What Dunkin' does with your data
Pharmacy, beauty, specialty retail and restaurants. People use it through a rewards program, app, or connected service.
Data current as of 2026-09-25; statuses change.
- Program or app
- Dunkin' Rewards (formerly DD Perks)
- Members
- 13.6 million members (2019). Last filed figure: approximately 13.6M DD Perks members as of 2019-12-28. Inspire Brands took Dunkin' private in 2020; no later filings.
- Retail media
- None found in the research
What it collects and does with your data
- Policy says Dunkin' uses technology in connected devices, including the customer's vehicle, home assistant, or smartwatch, to determine location, serve advertising, or provide offers, and that the data may include voice, location, payment information, or biometric data.
- Policy lists data brokers or resellers from which Dunkin' or its vendors purchase demographic data and geolocation information to supplement collected data.
- Policy says Dunkin' discloses information to business partners and other entities for their own business purposes, including direct marketing, and shares with franchisees and Inspire Brands affiliates.
- Policy says the app may collect location in the foreground or background if permitted.
Sensitive data
- vehicle/connected-device data (per policy)
- voice
- precise and background location
- biometric (connected devices, per policy)
- payment/stored value
Enforcement and litigation
1 matter in the research. Where the research says alleged, pending, or settled without admitting wrongdoing, so does this page.
- New York AG consent order: alleged Dunkin' failed to notify customers of credential-stuffing attacks on DD Perks accounts (300,000+ customers) and misrepresented its security. $650,000 in penalties and costs plus refunds. Settled. Amount: $650,000.
Who else holds your data
Organizations holding a copy of your data, as the research counts them: at least 7. Floor: Dunkin', Inspire Brands, 5 sister brands. Franchisees and direct-marketing business partners not counted because none are named.
Third parties: Named: Inspire Brands plus 5 sister brands (Arby's, Baskin-Robbins, Buffalo Wild Wings, Jimmy John's, SONIC); franchisees. Policy dated 2022-12-23 is the version served at privacypolicy.dunkindonuts.com on 2026-09-25; the dunkindonuts.com privacy link redirected to the homepage during research.
Data brokers linked to Dunkin'
- Gets customer data from data brokers it doesn't name. "Policy lists data brokers or resellers from which Dunkin' or its vendors purchase demographic data and geolocation information to supplement collected data."
Confidence: confirmed means the company confirmed it or reported it in a filing. Alleged means a complaint or petition says so, with no ruling found. Reported means journalism or a Senate letter. How brokers are included
Data practices score
9 of 15. Five components, each 0 to 3. How the score works
- Sells or shares
- 3
- Enforcement
- 2
- Retail media scale
- 0
- Sensitive data
- 3
- Opt-out friction
- 1
Estimated emissions for one person
Research gaps
- No member count since 2019.
- No evidence found of a Dunkin' or Inspire retail media network; scored 0.
- Policy is dated 2022; could not confirm whether a newer version exists.
Sources (3)
- https://www.sec.gov/Archives/edgar/data/1357204/000135720420000015/dnkn-20191228x10k.htm
- https://privacypolicy.dunkindonuts.com/ 2022-12-23
- https://ag.ny.gov/press-release/2020/attorney-general-james-gets-dunkin-fill-holes-security-reimburse-hacked-customers 2020-09-15
The Sources page lists these with their kind and what else uses them.