TyraTag

Privacy Policy

Last updated: August 15, 2026 · Operator: TyraTag Inc.

TyraTag is a QR sticker that helps a first responder or Good Samaritan reach your emergency contacts and see the critical information you choose to share, if you are found unable to speak for yourself. Because that can involve sensitive health information, we hold your privacy to a high standard. This policy explains what we collect, why, who we share it with, and your rights under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Who we are

TyraTag Inc. operates TyraTag. For any privacy question or request, contact support@tyratag.com.

TyraTag is offered across Canada, excluding Quebec: we do not sell to, or open owner accounts for, residents of Quebec. This policy is framed on PIPEDA. Scanning a tag you have found works everywhere and never requires an account.

2. What we collect

Account information you give us: your name, email, and mobile number.

Emergency profile you build: the names and phone numbers of the emergency contacts you choose, and optional information about you.

Sensitive information (only if you choose to add it): blood type, allergies, medical conditions, medications, and free-text notes. You are never required to provide this. You add it only by explicit opt-in.

Scan events:when your tag is scanned we aim to record the time, which tag was scanned, whether it was the emergency or the everyday flow, and whether your medical details were shown, which is what lets you review your own medical-access history. That record is written by the scanner’s browser after the page loads, so a scan made with JavaScript disabled, or by a tool that only fetches the page, can display your information without producing a record. The scan record itself contains no location, device or browser information. As with any website, the scanner’s IP address is visible to the hosting and bot-protection providers listed in our sub-processors list.

Consent records:when you grant or decline a consent — the age/terms attestation, medical sharing, analytics — we record what was decided and when, together with a one-way hash of the originating IP address at that moment, never the IP address itself, so the consent is evidenced as PIPEDA requires.

Payment:handled on Shopify’s secure checkout when you buy a tag. Shopify processes the purchase and returns an order confirmation; we never see or store your full card number.

3. How we protect sensitive information

  • Field-level encryption. Medical fields and contact phone numbers are stored as ciphertext only (AES-256-GCM), never as readable text, at rest.
  • Encrypted in transit everywhere.
  • Progressive disclosure. A person who scans your tag sees only the minimum. Your medical and critical details are revealed only in a genuine emergency branch, only when you have consented, never in the everyday parked-vehicle flow.
  • Data minimization. We keep the least we can. Rate-limit counters expire on their own. A purge routine clears aged technical fields and removes deleted accounts; it is run on a schedule we operate rather than continuously, so removal happens in batches rather than the instant a window closes. Scan records are treated differently on purpose: the purge clears their technical columns but keeps the row, so the time, the tag and whether medical details were shown remain available to you as an access history.
  • Error reports are scrubbedof emails and phone numbers on a best-effort basis before they leave our systems. The filter matches common patterns and can miss unusual formats. It does not cover our hosting provider’s own request and application logs, which record standard technical details such as IP address, browser and page path, plus whatever an error message happens to contain.

4. Why we use your information

To operate your tag; to text your emergency contacts when someone who has scanned your tag chooses to alert them; to show a finder or first responder the information you chose to share; to manage your account and process payment; to prevent abuse and fraud; and to meet legal obligations. We do not sell your personal information.

5. Consent

We rely on your consent. For sensitive (medical) information we require your express, opt-in consent, given separately from account creation. You can do two different things at any time, and they are not the same: you can withdraw consent, which stops those fields being shown to anyone who scans your tag while the data stays in your profile, or you can delete a field, which erases it. Either way your tag continues to run the core emergency-notification rail.

6. Who we share it with

We share the minimum necessary with the service providers that run TyraTag. Each acts on our instructions:

  • Twilio — sends the text messages and verification codes.
  • Supabase and Vercel — host the app and the database.
  • Shopify — runs the checkout when you buy a tag.
  • Cloudflare — bot protection on the finder form at /find, and receives that visitor’s IP address.
  • Upstash — a rate-limit store used to prevent abuse. It sees only hashed request keys.
  • Sentry — monitors errors. Emails and phone numbers are removed on a best-effort basis, but free-text you typed into a medical note can appear in an error report and is not reliably matched by that filter.
  • PostHog — product analytics, only if you opt in. Stored in the United States. Never includes your medical or contact details, and never anything from a tag-scan page.

In a genuine emergency, the emergency contacts and finder you have configured see the information you chose to make visible. We may disclose information if required by law — our Law-Enforcement Guidelines explain what we require and, more importantly, how little we actually hold.

7. Where your information is processed (cross-border)

Some providers process data outside Canada, primarily in the United States. By using TyraTag you understand your information may be stored or processed in the U.S. and may be accessible to U.S. authorities under U.S. law. We use providers that offer contractual and technical safeguards.

8. How long we keep it

Your account and emergency profile: kept for as long as your account is open. When you ask us to delete your account we mark it for deletion straight away and it stops being usable, then erase it and everything it owns when we next run our removal job. There is a short grace window first, so an accidental deletion can be undone.

Scan records: kept as your own access history, so you can see when your tag was scanned and whether your medical details were shown. The removal job clears the technical columns and keeps the row. We are not yet able to state a fixed period for these rows, and we would rather say so than publish a number we do not enforce.

Consent records: the decision itself is kept as long-lived evidence. The hashed IP address on a consent record is not kept long-term: once it is more than thirty days old it is cleared by the same removal job described above.

Verification codes and rate-limit counters: short-lived. These expire on their own in the store that holds them, without needing the removal job.

How removal actually runs. Aged records are cleared by a job we run, rather than by a timer that fires the instant a window closes, so removal happens in batches. We would rather describe this plainly than imply an automation we have not switched on.

We do not retain location data, because we do not collect it.

9. If there is a data breach

If personal information under our control is lost, accessed or disclosed without authorization, and we judge that it creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and notify you directly, as soon as feasible. We will also tell any other organization that could reduce the harm. We keep a record of every breach, including ones that do not meet that threshold.

10. Your rights

You may access the personal information we hold about you, correct it, delete it, withdraw consent, and ask us how it is handled. Two of these you can do yourself, without asking us: you can download a copy of your account data from your settings at any time, and you can delete your account from the same place.

Withdrawing consent and deleting are not the same thing, and section 5 explains the difference — withdrawing stops your medical details being shown to anyone who scans your tag while the data stays in your profile; deleting erases it.

For anything else, email support@tyratag.com from your account address — we authenticate against the account you already have and never make you create a new one. We respond within 30 days. If a request needs longer we will tell you before that deadline, and why. Consumer health data requests run on a different clock, described in our Consumer Health Data Privacy Policy.

You may complain to the Office of the Privacy Commissioner of Canada at any time, and you do not have to come to us first. Our privacy officer can be reached at the address above.

11. Children

You must be 18 or older to hold a TyraTag account, and we do not knowingly collect personal information from anyone under 18 as an account holder. A tag configured for a minor is managed by a parent or guardian, who provides consent on the child’s behalf.

12. Changes

We will post any change here and update the last-updated date. Material changes affecting sensitive data will be notified to you.