Privacy policy
Last updated: August 6, 2026
Heed is a service operated by Shawn Hong, carrying on business as Tevah (“Tevah,” “we,” “us,” or “our”), from Toronto, Ontario, Canada. This Privacy Policy explains what information Heed collects, why, who it is shared with, and what you can do about it.
1. Who this policy covers, and who is responsible for what
Merchants are businesses — medspas, salons, cafes and similar — who create a Heed account to run a loyalty stamp card and collect feedback.
Membersare the merchant's own customers, who join a merchant's loyalty program or leave feedback through a merchant's Heed link.
Two different relationships apply:
- For merchant account data, Heed is the organization responsible. We decide what we collect and why, and this policy governs it.
- For member data, the merchant is responsible. They decide who to enrol, what to write in messages, and how long to keep the program running. Heed processes that data on the merchant's instructions, as their service provider, and does nothing else with it.
If you are a member and want your data corrected or deleted, the fastest route is the merchant you gave it to. You can also contact us and we will act on it directly or pass it to them — see section 11.
2. What we collect
From merchants
When you create an account:
- Your business name
- An email address and password for signing in
- A business phone number (optional)
- Your website and Google Business Profile
- Your time zone
- The version of our terms you accepted, and when you accepted them
As you set the product up:
- Business logo and card artwork you upload
- Business locations, if you add them so wallet cards can surface near your shop
- A hashed staff PIN, if you set one for the stamping screen
We do not ask for your personal name — an account is identified by its business name and sign-in email.
When you subscribe, Stripe collects a billing name and address to calculate sales tax, and holds them with your payment method. Card numbers and billing addresses never reach Heed's servers; we store only Stripe's customer and subscription identifiers.
From members who join a loyalty program
At sign-up, the member enters:
- First name and last name
- Mobile phone number — this is how a member is identified within a merchant's program
- Email address (optional)
- Birthday month and day (optional; no birth year is collected)
- Their express consent to receive loyalty messages and review requests from that merchant, with the time it was given
As the card is used, Heed records:
- Every stamp, reward redemption, correction and undo, as a dated, permanent entry. This is the record a merchant relies on to settle “I earned that reward” disputes, so entries are never edited or removed individually — corrections are added as new entries. The whole history is deleted when the member or the merchant's data is deleted (section 6).
- Current stamp count, lifetime stamps, rewards redeemed and last-stamped date
- Whether a review request has been shown, and when
- Which messages were delivered to the member's card
- Wallet technical data: a pass serial number, a hashed pass authentication token, the wallet platform, and — once the card is added to a phone — a device identifier and push token used to update the card
From people who leave feedback
- First name as entered, star rating, written feedback if given
- Phone and/or email, only if the person provides them
- The feedback category selected (for example, wait time)
- Which link or QR code they arrived from
- A one-way hash of their IP address, used solely to stop duplicate and abusive submissions. The stored value cannot be traced back to an IP address.
What we never ask for
- Health information, medical records, or treatment details. Heed has no field for them, and merchants must not enter them into names, reward descriptions or messages.
- Government identification numbers.
- Payment details from members. Members never pay through Heed.
3. Why we use it
Merchant data — to create and run your account; to send you alerts when a member leaves private feedback or reaches a reward; to bill your subscription and send billing reminders; to show your branding on your member-facing pages and wallet card; and to send you occasional service updates.
Member data— on the merchant's behalf, to:
- Issue and update the wallet loyalty card, and keep its stamp count correct
- Show the merchant their member list and each member's history
- Send the messages and review requests the member consented to
- Decide who a merchant's message goes to, when the merchant targets a group such as “joined this week,” “reward ready,” “hasn't visited recently,” or “birthday this month”
- Produce aggregate statistics for the merchant (visits, redemptions, rating trends)
We do not sell member data. We do not use it for advertising. We do not use it to build profiles across merchants — a member's data stays inside the program they joined. We do not use personal data to train AI models.
4. Messages sent to members
When a merchant sends a message, it appears on the member's own loyalty card — on the back of the card and, on a supported phone, as a notification. The merchant is the sender; Heed is the delivery mechanism. Heed does not write, review or approve message content, and does not send members marketing of its own.
A member consents to these messages when they join, the merchant is named in every message, and every card carries an unsubscribe link on its back. Opting out stops loyalty messages and review requests immediately; the card keeps working and stamps keep counting.
5. Who we share information with
We share information only with the providers below, only as needed to run the Service. Each is bound by its own privacy terms and a data processing agreement.
- Supabase: database, authentication and file storage (United States, US East)
- Vercel: application hosting, request logs, and cookieless traffic analytics (United States)
- Stripe: merchant subscription payments
- Resend: email to merchants (alerts, billing)
- Google — Places API: validating a merchant's business profile and reading its public rating
- Google — Google Wallet: for members who add a Google card only. The member's name, their Heed member identifier, and their stamp status are sent to Google so the card can exist and update in Google Wallet.
- Apple — Push Notification service: for members who add an Apple card only. A device push token is used to signal “your card changed.” The notification itself carries no content — the phone then asks Heed for the update over an encrypted connection.
We do not sell, rent or share information with advertisers, data brokers or marketing companies. We disclose information to law enforcement or a government body only where the law requires it.
6. Where data lives, and how long we keep it
Heed's database is hosted in the United States (US East). Members and merchants in Canada should understand that their information is stored and processed in the United States and is therefore subject to lawful access requests by US authorities. If you need Canadian data residency, contact us before signing up.
- Active merchant account: kept while the account is active.
- Cancelled merchant account: member and feedback data is deleted 90 days after cancellation, and the account record is anonymized.
- A member deleted by their merchant: hidden immediately, permanently erased 90 days later.
- A member who unsubscribes: kept, but excluded from all messages and review requests, unless they also ask to be deleted.
- Feedback submissions: kept while the merchant's account is active.
7. Security
- All traffic is encrypted in transit (HTTPS/TLS).
- Passwords and staff PINs are hashed, never stored in readable form.
- Database access is restricted per merchant by row-level security; one merchant can never read another's members.
- Wallet pass tokens are stored only as hashes; the usable token exists only inside the pass on the member's phone.
- IP addresses from the feedback form are hashed with a secret salt before storage; the stored value cannot be traced back to an IP address.
- The loyalty history is append-only at the database level: entries cannot be edited or deleted through the application, only added.
- A small number of Heed personnel can access member records for support, troubleshooting and deletion requests. Access is limited to named accounts.
No system is perfectly secure and we cannot guarantee absolute security. If a breach creates a real risk of significant harm, we will notify affected merchants without undue delay and report to the Office of the Privacy Commissioner of Canada as required by law. Merchants are responsible for notifying their own members where their law requires it.
8. Cookies
Heed uses cookies only to make the product work:
- A session cookie to keep a signed-in merchant signed in
- A short-lived session cookie for the staff stamping screen
We also use Vercel's traffic analytics, which measures page views without cookies and without identifying individuals. We do not use advertising cookies, tracking pixels, cross-site trackers, or third-party marketing cookies.
9. Automated decisions
Heed does not make automated decisions that produce legal or similarly significant effects. Message targeting and reward eligibility are simple rules a merchant configures — a stamp count, a join date, a birthday month — not profiling or scoring.
10. Children
Heed does not collect anyone's age or year of birth. Where a member gives a birthday, it is the month and day only, so no age can be worked out from it.
You must be 18 or older to open a merchant account. Merchants are responsible for not enrolling children in a loyalty program without a parent or guardian's consent. If we learn that we hold a child's information without proper consent, we will delete it.
11. Your rights and how to use them
You may ask to:
- Access the personal information held about you
- Correct anything inaccurate
- Have your information deleted
- Withdraw consent at any time — members can unsubscribe from the link on the back of their card, or ask their merchant to remove them entirely; merchants can close their account by contacting us
- Get an explanation of how a decision about you was made
- Complain about how we handled your information
Members: contact the business whose card you hold — they control your record and can delete it from their dashboard. If you cannot reach them, contact us at the address below and we will help.
Merchants: contact us directly.
We respond within 30 days. If you are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to your provincial privacy regulator.
12. Legal notes
Heed is operated from Ontario, Canada, and follows the Personal Information Protection and Electronic Documents Act (PIPEDA). Messages sent through Heed are subject to Canada's Anti-Spam Legislation (CASL): consent is collected expressly at sign-up, the sending merchant is identified in every message, and an unsubscribe mechanism is on every card. Merchants are responsible for their own compliance as the sender.
Heed collects experience feedback and loyalty activity, not personal health information as defined by Ontario's Personal Health Information Protection Act (PHIPA). Names, contact details, visit counts and experience ratings collected through Heed are not PHIPA-regulated health information. Merchants in regulated sectors should confirm their own obligations with their own counsel and must not enter clinical detail into Heed.
13. Changes to this policy
We may update this policy. Material changes are emailed to merchants, and the “last updated” date at the top always reflects the current version. Continuing to use Heed after a change means you accept the updated policy.
14. Contact
For privacy questions or requests:
Tevah — Heed
Attn: Shawn Hong, privacy contact
Email: hello@tryheed.ca
Toronto, Ontario, Canada