California Consumer Privacy Act Notice to Applicants and Employees
Pursuant to the California Consumer Privacy Acdsxt (“CCPA”), this notice provides information about the categories of personal information Grocery Delivery E-Services USA, Inc. (dba HelloFresh) collects about applicants and employees, and the purposes for which the categories of personal information shall be used and disclosed.
For additional information about HelloFresh’s data privacy practices, please see our website Privacy Policy here.
For purposes of this notice, “personal information” means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular California resident or household, or as otherwise defined under the CCPA.
“Personal information” does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records, nor does it include consumer information that is de-identified or aggregate consumer information. It also does not include health or medical information covered by the Health Insurance Portability and Accountability Act (“HIPAA”) or the California Confidentiality of Medical Information Act (“CMIA”), nor does it include personal information covered by other specific privacy laws, such as the Fair Credit Reporting Act (“FCRA”), the Gramm-Leach-Bliley Act (“GLBA”), the California Financial Information Privacy Act (“FIPA”), or the Driver’s Privacy Protection Act.
HelloFresh collects or has collected in the preceding 12 months the following categories of personal information about applicants and/or employees:
Categories of Information (with Examples of Specific Information That May Be Collected)
A. Identifiers: Real name, alias, postal address, email address, social security number, driver’s license number, passport number.
B. Personal information, as defined by California Civil Code Section 1798.80(e): Name, signature, social security number, address, telephone number, driver’s license or state identification card number, education, employment, employment history, bank account number, or any other financial information, medical information, or health insurance information.
C. Characteristics: HelloFresh may collect characteristics of protected classifications (for example, age) under California or federal law as legally required, as permitted and in accordance with applicable state, federal, or local law.
D. Commercial information: HelloFresh may collect commercial information (for example, purchase history) for applicants or employees who are also customers.
E. Internet or other electronic network activity information: This may include, without limitation:
All activity on the Company’s information systems, such as internet browsing history, search history, intranet activity, email communications, social media postings, stored documents and emails, usernames and passwords
All activity on communications systems, including phone calls, call logs, voice mails, text messages, chat logs, app use, mobile browsing and search history, mobile email communications, and other information regarding an employee’s use of Company -issued devices
F. Geolocation data: This may include GPS location data such as from Company-owned or Company-issued mobile devices, applications, or vehicles.
G. Audio, electronic, visual, thermal, olfactory, or similar information: This may include, without limitation, information collected from cameras and similar devices or thermal information.
H. Professional or employment-related information: This may include, without limitation:
Data submitted with an employment application including employment history, recommendations, etc.
Background check and criminal history; security check
Work authorization
Professional licenses, certifications, educational degrees
Performance and disciplinary records
Fitness for duty data and reports
Benefit plan enrollment, participation, and claims information
Leave of absence information including religious and family obligations and physical and mental health data concerning employees and their family members
I. Sensitive information: This may include, without limitation:
Social security, driver’s license, state identification card, or passport numbers
Account log-in, financial account, debit card, or credit card numbers in combination with any required security or access code, password, or credentials allowing access to an account
Precise geolocation
Racial or ethnic origin
Religious or philosophical beliefs
Contents of your mail, email, and text messages (unless the Company is the intended recipient of the communication)
Genetic information
Health information
Information related to sex life or sexual orientation
Information related to citizenship or immigration status
J. Inferences: This may include inferences drawn from any of the information identified above to create a profile about an applicant’s or employee’s behavior, abilities, attitudes, and aptitude, depending on position or to identify correlations between certain characteristics and job success, analyzing data to improve retention, and analyzing employee preferences to inform HR policies, programs, and procedures.
Sources of Personal Information
We may collect your personal information from the following sources:
You. We may collect personal information directly from you or through your use of our facilities or systems, when you send us an email, contact us by phone, or otherwise communicate or interact with us as an applicant or during or after your employment. We may also collect information automatically from you when you use our information systems, etc.
Related Entities and Affiliates. We may collect information about you from our related parties and affiliates.
Social media and related services. We may collect information about you through your social media services consistent with your settings on such services.
Third parties. We may collect information about you from third parties such as your references, background check vendors, staffing agencies, members, colleagues, emergency contacts, or other third-party sources that are lawfully entitled to share your personal information with us. This may include service providers or contractors who collect or process your personal information on our behalf.
How We Use Your Personal Information
HelloFresh uses the personal information listed above for conducting the recruiting and application process, performing onboarding, and managing the employment and post-employment relationship, for business-related purposes, and for legal compliance. For example:
Collecting and processing employment applications, including confirming eligibility for employment, performing background and related security checks, and conducting onboarding.
Communicating with applicants about a current application or future job opportunities.
Processing payroll and other forms of compensation; designing employee benefit plans, programs and administration including enrollment, claims handling, and leave of absence administration.
Maintaining occupational health programs.
Maintaining personnel records and complying with record retention requirements.
Communicating with employees/contractors and/or their emergency contacts and plan beneficiaries.
Complying with applicable state and federal health, labor, employment, benefits, workers’ compensation, disability, equal employment opportunity, workplace safety, and related laws, guidance, or recommendations.
Preventing unauthorized access, use, or disclosure/removal of the company’s property, including the company’s information systems, electronic devices, network and data, vehicles and other assets.
Ensuring and enhancing employee/contractor productivity, efficiency and logistics.
Ensuring compliance with the company’s policies and procedures including those related to its assets, information systems, and data.
Providing training and development opportunities.
Providing requested accommodations.
Designing, implementing, and promoting the company’s diversity and inclusion programs.
Facilitating the efficient and secure use of the company’s information systems.
For purposes related to the safety of employees, customers, and the public.
Improving accuracy of time management systems and attendance, including vacation, sick leave, and other leave of absence monitoring.
Evaluating an individual’s appropriateness for a particular position at the company or promotion to a new position.
Investigating complaints, grievances, suspected violations of company policies and for other workplace investigations; establishing, responding to and managing legal claims against the company and/or its personnel including civil discovery in litigation.
Facilitating other business administrative functions and strategic activities, such as coordinating travel, for risk management, information technology and communications, financial management and reporting, workforce and succession planning, merger and acquisition activities, and maintenance of licenses, permits and authorization applicable to the company’s operations.
As required by applicable law.
Disclosures
To carry out the purposes outlined above, we may disclose your personal information to the following categories of third parties:
Business partners
Service providers, contractors, and vendors (e.g., background check providers, third-party staffing agencies, payroll processors, benefits administrators, insurers, travel agencies, security consultants, information technology providers, data storage providers, etc.)
Professional advisors (e.g., lawyers, auditors, accountants, consultants)
Government entities (e.g., regulatory agencies; law enforcement concerning conduct or activity that we reasonably and in good faith believe may violate federal, state, or local laws)
Third parties for legal, compliance, or business related purposes, including as needed to comply with federal, state, or local laws; comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities; investigate claims or allegations or to establish, exercise or defend legal claims; or to evaluate or conduct a merger, acquisition, bankruptcy, or other transaction in which the third party assumes control or acquires all or part of the assets of our business.
Third parties as directed by you
The following lists the categories of personal information and the third parties to whom we disclose or may have disclosed this information in the preceding 12 months.
Categories of Personal Information (with Categories of Third Parties to Whom Disclosed)
Identifiers and contact information: NOTE: The information in this category may also include elements of Sensitive Personal Information such as Social Security number, driver’s license number, state identification card number, and/or passport number.
Service providers, etc.
Professional advisors
Government entities
Third parties for legal or compliance related purposes
Third parties as directed by you
Protected status: NOTE: The information in this category may also include the following elements of Sensitive Personal Information: racial, ethnic, or national origin, data related to citizenship or immigration status.
Service providers, etc.
Professional advisors
Government entities
Third parties for legal or compliance related purposes
Third parties as directed by you
Commercial information:
Business partners
Service providers, etc.
Professional advisors
Government entities
third parties for legal or compliance related purposes
Third parties as directed by you
Internet or other electronic network activity: NOTE: The information in this category may include the following elements of Sensitive Personal Information: the contents of mail, email, or text messages, to which the business was not the intended recipient.
Service providers, etc.
Professional advisors
Government entities
Third parties for legal or compliance related purposes
Third parties as directed by you
Geolocation data: NOTE: The information in this category may include the following elements of Sensitive Personal Information: precise geolocation.
Service providers, etc.
Professional advisors
Government entities
Third parties for legal or compliance related purposes
Third parties as directed by you
Audio, electronic, visual or similar information:
Service providers, etc.
Professional advisors
Government entities
Third parties for legal or compliance related purposes
Third parties as directed by you
Education or professional and employment information: NOTE: The information in this category may include Sensitive Personal Information.
Service providers, etc.
Professional advisors
Government entities
Third parties for legal or compliance related purposes
Third parties as directed by you
Sensitive information:
Service providers, etc.
Professional advisors
Government entities
Third parties for legal or compliance related purposes
Third parties as directed by you
Inferences drawn from personal information: NOTE: The information in this category may include the following elements of Sensitive Personal Information: racial or ethnic origin, religious or philosophical beliefs, union membership, health information.
Service providers, etc.
Professional advisors
Government entities
Third parties for legal or compliance related purposes
Third parties as directed by you
Selling and Sharing Personal Information
The Company does not “sell” or “share”, as those terms are defined under the CCPA, the categories of personal information we collect. We do not have actual knowledge that we sell or share the personal information of individuals under the age of 16 years.
The Company does not use or disclose your sensitive personal information for purposes that, with limited exceptions, are not necessary for the application process or the employment/post-employment relationship; are not reasonably expected by an average individual in this context, or are not otherwise permitted under the CCPA or by regulation.
Retention
We retain your personal information for as long as necessary to achieve the purpose for which it was collected. We may retain your personal information for longer as necessary to comply with our legal or reporting obligations, to satisfy our legitimate business needs (e.g., resolve disputes, enforce our legal agreements and policies), or as otherwise permitted or required by applicable law. We may also retain your personal information in a deidentified or aggregated form so it can no longer be associated with you.
To determine the appropriate retention period for your personal information, we consider various factors such as the amount, nature, and sensitivity of your information; the potential risk of unauthorized access, use or disclosure; the purposes for which we collect or process your personal information; and, any applicable legal requirements.
California Resident Individual Rights Requests
Individuals who are residents of the State of California have the following rights, subject to certain limitations and verification of identity or authority to make a request.
Right To Know About Personal Information Collected or Disclosed. You have the right to request information beyond what we have disclosed above regarding the following, to the extent applicable:
The categories of personal information the company collected about you
The categories of sources from which that personal information was collected
The business or commercial purposes for which that information was collected, sold, or shared
The categories of third parties to whom the information was disclosed
The specific pieces of personal information collected
Right To Request Deletion of Your Personal Information. You have the right to request that we delete the personal information we collected or maintain about you. Once we receive your request, we will let you know what, if any, personal information we can delete from our records and will direct any service providers and contractors to whom we disclosed your personal information to also delete your personal information from their records.
There may be circumstances where we cannot delete your personal information or direct service providers or contractors to delete your personal information from their records. Such instances include, without limitation, when the information at issue is maintained: (a) to enable solely internal uses that are reasonably aligned with your expectations based on your relationship with the company and compatible with the context in which you provided the information, or (b) to comply with a legal obligation.
Right to Request Correction. You have the right to request that the company correct any inaccurate personal information we maintain about you, taking into account the nature of that information and purpose for processing it.
We will not discriminate or retaliate against you for exercising any of the rights described above.
Submitting CCPA Rights Requests
To submit a CCPA Rights request, please email us at privacy@hellofresh.com.
We reserve the right to only respond to verifiable Requests to Know, Delete, or Correct that are submitted as instructed. A verifiable consumer request is one made by any individual who is:
The individual who is the subject of the request,
An individual on behalf of the individual’s minor child; or
The authorized agent of the individual.
What to submit. If we request, you must provide us with sufficient information to verify your identity and/or authority to act on behalf of the individual. In general, we may ask you to provide identifying information that we already maintain about you or we may use a third-party verification service. In either event, we will try to avoid asking you for sensitive personal information to verify your identity. We may not be able to respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. However, making a verifiable request does not require you to create an account with us.
Additionally, you will need to describe your request with sufficient detail to allow us to review, understand, assess, and respond. We will not use the personal information we collect from an individual to determine a verifiable request for any other purpose, except as required or permitted by law.
Our response. We reserve the right to charge a fee to process or respond to your request if it is excessive, repetitive, or manifestly unfounded. If we determine that a request warrants a fee, we will attempt to notify you as to why we made that decision and provide a cost estimate before completing your request.
Authorized Agent. You may authorize a natural person or a business (the Agent) to act on your behalf. When you submit a Request to Know, Correct, or Delete, the Agent must provide proof that you gave the Agent signed permission to submit the request, and you either must (i) verify you own identity with the business or (ii) directly confirm with us that you provide permission to the Agent. However, these steps are not required when you have provided the authorized agent with power of attorney pursuant to Probate Code sections 4000 to 4465. We reserve the right to deny requests from persons or businesses claiming to be authorized agents that do not submit sufficient proof of their authorization.
Spouses, Dependents, and Associates
If you have knowledge that the company has collected personal information related to your spouse, dependent, or associate, please share a copy of this notice with all such individuals.
We reserve the right to amend this notice at any time without advance notice. Please direct questions about this notice by emailing us at privacy@hellofresh.com.
Last Updated: May 9, 2025
For more information or any questions about this notice or HelloFresh’s privacy policy, please contact your HR manager.
Have you reviewed the above California Consumer Privacy Act Notice to Applicants and Employees?