factual

What is the Circle K franchisee's responsibility regarding the disclosure of Customer Information?

Circle_K Franchise · 2025 FDD

Answer from 2025 FDD Document

  • (a) Franchisor owns all Customer Information (as defined below) and may use the Customer Information as it deems appropriate (subject to applicable law), including disclosing it to vendors.

Franchisee may only use Customer Information for the purpose of operating the Store to the extent permitted under this Agreement, including the Business Systems Manuals, during the term hereof and subject to such restrictions as Franchisor may from time to time impose and in compliance with all data privacy, security and other applicable laws. "Customer Information" means any contact information (including name, address, phone and fax numbers, and e-mail addresses), sales and payment history, and all other information about any customer, including any personal information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household.

As used in this Agreement, the term "customer" refers to any person or entity (i) included on any marketing or customer lists that Franchisee develops or uses; (ii) who has purchased or purchases products or services at the Store; or (iii) whom Franchisee has solicited to purchase any products or services at the Store.

Franchisor may use the Customer Information as it deems appropriate, including sharing it with its Affiliates.

  • (b) Without limiting the foregoing, Franchisee agrees to comply with applicable law in connection with its collection, storage, disclosure and its use and Franchisor's use of such Customer Information, including complying with all laws and regulations relating to data protection, privacy and security, including data breach response requirements ("Privacy Laws"), as well as data privacy and security policies, procedures and other requirements Franchisor may periodically establish.

Some laws require Franchisee to obtain consent to collect, store, disclose, and use (collectively "process") personal information.

Franchisee is responsible for obtaining appropriate Customer consent to ensure Franchisee and Franchisor may process Customer Information as outlined in this Agreement.

Franchisee must notify Franchisor immediately of any suspected data breach at or in connection with the Store.

Franchisee must fully cooperate with Franchisor and its counsel in determining the most effective way to meet Franchisor's standards and policies pertaining to Privacy Laws within the bounds of applicable law.

Franchisee is responsible for any financial losses it incurs or remedial actions that it must take as a result of breach of security or unauthorized access to Customer Information in Franchisee's control or possession.

  • (c) If any federal or state Privacy Law, including the California Consumer Privacy Act, as revised by the California Consumer Privacy Rights Act , Cal.

Civ.

Code § 1798.100, et seq. (collectively, "CCPA") and any related regulations, applies to the operation of the Store, whenever and to the extent Franchisee operates as a "Service Provider" or "Contractor" under the CCPA, a data processor, or in a similar capacity under any federal or state Privacy Law, Franchisee represents and warrants that:

  • (1) Except for the purpose of operating the Store and in accordance with the Business Systems Manuals, Franchisee will not retain, use, combine or disclose any Customer Information;

  • (2) Franchisee will not sell, share, make available or otherwise disclose any Customer Information to any third party for valuable consideration or for the purpose of performing cross-context behavioral advertising;

  • (3) Franchisee will not retain, use, or disclose Customer Information outside of the direct business relationship between Franchisee and Franchisor;

  • (4) Franchisee will delete any Customer Information upon Franchisor's request unless Franchisee can prove that such request is subject to an exception under applicable law;

  • (5) If Franchisee receives a Customer Information data request (e.g. a request to delete Customer Information) directly from a consumer (e.g., a California resident under the CCPA or CPRA, or a resident of another jurisdiction under other applicable Privacy Law), Franchisee shall inform Franchisor of that request within one business day and cooperate with Franchisor to ensure that the consumer receives an appropriate and timely acknowledgement and response;

  • (6) Franchisee will implement reasonable security procedures and practices appropriate to the Customer Information it collects, retains, uses or discloses, in order to protect it from unauthorized or illegal access, including following minimum requirements that may be set forth in the Business Systems Manuals;

Source: Item 22 — CONTRACTS (FDD page 100)

What This Means (2025 FDD)

According to the 2025 Circle K Franchise Disclosure Document, Circle K owns all customer information and can use it as it sees fit, following the law, including sharing it with vendors and affiliates. Customer Information includes contact details, sales history, and any data that can identify a customer. The franchisee can only use this information to operate the store as allowed by the franchise agreement and Circle K's Business Systems Manuals.

The Circle K franchisee must follow all data privacy and security laws and any data privacy and security policies that Circle K establishes. Some laws require the franchisee to get consent to collect, store, disclose, and use personal information. The franchisee is responsible for getting the customer's consent so that both the franchisee and Circle K can use customer information as described in the agreement. The franchisee must immediately inform Circle K of any suspected data breach at the store and work with Circle K to meet its privacy law standards and policies.

Furthermore, the Circle K franchisee is responsible for any financial losses or remedial actions resulting from a security breach or unauthorized access to customer information under their control. If privacy laws like the California Consumer Privacy Act (CCPA) apply, the franchisee must not retain, use, combine, or disclose any Customer Information except for operating the store as per the Business Systems Manuals. They also cannot sell or share this information for advertising purposes or outside the direct business relationship with Circle K. The franchisee must delete any Customer Information upon Circle K's request, unless there's a legal exception. If a customer requests data deletion, the franchisee must inform Circle K within one business day and cooperate to ensure a timely response. The franchisee must also implement reasonable security measures to protect Customer Information from unauthorized access, following any minimum requirements in the Business Systems Manuals.

Disclaimer: This information is extracted from the 2025 Franchise Disclosure Document and is provided for research purposes only. It does not constitute legal or financial advice. Consult with a franchise attorney before making any investment decisions.