Papa Johns (GB) Limited (trading as Papa Johns) is committed to complying with the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018 (DPA 2018) and the Privacy and Electronic Communications Regulations (PECR), as amended or updated from time to time (“Applicable Privacy Legislation”). All references in this Privacy Notice to “processing”, “personal data”, “processor”, “controller”, and “data subject” shall have the meanings given in the above referenced Applicable Privacy Legislation.
APPLICABILITY
This Privacy Notice describes how we collect, store, use, and share personal data about you when you interact with us. It applies to the practices on all Papa Johns websites and mobile applications where a link to this Privacy Notice appears (the “Sites”). Your use of our Sites is additionally subject to our Terms and Conditions, Cookie Policy, and other notices posted on our Sites.
Papa Johns (GB) Limited, located at 11 Northfield Drive, Milton Keynes, MK15 0DQ, (referred to herein as “Papa Johns”, “we”, and “our”) is the controller of the Sites. For questions about our data protection practices, you may contact Papa Johns data protection representative by email, phone, or postal mail at the following:
Data Protection
Papa Johns (GB) Limited
11 Northfield Drive, Milton Keynes, MK15 0DQ
dataprotection@papajohns.co.uk
Tel: 0203 6936800
Our Sites are not intended for children under 13 years of age. Children aged 13 years or younger may submit personal data through our Sites only with advance permission from their parents or legal guardians.
PERSONAL DATA WE COLLECT
We may collect the types of personal data listed below when you visit our Sites or otherwise place an order with us:
- Contact information. We collect names and addresses. We also collect phone numbers and email addresses.
- Account information. When you create an account, you provide us with a password. You can also provide your month and day of birth.
- Payment information. We or our processors collect payment information if you make a purchase. This includes credit or debit card numbers and security codes, or other methods of payment information.
- Transaction data. We collect information about purchases. This includes amount purchased and the time and day of your purchases. We also keep track of whether you used a discount or promotional code. We also collect information about your favourite orders and food preferences. We also collect information related to your participation in our loyalty scheme Papa Rewards.
- Information you submit or post. We collect information that you post on our site. This includes public comments. We may also collect survey response information.
- Location information. We may approximate your location based on your IP address. We may also collect app geo-location data.
- Site and device information. We collect log and session data. We also collect browser and operating system information. We may collect IP addresses or device identifiers. This may include precise location information if those settings are turned on in your phone. We also may collect what site you came from or what site you visit when you leave us. We may also collect information about your interactions with our emails and advertisements.
- Social media activity. We may collect information about you from social media. This includes when you follow us or share our content. The information we collect depends on your privacy settings with the social network.
- Audio and visual information. We may collect information from in-store security videos. We may collect information from customer service audio calls.
- Inferences from the above categories. We may generate inferences based on your preferences or behaviours. We may also generate inferences based on your purchasing activity.
BUSINESS PURPOSES FOR USING YOUR PERSONAL DATA
We may use your personal data for the purposes listed below when you visit our Sites or otherwise place an order with us:
- Delivering products and providing services to you. We use your personal data to complete and deliver your orders. We also use your personal data to process payments. This processing is necessary for the performance of a contract to which you are a party. We may also use your personal data to maintain your account, or to help find a store near you. We have a legitimate interest to collect and process your personal data for these reasons: to provide you with requested products and services.
For orders that are placed using Amazon Alexa, customers should visit:
https://www.amazon.co.uk/gp/help/customer/display.html?nodeId=GVP69FUJ48X9DK8V to understand more on how Amazon will manage your personal data. - Communicating with and responding to you. We use your personal data to answer questions or respond to feedback. This may include things like providing you with customer service and sending you service messages such as order confirmations and delivery time estimates. We may also contact you in response to questions about this policy or our terms. We have a legitimate interest to collect and process your personal data for these purposes: to allow us to respond to your comments and questions, and to update you on order status and delivery times.
- Improving products and platforms. We may use your personal data to improve our platforms and products, or your experience with us. This may include customizing our platforms for you. We also use your personal data to maintain accounts or perform services. We have a legitimate interest to collect and use your personal data for these reasons: to continue improving the products and services we provide to you.
- Marketing or promotions. We may provide you with new products or offers using your personal data. This may be about our products or others in which we think you may be interested. We might also tell you about new platform features. We may also provide this information on social media platforms. We may also send you push notifications. We may use inferred interests in order to deliver advertising content to you. This might include reviewing your order purchase history. We may communicate by email or text. We have a legitimate interest to collect and process your personal data for these purposes: to better understand your preferences, personalise offers we send to you, and generally improve the way we market our products and services to you. If we send you push notifications, we will rely on your consent.
If you haven’t placed an order with us in the last 24 months, you will automatically be opted out of receiving our direct marketing. If you order from us again through our Sitesand have not previously opted out, we have a legitimate interest to recommence sending you marketing communications about our products.
You can opt out of marketing communications at any time by going to your online account, by using our unsubscribe page located at: www.papajohns.co.uk/unsubscribe or by clicking the unsubscribe link on an email or SMS marketing message. - Papa Rewards – our loyalty scheme. We may also use your personal data to administer and run our loyalty scheme, Papa Rewards. We may send you updates, offers and promotions related to Papa Rewards. We have a legitimate interest to collect and process your personal data for these purposes: to provide you with promotions and offers related to our loyalty scheme, Papa Rewards. You can opt out of receiving Papa Rewards marketing and promotions at the time of enrolment by ticking the relevant box on the Papa Rewards enrolment page. You can unsubscribe from Papa Rewards at any time by going to your online account, using our unsubscribe page located at: www.papajohns.co.uk/unsubscribe or by clicking the unsubscribe link on an email or SMS marketing message.
- Protecting our company and constituents. We use information to protect our company and customers. We also use personal data to identify fraud and secure our systems. We will also use personal data to comply with applicable law, including responding to law enforcement or regulatory requests. We have a legitimate interest to collect and use your personal data for these purposes.
- We use all categories of information for other purposes as permitted by law or as we may notify you.
SHARING PERSONAL DATA
We may share your personal data in the ways listed below:
- We share information for marketing and advertising purposes. We may securely share your personal data with certain third-party platforms like Meta, Google, and Braze Inc. These companies assist us with marketing efforts by providing us with data matching, data analytics, direct marketing, and digital advertising services. They process your personal data solely on our behalf and are only permitted to use your personal data for purposes of providing services to us. If you object to us sharing your data with these companies for these purposes, you may contact dataprotection@papajohns.co.uk to update your preferences. You can also opt out of receiving digital advertising from Papa Johns when you visit Meta and Google by updating your marketing settings directly on these platforms.
- We disclose information to our affiliates and to our franchisees. We may share your personal data with our affiliate companies, including Papa John’s International, Inc., and franchisees to manage our daily operations and pursue our business interests, and have a legitimate business interest to do so.
- We disclose information to service providers who perform services on our behalf. We may share your personal data with trusted service providers, such as IT vendors and maintenance companies. This may also include vendors who help us send email communications or deliver products. It may also include payment processors or fraud prevention companies.
- We disclose information to our promotional partners. We may provide contact information to third parties who co-sponsor contests and promotions. These partners may send you information about events and products.
- We disclose information to comply with law or to protect ourselves. We may disclose your personal data to respond to a court order or other legal obligation. We may also disclose your personal data in response to a government agency or investigatory body request. We may also disclose your personal data to investigate potential fraud or to enforce our policies and terms. We may make these disclosures where we have a good faith belief that we are required to make a disclosure.
- We will transfer information with successors to all or part of our business. If all or part of our business is sold, we may transfer your personal data as part of that transaction. We may also transfer your personal data as part of a merger or acquisition. We have a legitimate interest to use your personal data for these purposes: to carry on our routine business affairs.
INFORMATION STORAGE
Generally, we will store your personal data for as long as is necessary to provide you with the services we provide to you, in accordance with our data retention policy. If you do not place an order with us using your Papa Johns account for 24 months, we will automatically pseudonymise your personal data in accordance with this Privacy Notice and our data retention policy. Your personal data that we collect may be transferred and stored outside the European Economic Area (“EEA”), in which case we will treat your data securely and in accordance with this Privacy Notice. Any such transfers will be made pursuant to: (a) model clauses published by the European Commission as set out in the Annex to the Commission Implementing decision C(2021) 3972 dated 4 July 2021 (Module 2 – Controller to Processor)) or (b) model clauses published by the European Commission as set out in the Annex to the Commission Implementing decision C(2021) 3972 dated 4 July 2021 (Module 1 – Controller to Controller).
YOUR DATA SUBJECT RIGHTS
Under Applicable Privacy Legislation you have certain rights regarding how we process your data. You may exercise your rights at any time, free of charge. We are obligated to take reasonable measures to verify your identity when processing a request and may ask you for identification. You can read more about your rights here: https://ico.org.uk/for-the-public/ To exercise any of the following data subject rights, please use the contact details supplied at the bottom of this page:
- Right of access: You have the right to ask us for copies of your personal data. There are some exemptions, which means you may not always receive all the information we process.
- Right of rectification: You have the right to ask us to correct information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
- Right to be forgotten: In certain circumstances you can ask for the data we hold about you to be erased from our records.
- Right to restriction of processing: Where certain conditions apply you have a right to restrict the processing of your personal data.
- Right of portability: In some situations, you have the right to have the data we hold about you transferred to another organisation.
- Right to object: You have the right to object to certain types of processing, such as direct marketing.
- Rights related to automated decision-making including profiling - You have the right not to be subject to a decision based solely on automated processing, including profiling.
COOKIES AND TRACKING TOOLS
We use common tracking tools, such as browser cookies and web beacons, on our Sites to identify you, process your order, serve content to you based on your behaviours and interests, and other purposes. We also engage vendors who place third party cookies on our Sites to help improve customer experience or to track the performance of our marketing programs. For more information on the types of cookies deployed on our Sites, visit: https://www.papajohns.co.uk/cookie-policy. You can manage your cookie preferences by visiting our Privacy Preference Centre when you first visit our website. For further information on cookies in general and how you can control them, you can visit https://ico.org.uk/for-the-public/online/cookies/.
THIRD-PARTY SITES AND LINKS
Our Sites may have links to third party sites or applications. If you click on a third-party link, you will be taken to platforms we do not control. This Privacy Notice does not apply to the privacy practices of those platforms. Read the other companies’ privacy policies carefully. We cannot be and are not responsible for these third parties.
HOW TO CONTACT US
If you have any questions about this Privacy Notice, wish to exercise your data rights or make a complaint about how your personal data is being processed by us you may contact Papa Johns data protection representative at:
Data Protection
Papa Johns (GB) Limited
11 Northfield Drive, Milton Keynes, MK15 0DQ
dataprotection@papajohns.co.uk
Tel: 0203 6936800
You also have the right to lodge a complaint directly with the Supervisory Authority who, in the UK, is the Information Commissioner's Office (ICO). Their contact details are:
The Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
https://ico.org.uk/make-a-complaint/
Tel: 0303 123 1113
UPDATES TO THIS PRIVACY NOTICE
We may make updates to this notice from time to time. We will notify you as required by law and will post the updated version on the Sites where a link to this Privacy Notice appears. Please check back periodically for updates. This Privacy Notice was last updated on 19 December 2024.