Your information should help recover a bike—not expose you.
This notice describes the operating privacy controls in BikeBeacon Canada. Live paid charging and active Quebec promotion remain disabled until the permanent legal entity, privacy officer, domain, and required legal assessments are complete.
Accountability and contact
BikeBeacon Canada is currently an independently operated pilot and provisional working name. The permanent Canadian legal entity and named privacy officer have not yet been approved. Until that launch gate is complete, signed-in users can contact the privacy administrator through My BikeBeacon → Privacy & data. A permanent postal address and monitored privacy email will be published before unrestricted or paid launch.
Information we collect
We collect the verified account email provided by platform-managed sign-in, an optional display name and profile, private bike registrations, lost and found incidents, coarse locations, private recovery messages, photos, optional proof documents, consent history, organization memberships, and billing state. Security records can include an IP address, action, request time, and affected record. We do not collect advertising identifiers.
Purposes and limits
Information is used only to operate the private registry, publish intentionally limited alerts, identify possible matches, relay private contact, provide organization programs, prevent abuse, keep audit records, deliver requested email, administer subscriptions, and answer privacy requests. BikeBeacon does not sell personal information, run behavioural advertising, add tracking pixels, or use non-essential cookies.
Public and organization views
Public reports may show appearance, scrubbed photos, a general area, a masked serial suffix, report timing, and useful non-sensitive details. Email, full serial, exact coordinates, proof documents, and private messages are not public. Organizations receive only attributed registrations and consented aggregate measures. They do not receive rider email, private messages, proof, full serials, or precise location by default.
Location and photos
Coordinates are rounded before insertion into the database. Exact browser location stays on the device and is used only for local distance sorting. Public maps use a first-party coarse display, not third-party map tiles. Raster uploads are normalized, dimension-limited, signature-checked, and stripped of EXIF, GPS, and common metadata before storage.
Service providers and cross-border processing
The pilot uses OpenAI’s platform-managed sign-in and hosting surface, Cloudflare Workers/D1/R2 for application hosting and storage, Resend for transactional email when configured, and Stripe-hosted Checkout and Customer Portal for subscriptions. These providers may process information outside Canada. No card number is stored by BikeBeacon. A documented cross-border assessment and Quebec privacy-impact assessment are launch requirements before active Quebec promotion.
Retention schedule
Posts and associated media can be hidden immediately and recovered for 30 days before they are purged. Owners and finders may instead choose immediate permanent deletion, which removes the entry and its associated files and recovery data without a restoration window. A documented legal or security hold may prevent either purge. Closed conversations are kept up to 12 months. Ordinary security audit records are kept 12 months; breach records at least 24 months; billing and consent evidence seven years. Unclaimed assisted registrations are purged after 30 days. Institutional contracts may choose a shorter operational retention period where legally permitted. Only non-identifying aggregate measures remain after personal records are purged.
Your choices
My BikeBeacon lets you correct a profile, edit and manage posts, download account data, change email frequency, opt in or out of marketing separately, block users, request correction, and schedule account deletion. Account deletion disables the account and hides public posts immediately; it can be cancelled for 30 days. You may complain to the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator after first giving the privacy administrator an opportunity to respond.
Consent, email, and incidents
Essential security, privacy, billing, and invitation notices are separate from optional marketing. Marketing is off by default and keeps consent history; each marketing message must provide one-click unsubscribe. Delivery, bounce, complaint, failure, and suppression events are signed and deduplicated. Suspected privacy incidents are contained, assessed, documented, and reported to regulators and affected people when required by law.
Operational privacy notice version 2026-08-07. Permanent entity and officer details, Canadian legal review, and Quebec privacy-impact review remain explicit paid-launch gates.