Halal Food Pass
Legal

Privacy Policy

Last updated 10 July 2026 · Applies to halalfoodpass.ca and the Halal Food Pass member, partner and admin apps.

Who we are

Halal Food Pass ("we", "us") operates a dining-membership service in the Greater Toronto Area, Canada. This policy explains what personal information we collect, why, who we share it with, and the choices you have. We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

What we collect

Account & membership. Your email address (used to sign you in with one-time codes, we never store passwords), the display name you choose for your pass, your membership plan, status, member number and billing dates.

Optional profile details. If you choose to add them, your date of birth, gender and home town. These are entirely optional, used only to show you more relevant deals and offers (for example your city first, or a birthday treat), visible only to you and our team, and you can clear them at any time from your profile.

Payments. A free membership involves no payment details at all, none are collected and none are stored, which is why we cannot charge you automatically. If you choose a paid membership, payments are processed by Stripe: we never see or store your full card number; we keep your Stripe customer reference, plan, price and billing status. Where a card was used to start a trial, Stripe provides us a non-reversible card fingerprint which we store to enforce one trial per card.

Preventing duplicate free memberships. Because the free month needs no card, we instead store a one-way hash of your email address in a form that treats obvious variations of the same inbox as one person (plus-tags removed, and dots ignored for providers that ignore them). We also store one-way hashes of the IP address and an opaque browser identifier used at sign-up, to detect one person creating many accounts. These are hashes, not the values themselves, and they are used only to enforce one free month per person.

Usage needed to run the service. Redemptions you record or a restaurant validates (restaurant, offer, amount saved, time), private feedback you send about a restaurant, referrals made with your link, contact-form messages, and device signals we use for security (IP address, browser type, session records). If you turn on deal alerts, we store your push-notification subscription and chosen city.

How we use it

To create and manage your membership, issue and verify your pass, compute live deal availability, process billing, prevent fraud and abuse (rate limits, block lists, one free month per person, one trial per card), respond to your messages, and, only with your consent, in line with Canada's Anti-Spam Legislation (CASL), send you marketing you can opt out of at any time. Transactional email (like login codes and billing notices) is not marketing.

Who we share it with

We do not sell or rent your personal information, and we don't share it with restaurants beyond what a redemption inherently shows them at the till. We use a small number of service providers to run the service: Stripe (payments), Cloudflare (hosting, security and our database), and our transactional email provider (login codes and notices). Each processes data only on our instructions. We may disclose information if required by law.

Where it's stored & how long

Data is stored with Cloudflare and Stripe, whose infrastructure may be located outside Canada; where that's the case it is protected by contractual safeguards. We keep account data while your account is active and for a reasonable period afterwards to meet legal, accounting and fraud-prevention obligations; security and rate-limit logs are pruned on a rolling basis.

Your choices & rights

You can view and edit your name and optional profile details (or clear them) in the app, cancel your membership at any time, and unsubscribe from marketing with one click. You may request access to, correction of, or deletion of your personal information by emailing us; we'll respond within 30 days. Deleting your account removes your personal information except records we must keep (for example billing records).

Cookies, measurement & your analytics choice

We use strictly necessary, first-party session cookies to keep you signed in (HttpOnly, secure). We also set two first-party identifiers so we can measure how the site is used: one anonymous analytics id, and one that remembers which listings a browser has already been shown so the same view is not counted twice. Neither carries your name, your email address or your IP address.

We use Google Analytics 4 (through Google Tag Manager), Google Ads measurement and Microsoft Clarity to understand traffic and improve the site. These are third-party services and they set their own cookies. We do not sell your information, and we do not run third-party advertising cookies that follow you around unrelated sites.

Halal Food Pass is served to Canada only, so analytics are on by default under PIPEDA's implied consent for non-sensitive analytics, with the notice you are reading now. You can turn them off for this browser at any time, and your choice is remembered and always wins:

Children

Halal Food Pass is not directed at children under 13 and we do not knowingly collect their information.

Changes & contact

If we make material changes to this policy we'll post the update here and, where appropriate, email members. Questions or requests: hello@halalfoodpass.ca.