3.1 When We Share Your Information
We do not sell, rent, or trade your personal information. However, we disclose personal information in the following circumstances:
- Partner Shops: We share your name, email, phone number, vehicle information, and service preferences with the Partner Shop where you have booked an appointment, solely for the purpose of fulfilling your booking.
- Payment Processors: We disclose payment information to our secure, PCI-DSS compliant payment processor to process transactions.
- Service Providers: We share personal information with third-party service providers who assist us in operating the Platform and providing services, including: (a) Google Gemini for AI-powered recommendations and features; (b) Cloudinary for image storage and optimization; (c) Resend for email delivery; (d) Vercel for platform hosting and content delivery; (e) Neon for database services.
- Legal Requirements: We disclose information when required by law, court order, or government request, or to enforce our Terms of Service and other agreements.
- Safety: We may disclose information to protect the security of the Platform, prevent fraud, or protect against harm to users or the public.
3.2 Third-Party Service Providers
All service providers are contractually obligated to use your personal information solely for the purposes for which they are engaged and to maintain the confidentiality and security of your information. These service providers include:
- Google Gemini: Processes tire recommendation queries and Q&A interactions to provide AI-powered features.
- Cloudinary: Stores and delivers tire images and user profile pictures.
- Resend: Delivers transactional and marketing emails.
- Vercel: Hosts the Platform and delivers content globally.
- Neon: Provides managed database services for user and transaction data.
Each service provider maintains their own privacy policies. We encourage you to review their privacy practices.
4. Consent and Lawful Basis for Processing
4.1 Consent
By creating an account and using the Platform, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy.
4.2 Withdrawal of Consent
You may withdraw your consent to non-essential processing at any time by contacting us at info@tiresync.ca. This may limit your ability to use certain features of the Platform. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.
4.3 Mandatory Information
Certain information is required to provide services (e.g., name, email, booking details). If you do not provide this mandatory information, we cannot create your account or process your booking.
5. Security and Data Protection
We implement industry-standard security measures to protect your personal information, including:
- Encryption: All data transmitted over the internet is encrypted using TLS/SSL encryption.
- Secure Storage: Personal information is stored on secured servers with restricted access.
- Access Controls: Only authorized personnel have access to personal information, and such access is limited to what is necessary to fulfill their roles.
- Regular Audits: We conduct regular security audits and updates to identify and address vulnerabilities.
- PCI Compliance: Payment information is processed through a PCI-DSS compliant third-party payment processor; we do not store complete credit card numbers on our servers.
However, no security system is impenetrable. While we strive to protect your information, we cannot guarantee absolute security. You acknowledge the inherent risks of transmitting information over the internet.
6. Data Breach Notification
In the event of a data breach that compromises the security, confidentiality, or integrity of your personal information and poses a real risk of significant harm, we will:
- Notify you without unreasonable delay (generally within thirty (30) days of discovering the breach).
- Provide information about the nature of the breach, the personal information affected, and the steps we have taken to address the breach.
- Offer information about steps you can take to protect yourself.
Notification will be sent to the email address associated with your account, or by mail if appropriate. We will also notify applicable privacy regulators as required by law.
7. Retention of Personal Information
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or authorized by law.
- Account Information: Retained while your account is active and for seven (7) years after account closure for legal, tax, and audit purposes.
- Booking and Transaction Records: Retained for seven (7) years to comply with consumer protection and tax legislation.
- Payment Information: Credit card details are not stored; transaction records are retained for seven (7) years.
- Marketing Communications: Retained until you unsubscribe.
- Log Files and Usage Data: Retained for up to ninety (90) days, then deleted or anonymized.
8. Access, Correction, and Deletion
8.1 Access to Your Information
You have the right to access the personal information we hold about you. To request access, contact us at info@tiresync.ca. We will provide a copy of your information within thirty (30) days, or as otherwise required by applicable law.
8.2 Correction of Inaccurate Information
You have the right to correct inaccurate personal information. You may update your account information directly through your account settings, or contact us at info@tiresync.ca to request corrections.
8.3 Deletion of Personal Information
You have the right to request deletion of your personal information, subject to legal and operational constraints. We may retain certain information as required by law (e.g., for tax, legal, or consumer protection purposes). To request deletion, contact us at info@tiresync.ca.
8.4 Opt-Out of Marketing
You may opt out of marketing communications by clicking the unsubscribe link in any marketing email or by contacting us at info@tiresync.ca. You will continue to receive transactional communications related to your account and bookings.
9. International Transfers
Some of our service providers (Google Gemini, Vercel) are located in the United States. By using the Platform, you consent to the transfer of your personal information to the United States for processing. While the United States does not have the same level of privacy protection as Canada, our service providers are contractually obligated to maintain the confidentiality and security of your information and to comply with applicable privacy laws.
Your personal information may also be transferred if we are acquired by or merged with another organization, subject to the terms of this Privacy Policy and applicable privacy laws.
10. Quebec Residents
For residents of Quebec, we acknowledge the Quebec Law 25 amendments to the Quebec Law on the Protection of Personal Information (Bill 64) and the standards established by the Commission d'accès à l'information (CAI). You have enhanced privacy rights, including:
- The right to be informed of your rights and obligations regarding personal information.
- The right to access, correct, and delete your personal information.
- The right to withdraw consent at any time.
- The right to lodge a complaint with the CAI if you believe your privacy has been violated.
Where Quebec's privacy standards are more stringent than PIPEDA, we will comply with Quebec's standards.
11. Children's Privacy
The Platform is not intended for children under thirteen (13) years of age. We do not knowingly collect personal information from children under thirteen (13). If we become aware that a child under thirteen (13) has created an account or provided personal information, we will delete such information and close the account without unreasonable delay.
For users between thirteen (13) and eighteen (18) years of age, parental or guardian consent is required. Parents or guardians may contact us at info@tiresync.ca to request deletion of a minor's personal information.
12. Third-Party Links and Services
The Platform may contain links to third-party websites and services (e.g., Partner Shop websites). This Privacy Policy does not apply to third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services before providing your personal information.
13. Updates to This Privacy Policy
We may update this Privacy Policy at any time to reflect changes in our privacy practices or applicable laws. Material changes will be communicated via email or prominent notice on the Platform at least thirty (30) days before they take effect. Your continued use of the Platform after such notice constitutes acceptance of the updated Privacy Policy.
The date this Privacy Policy was last updated is shown at the top of this page.
14. Contact Us
If you have questions about this Privacy Policy, wish to request access to, correction of, or deletion of your personal information, or have privacy concerns, please contact us:
- Email: info@tiresync.ca
- Email (General): info@tiresync.ca
- Website: tiresync.ca
- Mailing Address: TireSync Inc., Canada
For privacy complaints or to request assistance from a privacy regulator, you may file a complaint with the Privacy Commissioner of Canada or your provincial privacy regulator.