8 Total
0 High severity
6 Medium severity
2 Low severity
Summary

This document establishes Starbucks' data collection, use, and sharing practices for personal information obtained through its mobile app, website, in-store transactions, and Rewards program. The policy authorizes collection of precise location data, purchase history, payment details, and voice recordings from customer service interactions, with disclosed sharing of such information to advertising partners and analytics vendors in transactions classified as sales or sharing under California law. California residents are provided mechanisms to opt out of such sales or sharing through a designated link on the Starbucks website.

Technical / Legal Breakdown

This document is Starbucks' Privacy Notice governing the collection, use, and sharing of personal information across its websites, mobile applications, in-store services, and Starbucks Rewards program, with stated legal basis rooted in consent, contractual necessity, and legitimate business interests. The notice states that Starbucks collects identifiable data including name, email, phone, payment card details, precise geolocation, purchase and transaction history, device identifiers, voice and audio data from customer service interactions, and inferences drawn from consumer behavior to build profiles used for personalized marketing, loyalty program administration, and analytics. The notice authorizes sharing of personal data with a broad range of third parties including advertising partners, data analytics vendors, social media platforms, and business partners for cross-context behavioral advertising purposes, and discloses the sale or sharing of personal information as defined under California law, which triggers specific opt-out rights; the breadth of inference and profiling activities, combined with sharing for advertising purposes, represents a notable scope of data monetization relative to what a retail food-and-beverage consumer might reasonably anticipate. The notice explicitly engages the California Consumer Privacy Act as amended by the California Privacy Rights Act, citing rights to know, delete, correct, opt out of sale or sharing, and limit sensitive personal information use, and references compliance with Washington State privacy law for Washington residents; the document is primarily US-focused with no substantive GDPR or UK GDPR framework described, which may create gaps for any EU or UK customer interactions. Compliance teams should note that the notice discloses collection of precise geolocation, voice and audio data, and inferences as categories of sensitive or functionally sensitive data, each carrying heightened regulatory attention under the CPRA and emerging state privacy statutes, and that the disclosed advertising-partner data-sharing model warrants ongoing assessment under FTC unfair or deceptive practices authority.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial
Medium — 6 provisions
Low — 2 provisions

Monitoring

Starbucks has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Sale and Sharing of Personal Information for Behavioral Advertising and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:29 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000625
Version ID CA-V-001281
SHA-256 d5e55caca30087576ff29e8885b4a497cdbdb144634f613e23bb0595052cacad
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans