California Privacy Rights Act

Heritage Grocers Group, LLC (“HGG” “us” or “we”) adopts this Privacy Notice to California Employees and Job Applicants Regarding the Collection of Personal Information (the “Privacy Notice”) to comply with the California Consumer Privacy Act (“CCPA”) and the California Privacy Rights Act (“CPRA”). If you are not a California resident, you may refer to this Privacy Notice for your knowledge regarding the collection, use and retention of your personal information by HGG. Any terms defined in the CCPA and/or CPRA have the same meaning when used in this Privacy Notice. Employees and job applicants with disabilities may access this Privacy Notice in an alternative format by contacting HGG Human Resources.

HGG is committed to protecting the privacy and security of personal information. HGG, in the regular course of its business, asks job applicants, prospective employees, and employees to provide personal information that is necessary and related to your employment or prospective employment with us. This Privacy Notice describes how HGG collects and uses your personal information, the categories of personal information it collects, and instances where HGG may disclose your personal information to third parties. HGG will only collect and process your personal information in accordance with this Privacy Notice, unless otherwise required by applicable law.

Categories of Personal Information and Sensitive Personal Information HGG Collects and How We Use It

HGG collects and processes your information for human resource, employment and benefit administration purposes, to communicate with you, and where necessary to comply with any local, state, and federal legal obligations. HGG obtains the categories of personal information and sensitive personal information listed below directly from you and the information you provide during your job application, your new hire paperwork and employee onboarding process, during the selection of your employee benefits, and in the course of your employment with us. Depending on the position, HGG may also obtain a background check from an outside agency using your information.

HGG collects the following information:

  1. Personal identifiers you provide when you apply for a job, supply information for your benefits, or in the context of your employment with us, such as your first and last name, your address, your email address, telephone number, date of birth, social security number, telephone number, unique personal identifier, driver license number, passport number, and/or other government identification numbers, immigration and work authorization status, signature, and username created when you apply for a job with us. HGG collects this information to make an employment and/or job related decisions that involve you, to fulfill or meet the reason you provided the information as a job applicant or employee, to provide you with employment with HGG, to manage your employment relationship with us, to communicate with you, for general employee administration and processing (including employee payroll and tax purposes and benefits administration), for I-9 processing and to determine your eligibility to work, for 1099 processing for independent contractors, and to send company information to you. This information is retained for seven (7) years after your employment has ended unless legally required to retain for a longer or shorter period of time.
  2. Demographic and diversity information such as age, race, sex, gender, citizenship, national origin, marital status, veteran or military status, medical condition, and mental or physical disability. HGG collects this information to comply with local, state, and federal laws and regulations, new hire processing, for payroll and benefit purposes, for I-9 processing, for Equal Employment Opportunity reporting, to provide any necessary accommodation in accordance with the Americans with Disabilities Act, and for providing work-sponsored health insurance. This information is retained for seven (7) years after your employment has ended unless legally required to retain for a longer or shorter period of time.
  3. Financial information such as bank account information, state identification number, signature, tax selections, pay rate, payroll deduction information, and medical information. HGG collects this information for employee related human resource administration (including employee payroll and benefits administration), benefit selection and enrollment, I-9 and 1099 processing, for processing work-related claims (for example, insurance or payment claims), and for payroll and direct deposit purposes. This information is retained for seven (7) years after your employment has ended unless legally required to retain for a longer or shorter period of time.
  4. Benefit selection and related information such as your benefit selection, social security number or other government identification number, and date of birth. HGG collects this information to administer benefit claims and for employee related human resource administration. Information regarding benefit selection and related information are retained for the duration of the benefit plan plus six (6) years unless legally required to retain for a longer or shorter period. Other information containing social security number or other government identification number and date of birth are retained for seven (7) years after your employment has ended unless legally required to retain for a longer or shorter period of time.
  5. Biometric information from fingerprints. HGG collects this information for timeclock tracking purposes. This information is retained for as long as necessary to ensure the safety and protection of the company’s employees and to ensure compliance with company’s policies, rules and procedures as well as compliance with applicable state laws.
  6. Sensory data observed on general business security video surveillance at company facilities and operations and within company property. HGG collects this information to ensure the safety and protection of our employees, assets, resources, and communities and to comply with requests, demands or orders received from law enforcement agencies, government bodies or regulatory agencies, courts with competent jurisdiction and other third parties with the right, authority or authorization to make such request, demand or order. This information is retained for up to sixty (60) days from the date that the sensory data is captured on security video surveillance.
  7. Location information, including geolocation information provided through HGG server logs by your device interacting with our website, or associated with your IP address, or through company-provided mobile GPS devices and applications, where we are permitted by law to process this information. HGG collects this information to identify and communicate with you, to ensure the safety and protection of the company’s employees, assets, resources, and communities and for our business operations. Additionally, in the event you enter into a promotional sweepstakes or contest, HGG may collect location information to ensure compliance with the official rules associated with those contests or promotions. This information is retained for as long as is necessary to ensure the safety and protection of the company’s employees and customers or, in the case of information collected during promotional sweepstakes and contests, for as long as is necessary to ensure compliance with the official rules.
  8. Professional and employment-related information such as current or past employment history, degrees earned, employee status and title, training and development information, disciplinary and counseling information, and termination information. HGG collects this information to make hiring and promotion decisions and for other general human resource administration purposes. This information is retained for seven (7) years after your employment has ended unless legally required to retain for a longer or shorter period of time.
  9. Inferences drawn from other personal information, which may include aptitude or personality assessments and leadership training. HGG collects this information for education, training, and development of personnel.
  10. Beneficiary Information of your beneficiaries and dependents, such as name and contact information, relationship to you, birth date, social security or other government identification number, and any other information necessary to process any benefits claims. HGG collects this information for benefit administration purposes. This information is retained for seven (7) years after your employment has ended unless legally required to retain for a longer or shorter period of time.
  11. Emergency Contact Information of person(s) you designate as your emergency contact(s) such as their name and contact information, and their relationship to you. HGG collects this information to maintain contact information should an emergency involving you arise during your employment.
  12. During the COVID-19 pandemic, information relevant to the COVID-19 pandemic, such as your temperature, vaccines and vaccination status, copies of your vaccination card, health screening questions of whether you are experiencing related symptoms, whether you have been quarantined or selected to self-quarantine, whether you have been tested for COVID-19 and the date and results of any such test, and the date you returned to work after any COVID-19 related absence. HGG collects this information in an effort to curb the spread of COVID-19, to implement any sanitary measures necessary, to monitor and protect the health and safety of all related employees and to comply with requests, demands or orders received from law enforcement agencies, government bodies or regulatory agencies, courts with competent jurisdiction and other third parties with the right, authority or authorization to make such request, demand or order. This information is retained for seven (7) years after your employment has ended unless legally required to retain for a longer or shorter period of time.
  13. HGG will not collect additional categories of personal information or use the personal information collected for materially different, unrelated, or incompatible purposes without first providing you with additional or updated notice.

Data Retention

Unless otherwise indicated above, HGG will retain the above information for the duration of your employment with HGG plus an additional two years after employment has ended unless legally required to retain the information for a longer or shorter period of time. In the case of a job applicant who is not hired by HGG, we will retain the information for two years unless legally required to retain for a longer or shorter period of time.

Disclosure to Third Parties

HGG does not sell or otherwise disclose your personal information to any third parties for any monetary consideration. HGG only shares your personal information with service providers to the extent necessary in order to administer employee benefits, including for payment of wages, tax processing, and health insurance, in connection with its human resource activities and to perform services as an employer as required or directed by applicable law. HGG also discloses your information when required to by local, municipal, state, or federal law.

Any disclosure of COVID-19 related information to management and employees at locations where an employee that tests positive was working will be to the extent necessary so that other employees in contact with them can self-isolate, monitor symptoms, and/or get a COVID-19 test, for sanitizing purposes, or to report to relevant authorities. The result of a positive test may also be shared anonymously to third-party cleaning services to the extent necessary that sanitizing action needs to be taken due to a positive test to protect the safety of other employees.

Your Rights Regarding the Information Collected

If you are a California resident, you can make certain requests regarding your personal information. We will fulfill each of these requirements per the requirements of California law.

You can request a copy of the personal information we have about you, including a list of categories of your personal information that we have shared with another company for a business purpose.

You can request that we correct or delete your personal information. Any request to delete may be limited by HGG’ rights and legal obligations under the CCPA, CPRA and other applicable federal and state law.

You can request that we limit the use and disclosure of your precise geolocation.

To exercise the California privacy rights described above, please mail your request at 2501 East Guasti Road, Ontario, California 91761, call us at (855) 550-0007 or submit securely online via http://www.lighthouse-services.com/heritagegrocers/privacy.

Changes to This Privacy Notice HGG reserves the right to update this Privacy Notice at any time and will provide you with a new Privacy Notice when and if any updates are made. If HGG would like to use your previously collected personal data for different purposes than those it notified you about at the time of collection, HGG will provide you with notice and, where required by law, seek your consent, before using your personal data for a new or unrelated purpose. HGG may process your personal data without your knowledge or consent only where required by applicable law or regulation.