Effective Date 12/30/2016 (last updated 03/04/2019)
This policy describes the privacy practices of The Hershey Company, located at 100 Crystal A Drive, Hershey, PA 17033, USA (“Hershey”, “our” or “we”), for its website www.thehersheycompany.com (“Website”). This includes the mobile version of the Website. This policy does not apply to information we collect offline. This policy does not apply to the websites of Hershey Entertainment and Resorts Company, including The Hotel Hershey and Hersheypark. It also does not apply to the Hersheypark mobile app.
How we process Personal Data from and about you.
Personal data is any information relating to an identified or identifiable natural person. This includes, in particular, your name, email address, telephone number, address, date of birth, as well as various data that you provide during a query submitted via the contact form or when signing up for our newsletter (hereinafter referred to as, “Personal Data”).
- Contact us function. We process your first and last name, your e-mail address, your country of residence and the information you provide us in connection with the comments, questions or feedback shared with us when you use our “Contact Us” form. We process this Personal Data based on the necessity for the performance of a quasi-contract with you, i.e., to respond to your request. We retain this Personal Data for as long as required to respond to your request and, where applicable, as required or permitted by statutory law, e.g., for financial statements or legal claims.
- Submit an idea. We process your month and year of birth, your first and last name, your e-mail and your postal address as well as the information on your idea that you provide us with when you use the “Submit An Idea” function on the Website. We process this Personal Data based on the necessity for the performance of a quasi-contract with you, i.e., to evaluate your idea. We retain this Personal Data for as long as required to evaluate your idea and, where applicable, as required or permitted by statutory law, e.g., for financial statements or legal claims.
- Newsletter subscription. We process your first and last name, your e-mail address and information on your state/province and ZIP/Postal Code when you sign up for our newsletter. We process this Personal Data to send you newsletters with information – upon your choice - about our products and services, provide special offers and promotions in your area that may be of interest to you based on your consent. These newsletters also contain third party offers or products we think you might find interesting. You may withdraw your consent at any time by unsubscribing from the newsletter. We will process this Personal Data for as long as you show interest in our services and newsletters or until you withdraw your consent. If you have not shown interest in our services for more than 18 months, we will delete this Personal Data. Withdrawing your consent will not affect the lawfulness of the processing before the withdrawal.
- Job application. We process your first and last name, e-mail address, phone number, home address, data on your educational and professional background and further information you provide us with when you apply for a job with us. We process this Personal Data as a necessity to assess your application and contact you about employment. If your application is successful, we retain the Personal Data for the duration of your employment with us, and beyond based on statutory retention periods. If we do not employ you we will delete your Personal Data when applicable time limits for legal actions have lapsed.
- Financial Alerts. We process your e-mail address when you subscribe to our financial alerts on the Website. We process this Personal Data to send you the alerts that you select upon subscribing. We will process this Personal Data until you withdraw your consent. You may withdraw your consent at any time by unsubscribing from the alert(s). Withdrawing your consent will not affect the lawfulness of the processing before the withdrawal.
- Report Downloads. We process your first name, last name, business e-mail and phone number when you download a report that is made available on the Website. We process this Personal Data to establish or renew a business relationship with your company, and to contact you regarding future reports or for other business development purposes. We will process this Personal Data until you withdraw your consent. You may withdraw your consent at any time by submitting a request to firstname.lastname@example.org. Withdrawing your consent will not affect the lawfulness of the processing before the withdrawal.
We may also tailor the Website to your interests and needs, by collecting information about your device and linking this to your Personal Data so as to ensure that our Website offers the best user experience for you.
- Contact you. We process your name and your contact details, e.g., your e-mail address, to tell you about changes to this Policy or our website Terms. The processing of your Personal Data for this purpose is based on our legal obligations to notify you. We retain the Personal Data until you notify us that you do not want to use our services anymore or request deletion of your contact details.
How we share information with third parties.
- We will share information with third parties who perform services on our behalf. For example, we share information with vendors who operate our websites, run promotions, and send emails. We may authorize these vendors to collect information on our behalf and share certain information with their subcontractors, but only to the extent necessary for the vendors to perform services on our behalf. Our vendors may be located within or outside of the North America. You can contact us if you want to learn more about how our service providers use your information.
- We will share information with our business partners. For example, we will share information with third parties who co-sponsor a promotion with us. We might also share information with a business partner who distributes our products. These partners may send you information about our events and products by mail or email if you have consented to such marketing.
- We will share information with Hershey Entertainment and Resorts Company. For example, sometimes we receive questions about The Hotel Hershey or Hersheypark. We may share information so that The Hotel Hershey or Hersheypark can address those questions.
- We will share information if we think we have to in order to comply with the law or to protect ourselves. For example, we will share information to respond to a court order or subpoena. We may also share it with a government agency or investigatory body if such agency or body requests it.
- We will share information with any successor to all or part of our business. For example, if part of our business was sold we may give our customer list as part of that transaction, insofar as permitted by law.
- Third country transfers. Some of the recipients of your Personal Data listed above may be located in countries outside the EU/EEA that do not offer the same level of protection with regard to Personal Data as required in the EU/EEA and where there is no adequacy decision by the European Commission. In that case we will ensure an adequate level of data protection by appropriate safeguards, e.g. EU Model Clauses, Privacy Shield or BCR certification. If you would like to obtain a copy of the safeguard that we use, please contact us online.
Your rights with regard to your Personal Data.
- You can opt out, meaning withdraw your consent, of receiving our marketing emails. To stop receiving our promotional emails, follow the opt-out link in any of our promotional emails or call us at 1 (800) 468-1714. Even if you opt out of getting marketing messages, we will still send you transactional messages. These include responses to your questions. If you object to our use of your information for direct marketing purposes, please contact us.
- EU rights. If you are using the Website from the EU, you have the right to
- Obtain from us confirmation as to whether or not we process Personal Data from you and, where that is the case, access to your Personal Data;
- Rectification of inaccurate Personal Data;
- Erasure of Personal Data;
- Objection to the processing of Personal Data;
- Restriction of processing of Personal Data; and
- Portability of Personal Data - receive the Personal Data you have provided to us in a structured, commonly used and machine-readable form and transmit those data it to another data controller.
Also, where our processing of your Personal Data is based on your consent, you may withdraw consent at any time for the future. Please note that withdrawing your consent will not affect the lawfulness of the processing before the withdrawal.
- EU supervisory authority. If you are using the Website from the EU, you also have the right to lodge a complaint with an EU supervisory authority if you do not think we are handling your Personal Data in compliance with applicable law.
- You have other controls you can exercise. You can choose whether or not to share personal information. If you choose not to share, some parts of our sites and some services may be more difficult or impossible to use. If you turn off cookies or tracking tools, parts of our site and services may also not work properly.
These sites and children
Our Website is meant for adults. We do not knowingly collect personally identifiable information from children (including children under 13 in the United States and under 16 in the EU/EEA).
As part of the CARU Safe Harbor, we are subject to audits and frequent monitoring of our websites and other enforcement and accountability mechanisms administered independently by CARU.
If you believe that we have not responded to your inquiry or your inquiry has not been satisfactorily addressed, please contact CARU at:
CARU COPPA Safe Harbor Program
112 Madison Avenue, 3rd Floor
New York, NY 10016
Parents, if you think your child has provided personal information on one of our sites, you can request that the information be changed or deleted by contacting us via the contact details provided below. To learn more about how to protect your child online, read the helpful information provided by the Federal Trade Commission about protecting children's privacy online by clicking here.
Your California Privacy Rights
We use standard security measures.
The Internet is not 100% secure, though. We thus cannot promise that your use of our sites will be completely safe. We encourage you to use caution when using the Internet. This includes not sharing your passwords.
We store information both in and outside of the United States.
We may link to other sites or apps or have third party services on our platforms we don’t control.
If you click on a third party link, you will be taken to a platform we do not control. This policy does not apply to the information practices of that website or platform. Read other companies’ privacy policies carefully. We are not responsible for these third parties.
How to contact us
Feel free to contact us if you have more questions.
You can contact us online or write to us at:
Public Relations Department
The Hershey Company
PO Box 810
100 Crystal A Drive
Hershey, PA 17033
Or call 1-800-468-1714
If you have any questions about this Policy or want to review, access, delete, correct or update your information, please contact us online.
How to contact our EU representative
Hershey Netherlands B.V.
Attn. GDPR Services Team
Prins Bernhardplein 200
1097 JB Amsterdam
We may update this policy.
From time to time we may change our privacy policies. We will provide notice of any material changes to our Policy as required by law. We will also post an updated copy on our website. Please check our site periodically for updates.
© 2019 The Hershey Company. All rights reserved.