Effective: June 4, 2018
We follow the requirements of the General Data Protection Regulation ("GDPR") and applicable national laws.
1. What information do we collect?
Information collected voluntarily provided by you
We, and our third party service providers who perform services on our behalf, collect information in a variety of circumstances when you visit and use our Sites.
For example, we may collect information in the following circumstances:
The information we collect includes personal data that can uniquely identify you (whether alone or in combination with other data or information), such as your name, postal address, telephone number, email address, date of birth, or similar data. Personal data also includes technical information we may collect through your use of the Sites, such as IP address, device ID, unique online identifier and geo-location. Although it isn't personal data, we also process certain information related to your finances such as a credit card number or other payment account number (including the three (3) or four (4) digit validation code for your credit card).
In order for you to take advantage of the services provided through the Sites, we may require that you provide personal data to us. For certain business accounts, your employer may provide personal data for you. We may also collect information about your use of our Sites and other non-personal information, but when it is linked to your personal data, we will treat it as personal data.
We do not collect any personal data which the law considers to be "sensitive" such as health information, information about your religious or philosophical beliefs or information about your sexual preferences.
Information collected automatically
We and our third party service providers may collect certain types of usage information when you visit our Sites, read our emails, or otherwise engage with us, including IP address, device ID, unique online identifier and geo-location. We use this information to enhance and personalize your user experience, to monitor and improve our websites and services, and for other internal purposes. This may contain usage data which may or may not be personally identifiable. In any instance where it is not personally identifiable and we combine it with personal data, the combined information will be treated by us as personal data.
We and our third party partners use tracking technologies, including cookies, web beacons, embedded scripts, location-identifying technologies, file information, and similar technology to automatically collect usage and device information, such as:
How to control cookies
If you would prefer not to accept cookies, most browsers will allow you to: (i) change your browser settings to notify you when you receive a cookie, which lets you choose whether or not to accept it; (ii) disable existing cookies; or (iii) set your browser to automatically reject cookies; however, doing so may negatively impact your experience using the Sites, as some features and services on our Sites may not work properly. You may also set your email options to prevent the automatic downloading of images that may contain technologies that would allow us to know whether you have accessed our email and performed certain functions with it.
For more information on disabling Google cookies see: https://policies.google.com/technologies/partner-sites
For more detailed information on how to control cookies you may wish to visit www.allaboutcookies.org
How we respond to "Do Not Track" signals. Although we do our best to honor the privacy preferences of our users, we are currently unable to respond to Do Not Track signals set by your browser.
Location information. With your consent, we may obtain information about your physical location through geolocation features on your device, including GPS (e.g. latitude and/or longitude). We will remind you that we are tracking your location and give you options to turn this location tracking off from time to time. We may use this information to improve order efficiency and enhance your user experience. We may also infer your location based on other information we collect. For example, your IP address indicates the general geographic region from which you are connecting to the Internet.
Information collected from third party sources. We may receive personal data from your corporate employer including, but not limited to, name, postal address, telephone number, e-mail address, credit card number or other payment account number (including the three (3) or four (4) digit validation code for your credit card). This information will be used for the initial set up and provisioning of the account you will use to access the services via the Site.
2. How do we use your information?
3. Who do we share your information with?
Corporate employers. We share information with your corporate employer as needed to fulfill orders you place through your employer's corporate account.
Agents and service providers. We work with third parties who provide services such as website hosting, data analysis, payment processing, order fulfillment, infrastructure provision, IT services, customer service, e-mail delivery services, credit card processing and other similar services. We may share personal data that we receive from you or from your corporate employer with these third parties to enable them to provide services. These service providers are given access to personal data that we receive from you or from your corporate employer to the extent needed to perform their functions, but are restricted from using the personal data for purposes other than providing services for us. We require that our agents and service providers that have access to personal data that we have received from you or from your corporate employer to enter into written agreements with us that require the service providers to provide at least the same level of data protection as is required by the GDPR.
Advertising and analytics partners. We may share your information with third party advertising partners who perform analytics and/or site performance analysis functions on our behalf.
Third parties as needed to detect, prevent or otherwise address actual or suspected fraud, harassment, security or technical issues, any violations of any law, rule, regulation or the policies of the Sites, and to verify your purchase to holder(s) of any credit card(s) or other payment account(s) used to place order(s) using your account or your information.
Restaurants and brands and their third party service providers from which you have placed orders through the Sites. These restaurants and brands may use your information to fulfill orders. These restaurants are restricted from using the personal data for purposes other than fulfilling orders.
Third party marketing partners in connection with integration, co-marketing and certain other coordinated efforts.
An affiliate or other third party in connection with a reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including without limitation in connection with any bankruptcy and/or similar proceedings).
In other circumstances where it is legally permissible (a) under applicable law; (b) to respond to requests from public and government authorities, including public and government authorities outside your country of residence; (c) to protect our rights, privacy, safety and/or property, and/or that of our affiliates, you and/or others; and (d) otherwise in accordance with your consent.
4. Legal Basis for Processing Personal Information.
If you are located in the European Economic Area ("EEA") Seamless Europe, Ltd. is the data controller of your personal information. Our legal basis for collecting and using the personal data described above will depend on the personal data concerned and the specific context in which we collect it. However, we will normally collect personal data only where we have your consent to do so, where we need the personal data to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect personal data from you.
If we ask you to provide personal data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal data is mandatory or not (as well as the possible consequences, if any, if you do not provide your personal data). Similarly, if we collect and use your personal data in reliance on our legitimate interests (or those of a third party), we will make clear to you at the relevant time what those legitimate interests are.
5. Third Party Tracking and Online Advertising.
To learn more about interest-based advertising and how you may be able to opt-out of some of this advertising, you may wish to visit the Network Advertising Initiative's ("NAI") online resources, at http://www.networkadvertising.org/choices , and/or the Digital Advertising Alliance's ("DAA") resources, available at www.aboutads.info/choices. You may also be able to set your browser to delete or notify you of cookies by actively managing the settings on your browser or mobile device. Please note, however, that some advertising opt-outs may not be effective unless your browser is set to accept cookies. Furthermore, if you use a different device, change browsers or delete the opt-out cookies, you may need to perform the opt-out task again.
You may also be able to limit certain interest-based mobile advertising through the settings on your mobile device by selecting "limit ad tracking" (iOS) or "opt-out of interest based ads" (Android).
Google Analytics and Advertising. We may also utilize certain forms of display advertising and other advanced features through Google Analytics, such as Remarketing with Google Analytics, Google Display Network Impression Reporting, and Google Analytics Demographics and Interest Reporting. These features enable us to use first-party cookies (such as the Google Analytics cookie) and third party cookies (such as the DoubleClick advertising cookie) or other third party cookies together to inform, optimize, and display ads based on your past visits to the Sites. You may control your advertising preferences or opt-out of certain Google advertising products by visiting the Google Ads Preferences Manager, currently available at https://google.com/ads/preferences, or by vising NAI's online resources at http://www.networkadvertising.org/choices.
6. Profiles and Interactive Areas.
We and our third party service providers may make available through the Sites certain features and services (for example, ratings and reviews, photo uploads, and chat functionality) to which you may be able to post information and materials. Please note that any information you provide in connection with such services may become public, and may be available to visitors to the Sites and to the general public, including without limitation the ratings, reviews and photographs that accompany many restaurant listings. We urge you to exercise discretion and caution when deciding to disclose your personal data and/or any other information and/or materials on the Sites.
We and our third party service providers employ reasonable and appropriate safeguards to protect personal data that we receive. The safeguards we use include organizational, technical and administrative measures to protect against unauthorized or unlawful processing and against accidental loss, damage or destruction. Unfortunately, no data transmission over the Internet or data storage system can be guaranteed to be 100% secure. We ask that you do your part by keeping any computer passwords you use to access the Internet or the Site strictly confidential.
International Data Transfers. Your personal data may be transferred to, and processed in, countries other than the country in which you reside. These countries may have data protection laws that are different than the laws of your country, and in some cases, may not be as protective.
Specifically, our website servers are located in the U.S. and our affiliates, agents and third party service providers operate in the U.S., Mexico and Canada. This means that when we collect your personal data, we may process it in any of these countries.
Our Standard Contractual Clauses can be provided on request. We have implemented similar appropriate safeguards with our agents and third party service providers and further details can be provided upon request.
Data Integrity. We take reasonable steps to ensure that personal data we process is reliable for its intended use.
8. Data Protection Rights.
If you are a resident of the EEA you have the following data protection rights:
If you wish to exercise any of these rights or want further information, please contact email@example.com.
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.
You can review and correct the personal data that we maintain about you by adjusting your preferences in the "My Account" section of our website by logging onto your account from https://www.grubhub.com.
11. Data Deletion and Retention.
We retain personal data we collect from you where we have an ongoing legitimate business need to do so (for example, to comply with applicable legal, tax or accounting requirements and to enforce our agreements or comply with our legal obligations). When we have no ongoing legitimate business need to process your personal data, we will either delete or anonymise it, or if this is not possible (for example, because your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is possible.
12. Enforcement and Dispute Resolution.
If you have any questions or concerns, please write to us at the address listed below. We will investigate and use diligent, good faith efforts to resolve complaints and disputes regarding use and disclosure of personal data promptly.
13. Note Regarding the Use of the Sites by Children.
Under no circumstances are the Sites directed to and/or intended for use by individuals under the age of thirteen (13), and we do not knowingly collect personal data from children under age 13. If you believe that we might have any information from a child under 13, please contact us at firstname.lastname@example.org so that we may delete it as soon as possible.
15. Contact Information.
Grubhub Holdings Inc. Attention: Privacy Team, 1065 Avenue of the Americas, 15th Floor New York, NY 10018, United Sates of America; E-mail: email@example.com
Seamless Europe, Ltd. Attention: Privacy Team, 2 Riding House Street, London W1W7FA, UK; Email: firstname.lastname@example.org