Last Updated: November 18, 2022
This notice applies to information we collect:
- On our Website.
- In email, text, and other electronic communications between you and us, including between you and our Website and you and our social media pages.
- When you register for online promotions or participate in rewards programs, online programs, surveys, or other transactions or activities.
- Through or as a result of your entry upon any of our facilities or in connection with our operations, or attendance at an event organized or hosted by us.
- As a result of any sales, purchases, or other transactions made through us, including our supermarkets, our money services business, or any of the Services, or through a third-party ordering or delivery service.
- When you use or visit any of the Services.
- From any paper submitted by you to us offline.
- From any entry into any contest, sweepstakes, promotion, or giveaway by us or jointly with our promotional partners, or information submitted as part of any verification of claim paperwork when redeeming a prize.
It does not apply to information collected by any third party, including through any application or content (including advertising) that may link to or be accessible from or on our Website.
We are based in the United States. When we obtain Personal Information about you, we may transfer, process, and store such Personal Information in the United States. By using the Services, you consent to the transfer to, and to the processing and storage of such Personal Information in the United States, which may be outside your country of residence and may have different data protection laws than those in the country in which you reside.
Collection of Information
Information We Collect
- Personal identifiers you provide when you provide information for orders or registration via our Website, when you visit our facilities or operations, transact business with us, enter a contest or sweepstakes run by us, or otherwise use the Services, including your first and last name, alias, address, email address, telephone number, date of birth, social security number, fingerprint(s), gender, account name, online identifier, or any personal identifiers you provide to us when communicating with us.
- Transaction information you provide when you make a purchase from us, transact business with us, or use any of the Services, such as your first and last name, alias, address, telephone number, email address, and payment or financial information.
- Financial information you provide for payment information when you make a purchase from us, transact business with us, enter a contest or sweepstakes run by us, or use any of the Services, such as your social security number, bank account number, debit card number, and/or credit card number, and tax information.
- Records of commercial information such as your current and historical point-of-sale transactions and products purchased from us.
- Internet connectivity, usage, and activity information about your use, and the use by any person(s) you authorize, of our Website, including the content you view, browser device and type, unique device identifier and/or Internet Protocol (IP) address, and information about your interactions with our Website.
- Location information, including information about the local HGG supermarket where you prefer to shop and geolocation information provided through our Website’s server logs and through Google Analytics for our Website by your device interacting with our Website, or associated with your Internet Protocol (IP) address, where we are permitted by law to process this information.
- Sensory data observed on general business security video surveillance at our facilities and operations and within our properties for the security and safety of our employees, customers, operations, assets, resources, and communities.
- Demographic information, professional or employment-related information, work history, qualification/training information, education information, and any other information you choose to provide.
- Internet or other electronic network activity information, including, but not limited to, IP addresses, browsing history, search history, cookies, information about your interaction with our Website, and geolocation data.
Personal information does NOT include:
- Publicly available information from government records.
- Deidentified or aggregated consumer information.
- Information excluded from the California Consumer Privacy Act of 2018 (CCPA) scope, such as:
- Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data;
- Personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994.
How We Collect Your Information
We, or a service provider on our behalf, collect the categories of Personal Information about you via the information you voluntarily provide us when using or accessing the Services from the following categories of sources:
- Directly from you. We collect information you provide to us when you inquire about our goods or services; register with us; subscribe to our mailing list or mobile messaging programs; sign up to receive special offers or coupons, submit entry forms for our sweepstakes or contests; apply for a job through our career portal; place orders; participate in rewards programs, online programs, surveys, or other transactions or activities; through the billing and contact information you provide to us; communicate or otherwise interact with us through telephone, email or other electronic communication; through the use of our Website, the Services, our social media pages, or in person.
- Indirectly from you. We collect information from you, your household, or devices associated with you or your household through your use and actions on our Website, persistent cookies on our Website, and third-party analytics for our Website, as well as publicly available sources of information.
Automatically Collected Information
We, or a service provider that operates the Services or any features therein, collects, stores, and process Personal Information that is automatically collected when you use or access the Services. We (or such service provider) automatically collect Internet protocol (IP) address information (e.g., browser type and date/time stamp) when you access the Services. It is possible that we (or such service provider) would be able to identify you by a combination of your IP address and other information. Note that we, or a third party on our behalf (e.g., Google Analytics), may use “cookies” technology when you use or access the Services. Cookies are small text files that store information such as your preferences and account settings on your computer’s hard drive. We may also use Facebook pixel tags (tiny graphics with a unique identifier that are placed in the code of a webpage) or other similar tracking technologies from third parties, with the Services.
We may obtain information about you from other interactions you have with us outside of the Services, such as your in-store transaction history, customer service phone calls or in-store money transfer services. We may also obtain information about you from (i) third parties collecting such information on our behalf (e.g., via customer service surveys or third-party grocery delivery and pick-up services with which we partner), (ii) other third parties (e.g., demographic marketing information, address verification, or mailing list information) or (iii) data we obtained from prior mergers or acquisitions. We may combine such information with other Personal Information pertaining to you that we collect from the Services.
Information Pertaining To Children
The Services are not directed to, and we do not intend to, or knowingly, collect Personal Information online from, children under the age of 13. If we learn or have reason to suspect that a user of the Services is under the age of 13, we will promptly delete any Personal Information obtained from that user.
Use of Personal Information
We, or our service providers on our behalf, may use Personal Information for one or more of the following business purposes:
- To fulfill or meet the reason you provided the information. For example, if you share your name and contact information to ask a question about our products or services, or communicate with us through email, our Website, our social media pages, or by telephone, we will use that Personal Information to respond to your requests or inquiries and communicate with you. If you provide your Personal Information to make a purchase, we will use that information to process your payment and facilitate delivery or otherwise complete the purchase. We may also save your information to facilitate new purchases by you or process your requests.
- To have a means of communicating with you about transactions with us and send you information or request feedback about your purchases, the Services, and features on our Website, or changes to our policies.
- Delivering Weekly Ad, circulars or other marketing updates (including any mobile messaging programs which may be implemented at any time) pertaining to us or our affiliates and subsidiaries.
- Inviting you to participate in our market research surveys, focus groups, sweepstakes or contests sponsored by us or sponsored by our affiliates and subsidiaries.
- Providing you with special offers, coupons or promotions and special events invitations by us or our affiliates and subsidiaries.
- Offering you opportunities to become a brand ambassador for HGG or our affiliates and subsidiaries via social media, sign up for a potential future loyalty program or visit any e-commerce website we may operate.
- Operating an online grocery delivery or pick-up service by us or our affiliates and subsidiaries.
- If you submitted your Personal Information in connection with a job application, evaluating that application and related materials you submit to us or that we are able to obtain, including for purposes of reference checking, in connection with making an employment decision.
- Managing and improving the Services’ ongoing operation, including maintaining the security of the Services.
- Tracking information about usage trends and user activities online over time and conducting analytics to improve the Services’ operation and services.
- Serving you with advertisements that may be relevant to you and your interests.
- Creating aggregated or anonymized information for analytical and statistical purposes.
- Complying with applicable law or legal process (e.g., a search warrant, subpoena, or court order).
- Verifying and validating your identity or otherwise detecting, preventing, investigating, or providing notice of fraud, unlawful or criminal activity, or activities that may violate our policies.
- Enforcing our agreements and protecting or defending our rights.
- As described to you when collecting your Personal Information or as otherwise set forth in the CCPA.
- Administering and managing any sweepstakes or contests in which you may enter with us, our affiliates or subsidiaries, including to enable you to participate in any contest, drawing, promotion, or sweepstakes by us and be eligible to claim a prize, and for us to contact you regarding your eligibility or entries.
HGG will not collect additional categories of Personal Information or use the Personal Information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Disclosure of Personal Information
HGG does not sell your Personal Information to any third parties for any monetary or commercial benefit, and has not sold your Personal Information in the past twelve (12) months, for any monetary or commercial benefit.
We may disclose Personal Information described above to our affiliates and certain third parties (including regulatory bodies or service providers) under one or more of the circumstances described below: We may also disclose names of prize winners in our sweepstakes or contests when requested by the public or required to by law, or for promotional or advertising purposes.
As Required by Law – if we are required by applicable law to disclose the information;
As Authorized – if you request or authorize the disclosure of the information; and
As Part of Certain Business Transfers – We may disclose Personal Information in connection with a corporate business transaction, such as a potential or consummated merger, acquisition, or joint venture, or for the financing or sale of our assets and could be transferred to another party as one of the business assets in such a transaction. It may also be disclosed in the event of insolvency, bankruptcy, or receivership.
As Permitted by Law – We may also disclose Personal Information in other circumstances, including to law enforcement or other government agencies, tax authorities, applicable regulators (or in response to requests from such parties), in the context of litigation or when we otherwise believe in good faith that such disclosure is necessary or appropriate in connection with any activity that violates law.
Security of Personal Information
We restrict access to Personal Information in our possession solely to those employees, subsidiaries or affiliates of HGG who need to know that information to provide services to you and may disclose Personal Information to third parties as set out above. We require that these entities otherwise keep this information confidential, handle it in accordance with applicable law and implement appropriate technical and organizational measures to protect it. We maintain physical, electronic, and procedural safeguards that comply with applicable laws and regulations to guard Personal Information. The transmission of information via the Internet is not completely secure and we cannot guarantee the absolute security of our servers or databases or those of our service providers. Your use or access of the Services and any transmission of Personal Information through the Services is at your own risk.
Our Website May Have Third Party Links
Our Website may have links to third-party content. We do not control that content or the third party’s privacy practices. We encourage you to read their privacy policies to understand how they use your information.
Your Privacy Rights
We process all Personal Information described above to the extent required by and in accordance with applicable law (including in accordance with any applicable time limits).You may have certain rights in relation to such Personal Information, depending on where you live.
Residents of the State of California
The information in this section is directed only to those users that reside in California.
The California Consumer Privacy Act of 2018 (CCPA) provides California residents who are “consumers,” as defined in the CCPA, with specific rights regarding their Personal Information. This section of this Privacy Notice describes the rights of “consumers,” as defined in the CCPA, and explains how California consumers can exercise those rights (“CCPA Privacy Notice”). Any terms defined in the CCPA have the same meaning when used in this CCPA Privacy Notice. Consumers with disabilities may access this CCPA Privacy Notice in an alternative format by contacting HGG through any one of the methods set forth below.
Right to Request Disclosure About the Personal Information Collected About You
Consumers, as defined in the CCPA, have the right to request that HGG disclose certain information to you about our collection and use of your Personal Information over the past twelve (12) months. Once we have received and verified your request, we will disclose to you:
- The categories of your Personal Information we have collected;
- The categories of sources from which we collect your Personal Information;
- The business or commercial purpose for collecting your Personal Information;
- The categories of third parties with whom we share your Personal Information;
- The specific pieces of your Personal Information we have collected (also called a data portability request); and
- If we disclosed your Personal Information for a business purpose, a list of the categories of Personal Information we have disclosed in the prior 12 months.
However, HGG will not at any time in response to a request disclose a consumer’s financial account number or an account password, or security questions and answers.
HGG is not required to retain any Personal Information collected for a single, one-time transaction, if the information is not regularly retained by HGG, or re-identify any anonymous or de-identified information, in order to disclose that information to you.
We do not sell Personal Information.
Deletion Request Rights
Consumers, as defined in the CCPA, have the right to request that HGG delete any of your Personal Information that we collected from you and retained, subject to certain exceptions. Once we have received and verified your identify and request, we will delete your Personal Information from our records, unless an exception applies.
We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:
- Complete the transaction for which we collected the Personal Information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
Exercising Access and Deletion Rights
If you are a California resident and you wish to exercise your rights to access the information HGG has collected about you and/or request that HGG delete the information about you, you will need to submit a verifiable consumer request so that HGG is able to corroborate your identity and provide your information to you.
You may submit requests for access or deletion to us via the methods set forth in the Contact Us section below. We will respond to your requests within the applicable time periods and in the manner prescribed by the CCPA.
Only you, or a person registered with the California Secretary of State that is authorized by you to act on your behalf, may submit a request for access to, or deletion of, Personal Information.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you.
We will only use Personal Information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request. Any request to delete submitted through an online request will require you first to submit the request and, second, separately confirm that you want the information deleted.
We will not deny services, charge different prices, offer a different quality of service or otherwise discriminate against an individual for exercising the rights afforded to him or her under the CCPA.
However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your Personal Information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt-in consent, which you may revoke at any time.
Some browsers may transmit “do-not-track” (“DNT”) signals to mobile applications with which the user communicates. We currently do not change our tracking practices in response to DNT settings in your browser. We may have our third-party service providers, as discussed above, collect information about your online activities over time. These third parties may not change their tracking practices in response to DNT settings in your browser.
Residents of the State of Nevada
The information in this section is directed only to those users that reside in Nevada.
Under Nevada Revised Statutes Chapter 603A, individuals who are residents of Nevada and whose Personal Information we collect and process may have certain legal rights with respect to such Personal Information.
You may submit requests to review or correct any Personal Information that we have collected through the Services via the methods set forth in the Contact Us section below. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.
Nevada residents who wish to exercise their right to opt-out of the sale of their Personal Information under Nevada Revised Statutes Chapter 603A may submit a request to the designated addresses set forth in the Contact Us section below. We do not, however, sell any Personal Information.
We endeavor to ensure that Personal Information is kept as current as possible and that irrelevant or excessive data is deleted or made anonymous as soon as reasonably practicable. We will retain Personal Information for as long as we determine is required to satisfy the purpose for which we, or a third party on our behalf, collected it or you provided it to us, subject to your right, under certain circumstances, to have certain of such Personal Information erased (see Your Rights above), unless a longer period is required under applicable law or is needed to resolve disputes or protect our legal rights subject to any statutory limitation. We may decide to retain some Personal Information for varying time periods in order to comply with legal and regulatory obligations and for other legitimate business reasons.
HGG Markets LLC
2501 East Guasti Rd.
Ontario, CA 91761
Privacy Inquiries: http://www.lighthouse-services.com/heritagegrocers/privacy
Toll-free Number: (855) 550-0007
In connection with any privacy-related requests you submit to us in exercising rights to which you are entitled under applicable law, we will undertake steps to verify your identity. We may ask you to provide information that we have on file about you or, if the request is submitted in writing or electronically, we may contact you via another method (e.g., telephone) to verify your identity. We will only use Personal Information provided in a request to verify the requestor’s identity and authority to make the request and we will maintain a record of any such requests as required by law.