LAST REVISED: June 29, 2018
Your privacy is important to us. So we’ve developed a Privacy Statement that describes how we collect, use, disclose, transfer, and store your information. It will also tell you about your rights with regard to your personal data.
HOW TO CONTACT US
If after reviewing this Privacy Statement, you would like to submit a request or you have any questions or privacy concerns, please contact:
The Subway Group Privacy Office
c/o Franchise World Headquarters, LLC
325 Sub Way
Milford, CT 06461
Telephone Number: (203) 877-4281 or Toll Free: 1-800-888-4848
Facsimile: (203) 783-7479
Email Address: firstname.lastname@example.org
- ABOUT THIS STATEMENT
- PERSONAL INFORMATION WE COLLECT
- HOW WE USE YOUR PERSONAL INFORMATION
- SHARING YOUR INFORMATION
- TARGETED ADVERTISING
- OPTING OUT
- YOUR RIGHTS AND CHOICES
- INTERNATIONAL TRANSFERS AND PRIVACY SHIELD
- HOW LONG WE KEEP YOUR INFORMATION
- CHILDREN’S PRIVACY
- OUR SECURITY
- OUR GROUP COMPANIES
The Subway Group. The Subway Group (we, us or our) is made up of a variety of companies including but not limited to, Subway IP, Inc. (the owner of our proprietary system for establishing and operating restaurants in order to develop Subway® restaurants worldwide), FWH Technologies, LLC (the owner and licensor of the SubwayPOS® software for use in Subway® restaurants worldwide), Franchise World Headquarters, LLC (a service-oriented company that provides core business related services to other Subway Group entities), the Subway® franchisors (which offer and sell franchises worldwide), and the Subway® advertising entities (which administers national and local advertising funds and activity for Subway® restaurants and Subway® franchisees worldwide). To see a list of the Subway Group entities that may come in contact with your personal information, please see “Our Group Companies” section below.
What this statement applies to. This Privacy Statement applies to the personal information that the Subway Group collects when you interact with the Subway® brand online and offline. This includes information collected through our websites, WiFi services or similar technology provided in Subway® restaurants, branded pages on third party platforms (i.e. social networking services), mobile applications, and through our direct marketing campaigns or other communications, as well as, when you purchase our products, subscribe to our news and offers, enter into one of our promotions or contact customer support (collectively, “Subway Services”).
Changes to this statement. If we make a change to this statement, we will make previous versions available upon request so that you can see when changes occurred and what they are. If we make any material changes to this statement, we will notify you by means of a notice on this site or by an email (sent to the email address specified in your account). Where we are required by applicable data protection laws, we will also seek your consent to any material changes that affect how we use your personal information. We encourage you to periodically review this page for the latest information on our privacy practices.
The personal information we collect falls into three categories: (a) information you provide us directly; (b) information we collect through automated methods; and (c) information we collect from third parties.
Information You Provide Directly
When you use Subway Services, we may ask you to provide certain personal information to obtain our products or use our services. The personal information we collect from you depends on the nature of your interaction with us or the Subway Services you use, but may include the following:
- Contact Information. We may collect personal and/or business contact information including your first name, last name, mailing address, telephone number, fax number, email address, and other similar data.
- Payment Information. If you make a purchase online, you will be required to provide a credit/debit card number and related financial information (such as expiration date, security code and billing address), or other payment (such as via your Subway® Card), depending on the form of payment you choose.
- Account Information. We collect information such as your username and password when you create an account, access our online services, or buy our products. Account information may also include how you purchased or signed up for Subway Services, your transactions, billing and support history the Subway Services you use and anything else related to the account you create.
- Usage Data. This is the personal data we collect about you when you are using Subway Services, which may include information about the date and time of your logins and details of your use of third party applications and advertising you receive.
- Marketing and Communications. We may also collect your preferences in receiving marketing from us and our third parties.
- Security Credentials. We collect user IDs, passwords, email, and similar security information required for authentication and access to your Subway® accounts.
- Information through Social Media. You may also be given the option to link to your Facebook or other social media accounts through Subway Services. Your use of these features may result in the collection or sharing of information about you, depending on the feature. For example, these Features may collect your IP address, which page you are visiting on our site, and may set a cookie to enable the Feature to function properly. They may also allow third-party social media services to provide us information about you, including your name, email address, and other contact information. The information we receive is dependent upon your privacy settings with the social network. We encourage you to review the privacy policies and settings on the social media sites you use to make sure you understand the information that is collected, used, and shared by those sites.
- Customer Service, Surveys & Promotions. There may be times you provide us additional personal information when you interact online or by phone or mail with our customer support channels; when you participate in our customer surveys or promotions; or to facilitate delivery of Subway Services or to help us respond to your inquiries. Types of additional personal information may include voice recordings, photographs and videos.
- Information You Provide about a Third Party. You may decide to provide us with another person’s information (such as their name, email, address or phone number) so that we may recommend or send products or services to that person. Local law may require you to get the consent of that person to provide their information to the Subway Group. We may in turn use the information you provide in accordance with this Privacy Statement.
- If you fail to provide your personal information. Where we need to collect your personal information by law, or under the terms of a contract we have with you, and you fail to provide that information when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, in order to provide you with our products or services). In this case, we may have to cancel the contract and notify you accordingly.
Information Collected Automatically
Whenever you visit or interact with Subway Services as well as any third party advertisers and/or service providers, we may use a variety of technologies that automatically or passively collects information about your online activity. This information may be collected in the following ways:
- Device & Technical Data. We collect technical information when you visit our websites or use our mobile applications or services. This includes information such as you Internet Protocol (IP) address, your login data, the type of mobile device you use, your device operating system and browser type, time zone setting and location, language, a unique device identifier, the address of a referring website, the path you take through our websites, and other information about your session on our websites.
- Geolocation Data. We may collect information about your location when your device is set to provide location information. For example, your device’s GPS signal allows us to show you the nearest Subway® restaurant. To assist us in providing proximity based marketing and other location based services we utilize our Service Provider Google’s Maps API per Google’s Terms of Service which you consent to. For most mobile devices and computer systems, you are able to withdraw your permission for us to collect this information by using your browser or device settings. To withdraw your Google Maps API permission setting please follow the procedures in Google’s Terms of Service. If you have any questions about how to prevent us from collecting exact information about your location, we recommend you contact your mobile-device provider, the device manufacturer, or your web-browser provider. Some online services and in-restaurant technology may not work properly without information about your location.
Information Received from Third Parties
We may collect information about you from other companies and organizations, including public databases, social media platforms, our third party marketing partners or various independent purchasing organizations established for the benefit of Subway® franchisees.
Independent purchasing organizations provide a variety of support functions to Subway® franchisees in that region. Support functions may include, but is not limited to, administering loyalty and gift card programs, in which we may work with the independent purchasing organization in joint marketing efforts in relation to those programs. The Independent purchasing organizations we work with are Independent Purchasing Cooperative, Inc. (United States, its territories, and Canada), Independent Purchasing Company (Australasia) Ltd. (Asia, Australia, and New Zealand), Latin American and Caribbean Independent Purchasing Company (Latin America and Caribbean), Independent Purchasing Company Europe Limited (Europe) and Middle East Independent Purchasing Company Ltd. (MEIPC) (Middle East).
We may also collect information that is publically available. For example, we may collect public information about your when you interact with us through social media. By collecting additional information about you, we can correct inaccurate information, enhance the security of your transactions, and give you product recommendations and special offers that are more likely to interest you.
We may combine the information we receive about you, including information you provide directly to us and information we automatically collect through Subway Services, as well as information collected across other computers or devices that you may use, from other online or offline sources, and from third parties. If we combine your personal information and non-personal information, we will treat the combined information as personal information in accordance with this Privacy Statement.
Anonymous and Aggregated Information
Anonymized and aggregated information does not identify a specific person and is not personal information. We use this type of information for a variety of functions, including measuring users’ interest in and use of Subway Services, conducting internal analysis, data analytics and research. We may also share anonymized or aggregated information with third parties for our or their purposes, but none of this information can be used to identify you or determine anything else personal about you.
We may use the information we collect in the following ways.
To provide our services and contract with you:
- carry out your requests, fulfill orders, and process payments for our products and services;
- communicate with you about your orders, purchases or accounts with us, including handling any requests, questions or comments you may have;
- provide online services to you, which includes our websites and/or mobile applications; and
- provide customer support, including processing any concerns about our services.
To market to you, improve our services, and the following legitimate business interests:
- tell you about our products and services, competitions, offers, promotions or special events that we believe may interest you when you are part of a Subway® loyalty program;
- personalize your experience in our restaurants and on our online services;
- verify your identity or communicate with you about your activities with respect to Subway Services;
- manage our business, including developing new products and services, conducting consumer and operations research, and assessing the effectiveness of our sales, marketing and advertising;
- use analytics and profiling technology to personalize your experience; deliver content (including advertising) tailored to your interests and let you know how to use Subway Services (see “TARGETED ADVERTISING” below for more information);
- link or combine with information we receive from others to help understand your needs, use for interest-based or targeted advertising or re-targeting on your computers or other devices;
- ensure the security of our networks and systems, including to help diagnose technical and service issues, troubleshoot issues, bugs or defects related to your account or activities;
To comply with applicable law:
- protect against fraud and other crime, claims and liabilities;
- comply with legal obligations and our policies;
- establish or defend a legal claim; and
- monitor and report compliance issues.
For the public interest:
- we may use your personal information if we reasonably believe that there is an inherent security or product issue that we must either disclose to you or the authorities and the use of your information will prevent or potentially minimize the danger to you or others.
With your consent (where required by applicable law), we may use the information we collect for the following purposes:
- to send you emails or text messages about the products and services, competitions, offers, promotions or special events we believe may interest you;
- to send you emails or text messages about the products and services of our business partners;
- provide location-based services;
We may use the information we collect about you in other ways, which we will tell you about at the time we collect it and for which we will seek your consent if required by law.
We do not sell any of your personal information including your name, address, email address or credit card information to any third party.
However, we may share the information collected from or about you with the following categories of companies in the following ways:
Within the Subway Group
The Subway Group may share your information amongst our entities in order to administer our loyalty programs, process orders and requests, and expand and promote our product and service offerings. Members of the Subway Group who receive your personal information are not authorized to use or share the information, except as set out in this Privacy Statement.
With Third Parties
Subway® Franchisees and Development Agents. If you choose to contact us or submit a survey about your experience in a Subway® franchisee’s restaurant, we may share your information to the Subway® franchisee in order for them to address your request, compliment or complaint. We may also share your information with the Development Agent who oversees the operations of the restaurant. Development Agents are independent contractors of the Subway® franchisor who are responsible for the growth of the franchise in a specific territory.
Independent Purchasing Organizations. Depending on your region, we may share your personal information with the applicable independent purchasing organization in your market and their subsidiaries in connection with online purchases, registration of gift cards and the administration of loyalty programs.
Third Party Service Providers. We may share your personal information with vendors who provide services to us, such as business, professional or technical support functions. This includes, but is not limited to: service providers that host or operate Subway Services; payment processors; data processing or other information technology services; carrying out research and analysis, providing customer experience management services and personalizing individual customer experiences. We do not allow these vendors to use or share this information for any purpose other than to provide services on our behalf.
Other Third Parties: Your personal information may also be shared with our sponsors, partners, advertisers, advertising networks, advertising servers, and analytics companies or other third parties in connection with marketing, promotional, and other offers, as well as product information. Your information may also be shared with third parties we identify at the time you provide your personal information or otherwise with your consent.
Sweepstakes, Contests, and Promotions: If you choose to enter into one of our sweepstakes, contests, or other promotions, we may disclose your information to third parties or the public in connection with the administration of such promotion, as required by law, as otherwise permitted by the Promotion’s official rules, or otherwise in accordance with this Privacy Statement.
Business Transfers. Your Personal Information is considered a company asset and may be disclosed or transferred to a third party in the event of a proposed or actual purchase, any reorganization, sale, lease, merger, joint venture, assignment, amalgamation or any other type of acquisition, disposal or financing of all or any portion of our business or of any of the business assets or shares (including in connection with any bankruptcy or similar proceeding) of the Subway Group or a division thereof, in order for you to continue to receive the same products and services from, or to continue the same or similar relationship with, the third party.
Legal Disclosures. We may disclose your information if we believe that the disclosure is required by law, a subpoena or other legal process, if we believe that the disclosure is necessary to enforce our agreements or policies, or if we believe that the disclosure will help us protect the rights, property or safety of the Subway Group or our customers or partners.
When You Consent. We may share your information with other companies if you give us permission or direct us to share the information.
We use third parties’ analytics and tracking tools, such as Google Analytics, Adobe Marketing Cloud, Facebook Customer Audience and others, to help us track, segment and analyze usage of the Subway Services, and to help us or those third parties serve more targeted advertising to you on the Subway Services and across the Internet. Those tools may use technology such as cookies, web beacons, pixel tags, log files, Flash cookies, or other technologies to collect and store non-personal information.
At our request, these third parties collect, and share with us, usage information about visits to our websites, measure and research the effectiveness of our advertisements, track page usage and paths followed during visits through our websites, help us target our Internet banner advertisements on our websites and on other sites, and track use of our Internet banner advertisements and other links from our marketing partners' sites to our websites. They may also combine information they collect from your interaction with Subway Services with information they collect from other sources.
Cookies and Other Technologies
If you have agreed to receive marketing communications from us, you can later opt out by following the opt-out instructions in the marketing communications we send you or you can also contact us by using the contact details provided under the “How to Contact Us” section above. Depending on the Subway Services you use, you may also have the ability to change your communication preferences in the profile section of the online services that you use or in your device settings. Where our mobile applications allow for the delivery of “push notifications”, you can also opt out of receiving these notifications by going into your mobile phone settings and toggling the “Notifications” switch within our mobile application to “off”.
If you do opt out of receiving marketing communications from us, we may still send communications to you about your transactions, any accounts you have with us, and any contests, competitions, prize draws or sweepstakes you have entered. Opting out of one form of communication does not mean you’ve opted out of other forms as well. For example, if you opt out of receiving marketing emails, you may still receive marketing text messages if you’ve opted in to receiving them. Please note that if you are receiving communications from a Subway® franchise, then you will need to opt out from them directly.
U.S. and Canada. Participation in the Subway® loyalty program is voluntary; you may end your participation in the Subway® loyalty program by using the contact details provided under the “How to Contact Us” section above, in which case any data gathered through the program will be deleted except what we are legally required to keep. Please note that data originating through other non-program interactions may remain with us.
International. If you would like to opt out of an international loyalty program, please contact the independent purchasing organization that is responsible for administering the program in the region in which you registered. For a list of all the independent purchasing organizations and their regions, please see the “Information Received from Third Parties” section above.
App Tracking Preferences
Opt Out By Deletion. You may opt out of all information collected via our app(s) by uninstalling it. You may use the standard uninstall, application, and data management processes available through your mobile device. Once you have uninstalled the app, all the information that is stored in the app is deleted, including any preferences you previously set for location permissions and whether you have allowed us to send you push notifications. Once the app is uninstalled and preferences are deleted, push notifications from the app will stop. You may also refrain from using application features that collect specific types of data.
Location Opt Out. You may be able to adjust the settings of your device so that information about your physical location is not sent to us or third parties by (a) disabling location services within the device settings; or (b) denying certain websites or mobile applications permission to access location information by changing the relevant preferences and permissions in your mobile device or browser settings. Please note your location may be derived from your WiFi, Bluetooth, and other device settings. See your device settings for more information.
Under certain circumstances, you have rights under applicable data protection laws in relation to your personal information. You have the right to:
Access Your Personal Information. You can request access to your personal information. This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it. You may reasonably access your personal information by contacting the Subway Group Privacy Office regarding the accuracy of your personal information. Please note that we may request specific information from you to enable us to confirm your identity and right to access, as well as to search for and provide you with the personal information we have about you.
Your right to access the personal information that we hold about you is not absolute. There are instances where applicable law or regulatory requirements allow or require us to refuse to provide some or all of the personal information we hold about you. In addition, the personal information may have been destroyed, erased or made anonymous. If we cannot provide you with access to your personal information, we will inform you of the reasons why, subject to any legal or regulatory restrictions.
Modify or Update Your Personal Information. We aim to ensure that personal information in our possession is accurate, current and complete. If you believe that the personal information about you is incorrect, incomplete or outdated, you may request the revision or correction of that information. We will use reasonable efforts to revise it and, if necessary, to use reasonable efforts to inform agents, service providers or other third parties, which were provided with inaccurate information, so records in their possession may also be corrected or updated. However, we reserve the right not to change any personal information we consider accurate.
Erasure of Your Personal Information. You may ask us to delete or remove personal information where there is no legal reason for us to continue using it. You also have the right to ask us to delete or remove your personal information where you successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal information to comply with law. Please note that we may not always be able to comply with your request of erasure for specific legal reasons which we will notify you, if applicable, at the time of your request.
Object to Processing Your Personal Information. You may have the right to object to us processing your information in certain circumstances. This right applies when we are processing your personal information based on a legitimate interest (or those of a third party), which you may challenge if you feel it impacts your fundamental rights and freedoms. You also have the right to object where we are processing your personal information for direct marketing purposes. However, in some cases, we may demonstrate that we have compelling legitimate ground to process your information or legal obligations which override your rights and freedoms.
Data Portability. You may request the transfer of your personal information to you or a third party. We will provide to you, or a third party you have chosen, your information in a structured, commonly used, machine-readable format. Please note this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
California Resident Privacy Rights. California law permits residents of California to request certain details about how their personal information is shared with third parties or affiliated companies for direct marketing purposes. If you are a California resident and would like to make such a request, please contact us at: email@example.com and include “My California Privacy Rights” in the subject line.
Please note that if you opt out of receiving marketing communications from us, we may still send communications to you about your transactions, any accounts you have with us, and any contests, competitions, prize draws or sweepstakes you have entered. Opting out of one form of communication does not mean you’ve opted out of other forms as well. For example, if you opt out of receiving marketing emails, you may still receive marketing text messages if you’ve opted in to receiving them. Please note that if you are receiving communications from a Subway® franchisee, then you will need to opt out from them directly.
If you wish to exercise any of the rights set above, please contact us. We will need you to provide specific information to help us confirm your identify. This is a security measure to help ensure that your personal information is not disclosed to someone that does not have the right to receive it.
Due to our global operations, your personal information may be transferred to and processed in the United States and other countries that may not provide the same level of data protection as your home country. The Subway Group’s privacy practices are consistent with all applicable country, national, state, and local data protection and security laws.
For our customers whose use of Subway Services results in the transfer of personal information from the European Economic Area (EEA) or Switzerland to non-EEA countries, we rely on one or more of the following legal mechanisms: the EU-U.S. Privacy Shield, the Swiss-U.S. Privacy Shield, Standard Contractual Clauses, and consent of the individual.
The Subway® Group’s service entity, Franchise World Headquarters (FWH), and our other U.S. affiliates comply with the EU-U.S. and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the transfer of personal information from the European Economic Area (EEA) and Switzerland to the United States. Our U.S. affiliates certified that they adhere to the Privacy Shield Principles of notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse and liability. If there is any conflict between the terms of this Privacy Statement and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield Program, and to view our certification page, visit https://www.privacyshield.gov.
Franchise World Headquarters and other U.S. affiliates commits to cooperate with EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) and comply with the advice given by such authorities with regard to human resources and non-human resources data transferred from the EU and Switzerland.
In compliance with the EU-US and Swiss-US Privacy Shield Principles, Franchise World Headquarters and other U.S. affiliates commit to resolve complaints about your privacy and our collection or use of your personal information. European Union or Swiss individuals with inquiries or complaints regarding this Privacy Statement should first contact the Subway’s Privacy Office (see “How to Contact Us” above).
Franchise World Headquarters and other U.S. affiliates are subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC) with respect to the Privacy Shield. Under certain conditions, if your complaint is not satisfactorily resolved with us directly, you may submit Privacy Shield-related complaints to the attention of your Data Protection Authority (DPA): http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm, which will establish a panel to investigate and resolve complaints brought under the Privacy Shield. We will fully comply with the advice given by the DPAs and take necessary steps to remediate any non-compliance with the Privacy Shield Principles. Such independent dispute resolution mechanisms are available to EU and Swiss citizens free of charge. Additionally, you may have a right to invoke binding arbitration under the Privacy Shield.
To the extent permitted by applicable law, we retain your personal information as long as (1) it is needed for the purposes for which we obtained it and in accordance with this Privacy Statement or (2) we have another lawful basis, stated in this Privacy Statement or at the point of collection, for retaining that information beyond the period for which it is necessary to serve the original purpose for obtaining the personal information. If the lawful basis for processing that data is based solely on consent, we will delete the personal information if that consent is revoked.
Our services are not intended for use by children under the age of 13 or equivalent minimum age depending on the jurisdiction.
If you are a parent or legal guardian and believe we may have collected information about your child, please contact us as described in the “How to Contact Us” section above.
If we learn that we have inadvertently collected the personal information of a child under 13, or equivalent minimum age depending on the jurisdiction, we will take steps to delete the information as soon as possible.
We recognize the importance of maintaining the security of your personal information. We protect your information using security measures, including physical, administrative, and technical safeguards to reduce the risk of loss, misuse, unauthorized access, disclosure or modification of your information.
While we have employed security technologies and procedures to assist safeguarding your personal information, no system can be guaranteed to be 100% secure. Please note that we cannot ensure or warrant the security of any information you transmit to us. You use Subway Services and provide us with your information at your own risk.
Here is a list of our entities that may be involved in processing your personal information:
- Doctor's Associates Inc.
- Franchise World Headquarters, LLC
- FWH Technologies, LLC
- Sandwich and Salad Franchises of South Africa (Proprietary) Ltd.
- SJ Marketing Kabushiki Kaisha
- Subway Brand Management & Consultant (Shanghai) Co., Ltd.
- Subway Franchise Systems of Canada, Ltd.
- Subway Franchisee Advertising Fund of Australia Pty. Ltd.
- Subway Franchisee Advertising Fund Trust B.V.
- Subway Franchisee Advertising Fund Trust Ltd.
- Subway Franchisee Canadian Advertising Trust
- Subway Franchisee Gift Certificate Management Company, LLC
- Subway International B.V. - Ecuador
- Subway International B.V. - South Korea Branch
- Subway International B.V. - Taiwan Branch
- Subway International B.V.
- Subway International B.V. Sucursal del Peru
- Subway International de Mexico, S.A. de C.V.
Subway IP Inc.
- Subway Japan, Inc.
- Subway MyWay of Canada, ULC
- Subway MyWay, LLC
- Subway Partners Colombia C.V.
- Subway Realty e Desenvolvimento de Software do Brasil Ltda.
- Subway Realty Limited
- Subway Realty of France EURL
- Subway Realty of Italy S.r.l.
- Subway Realty of Spain, S.L.U.
- Subway Realty of the Netherlands B.V. Merkezi Hollanda Istanbul Merkezi Şubesi
- Subway Restaurant Management (Shanghai) Co., Ltd.
- Subway Subs of Canada, Ltd.
- Subway Systems Australia Pty. Ltd.
- Subway Systems do Brasil Ltda.
- Subway Systems India Private Limited
- Subway Systems Middle East FZ-LLC
- Subway Systems Singapore Pte. Ltd.
- Subway Vermietungs-und Servicegesellschaft mbH
- Subway Vermietungs-und Servicgesellschaft G.m.b.H. -organizachi slozka (Czech Republic)
Thank you for reading our Privacy Statement. If you have any questions about this Statement or about how we process personal information, please contact us by using the contact details provided under “How to Contact Us”, which is located at the top of this document.
If we are unable to resolve your concerns, you have the right to contact a data privacy supervisory authority in the country where you live or work, or where you consider that the data protection rules have been breached or seek a remedy through the courts.