PopupReach Back to site
Legal & Privacy

PIPEDA Compliance Statement & Consent Framework

How PopupReach complies with Canada's PIPEDA and the 10 Fair Information Principles, and how consent is implemented across the platform.

Version 1.0Effective July 20, 2026PopupReach Inc., Winnipeg, Manitoba, Canada
Privacy PolicyTerms of ServicePIPEDA & Consent

This document describes how PopupReach Inc. complies with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5) and its associated regulations, and how we implement consent for the collection, use, and disclosure of personal information through the PopupReach platform.

1. Overview and Commitment

PopupReach Inc. is committed to protecting the personal information of all individuals who interact with our platform — including merchant account holders and the consumer participants who engage with merchant campaigns. We recognize our obligations under PIPEDA and the 10 Fair Information Principles established in Schedule 1 of PIPEDA as the foundation of our privacy practices.

This PIPEDA Compliance Statement is provided in addition to our Privacy Policy and is intended to clearly articulate how each of the 10 Fair Information Principles is implemented in our operations.

2. The 10 Fair Information Principles — How PopupReach Implements Each

Principle 1 — Accountability

PopupReach Inc. is responsible for personal information under its control. The Founder and CEO, Espoir Kajabika, serves as the designated Privacy Officer accountable for PopupReach's compliance with PIPEDA. Contact: privacy@popupreach.com.

Third-party service providers (Clerk, Stripe, Supabase, Vercel, Railway) who process personal information on PopupReach's behalf are bound by contractual data processing agreements that require compliance with PIPEDA-equivalent standards.

Merchants who collect Consumer Data through the PopupReach platform are independent data controllers responsible for their own PIPEDA compliance with respect to Consumer Data.

Principle 2 — Identifying Purposes

PopupReach identifies the purposes for which personal information is collected before or at the time of collection. The purposes are documented in our Privacy Policy (Section 3) and summarized below:

  • Merchant account information: to create and manage accounts, process payments, deliver the Services, and provide customer support
  • Campaign performance data: to provide analytics, measure campaign effectiveness, and improve the Platform
  • Consumer phone numbers (opted-in): to enable the merchant to build an owned customer audience and send future promotional messages
  • Technical/log data: to maintain platform security, diagnose technical issues, and measure performance

If PopupReach wishes to use personal information for a materially different purpose than originally identified, we will obtain fresh consent or provide notice and opportunity to withdraw.

Principle 3 — Consent

Merchant Consent

Merchants provide express consent at account registration through acceptance of our Terms and Conditions and Privacy Policy. This consent covers all uses described in those documents. Merchants may withdraw consent by closing their account (subject to legal retention obligations).

Consumer Participant Consent

Consumer phone number capture is the primary personal data collection point involving Consumer Participants. PopupReach implements the following consent framework:

  • Consumer Participants are never required to provide a phone number to claim a deal or receive a QR code — the claim flow is completed before any personal information is requested
  • After redemption, Consumer Participants are presented with a PIPEDA-compliant consent interface that includes: (a) a clear explanation of who is collecting the information (the specific merchant, by name); (b) the purpose of collection (to receive future promotional offers from that merchant); (c) an explicit opt-in checkbox (pre-unchecked); and (d) information about how to unsubscribe
  • No pre-ticked boxes, dark patterns, or bundled consent is used
  • A record of consent (timestamp, merchant ID, campaign ID) is stored in the PopupReach database

PopupReach's consent architecture ensures that a Consumer Participant who does not wish to join a merchant's audience can claim and redeem their deal without providing any personal information beyond what is technically necessary to deliver the QR code.

Implied Consent

We rely on implied consent for technical data collection (log data, session cookies) that is clearly necessary to operate the platform and would reasonably be expected by users. This is disclosed in our Privacy Policy and Cookie Policy.

Principle 4 — Limiting Collection

PopupReach collects only the personal information necessary for the identified purposes. Specific limits include:

  • Merchant accounts: we do not collect government-issued ID, social insurance numbers, or sensitive personal information not required to deliver the Services
  • Consumer participants: we collect only phone number (optional, opt-in only), claim/redemption timestamp, and associated campaign ID — not name, email, address, or payment information
  • No precise geolocation: we do not collect GPS coordinates. Approximate location derived from IP address is used only for platform analytics and is not disclosed to merchants
  • No behavioural profiling: we do not build individual consumer profiles or track consumers across merchant campaigns

Principle 5 — Limiting Use, Disclosure, and Retention

Personal information is used only for the purposes for which it was collected, except with consent or as required by law. Specific commitments:

  • Consumer phone numbers collected for Merchant A are not used for Merchant B's campaigns
  • Merchant account information is not sold to or shared with third parties for marketing purposes
  • Aggregated and de-identified data may be used for platform improvement and industry reporting — this data does not identify individuals

Retention periods are specified in our Privacy Policy (Section 6). Personal information is securely deleted when no longer required for its identified purpose or as required by law.

Principle 6 — Accuracy

PopupReach maintains reasonable procedures to ensure personal information is accurate, complete, and up-to-date:

  • Merchants can update their account information at any time through the platform dashboard
  • Merchants are responsible for the accuracy of Consumer Data collected through their campaigns
  • Individuals may request correction of inaccurate information by contacting privacy@popupreach.com

Principle 7 — Safeguards

PopupReach protects personal information with security safeguards appropriate to the sensitivity of the information. Safeguards include:

  • Technical: TLS 1.2+ encryption in transit; encryption at rest in Supabase (PostgreSQL); bcrypt password hashing via Clerk authentication
  • Access controls: role-based access controls; principle of least privilege; multi-factor authentication support
  • Organizational: privacy and security training for all personnel with access to personal data; vendor security assessments
  • Physical: data hosted in SOC 2 compliant data centres operated by AWS (via Supabase) and Vercel
  • Incident response: documented security incident response plan; breach notification procedures consistent with PIPEDA's breach reporting requirements

In the event of a privacy breach that creates a real risk of significant harm to individuals, PopupReach will report the breach to the Office of the Privacy Commissioner of Canada and notify affected individuals as required by PIPEDA's Breach of Security Safeguards Regulations.

Principle 8 — Openness

PopupReach makes information about our privacy practices readily available through:

  • Privacy Policy: published at popupreach.com/privacy
  • Terms and Conditions: published at popupreach.com/terms
  • PIPEDA Compliance Statement: published at popupreach.com/pipeda
  • In-product consent notices: displayed at the point of consumer phone number capture
  • Direct response: privacy@popupreach.com for any questions about our practices

Principle 9 — Individual Access

Upon written request, PopupReach will inform individuals of the existence, use, and disclosure of their personal information and provide access to that information within 30 days. Requests must be submitted to privacy@popupreach.com with sufficient information to verify identity.

PopupReach may decline access where: the information is protected by solicitor-client privilege; disclosure would reveal personal information about a third party; the information was collected in the course of an investigation into a breach of an agreement; or other exceptions apply under PIPEDA.

If access is refused, we will explain the reason for the refusal and provide information about how to complain to the Office of the Privacy Commissioner of Canada.

Principle 10 — Challenging Compliance

Individuals may direct complaints and challenges concerning PopupReach's compliance with PIPEDA to our Privacy Officer at privacy@popupreach.com. We will investigate all complaints and respond within 30 days. If a complaint is found to be justified, we will take appropriate corrective action.

If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada:

  • Website: priv.gc.ca/en/report-a-concern
  • Phone: 1-800-282-1376
  • Mail: Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, QC K1A 1H3

3. CASL Compliance (Canadian Anti-Spam Legislation)

Merchants who collect consumer phone numbers through the PopupReach platform and use them to send commercial electronic messages (including SMS) must comply with Canada's Anti-Spam Legislation (CASL, S.C. 2010, c. 23).

Key CASL requirements for merchants using PopupReach Consumer Data:

  • Express consent is required before sending commercial SMS messages. The consent checkbox in PopupReach's redemption flow is designed to satisfy CASL's express consent requirements, provided merchants accurately describe the nature of messages consumers will receive.
  • Every commercial message must clearly identify the merchant and include an unsubscribe mechanism that is: easy to use, free of charge, processed within 10 business days, and effective for at least 60 days.
  • Merchants must maintain records of consent, including the date, time, method, and content of the consent request.
  • Merchants are solely responsible for their own CASL compliance. PopupReach provides the technical infrastructure for consent capture and record-keeping but does not guarantee CASL compliance on behalf of merchants.

Merchants who send commercial messages without valid CASL consent may be subject to administrative monetary penalties of up to $1,000,000 for individuals and $10,000,000 for corporations per violation. PopupReach strongly recommends consulting legal counsel regarding CASL obligations.

4. Consumer Consent Flow — Technical Specification

The following describes the technical implementation of PopupReach's PIPEDA-compliant consumer consent capture flow:

Step 1 — Claim Flow (No Personal Information Required)

Consumer clicks ad → lands on /claim/[campaignId] → views offer details, countdown timer, and distance → clicks "Claim Deal" → receives unique QR code at /claimed/[claimCode]. No personal information is collected at this stage.

Step 2 — In-Store Redemption

Consumer shows QR code → cashier opens /r/[claimCode] → scans or enters code → system verifies code validity and marks as redeemed. No personal information is collected at this stage.

Step 3 — Post-Redemption Consent Interface (Optional)

After successful redemption, the consumer is presented with a consent interface containing:

  • Heading: "Want to hear about future deals from [Merchant Name]?"
  • Subtext: "Enter your phone number to join their customer list and receive exclusive offers by SMS."
  • Phone number input field (optional — clearly labelled as optional)
  • Opt-in checkbox (pre-unchecked): "I agree to receive promotional SMS messages from [Merchant Name]. I can unsubscribe at any time by replying STOP."
  • "Submit" button — disabled until checkbox is checked
  • Link to merchant's privacy policy (where available) and PopupReach's Privacy Policy

If the consumer does not check the checkbox or does not enter a phone number, they are not added to the merchant's audience. The claim and redemption are complete and valid regardless of this step.

Step 4 — Consent Record

When a consumer submits their phone number with the checkbox checked, the following record is stored in the PopupReach database:

  • Merchant ID
  • Campaign ID
  • Claim code (anonymized reference)
  • Consent timestamp (UTC)
  • Consent method: "web form — PIPEDA compliant checkbox"
  • Phone number (encrypted at rest)

The consent record is accessible to the merchant through their dashboard export and to PopupReach for audit purposes. The phone number itself is only accessible to the specific merchant associated with the campaign.

5. Data Processing Agreement (Merchant-PopupReach)

By accepting PopupReach's Terms and Conditions, each Merchant enters into a data processing agreement with PopupReach whereby:

  • The Merchant is the data controller for Consumer Data collected through their campaigns
  • PopupReach is the data processor, processing Consumer Data only on the Merchant's documented instructions
  • PopupReach implements the technical and organizational security measures described in Section 2 (Principle 7 — Safeguards)
  • PopupReach will not process Consumer Data for any purpose other than providing the Services to the Merchant
  • PopupReach will assist the Merchant in responding to individual access and correction requests relating to Consumer Data
  • PopupReach will notify the Merchant without undue delay upon becoming aware of a personal data breach affecting Consumer Data
  • Upon termination of the Merchant's account, PopupReach will delete Consumer Data within 30 days unless the Merchant exports it beforehand

6. Updates to This Statement

This PIPEDA Compliance Statement will be reviewed and updated annually or whenever there are material changes to our data practices. The effective date at the top of this document indicates when the current version came into force. Material changes will be communicated to merchant account holders via email with at least 14 days' notice before taking effect.

7. Contact and Complaints

  • Privacy Officer: PopupReach Inc.
  • Email: privacy@popupreach.com
  • Response time: 5 business days for acknowledgement, 30 days for full response
  • Office of the Privacy Commissioner of Canada: priv.gc.ca | 1-800-282-1376
  • CRTC (CASL complaints): crtc.gc.ca/eng/internet/anti.htm
PopupReach

Real-time, hyper-local deal campaigns for local businesses. Winnipeg, Manitoba, Canada.

Privacy PolicyTerms of ServicePIPEDA & Consentinfo@popupreach.com
© 2026 PopupReach Inc. · Winnipeg, Manitoba, Canada · Shop Local, Thrive Local.