8 Total
0 High severity
6 Medium severity
2 Low severity
Summary

This is Starbucks' privacy policy, explaining what personal information the company collects when you use its app, website, in-store services, or Rewards program, and how that information is used and shared. The most important thing to know is that Starbucks collects a wide range of data about you, including your precise location, purchase history, payment details, and voice recordings from customer service calls, and shares this data with advertising and analytics partners in ways that California law classifies as a 'sale' or 'sharing' of personal information. If you are a California resident, you can opt out of the sale or sharing of your personal information by visiting Starbucks' 'Do Not Sell or Share My Personal Information' link on their website.

Technical / Legal Breakdown

This document is Starbucks' Privacy Notice governing the collection, use, and sharing of personal information across its websites, mobile applications, in-store services, and Starbucks Rewards program, with stated legal basis rooted in consent, contractual necessity, and legitimate business interests. The notice states that Starbucks collects identifiable data including name, email, phone, payment card details, precise geolocation, purchase and transaction history, device identifiers, voice and audio data from customer service interactions, and inferences drawn from consumer behavior to build profiles used for personalized marketing, loyalty program administration, and analytics. The notice authorizes sharing of personal data with a broad range of third parties including advertising partners, data analytics vendors, social media platforms, and business partners for cross-context behavioral advertising purposes, and discloses the sale or sharing of personal information as defined under California law, which triggers specific opt-out rights; the breadth of inference and profiling activities, combined with sharing for advertising purposes, represents a notable scope of data monetization relative to what a retail food-and-beverage consumer might reasonably anticipate. The notice explicitly engages the California Consumer Privacy Act as amended by the California Privacy Rights Act, citing rights to know, delete, correct, opt out of sale or sharing, and limit sensitive personal information use, and references compliance with Washington State privacy law for Washington residents; the document is primarily US-focused with no substantive GDPR or UK GDPR framework described, which may create gaps for any EU or UK customer interactions. Compliance teams should note that the notice discloses collection of precise geolocation, voice and audio data, and inferences as categories of sensitive or functionally sensitive data, each carrying heightened regulatory attention under the CPRA and emerging state privacy statutes, and that the disclosed advertising-partner data-sharing model warrants ongoing assessment under FTC unfair or deceptive practices authority.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
Medium — 6 provisions
Low — 2 provisions

Monitoring

Starbucks has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Sale and Sharing of Personal Information for Behavioral Advertising and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:29 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000625
Version ID CA-V-001281
SHA-256 d5e55caca30087576ff29e8885b4a497cdbdb144634f613e23bb0595052cacad
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans