Privacy Policy

Privacy Policy

Effective Date: January 1, 2023

Cinnabon Franchisor SPV LLC and Cinnabon LLC, and their affiliates (collectively, “ Cinnabon,” “ we,” “ our,” “ us”) value your privacy. In this Privacy Policy, we describe how we collect, use, and process the personal information we obtain about people who use our websites or mobile apps, browse or purchase our products, apply to become franchisees, or who otherwise interact with us online or offline (collectively, our “ Services”). This Privacy Policy does not apply to any websites or mobile apps that are created, run, or controlled by independently owned or operated Cinnabon franchisees or any other third party.

This Privacy Policy and our  Cookie Policy  describe our collection, use, and disclosure of personal information. By downloading, using, creating an account on, or registering for our Services, or by otherwise providing your personal information to us, you are agreeing to this Privacy Policy and our Terms and Conditions

In this Privacy Policy, “ personal information” (a/k/a “ personal data”) means any information that Cinnabon processes that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular person or household.

  • California residents please click here or our Notice at Collection under the California Consumer Privacy Act and here to learn about our financial incentive offers.
  • Virginia residents please click here to learn more about your privacy rights.
  • European Economic Area and United Kingdom residents please click here to learn more about your privacy rights.
  • Residents of Canada please click here to learn more about your privacy rights.

PERSONAL INFORMATION WE COLLECT ABOUT YOU

We may collect personal information directly from users of our Services. You can use some parts of our Services without registering or directly submitting your personal information to us, but we may automatically collect certain information about your use of our Services through cookies and other tracking technologies.

Information We Collect Directly From You. To use some features of our Services (for example, to sign up for rewards programs, enter contests, make a purchase, or request a franchise kit from us), you must register with us or otherwise provide us with your personal information. We also may collect personal information that you enter through our Services or provide to us in other ways, such as through email or text message. The types of personal information that we collect from you will depend on your interactions with us and how you use our Services, but may include:

  • personal details, such as full name, mailing address, email address, phone number, and other contact information;
  • purchase transaction information, such as information about the products you buy, billing address, method of payment, and payment details;
  • location data; and
  • other personal information you choose to provide to us.

Information We Collect Automatically. We, and the vendors we work with, may also collect other information about your use of our Services using automated tools. For example, cookies and other passive information collection technologies enable us to compile aggregate statistics concerning use of our Services, analyze trends, enhance the security of our Services, deliver content and advertisements, and otherwise administer and improve our Services. This information may include your browser type, language preference, operating system, device identifier, device type, access time, Internet Protocol (IP) address, the URLs of websites you visited before and after visiting our websites, the web search that landed you on our websites, the length of your visits to our websites, and the links you click and pages you visit within our websites. You can set your browser not to accept cookies, to remove cookies, or to notify you when you are sent a cookie, giving you the opportunity to decide whether or not to accept it. However, please note that if you disable the use of cookies on your computer, some functionality of our websites will not work. Please see our Cookie Policy for more information.

Your web browser may have settings that allow you to transmit a “Do Not Track” signal when you visit various websites or use online services. Like many websites, our websites are not designed to respond to “Do Not Track” signals received from browsers.

We may use certain third-party web analytics services to help us understand and analyze how visitors use our Services and to serve advertisements on our behalf across the Internet. We have implemented Google Analytics Advertising features such as dynamic remarketing, interest-based advertising, audience targeting, behavioral reporting, demographics and interests reporting, user segment analysis, device reporting, display advertising, and video ads reporting. We may use cookies and other identifiers to deliver advertisements, create a profile of you, measure your interests, personalize content, and detect your demographics, location, or device. For more information on how Google Analytics uses data, visit www.google.com/policies/privacy/partners/ . To opt out of Google Analytics cookies, visit www.google.com/settings/ads / and tools.google.com/dlpage/gaoptout/ .

We use Hotjar, a service provider, to help us understand and analyze how visitors use our services, and to improve the services. Hotjar may collect the following types of information from users of our websites:

  • device IP Address
  • device screen size
  • device type (unique device identifiers)
  • browser information, geographic location (country only)
  • preferred language used to display our website

Hotjar stores the above information in a pseudonymized format. Hotjar does not use this information to identify individual users, or match or link the information with other information about users. Hotjar is contractually forbidden to sell any of the data collected on our behalf. For more information regarding Hotjar's collection and use of information, please visit Hotjar's privacy policy  here .

Information We Collect About Your Location. Our Services may access and collect your geolocation information to facilitate our provision of Services, such as to provide you with information about stores near you. We also may use information about the location of the device you are using to help us understand how our Services are being used and to deliver more relevant advertising. For most mobile devices and computer systems, you are able to withdraw your permission for us to collect this information through your device or web-browser settings.

Information We Collect From Others. We may collect personal information about customers, prospective franchisees, and current franchisees from our affiliated companies, franchisees, service providers, and third parties. We also may collect information about any comments or reviews you post about us on third-party websites. When submitting information to a third party, you are subject to that third party’s terms of use and privacy policies. Cinnabon may combine information about you that we already have with information we obtain from third parties. If you submit someone else’s personal information to us, you represent that you have been authorized to provide this information to us.

 

HOW WE USE YOUR INFORMATION

We may use your personal information to:

  • communicate with you, including to respond to your questions and requests, provide you with documentation or communications you have requested, send you notices about our Services, offer customer support, or contact you for information or after-sales support;
  • process your orders or purchases;
  • market and advertise our products, including to send you news, updates, special offers and promotions, and targeted advertising;
  • personalize our content, including to make recommendations to you about our Services, to tailor the information we send or show you, and to offer location-based customizations and personalization based on your purchase history or past interactions with our Services;
  • monitor and analyze trends, usage, and the activities of users of our Services to better understand how our users access and use our Services in order to improve them, respond to user preferences, and for other research purposes;
  • improve our Services and notify you about important updates;
  • perform business analyses or for other business purposes, such as evaluating transactions involving our Services;
  • facilitate, manage, personalize, and improve our partnership and franchisee relationships;
  • identify, prevent, investigate, and take other actions with respect to suspected or actual fraud or illegal activity or other activity that violates our policies;
  • ensure the security and integrity of our personal information processing;
  • protect our rights, property, or safety and that of our users and our confidential and proprietary information;
  • comply with applicable laws, rules, regulations, and legal processes as well as our company policies, including to respond to claims asserted against us and to enforce or administer terms and agreements; and
  • achieve other purposes, with your consent (when required).

HOW WE DISCLOSE YOUR INFORMATION

We may disclose your personal information within our company, with our affiliates, with our business partners and franchisees, and with our vendors. We also may disclose your personal information to:

  • provide you with products or services, such as when we use a payment processor or app developer;
  • better respond to your inquiries;
  • advertise or market our products and services;
  • perform marketing research and for sales, support, and service-related purposes;
  • protect rights, property, life, health, security, and safety;
  • respond to legal process, including to disclose personal information to a court, legal authority, opposing party in litigation, our legal counsel, or other advisors in connection with a judicial proceeding, court order, subpoena, or other legal process;
  • negotiate or complete any proposed or actual merger, purchase, sale, or any other type of acquisition or other transaction, including a transfer of all or a portion of our business to another organization;
  • disclose personal information with your consent or at your direction; and
  • achieve any other purpose consistent with our statements in this Privacy Policy or otherwise allowed by applicable law.

We may disclose your personal information to comply with applicable law, such as in response to requests from law enforcement agencies, regulators, other public authorities, courts, and third-party litigants in connection with legal proceedings or investigations.

Any information, including personal information, that you post on any public areas of our Services, such as reviews, comments, and photos, may be available to, and searchable by, all other users. Reviews also may be publicly accessible.

 

LINKS TO OTHER WEBSITES

Our Services may include links to other websites that we do not own or operate. This Privacy Policy does not apply to those websites, which may have their own privacy policies that you should review to understand how they may collect, use, or disclose your personal information. We are not responsible for the content or privacy practices of any linked websites that are not under our control.

 

SOCIAL FEATURES

Certain features of our Services may permit you to interact with social media networks operated by unaffiliated parties, for example, if you “like” or “follow” us on those platforms (“ Social Features”). If you choose to “like” or share content or post information using Social Features, that information may be publicly displayed, and the party operating the social media platform may receive information about you and your use of our Services. Similarly, if you interact with us through Social Features, we may have access to information about you from the social media platform. In addition, we may track when you like us, follow us, or share our content through Facebook, Twitter, or other social media platforms.

Please note that if you mention Cinnabon, or comment about or in response to us, in your post on a social media platform, that platform may allow us to publish your post on our Services or public social media pages or otherwise use your post about us. You should review the terms, policies, and settings of these platforms to learn more about their data practices and adjust your settings accordingly.

 

USER GENERATED CONTENT

Any content you post to our Services or public social media pages (“ User Generated Content”) may be visible to and searchable by all users or the general public, and we may not be able to prevent such content from being used in a manner that violates this Privacy Policy, the law, or your personal privacy. For instance, third parties may have republished your User Generated Content, or it may have been archived by search engines and others that we cannot control. We may revise such User Generated Content, remove it, or combine your User Generated Content with other information we have collected about you and use it as described in this Privacy Policy. All User Generated Content is subject to our Terms and Conditions .

In addition, we may collect information from you when you contact us or when you submit a review, comment, or other content to our Services or on our social media pages. We may choose to disclose the personal testimonials of our customers, including your name, on our Services or with our affiliates, our business partners and franchisees, and our vendors. If you wish to update or delete your testimonial, you can contact us at privacy@cinnabon.com .

 

SECURITY OF YOUR PERSONAL INFORMATION

We maintain appropriate safeguards designed to protect personal information from loss, theft, misuse, and unauthorized access, disclosure, alteration, and destruction. Nevertheless, no data security measures can guarantee 100% security. We encourage you to safeguard your passwords, ID numbers, and other information you use to access our Services.

 

OUR RETENTION OF YOUR PERSONAL INFORMATION

We retain personal information for as long as necessary or permitted for the purposes described in this Policy or otherwise authorized by law. This generally means holding the information for as long as one of the following apply:

  • your personal information is reasonably necessary to manage our operations, to manage your relationship with us, or to satisfy another purpose for which we collected the information;
  • your personal information is reasonably necessary to carry out a disclosed purpose that is reasonably compatible with the context in which the personal information was collected;
  • the personal information is reasonably necessary to protect or defend our rights or property (which will generally relate to applicable laws that limit actions in a particular case); or
  • we are otherwise required or permitted to keep your personal information by applicable laws or regulations.

Where personal information is used for more than one purpose, we will retain it until the purpose with the latest period expires. For more information about our retention practices, please contact us using the contact details below.

 

YOUR CHOICES

Updating Your Information. If you wish to update the personal information you have provided to us, you may do so by logging in to your account or by contacting us at Contact Us . Please note that outdated copies of information that you have updated may remain viewable in cached and archived pages for a period of time, and we may maintain records in our systems of this information as well.

Marketing Emails. We may send periodic promotional or informational communications to you. You may opt out of such communications by following the opt-out instructions contained in any email you receive from us or by submitting your request here . Please note that it may take up to ten (10) business days for us to process opt-out requests. If you opt out of marketing communications, we may still send you administrative emails about your account or any product you have requested or received from us.

Text Messages. You have the choice to opt-in to receiving text messages and alerts on the mobile phone number(s) you disclose to us. Once you opt-in, we may send you text messages (i) regarding your account and your orders; (ii) about our products and promotions (including advertisements, sales, and special offers); (iii) to investigate or prevent fraud; and (iv) to alert you in the event of an issue with any of your purchases. You do not have to opt-in to text messages and alerts to use and enjoy our website or products. If you opt-in, standard text messaging charges may apply. You may choose to opt-out of our text messages and alerts at any time by sending us a text message from your mobile phone with the word STOP, STOP ALL, END, QUIT, CANCEL or UNSUBSCRIBE, and we will unsubscribe you from text communications.

Mobile App. If you no longer wish to provide us with information through one of our mobile apps, you may delete or deactivate your account through the app or our website.  Please see our Terms and Conditions for instructions.

 

PRIVACY OF CHILDREN

Our Services are not intended for children, and we do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will delete it in accordance with applicable law.

 

ADDITIONAL INFORMATION FOR FRANCHISEES

If you submit your personal information to request more information from us about our franchise opportunities, we may use that information to contact you to discuss our franchise opportunities. We may ask that you complete our franchise application, which requests the following additional types of personal information from you, including:

  • franchise ownership details and history;
  • financial information, including details of current assets and liabilities, annual income, investments, mortgages, insurance, ACH information, and any history of bankruptcy;
  • driver’s license, state ID, social security, and passport numbers;
  • criminal history (if any).

We may disclose the information provided in our franchise application with our affiliated brands and vendors as needed to process your franchise application, including to run background checks and to determine creditworthiness.

If you provide personal information related to other people, such as your spouse, investment partners, or personal references, as part of the franchise application process, you guarantee that you do so with the knowledge and permission of those people. We may use any information you provide to contact those people and disclose it, as necessary, with our affiliated brands and vendors during the franchise application process.

 

CALIFORNIA PRIVACY NOTICE

As a supplement to the other information provided throughout this Privacy Policy, we provide the following additional information as a notice to residents of California who interact with use as consumers, franchisees, or vendors (collectively “ California residents ”) in accordance with the California Consumer Privacy Act (“ CCPA ”).

How and Why We Collect Personal Information. Cinnabon may, and in the previous twelve (12) months, has collected and used the following categories of personal information about California residents :

CATEGORY OF PERSONAL INFORMATION

CATEGORIES OF SOURCES

PURPOSES FOR COLLECTION

Identifiers , including name, alias, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers

Directly from you

Automatically when you use our Services

Advertising networks

Internet service providers

Data analytics providers

Social networks

Vendors that help us to fulfill and deliver orders, process payments, support our promotions, contests, gift cards, loyalty programs, and sweepstakes, and provide communications, marketing or other services on our behalf

Our affiliated brands and companies

Our franchisees

Data brokers

 

Processing your purchases of or requests for products or services

Communicating with you

To support our contests, promotions, loyalty programs, coupons, and sweepstakes

Customer service

Marketing and advertising

To better understand how users access and use the Services, to improve the Services, to respond to user desires and preferences, and for other research and analytical purposes

To help maintain the safety, security, and integrity of our Services, databases and other technology assets, as well as your account, orders, and deliveries

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Tailoring our content or otherwise personalizing the Services

As part of our application process for prospective franchisees

Personal records information described in Cal. Civ. Code § 1798.80(e) , including name, signature, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit or debit card number, other financial information (including gift cards)

Directly from you

Automatically when you use our Services

Advertising networks

Internet service providers

Data analytics providers

Social networks

Vendors that help us to fulfill and deliver orders, process payments, support our promotions, contests, gift cards, loyalty programs, and sweepstakes, and provide communications, marketing or other services on our behalf

Our affiliated brands and companies

Our franchisees

Data brokers

 

Processing your purchases of or requests for products or services

Communicating with you

Supporting our contests, promotions, loyalty programs, coupons, and sweepstakes

Customer service

Marketing and advertising

To better understand how users access and use the Services, to improve the Services, to respond to user desires and preferences, and for other research and analytical purposes

To help maintain the safety, security, and integrity of our Services, databases and other technology assets, as well as your account, orders, and deliveries

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Tailoring our content or otherwise personalizing the Services

As part of our application process for prospective franchisees

Characteristics of protected classifications under California or federal law , including gender, age, and date of birth

Directly from you

Our affiliated brands and companies

Data analytics providers

Data brokers

 

Communicating with you

To support our contests, promotions, loyalty programs, coupons, and sweepstakes

Marketing and advertising

To better understand how users access and use the Services, to improve the Services, to respond to user desires and preferences, and for other research and analytical purposes

Customer service

To help maintain the safety, security, and integrity of our Services, databases and other technology assets, as well as your account, orders, and deliveries

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Commercial information , including records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies

Directly from you

Automatically when you use our Services

Advertising networks

Data analytics providers

Social networks

Vendors that help us to fulfill and deliver orders, process payments, support our promotions, contests, gift cards, loyalty programs, and sweepstakes, and provide communications, marketing or other services on our behalf

Our affiliated brands and companies

Our franchisees

Data brokers

Processing your purchases of or requests for products or services

Communicating with you

Supporting our contests, promotions, loyalty programs, coupons, and sweepstakes

Customer service

Marketing and advertising

Tailoring our content or otherwise personalizing the Services

As part of our application process for prospective franchisees

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Internet or other electronic network activity information , including browsing history, search history, and information regarding interactions with our websites, applications, or advertisements

Directly from you

Automatically when you use our Services

Advertising networks

Internet service providers

Data analytics providers

Social networks

Our franchisees

Vendors that help us to fulfill and deliver orders, process payments, support our promotions, contests, gift cards, loyalty programs, and sweepstakes, and provide communications, marketing or other services on our behalf

To better understand how users access and use the Services, to improve the Services, to respond to user desires and preferences, and for other research and analytical purposes

To help maintain the safety, security, and integrity of our Services, databases and other technology assets, as well as your account, orders, and deliveries

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Marketing and advertising

Tailoring our content or otherwise personalizing the Services

Customer service

Geolocation data , including the location of the consumer inferred from IP address or mobile app usage

Automatically when you use our Services

Advertising networks

Internet service providers

Data analytics providers

Social networks

Vendors that help us to fulfill and deliver orders, and provide communications, marketing or other services on our behalf

Processing your purchases of or requests for products or services

Customer service

Marketing and advertising

To better understand how users access and use the Services, to improve the Services, to respond to user desires and preferences, and for other research and analytical purposes

To help maintain the safety, security, and integrity of our Services, databases and other technology assets, as well as your account, orders, and deliveries

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Tailoring our content or otherwise personalizing the Services

Audio, electronic, visual, thermal, olfactory, or similar information , including recorded phone calls and in-store video surveillance

Directly from you

Automatically when you use our Services. For example, if you interact with us by phone or video

Our franchisees

Processing your purchases of or requests for products or services

Customer service

To better understand how users access and use the Services, to improve the Services, to respond to user desires and preferences, and for other research and analytical purposes

To help maintain the safety, security, and integrity of our Services, databases and other technology assets, as well as your account, orders, and deliveries

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

As part of our application process for prospective franchisees

Professional or employment-related information

Directly from you

As part of our application process for prospective franchisees

Supporting our contests, promotions, loyalty programs, coupons, and sweepstakes

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

 

Inferences , including information used to create a profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, aptitudes.

Inferred from other categories of personal information we collect

Data analytics providers

Our affiliated brands and companies

 

To better understand how users access and use the Services, to improve the Services, to respond to user desires and preferences, and for other research and analytical purposes

Tailoring our content or otherwise personalizing the Services

Marketing and advertising

As part of our application process for prospective franchisees

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Among the categories of personal information listed above are the following categories of sensitive personal information:

CATEGORY OF SENSITIVE PERSONAL INFORMATION

CATEGORIES OF SOURCES

PURPOSES FOR COLLECTION

Personal information that reveals a Social Security, driver’s license, state identification card, or passport number

Directly from our franchisees and prospective franchisees

As part of our application process for prospective franchisees

Personal information that reveals a consumer’s precise geolocation (location within a radius of 1,850 feet)

Automatically when you use our mobile applications

 

We may use “Precise geolocation” for the following purposes: (i) facilitate locating a Cinnabon location; and (ii) improving your customer experience.

Marketing and advertising

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

In addition to the purposes described above, we may use and disclose any category of personal information or sensitive personal information we collect to comply with law, cooperate with and respond to law enforcement requests, or as otherwise required by applicable law, court order, or governmental regulations; to maintain appropriate records for internal administrative purposes; to protect our rights and interests and those of our franchisees, to resolve any disputes, to enforce this Policy or any of our other policies, to protect the rights or property of another, or to prevent harm; and to evaluate or conduct a merger, sale, or other acquisition of some or all of our organization or its assets.

Our Retention of Personal Information. We keep the categories of Personal information described above for as long as necessary or permitted for the purposes described in this Policy or otherwise authorized by law. More details about our retention practices are set forth above .

Disclosure of California Personal Information. Although we do not sell personal information in exchange for money, some of the ways in which we share personal information for advertising or disclose personal information to our affiliated brands and franchisees may be considered “sales” or “sharing” under California law. We do not have actual knowledge that we sell or share the personal information of anyone under 16 years of age.

The first chart below shows the categories of personal that we share for purposes of cross-context behavioral advertising or otherwise “sell,” as that term is defined under California law. The second chart describes the categories of personal information we disclose for a business or commercial purpose .

Sales and Sharing of Personal Information

CATEGORY OF PERSONAL INFORMATION

CATEGORIES OF THIRD PARTIES TO WHICH SOLD OR SHARED

PURPOSES FOR SELLING / SHARING

Identifiers

Our affiliated brands and companies

Our franchisees

Advertising partners and social media platforms

Analytics, data strategy, consultation on, development or improvement of products and services, marketing, advertising, and related services for the benefit of Focus Brands and its affiliated companies, brands, and franchisees

Co-marketing, ad targeting, remarketing, and customized advertising content

As part of our application process for prospective franchisees

Personal records

Our affiliated brands and companies

Our franchisees

Advertising partners and social media platforms

Analytics, data strategy, consultation on, development or improvement of products and services, marketing, advertising, and related services for the benefit of Focus Brands and its affiliated companies, brands, and franchisees

Co-marketing, ad targeting, remarketing, and customized advertising content

As part of our application process for prospective franchisees

Characteristics of protected classifications

Our affiliated brands and companies

Our franchisees

Advertising partners and social media platforms

Analytics, data strategy, consultation on, development or improvement of products and services, marketing, advertising, and related services for the benefit of Focus Brands and its affiliated companies, brands, and franchisees

Co-marketing, ad targeting, remarketing, and customized advertising content

Commercial information

Our affiliated brands and companies

Our franchisees

Advertising partners and social media platforms

Analytics, data strategy, consultation on, development or improvement of products and services, marketing, advertising, and related services for the benefit of Focus Brands and its affiliated companies, brands, and franchisees

Co-marketing, ad targeting, remarketing, and customized advertising content

Internet or other electronic network activity information

Our affiliated brands and companies

Advertising partners and social media platforms

Analytics, data strategy, consultation on, development or improvement of products and services, marketing, advertising, and related services for the benefit of Focus Brands and its affiliated companies, brands, and franchisees

Co-marketing, ad targeting, remarketing, and customized advertising content

Geolocation Data

Our affiliated brands and companies

Advertising partners and social media platform

Analytics, data strategy, consultation on, development or improvement of products and services, marketing, advertising, and related services for the benefit of Focus Brands and its affiliated companies, brands, and franchisees

Co-marketing, ad targeting, remarketing, and customized advertising content

Professional or employment-related information

Our affiliated brands and companies

Our franchisees

As part of our application process for prospective franchisees

Inferences

Our affiliated brands and companies

Our franchisees

Analytics, data strategy, consultation on, development or improvement of products and services, marketing, advertising, and related services for the benefit of Focus Brands and its affiliated companies, brands, and franchisees

As part of our application process for prospective franchisees

Disclosures for a Business or Commercial Purpose

CATEGORY OF PERSONAL INFORMATION

CATEGORIES OF RECIPIENTS

PURPOSES FOR DISCLOSURE

Personal Information

 

Identifiers

Franchisees

Our affiliated brands and companies

Service providers that we use to support our business and operations

Professional advisors, external auditors, and government bodies

 

Processing your purchases of or requests for products or services

Performing services on our behalf (e.g., fulfilling and delivering orders, processing payments, supporting our promotions, contests, gift cards, loyalty programs, and sweepstakes, and providing communications, technical, analytical, web hosting, cloud hosting and mobile application support, or other services on our behalf)

Providing advertising and marketing services (except for cross-context behavioral advertising)

Short-term, transient use, including, but not limited to, non-personalized advertising

Auditing, related to ad impressions

Ensuring security and integrity of personal information

Debugging to identify and repair errors that impair existing intended functionality

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

As part of our application process for prospective franchisees

Personal records

Franchisees

Our affiliated brands and companies

Service providers that we use to support our business and operations

Professional advisors, external auditors, and government bodies

 

Processing your purchases of or requests for products or services

Performing services on our behalf (e.g., fulfilling and delivering orders, processing payments, supporting our promotions, contests, gift cards, loyalty programs, and sweepstakes, and providing communications, technical, analytical, web hosting, cloud hosting and mobile application support, or other services on our behalf)

Providing advertising and marketing services (except for cross-context behavioral advertising)

Short-term, transient use, including, but not limited to, non-personalized advertising

Auditing, related to ad impressions

Ensuring security and integrity of personal information

Debugging to identify and repair errors that impair existing intended functionality

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

As part of our application process for prospective franchisees

Characteristics of protected classifications

Franchisees

Our affiliated brands and companies

Service providers that we use to support our business and operations

Professional advisors, external auditors, and government bodies

 

Performing services on our behalf (e.g., fulfilling and delivering orders, processing payments, supporting our promotions, contests, gift cards, loyalty programs, and sweepstakes, and providing communications, technical, analytical, web hosting, cloud hosting and mobile application support, or other services on our behalf)

Providing advertising and marketing services (except for cross-context behavioral advertising)

Short-term, transient use, including, but not limited to, non-personalized advertising

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Commercial information

Franchisees

Our affiliated brands and companies

Service providers that we use to support our business and operations

Professional advisors, external auditors, and government bodies

 

Processing your purchases of or requests for products or services

Performing services on our behalf (e.g., fulfilling and delivering orders, processing payments, supporting our promotions, contests, gift cards, loyalty programs, and sweepstakes, and providing communications, technical, analytical, web hosting, cloud hosting and mobile application support, or other services on our behalf)

Providing advertising and marketing services (except for cross-context behavioral advertising)

Short-term, transient use, including, but not limited to, non-personalized advertising

Auditing, related to ad impressions

Ensuring security and integrity of personal information

Debugging to identify and repair errors that impair existing intended functionality

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

As part of our application process for prospective franchisees

Internet or other electronic network activity information

Our affiliated brands and companies

Service providers that we use to support our business and operations

Professional advisors, external auditors, and government bodies

 

Processing your purchases of or requests for products or services

Performing services on our behalf (e.g., fulfilling and delivering orders, processing payments, supporting our promotions, contests, gift cards, loyalty programs, and sweepstakes, and providing communications, technical, analytical, web hosting, cloud hosting and mobile application support, or other services on our behalf)

Providing advertising and marketing services (except for cross-context behavioral advertising)

Short-term, transient use, including, but not limited to, non-personalized advertising

Auditing, related to ad impressions

Ensuring security and integrity of personal information

Debugging to identify and repair errors that impair existing intended functionality

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Geolocation data

Our affiliated brands and companies

Service providers that we use to support our business and operations

Professional advisors, external auditors, and government bodies

 

Processing your purchases of or requests for products or services

Performing services on our behalf (e.g., fulfilling and delivering orders, processing payments, supporting our promotions, contests, gift cards, loyalty programs, and sweepstakes, and providing communications, technical, analytical, web hosting, cloud hosting and mobile application support, or other services on our behalf)

Providing advertising and marketing services (except for cross-context behavioral advertising)

Short-term, transient use, including, but not limited to, non-personalized advertising

Auditing, related to ad impressions

Ensuring security and integrity of personal information

Debugging to identify and repair errors that impair existing intended functionality

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Audio, electronic, visual, thermal, olfactory, or similar information

Our affiliated brands and companies

Service providers that we use to support our business and operations

Professional advisors, external auditors, and government bodies

 

Performing services on our behalf (e.g., providing communications, technical, analytical, web hosting, cloud hosting and mobile application support, or other services on our behalf)

Debugging to identify and repair errors that impair existing intended functionality

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Professional or employment-related information

Our affiliated brands and companies

Service providers that we use to support our business and operations

Professional advisors, external auditors, and government bodies

As part of our application process for prospective franchisees

Performing services on our behalf (e.g., supporting our promotions, contests, gift cards, loyalty programs, and sweepstakes, or other services on our behalf)

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Inferences

Our affiliated brands and companies

Service providers that we use to support our business and operations

Professional advisors, external auditors, and government bodies

 

Performing services on our behalf (e.g., providing communications, technical, analytical, web hosting, cloud hosting and mobile application support, or other services on our behalf)

Providing advertising and marketing services (except for cross-context behavioral advertising)

Auditing, related to ad impressions

Ensuring security and integrity of personal information

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

As part of our application process for prospective franchisees

Sensitive Personal Information

 

Personal information that reveals a Social Security, driver’s license, state identification card, or passport number

Our affiliated brands and companies

Service providers that we use to support our business and operations

Services performed on our behalf (e.g., providing communications, cloud hosting, and other support for our franchise relationships)

Ensuring security and integrity of personal information

Detecting, investigating, or protecting against malicious, deceptive, fraudulent, or illegal activity

As part of our application process for prospective franchisees

Precise geolocation

Our affiliated brands and companies

Service providers that we use to support our business and operations

Professional advisors, external auditors, and government bodies

 

Processing your purchases of or requests for products or services

Performing services on our behalf (e.g., fulfilling and delivering orders, processing payments, supporting our promotions, contests, gift cards, loyalty programs, and sweepstakes, and providing communications, technical, analytical, web hosting, cloud hosting and mobile application support, or other services on our behalf)

Providing advertising and marketing services (except for cross-context behavioral advertising)

Short-term, transient use, including, but not limited to, non-personalized advertising

Auditing, related to ad impressions

Ensuring security and integrity of personal information

Debugging to identify and repair errors that impair existing intended functionality

Detecting, investigating, or protecting against malicious, deceptive, fraudulent or illegal activity

Right to Opt Out of Sales and Sharing. You have the right to direct us not to sell or share your personal information. To opt out of the sale or sharing of personal information through tracking technologies such as cookies and pixels, please go to the Your Privacy Choices link in the cookie banner or the footer of the website where you want to opt out. If you wish to opt out of the offline sale or sharing of your personal information, you may submit an opt-out request by clicking here , or by calling our toll-free CCPA Request Hotline at 1-877-845-7444. If you choose to use the Global Privacy Control (GPC) browser signal, or any other opt-out preference signal, you will be opted out of online, cookie-based sales or sharing of personal information associated with the browser for which you have enabled the signal. If you use multiple browsers or devices, you will need to activate the signal for each one that you use.

Right to Know. You have the right to know:

  1. The categories of personal information we have collected about you, including:
    1. The categories of sources from which the personal information was collected
    2. Our business or commercial purposes for collecting (or selling or sharing—if applicable) your personal information
    3. The categories of recipients to which we disclose personal information
    4. The categories of personal information about you that we sold, and for each category identified, the categories of third parties to which we sold that particular category of personal information; and
    5. The categories of personal information that we disclosed for a business purpose, and for each category identified, the categories of recipients to which we disclosed that particular category of personal information.
  2. The specific pieces of personal information we have collected about you.

Deletion. You have the right to request that we delete personal information that we collected from you, subject to certain exceptions. In response, we will delete, and instruct any applicable service providers or contractors to delete, your personal information, unless an exception applies. Where we use deidentification to satisfy a deletion request, we commit to maintaining and using the information in deidentified form and will not attempt to reidentify the information.

Correction. If you believe that personal information we maintain about you is inaccurate, you may submit a request for us to correct that information. Upon receipt of a verifiable request to correct inaccurate personal information, we will use commercially reasonable efforts to correct the information as you direct.

Right to Limit Use and Disclosure of Sensitive Personal Information. You may direct us to limit the use and disclosure of your sensitive personal information to uses/disclosures that are reasonably necessary to provide our goods and services, or as needed: to ensure security and integrity; to prevent fraud or illegal activity; for physical safety; for short-term, transient use, including for non-personalized advertising; to perform services on behalf of the business; and to verify or maintain the quality or safety of a service or device owned, manufactured, manufactured for, or controlled by us, and to improve, upgrade, or enhance such services or devices.

Non-Discrimination Rights. You have the right not to be discriminated against for exercising any of your CCPA rights. This means that, consistent with California law, we will not deny providing our products or services to you, charge you different prices or provide a different level or quality of products or services to you unless those differences are related to the value of your personal information.

How to Submit a Privacy Rights Request. You can submit your request using the online request form found here or by calling our toll-free CCPA Request Hotline at 1-877-845-7444, where a member of our team will process your request and guide you through the verification process. You are not required to create an account with us to submit a request.

Only you, or someone you authorize to act on your behalf, may make a request related to your personal information. If you designate an authorized agent to make a request on your behalf, you will still need to verify your identity directly with us before your request can be processed. An authorized agent may submit a request on your behalf using the webform or toll-free number listed above.

Certain CCPA privacy rights requests are subject to a verification process. If you submit a request to know, request to delete, or request to correct, you will be asked to log into your account or to provide 2-3 pieces of personal information that we will match against our records to verify your identity. We will not fulfill a CCPA privacy rights request unless we have been provided sufficient information for us to reasonably verify that the requestor is the person about whom we collected the personal information. Please follow any instructions provided and promptly respond to any follow-up inquiries so that we may confirm your identity. If you request that we provide you with specific pieces of information or request deletion or correction of certain kinds of information, we may apply heightened verification standards.

Our Financial Incentive Offers. From time to time, we offer coupons, specials, or other discounts to consumers who have opted-in to the receipt of promotional communications from us by providing us with certain personal information, such as an email address or a phone number. Occasionally, we also offer consumers the opportunity to enter contests and sweepstakes. Consumers who share certain personal information with us by entering have a chance to win the contest or sweepstake. Each contest or sweepstake is governed by its own terms, and the specific financial incentive offered will be detailed in such terms.

Consumers may also join our free rewards program. You will be enrolled in our rewards program only after you provide prior opt-in consent. Participation in our rewards program gives consumers the opportunity to accrue points with qualifying purchases that can be redeemed for rewards.

Material Terms of Our Financial Incentive Offers

When we offer coupons, specials, or other discounts that may be deemed a financial incentive, the offer will include an explanation of its material terms. The nature and value of any such offer or financial incentive may differ depending on the benefit provided and what information we collect. Most financial incentives that we offer will involve one or more of the following categories of personal information: personal identifiers, commercial information, and purchase records.

Our rewards program is subject to our Terms and Conditions . Our rewards program collects the following categories of personal information: identifiers (such as name and email address), personal  records (such as telephone number), characteristics or protected classifications under California or federal law (such as gender), commercial information/purchase records (such as products purchased), professional or employment-related information, and inferences from personal information collected (such as creation of customer profiles reflecting preferences).

Financial Incentive Offer Opt-In Consent and Right to Withdraw

Participation in our financial incentives, including our rewards program, requires your prior opt-in consent. You can opt-in to participate in our financial incentives by checking the opt-in box when you sign up for an account, or by entering a contest or sweepstakes we sponsor. You may opt out of marketing emails at any time by following the opt-out instructions contained in any marketing email we send to you.

Similarly, you may withdraw from our rewards program by deleting or deactivating your account through the app or our website.  Please see our Terms and Conditions for instructions. If you delete your profile, you will lose any points, rewards, and offers that have accrued.

Our Good Faith Valuation of California Consumers’ Personal Information

Our offers and financial incentives may be individualized to each consumer, or a group of consumers, based on one or more factors. Nonetheless, each offer or financial incentive related to the collection, retention, and other use of your personal information is based upon our reasonable determination of the estimated value of such information, which takes into consideration, without limitation, estimates regarding the anticipated revenue generated from such information, the anticipated expenses which might be incurred in the collection, storage, and use of such information in the operation of our business, and other relevant factors related to the estimated value of such information to our business, as permitted under the CCPA. Thus, the value of a consumer’s personal information will depend on the specific offer or financial incentive. With respect to our rewards program, we treat the value of consumer data collected through the program as the equivalent of relevant expenses related to the collection and retention of consumer’s personal information as part of the program .

California’s Shine the Light Law. California residents may ask Cinnabon to provide them with (i) a list of certain categories of personal information that we have disclosed to third parties for their direct marketing purposes during the immediately preceding calendar year, and (ii) the identity of those third parties. California residents may make one such request per calendar year.

To make this request, you may contact Cinnabon at privacy@cinnabon.com or send a letter to 5620 Glenridge Drive NE, Atlanta, GA 30342. In your request, please state that you are a California resident making a request under California’s Shine the Light Law and provide a current California mailing address for our response. Please allow up to thirty (30) days for a response. Cinnabon reserves its right not to respond to such requests submitted to addresses other than those specified in this paragraph.

Please note that rights under the CCPA and California’s Shine the Light law must be exercised separately.

 

ADDITIONAL INFORMATION FOR VIRGINIA CONSUMERS

As a supplement to the information provided throughout this Privacy Policy, we provide the following information to Virginia consumers, including a description of how to exercise their rights under the under the Virginia Consumer Data Protection Act (“ VCDPA”). Terms defined in the VCDPA that are used in this section shall have the same meaning as in the VCDPA.

Cinnabon LLC is the data controller for customer personal information collected through our Services. Please see the other sections of this Privacy Policy for information about the categories of personal information we process, our purposes for processing personal information, categories of personal information we disclose and who we disclose it to.

Additional Information about Certain Data Uses.

We may process your personal information for targeted advertising. To opt out of the use of your personal information for targeted advertising, please go to the Your Privacy Choices link in the cookie banner or the footer of the website where you want to opt out.

Virginia Privacy Rights

If you are a Virginia consumer, you have the right to submit certain requests relating to your personal information as described below. To exercise your rights, please submit a request through our webform or, to opt out of targeted advertising, go to the Your Privacy Choices link in the cookie banner or the footer of the website where you want to opt out. Please note that we will need to authenticate your identity before your request can be processed. For authentication, you will be asked to log into your account or to provide 2-3 pieces of personal information that we will match against our records.

Right to Access and Data Portability . You have the right to confirm whether we are processing your personal information, to access your personal information, and to obtain a copy of personal information you provided to us in a portable format.

Right to Correct . You have the right to request that we correct inaccuracies in your personal information, taking into account the nature of the personal information and our purposes for processing it.

Right to Delete . You have the right to request that we delete your personal information.

Right to Opt Out . Under the VCDPA, you have the right to opt out of the following uses of your personal information: (a) targeted advertising; (b) the sale of personal information; and (c) profiling in furtherance of decisions that produce legal or similarly significant effects. We do not use your personal information in ways that qualify as sales or profiling under the VCDPA. To opt out of targeted advertising, please submit a request as outlined above.

Right to Appeal . Sometimes we are unable to process requests relating to your personal information, in which case, your request will be denied. If you are a resident of Virginia whose privacy rights request has previously been denied by us and you believe we denied it in error, you may appeal for reconsideration of your request using our webform .

Please note that if you make a privacy rights request, we will retain a record of your request for recordkeeping purposes.

 

PRIVACY INFORMATION FOR NEVADA RESIDENTS

Nevada residents may opt-out of the “sale” of “covered information” to third parties, including but not limited to name, address, social security number, telephone number, email address, and other information through which a person may be contacted. Our uses of your personal information are not sales under Nevada law.  If you have any questions or if you would like to receive notice by email in the event we should engage in “sales” of personal information under Nevada law in the future, please contact us using the contact information provided below.

 

INTERNATIONAL USERS

Cinnabon is based in the United States. If you are using our Services outside the United States, please be aware that personal information we obtain about you may be transferred to and processed in the United States or other jurisdictions outside your own. Your personal information may be accessible by public authorities where it is processed. By using our Services and providing your personal information, you acknowledge that your personal information may be transferred to and processed in jurisdictions other than your own. Please be aware that the data protection laws and regulations that may apply to your personal information transferred to the United States or other countries may be different from the laws in your country of residence.

 

NOTICE TO EUROPEAN ECONOMIC AREA AND UNITED KINGDOM RESIDENTS

As a supplement to the information provided throughout this Privacy Policy, we provide the following information as a notice to residents of the European Economic Area (“ EEA”) of their rights under the European Union’s General Data Protection Regulation and residents of the United Kingdom (“ UK”) of their rights under the United Kingdom’s General Data Protection Regulation.

Cinnabon LLC is the data controller for customer personal information collected through our Services. Cinnabon Franchisor SPV LLC is the data controller with respect to the data of franchisees, prospective franchisees, and franchisee applicants it collects or otherwise processes. You may be required to provide certain personal information, such as your contact information and payment details, in order to use our Services and place an order for our products.

Legal Bases for Our Personal Information Processing. Your personal information is processed under the following legal bases:

  • The processing is necessary for us to provide you with the services you request or to respond to your questions.
  • We have a legal obligation to process your personal information, such as compliance with applicable tax laws or other government regulations or compliance with a court order or binding law enforcement request.
  • We have a legitimate interest in processing your personal information and our reasons for using your personal information outweigh the potential prejudice to your data protection rights. In particular, we have a legitimate interest in the following instances:
    • To analyze and improve the safety and security of our Services, including by implementing and enhancing security measures and safeguards and protecting against fraud, spam, and other abuses;
    • To maintain and improve our Services;
    • To operate and promote our Services, to advertise and provide you with information and communications about our Services that are tailored to, and in accordance with, your preferences; and
    • To protect our legal rights, prevent misuse of our Services, perform on a contract, or comply with other legal obligations.
  • You have consented to our processing of your personal information. When you consent, you may change your mind and withdraw your consent at any time by emailing us at privacy@cinnabon.com .

Your Privacy Rights. You may ask us to take the following actions with respect to your personal information:

  • provide you with information about our processing of your personal information and access to your personal information;
  • update or correct inaccuracies in your personal information;
  • delete your personal information;
  • transfer a copy of your personal information to you or a third party of your choice; and
  • stop or restrict our processing of your personal information.

You may submit these requests by emailing us at privacy@cinnabon.com . We may require specific information from you to help us verify your identity prior to processing your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to any legal restrictions on disclosing this information.

Submitting a Complaint. If you would like to submit a complaint about our use of your personal information or our response to your request regarding your personal information, you may contact us at privacy@cinnabon.com or submit a complaint directly to the data protection authority in your jurisdiction. If you reside in the EEA, you can find information about your data protection authority here . If you reside in the UK, you may file complaints with the Information Commissioner’s Office here .

Transfers of Your Personal Information. When you directly provide your personal information through our Services, you acknowledge that your personal information is being provided by you to a company based in the United States. The laws that apply to personal information protection in the United States differ from those applicable in the EEA and the UK. If it is necessary for us to transfer personal information out of the EEA and the UK, we do so by using suitable data transfer safeguards, such as the standard contractual clauses approved by the European Commission, which impose data protection obligations on parties to the transfer. You may obtain additional information about our data transfer mechanisms by contacting us at privacy@cinnabon.com .

 

NOTICE TO RESIDENTS OF CANADA

Your Privacy Rights. You have the following rights with respect to your personal information:

  • access to your personal information;
  • verify or correct inaccuracies in your personal information;
  • delete your personal information; and
  • where you have provided your consent to the collection, use, transfer, or other processing of your personal information, withdraw your consent under certain circumstances.

You may submit these requests by email to us at privacy@cinnabon.com . We may require specific information from you to help us verify your identity prior to processing your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to any legal or regulatory restrictions on disclosing this information. Please note, if you withdraw your consent, we may not be able to provide you with a particular product or service. We will explain any impact to you to help you with your decision.

 

CHANGES TO THIS POLICY

We may update or modify this Privacy Policy from time to time at our discretion. We will indicate changes to this Privacy Policy by updating the “Effective Date” at the beginning of the Privacy Policy. Please review this Privacy Policy periodically and especially before you provide any personal information to us. Your continued use of our Services after any update will constitute your acceptance of our changes.

 

CONTACT US

If you have questions about this Privacy Policy or Cinnabon privacy practices, please contact us at privacy@cinnabon.com or by mail at 5620 Glenridge Drive NE, Atlanta, GA 30342.