This Privacy Policy describes how The Hershey Company (“Hershey,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes Personal Data in connection with:
Collectively, we refer to the above as the “Services.”
In this Privacy Policy does not apply to the websites of or your interactions with Hershey Entertainment and Resorts Company, including The Hotel Hershey and Hersheypark. It also does not apply to the Hershey Park mobile app.
This Privacy Policy should be read in conjunction with our Cookie & Ads Policy, which is available below, and our Terms of Use. Your use of the Website indicates you agree to our collection, use, and disclosure of your Personal Data as described in this Privacy Policy.
Depending on how you interact with us or where you are located, different sections of this Privacy Policy may apply to you and include additional information relating to our data collection and use practices and your legal rights. Please review this Privacy Policy carefully to understand how we handle your Personal Data, and where applicable, the following sections:
We collect the categories of “personal information” (as defined in the California Consumer Privacy Act (CCPA)) listed in the table below.
Category of Personal Information Collected | Sold or Shared |
---|---|
Identifiers, including names, shipping addresses, email addresses, online identifiers, IP addresses, and other similar identifiers (e.g., social media identifiers) |
Yes |
Personal information categories listed in the California Customer Records statute, including telephone numbers and credit and debit card information |
No |
Protected classification characteristics under California law, including age and sex/gender expression |
No |
Commercial information, including items purchased, obtained, or considered and other purchasing or consuming histories or tendencies |
Yes |
Internet or other electronic network activity information, including internet browsing history, search history, and interactions with the Website and advertisements |
Yes |
Geolocation data, such as IP location |
Yes
|
Audio, electronic, visual, or similar information, such as photographs and phone call recordings (where permitted by law) |
No |
Inferences, meaning inferences drawn from any of the information in the above-listed categories of information |
No |
Sensitive personal information, including account log-in information in combination with passwords |
No |
As further described in the “How We Use Personal Data” section below, we generally collect and use the above-listed categories of personal information to provide and manage the Services, to process and fulfill your orders, to support and market our business, and to achieve other legitimate business or commercial purposes.
As noted in the table above, we “sell” or “share” (as these terms are defined in the CCPA) certain categories of personal information, and you may exercise your right to opt out of such disclosures by completing and submitting the form available here. Alternatively, where available, you may choose to enable an online tool that automatically communicates your opt-out preferences, such as the Global Privacy Control (“GPC”). When detected, we will process such signals as a request to opt out.
We retain each category of personal information that we collect for as long as necessary to fulfill the purposes described in this Privacy Policy, including to satisfy legal or reporting requirements.
More information, including a description of your legal rights, can be found in the “Additional Information for Residents of California” section below.
Download a copy of this full privacy policy
Depending on how you interact with us and/or the Website, we may collect a variety of information, including Personal Data.
When we use the term “Personal Data” in this Privacy Policy, we mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to you, such as your name, physical address, telephone number, email address, Internet Protocol (“IP”) address, or other online identifiers.
The specific categories of Personal Data we may collect include:
Depending on how you interact with us, we collect your Personal Data in the following ways:
When you access and engage with the Website or interact with our online media and content (including advertisements), we automatically collect information about your browser, device, and activity. We (and our partners) may use various tracking technologies (e.g., cookies, pixel tags (or web beacons), etc.) to collect information automatically. The information collected may include details about your behavior on the Website, including how you move and scroll through the Website, your keystrokes, the links you choose to click, and how you interact with forms. These technologies may also be used to collect information about you over time and across different websites, mobile applications, and devices.
To learn more about our use of cookies and other similar technologies and how you can control them, please review our Cookie & Ads Policy.
We generally use the Personal Data we collect for purposes associated with the growth, maintenance, and management of our business. Depending on how you interact with us, we may use your Personal Data in the following ways:
In connection with one or more of the purposes outlined above, we may disclose Personal Data from each of the categories of data described in the “Personal Data We Collect” section above to the following categories of third parties:
We may disclose your Personal Data for other reasons that we will describe at the time of data collection or prior to disclosing your data.
If you reside in the United States, depending on your state of residence, some of the disclosures described above constitute “sales” or “sharing” of Personal Data under applicable law. Details on how to exercise your legal rights with respect to such disclosures can be found in the “Additional Information for Residents of California” and “Additional Information for Residents of Other U.S. States” sections below.
Please note that we may de-identify or aggregate Personal Data so that it will no longer be considered “Personal Data” and disclose such information to other parties for purposes consistent with those described in this Privacy Policy.
We provide you with the ability to make certain choices about how we use your Personal Data. Additional details are below.
Depending on your country of residence, you may have some or all of the following rights:
We will not discriminate against you if you decide to exercise your privacy rights. However, please note that some features and services may not be available to you if you choose to restrict or otherwise opt out of the sharing of personal information where the services rely on that information. Please note that certain rights are subject to applicable exceptions by law.
How to Exercise Your Legal Rights
You can submit a request to exercise your rights by:
All requests must be verified. To protect your privacy, we will require the matching of up to three pieces of personal information provided with your request with information we maintain to verify that it is you making the request. Where applicable, we will use the requested information for verification purposes only. Please note that we may decline a request where we are unable to verify your identity and confirm the personal information we maintain relates to you.
Exercising your rights does not require you to create an account with us.
How to Exercise Your Sale and Sharing Opt-Out Right
As detailed in the chart above, we “sell” and “share” certain categories of personal information to and with third parties. If you are 16 years of age or older, in addition to the rights described above, you have the right to direct us to not “sell” or “share” your personal information at any time. To exercise your opt-out right, you may submit a request to us by:
Upon receipt of your request, we will endeavor to honor it based on the information that we collect and maintain.
Alternatively, where available, you can use certain preference signals to exercise your opt-out right automatically with all businesses that you interact with online, including Hershey. If you enable a browser-based opt-out preference signal that complies with the CCPA and other U.S. state privacy laws, such as the Global Privacy Control (GPC), upon receipt or detection, we will treat the signal as a valid request to opt out of the sale or sharing of personal information linked to that browser and any consumer profile we have associated with that browser. Please note that if you use different browsers or browser profiles, you will have to enable the signal on each once that you use.
Authorized Agents
You may authorize someone to submit a request on your behalf (an “authorized agent”). An authorized agent will need to demonstrate that you’ve authorized them to act on your behalf, unless you have provided the agent with power of attorney pursuant to applicable probate law. Depending on the evidence provided, we may also contact you to verify your identity with us or request confirmation from you that the agent is authorized to submit the request on your behalf.
Appealing Privacy Rights Decisions
You have the right to appeal a decision we have made in connection with your privacy rights request. To appeal a decision, please contact privacy@hersheys.com. If you are unsatisfied with the way that we have handled your appeal, you may have the right to complain to your state’s Attorney General or other agency that regulates privacy.
The Website may contain links to third-party websites, plug-ins, applications, or other online services. If you click on a link to a third-party service, you will be taken to a service we do not control and that is not governed by this Privacy Policy. We are not responsible for third parties’ privacy practices. We suggest that you read the privacy policies of every service with which you interact carefully.
The Website is intended for adults. We do not knowingly collect Personal Data from anyone under the age of 16 through the Website.
This Privacy Policy and the CARU icon shown on the Website confirm that The Hershey Company is a valid licensee and participating member in the CARU Safe Harbor Program (“CARU Safe Harbor”). To protect your privacy, we have voluntarily undertaken this privacy initiative. CARU has reviewed and certified that our websites are General Audience sites and that we meet established online data collection and use practices on all properties where this Privacy Policy is posted. As part of the CARU Safe Harbor, we are subject to audits and frequent monitoring of our websites and other enforcement and accountability mechanisms administered independently by CARU.
If you believe that we have not responded to your inquiry or your inquiry has not been satisfactorily addressed, please contact CARU at:
CARU Safe Harbor
Attn: Director
112 Madison Avenue, 3rd Floor
New York, NY 10016
infocaru@bbbnp.org
If you are a parent and think that your child has provided Personal Data on the Website, you can request that the Personal Data be changed or deleted by contacting us by calling the following toll-free phone number: 1-800-468-1714, contacting us Online, or writing to us at:
The Hershey Company
Consumer Relations
19 E. Chocolate Ave
Hershey, PA 17033
We retain your Personal Data as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or allowed under law.
To determine the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data; the potential risk of harm from unauthorized use or disclose of the Personal Data; the purposes for which we use the Personal Data; whether we can achieve the purposes through other means; and the applicable legal requirements.
If we de-identify data, we will maintain and use the data in de-identified form and not attempt to re-identify the data except as required or permitted by law.
We use commercially reasonable security measures, including physical, technical, and administrative safeguards to protect your Personal Data from loss; misuse; and unauthorized access, disclosure, modification, and deletion.
However, the Internet is not 100% secure. As a result, like all businesses, we cannot guarantee the security of the Personal Data you provide to us via the Website. We encourage you to use caution when using the Internet. This includes not sharing your passwords.
As a global organization, we will transfer and/or store Personal Data under our control in the United States and/or other countries where we have facilities or in which we engage service providers. As a result, your Personal Data may be transferred to other countries or regions.
If you live outside of the United States, you understand and agree that we may transfer your Personal Data to the United States. When we transfer your Personal Data outside of your country of residence, we do so in accordance with applicable law and take appropriate steps to ensure your data is protected. However, please note that while outside of the jurisdiction in which you reside, your Personal Data will be subject to applicable laws (including those in the United States), which may not provide the same level of protections for Personal Data as those in your country of residence.
If you are located in the EEA, UK, or Switzerland, please note that we may need to transfer your Personal Data to countries that have not been recognized as providing an adequate level of data protection. We generally use EU Standard Contractual Clauses (or other government-approved contracts) or other lawful data transfer mechanisms that provide appropriate safeguards for Personal Data that is transferred to countries that have not been recognized as providing an adequate level of protection. To learn more about the cross-border transfer of your Personal Data and the transfer mechanism(s) we use to lawfully carry out such transfers, please contact us online.
In certain countries, The Hershey Company acts as the “Controller” (as defined in applicable data protection law) of your Personal Data, and the following disclosures are provided in accordance with applicable law.
Below are the legal bases that we rely on to process your Personal Data:
If you have questions about this Privacy Policy or our data handling and privacy practices, please contact our EU representative by sending an email to GDPR-hershey@intertrustgroup.com. or writing to:
Hershey Netherlands B.V.
Attn. GDPR Services Team
Basisweg 10,
1043 AP Amsterdam,
The Netherlands
If you are located in Brazil, Canada, Mexico, or India, please review the following privacy policies, for additional information.
The California Consumer Privacy Act (CCPA) provides California residents with certain rights with respect to their “personal information” (i.e., information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your household). Pursuant to the CCPA, we are providing the following additional details regarding the categories of personal information that we collect, use, and disclose. This section also describes the rights available to you in relation your personal information and how to exercise your rights.
The following chart details which categories of personal information we have collected from and about California residents in the past twelve (12) months, the source(s) of each category of information, the categories of third parties to whom we have disclosed each category of information for a business purpose, and the categories of third parties to whom we have “sold” or with whom we have “shared” each category of information (as such terms are defined in the CCPA) (where applicable). Please note that the first column in the chart lists by category the types of information described in the “Personal Data We Collect” section above, as required by the CCPA.
Category of Personal Information | Categories of Source(s) | Disclosures of Personal Information for a Business Purpose | Sale or Sharing of Personal Information |
---|---|---|---|
Identifiers, including names, shipping addresses, email addresses, online identifiers, IP addresses, and other similar identifiers (e.g., social media identifiers) |
Directly from individuals Through automated means Third-party sources |
We have disclosed this category of information for a business purpose in the past 12 months to the following categories of third parties:
|
We have sold or shared this category of information in the past 12 months to or with the following categories of third parties:
|
Personal information categories listed in the California Customer Records statute, including telephone numbers and credit and debit card information |
Directly from individuals |
We have disclosed this category of information for a business purpose in the past 12 months to the following categories of third parties:
|
|
Protected classification characteristics under California law, including age and sex/gender expression |
Directly from individuals |
We have disclosed this category of information for a business purpose in the past 12 months to the following categories of third parties:
|
|
Commercial information, including items purchased, obtained, or considered and other purchasing or consuming histories or tendencies |
Directly from individuals Through automated means Third-party sources |
We have disclosed this category of information for a business purpose in the past 12 months to the following categories of third parties:
|
We have sold or shared this category of information in the past 12 months to or with the following categories of third parties:
|
Internet or other electronic network activity information, including internet browsing history, search history, and interactions with the Website and advertisements |
Through automated means |
We have disclosed this category of information for a business purpose in the past 12 months to the following categories of third parties:
|
We have sold or shared this category of information in the past 12 months to or with the following categories of third parties:
|
Geolocation data, such as IP location |
Through automated means |
We have disclosed this category of information for a business purpose in the past 12 months to the following categories of third parties:
|
We have sold or shared this category of information in the past 12 months to or with the following categories of third parties:
|
Audio, electronic, visual, or similar information, such as photographs and phone call recordings (where permitted by law) |
Through automated means |
We have disclosed this category of information for a business purpose in the past 12 months to the following categories of third parties:
|
|
Inferences, meaning inferences drawn from any of the information in the above-listed categories of information |
Through automated means Third-party sources |
We have disclosed this category of information for a business purpose in the past 12 months to the following categories of third parties:
|
|
Sensitive personal information, including account log-in information in combination with passwords |
Directly from individuals |
We have disclosed this category of information for a business purpose in the past 12 months to the following categories of third parties:
|
As described in more detail in the “How We Use Personal Data” section above, we collect personal information to provide and manage the Services, process and fulfill orders, to support and market our business, and to achieve other legitimate business or commercial purposes.
As detailed in the “How We Use Personal Data” section above, we disclose personal information to fulfill the purposes described. We will also disclose certain categories of personal information to competent governmental and public authorities and other third parties as necessary or appropriate, including when we have a legal or contractual obligation to disclose the information.
As detailed in the chart above, we “sell” and “share” (as such terms are defined in the CCPA) certain categories of personal information to and with third parties and have “sold” and “shared” certain categories of Personal Data in the past twelve (12) months. Please refer to the chart above for additional details.
We do not knowingly “sell” or “share” the personal information of individuals under the age of 16.
As detailed in the chart above, we collect certain “sensitive personal information” (as defined in the CCPA). However, we do not use or disclose such information for any purpose outside of the limited permissible purposes set forth in the regulations implementing the CCPA. Such purposes include providing the Services and verifying, maintaining the quality of, and improving the Services.
We may provide discounts or promotions when you agree to receive marketing and promotional communications from us or claim a specific offer when you interact with us and/or the Website (each, an “Offer”). The terms of each Offer will be provided to you when it is made available. You may opt out of marketing and promotional communications from us at any time as described in our messages to you and as described in the “Your Choices and Legal Rights” section above.
We collect and retain personal information to support and fulfill certain Offers, which may include information in the following categories:
The personal information we collect and retain may also be used to make your account or to supplement your account information (where applicable). Additional details regarding our use of personal information can be found in the “How We Use Personal Data” section above.
Because we collect and retain personal information in connection with our administration of certain Offers, they may be considered “financial incentives” or “price or service differences” under California law. The value of the personal information we collect will vary based on the Offer and is calculated based on expenses related to offering the Offer, which may include the costs associated with providing discounts or promotions, IP or marketing-related costs, and other related expenses.
You have the right to opt out of any Offer at any time in accordance with the terms of the Offer or by contacting us using the information in the “How to Contact Us” section below.
In addition to the rights described above, California’s “Shine the Light” law permits California residents that have an established business relationship with us to request certain information regarding our disclosure of certain types of personal information to third parties for their direct marketing purposes during the immediately preceding calendar year.
To make such a request, please click here, follow the onscreen prompts to send us an email, select “Privacy Policy/Ad and Cookie Policy” as the subject of your message, and indicate in your message that you are a California resident making a “Shine the Light” inquiry. This request may be made no more than once per calendar year. We will respond to your request in accordance with applicable law.
If you have any questions or concerns about this Privacy Policy or our data handling and privacy practices or would like to submit a request relating your Personal Data, please feel free to contact us online, call us at 1-800-468-1714, or write to us at:
Consumer Relations Department
The Hershey Company
19 E. Chocolate Ave.
Hershey, PA 17033
From time to time, we may update this Privacy Policy to reflect changes in our practices with respect to the collection, use, and disclosure of Personal Data and/or changes in applicable law.
The “Last Updated” date at the top of this page indicates when this Privacy Policy was last revised. If we make changes, we will revise the date at the top of this page and, in the case of material changes, we will provide you with additional notice (in accordance with applicable law).
Unless otherwise stated, the current version of this Privacy Policy applies to all Personal Data under our control. We encourage you to review this Privacy Policy periodically to remain informed about our data handling and privacy practices.
Last Updated: May 15, 2023
In this Cookie & Ads Policy, you will find information on the use of cookies and other similar technologies on our websites and how you can control them. This Cookie & Ads Policy also describes our interest-based advertising practices and your choices.
This Cookie & Ads Policy (“Cookie Policy”) explains how The Hershey Company (“Hershey,” “we,” “us,” or “our”) uses cookies and other similar technologies (collectively, “cookies”) on the following Hershey Company Brands websites, which are owned and operated by The Hershey Company: TheHersheyCompany.com, Hersheyland.com, CadburyUSA.com, Shop.hersheys.com, chocolateworld.com, and any other websites or online services that link to or display this Privacy Policy (collectively, the “Website”).
This Cookie Policy does not apply to the websites of and your interactions with Hershey Entertainment and Resorts Company, including The Hotel Hershey and Hersheypark. It also does not apply to the Hershey Park mobile app.
This Cookie Policy should be read together with our Privacy Policy and our Terms of Use.
“Cookies” are small text files sent from a website and stored on your device. Cookies are used for various purposes, including to make site navigation more efficient, help remember your preferences, and improve your browsing experience. They can also enable the delivery of relevant and personalized advertisements.
There are different types of cookies, which are distinguishable on the basis of their origin. “First-party cookies” are cookies that are stored by the website you are visiting, while “third-party cookies” are stored by a domain other than that of the website you are visiting. Cookies can also be distinguished on the basis of their functions and lifespan, as described below.
Cookie Type | Purpose of Use |
---|---|
Strictly Necessary Cookies |
These cookies are necessary for the Website to function and cannot be switched off in our systems. They are usually only set in response to actions taken by you that amount to a request for services, such as setting your privacy preferences, logging in, placing items in your cart, or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the Website will not then work. |
Functional Cookies |
These cookies enable the Website to provide services or to remember settings to improve your visit. They may be set by us or by third-party providers whose services we have added to our pages, including social media platforms. For example, these cookies help us remember your choice of language or region, show you have logged in to the Website, or help you share information on a social media platform (e.g., Facebook). If you disable these cookies, some or all of these services may not function properly. |
Performance Cookies |
These cookies are used to collect statistics on the Website’s performance (e.g., the number of visitors, how visitors move around the Website, the pages visited, and any errors that occur), which helps us measure and improve the performance of the Website. These cookies also measure the effectiveness of our advertisements. All information these cookies collect is aggregated. We use Google Analytics for these purposes. Google Analytics uses its own cookies. You can find out more about Google Analytics’ use of cookies and data handling practices here. To disable Google Analytics, download and install the Google Analytics Opt-out Browser Add-On, which is available here. |
Targeting Cookies |
These cookies may be set through the Website by our advertising partners, including social media platforms. They may be used by our partners to build a profile of your interests and show you relevant advertisements on other online services, which is known as “interest-based advertising.” These cookies uniquely identify your browser and device and observe your behaviors and browsing activities over time across multiple websites or other platforms. For more information on interest-based advertising, please see Section 4 below. |
Some of these cookies are temporary and erased once you close your browser (“session cookies”), while others stay on your browser until you delete them manually or until your browser deletes them based on the duration period set within the cookie (“persistent cookies”).
You can customize or change your cookie preferences at any time by accessing our cookie management system, available here.
Additionally, your browser may give you the ability to control cookies or other similar technologies or to reject cookies.
Because the options you select relating to cookies and other similar technologies are browser and device specific, you must exercise your choices on each browser and device you use.
For more information about cookies, including how they work and how to manage them, please visit www.allaboutcookies.org.
The Website includes social media features, such as the Facebook “like” button, and widgets, such as the “share this” button or other interactive mini-programs. These features may collect your IP address and other data about your visit to the Website and may set a cookie to enable the feature to function properly. We are not responsible for the privacy practices of the third parties that provide these services. We encourage you to read the privacy policy of every service with which you interact.
We engage in interest-based advertising to deliver online, relevant advertising to you. We also permit third-party online advertising networks, social media companies, and other third-party services to collect data about your use of the Website over time so that they may display advertisements tailored to you both on the Website and on third-party online services and across the devices you may use.
Generally, the data used to deliver interest-based advertising to you is collected through cookies or other similar technologies. These technologies collect data about your browser and device (e.g., IP address, device ID, cookie ID, mobile advertising ID, general location information, and geolocation information (with your consent)) and your activity on the Website. These technologies may also collect similar data on other websites you visit and across the devices you use, and such data may be linked to certain online and offline data. In addition to serving interest-based advertisements, our third-party partners may use data to deliver certain advertising-related services, such as reporting, attribution, analytics, and market research.
Some web browsers, websites/platforms, and mobile devices allow you to exercise certain choices with respect to interest-based advertising, as described below.
Please note that you will need to opt out separately on all of your browsers and devices, as each opt-out will apply only to the specific browser or device from which you opt out. If you delete or reset your cookies or mobile identifiers, change browsers, or use a different device, any opt-out cookie or tool may no longer work and you will have to opt out again. Even if you choose to opt out of receiving interest-based advertising, you may still receive advertising, but the advertisements may be less relevant.
Some of our partners may provide you with additional choices with respect to interest-based advertising. For example, certain social media platforms allow you to control your advertising preferences directly through their services. Please review the privacy policies of the third-party services you use for more information.
Depending on your U.S. state residency, our use and disclosure of Personal Data for interest-based advertising purposes constitutes “sharing” or the processing of Personal Data for “targeted advertising” under applicable law. Details on how to exercise your legal rights with respect to “sharing” or “targeted advertising” can be found in the “Additional Information for Residents of California” and “Additional Information for Residents of other U.S. States” sections of our Privacy Policy.
If you have any questions about this Cookie & Ads Policy, please contact us online, call us at 1-800-468-1714, or write to us at:
Consumer Relations Department
The Hershey Company
19 East Chocolate Avenue
Hershey, PA 17033
Hershey Netherlands B.V.
Attn. GDPR Services Team
Basisweg 10,
1043 AP Amsterdam,
The Netherlands
Email: GDPR-hershey@intertrustgroup.com