8 Total
0 High severity
7 Medium severity
1 Low severity
Summary

This document establishes Grubhub's practices regarding the collection, use, and disclosure of personal data from users who create accounts, place orders, and browse the platform. The policy authorizes Grubhub to collect order history, location data, browsing behavior, and inferred preferences, and to share name, email, order history, and browsing behavior with advertising partners for targeted advertising purposes. Users may opt out of data sharing for advertising through account settings or the 'Do Not Sell or Share My Personal Information' mechanism, and California residents have additional rights to access, delete, or limit use of sensitive personal information.

Technical / Legal Breakdown

This Privacy Policy, effective January 5, 2026, governs the collection, use, disclosure, and processing of personal information by Grubhub Holdings Inc. and its subsidiaries in connection with its Platform and Services, including websites, mobile apps, APIs, and in-store kiosks. The policy states that Grubhub collects a broad range of personal information categories including identifiers, payment data, commercial/purchase history, internet usage and browsing behavior, geolocation data, inferences, audio/visual data, and sensitive personal information; the terms authorize sharing of identifiers and commercial information with ad networks and advertising partners for cross-context behavioral advertising, and with third-party trusted partners for marketing and internal business purposes. Notably, the policy asserts that sharing identifiers and commercial information with ad networks for cross-context behavioral advertising may constitute a 'sale' or 'sharing' under California law, which the policy acknowledges by providing opt-out mechanisms; the document explicitly carves out payment information and sensitive personal information from advertising-related sharing, and states that text messaging opt-in data is not shared with third parties. The policy engages CCPA/CPRA frameworks for California residents, COPPA considerations for users under 13 (who are prohibited from using the platform), and interacts with FTC Act consumer protection standards governing deceptive data practices; state-level biometric and geolocation privacy laws may also require evaluation depending on where Grubhub operates. Material compliance considerations include the accuracy and timeliness of the opt-out mechanisms for behavioral advertising, the adequacy of consent mechanisms for sensitive data categories including precise geolocation and health-related inferences, and the sufficiency of data retention disclosures relative to applicable state law requirements.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
Medium — 7 provisions
Low — 1 provision

Monitoring

Grubhub has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Precise Geolocation Data Collection and Sharing and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 19, 2026 06:10 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000146
Version ID CA-V-000705
SHA-256 6278b17915ee5719a0b316cc819ef0f2aa16abc9a0beb08feb01c964e591c9ca
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans