Grubhub · Grubhub Privacy Policy · View original document ↗

Sensitive Personal Information Collection and Use

Medium severity Medium confidence Explicitdocumentlanguage Rare · 2 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Grubhub Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Grubhub may collect and use sensitive information including your precise location, health-related inferences (such as dietary restrictions or health conditions suggested by your orders), and potentially religious or other beliefs inferred from your food choices.

This analysis describes what Grubhub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Health-related and belief-related inferences drawn from food ordering data represent a sensitive category of personal information that carries heightened privacy risk, particularly if shared or used beyond the immediate service context.

Interpretive note: The scope of health-related and belief-related inferences drawn from order data is not precisely defined in the document, and whether these inferences are shared with advertising partners is not explicitly confirmed or excluded.

Consumer impact (what this means for users)

Grubhub may infer sensitive information about your health, dietary needs, or beliefs based on what you order, and may use these inferences to personalize your experience; California residents have the right to limit how this sensitive information is used.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Opt Out of Arbitration
    California residents should locate and use the 'Limit the Use of My Sensitive Personal Information' option referenced in the Grubhub privacy policy, accessible through account settings or the privacy rights request mechanism.

Cross-platform context

See how other platforms handle Sensitive Personal Information Collection and Use and similar clauses.

Compare across platforms →

Monitoring

Grubhub has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We may use this information to: (i) provide and improve the Platform and Services; (ii) personalize your Grubhub experience; (iii) detect and prevent fraud, abuse, or other harmful activities; and (iv) for other purposes described in this Privacy Policy. We may also use inferences we draw from your information, including information that may indicate health conditions, dietary preferences, or religious beliefs, to personalize your experience and for other purposes described in this Privacy Policy.

— Excerpt from Grubhub's Grubhub Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1) REGULATORY LANDSCAPE: CPRA establishes a distinct category of sensitive personal information (SPI) and requires businesses to provide consumers with the right to limit its use and disclosure to what is necessary to perform the services. The California Privacy Protection Agency enforces SPI obligations. Health-related inferences may also engage HIPAA if Grubhub is classified as a business associate, though this is unlikely given Grubhub's role as a food ordering platform. The FTC has increasingly scrutinized health data practices under its general unfairness authority. 2) GOVERNANCE EXPOSURE: Medium. The collection of precise geolocation and the drawing of health or belief-related inferences from order data creates SPI obligations under CPRA. If Grubhub uses these inferences for advertising or shares them with partners, additional restrictions apply. The adequacy of the 'Limit the Use of My Sensitive Personal Information' mechanism requires ongoing operational audit. 3) JURISDICTION FLAGS: California CPRA creates the clearest SPI framework and heightened exposure. Colorado, Connecticut, Virginia, and Texas privacy laws also recognize sensitive data categories that may include health and precise geolocation. Illinois residents may have additional protections if inferences touch on biometric data. EU/UK residents would have rights under GDPR Article 9 if health-related data is processed. 4) CONTRACT AND VENDOR IMPLICATIONS: Any service provider or partner receiving SPI must be bound by contracts limiting use to disclosed purposes. If advertising partners receive health-related inferences, this may violate CPRA's restrictions on SPI sharing for advertising. Data processing agreements should be audited to confirm SPI is excluded from behavioral advertising pipelines. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a data inventory specifically for SPI categories, confirm the 'Limit the Use' mechanism is functional and honored, and verify that health-related inferences are not included in data sets shared with ad networks or trusted partners. Privacy impact assessments for inference-drawing processes are advisable given the sensitivity of derived health and belief-related data.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive practices involving health-related data collection and use under the FTC Act
    File a complaint →
  • State AG
    California's Privacy Protection Agency enforces CPRA sensitive personal information protections, including the right to limit use of health-related inferences
    File a complaint →

Provision details

Document information
Document
Grubhub Privacy Policy
Entity
Grubhub
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 10, 2026
Record ID
CA-P-008862
Document ID
CA-D-00146
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
1d98da01ef00d67ec1c878e4bc9db00da944fb7c9c9d9615959000619c63379d
Analysis generated
May 8, 2026 00:04 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Grubhub
Document: Grubhub Privacy Policy
Record ID: CA-P-008862
Captured: 2026-05-08 00:04:48 UTC
SHA-256: 1d98da01ef00d67e…
URL: https://conductatlas.com/platform/grubhub/grubhub-privacy-policy/sensitive-personal-information-collection-and-use/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Grubhub's Sensitive Personal Information Collection and Use clause do?

Health-related and belief-related inferences drawn from food ordering data represent a sensitive category of personal information that carries heightened privacy risk, particularly if shared or used beyond the immediate service context.

How does this clause affect you?

Grubhub may infer sensitive information about your health, dietary needs, or beliefs based on what you order, and may use these inferences to personalize your experience; California residents have the right to limit how this sensitive information is used.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 2 platforms. See the full comparison.

Is ConductAtlas affiliated with Grubhub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grubhub.