Employee and Job Applicant CCPA Notice For California Residents Only

This notice is applicable to California residents only and describes the categories of personal information that may be collected by Cava Group, Inc. and its direct or indirect subsidiaries (collectively, “CAVA,” “we,” “us” or “Company”) and the purposes for which such information may be collected and used. It also provides information concerning the Company’s record retention practices and rights you may have under the CCPA. For more complete information about the Company’s Privacy Policy, please visit https://cava.com/privacy, which is incorporated into this notice and made a part hereof.

We retain your personal information for as long as necessary to process your application for employment and in accordance with the Company’s data retention schedule. We may retain your personal information for longer if it is necessary to comply with our legal obligations or reporting obligations, anticipate or resolve disputes, or as permitted or required by applicable law. We may also retain your personal information in a deidentified or aggregated form so that it can no longer be associated with you. To determine the appropriate retention period for your personal information, we consider various factors such as the amount, nature, and sensitivity of your information; the potential risk of unauthorized access, use or disclosure; the purposes for which we collect or process your personal information; and applicable legal requirements. Personal Information does not include certain categories of information, such as publicly available information from government records, deidentified or aggregated consumer information, and information subject to HIPAA or the California Confidential Medical Information Act.

The Categories of Personal Information Collected include the following: 1. Identifiers. This category includes names, addresses, telephone numbers, mobile numbers, email addresses, signature, account name, dates of birth, bank account information, and other similar contact information and identifiers. 2. Personal information under California Civil Code Section 1798.80(e).  This category includes names, signatures, physical characteristics or descriptions, addresses, telephone numbers, education, employment, employment history, bank account numbers, credit card numbers, debit card numbers, or any other financial information, medical information, or health insurance information. 3. Protected status.  This category includes, without limitation, citizenship, ethnic background, gender, or other similar identifiers. 4. Internet or other electronic network activity information. This category includes without limitation: all activity on the Company’s information systems, such as internet browsing history, search history, email communications, usernames and passwords, and all activity on communications systems including phone calls, call logs, voice mails, text messages, chat logs, and app use. 5. Audio, electronic, visual, thermal, olfactory, or similar information. This category includes, for example, information collected from camera, thermometers, and similar devices. 6. Biometric information. This category includes information such as an individual’s physiological, biological, or behavioral characteristics used or is intended to be used singly or in combination with each other or with other identifying data, to establish individual identity. 7. Professional and employment-related information. This category includes without limitation: data submitted with employment applications including employment history, recommendations, etc., background check and criminal history, work authorization, and fitness for duty data and reports. 8. Education information. This category includes education history. 9. Limited medical information. This category includes without limitation: fitness for duty data and reports, and leave of absence information (including information related to family obligations), and physical and mental health data concerning employee or job applicant and his or her family members. 10. Sensitive personal information. This category includes sensitive information such as social security, driver’s license, state identification card, or passport number, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, color, national origin, religion, sex, age, or disability, biometric information for the purpose of uniquely identifying a consumer, and information concerning health and sex life or sexual orientation. 11. Inferences drawn from the personal information in the categories above. This category includes engaging in human capital analytics, including but not limited to, identifying certain correlations about individuals and success on their jobs, analyzing data to improve retention, and analyzing preferences to inform HR Policies, Programs and Procedures.

The Purposes Personal Information, Including Sensitive Personal Information, is Used includes the following:  1. Collect and process employment applications, including confirming eligibility for employment, background and related checks, onboarding, and related recruiting efforts. 2. To maintain medical records and occupational health programs. 3. Maintaining personnel records and record retention requirements. 4. Communicate with you about your application. 5. Complying with applicable state and federal health, labor, employment, disability, equal employment opportunity, and related laws, guidance, or recommendations. 6. Preventing unauthorized access to, use, or disclosure/removal of the Company’s property, including the Company’s information systems, electronic devices, network, and data. 7. Investigating complaints, grievances, and suspected violations of Company policy. 8. Protect the legal rights, privacy, safety or property of Company or its employees, agents, contractors, customers or the public. 9. Protect against fraud or other illegal activity or for risk management purposes. 10. Enforce the Company’s terms of use.	11. Design, implement, and promote the Company’s diversity and inclusion programs. 12. Facilitate the efficient and secure use of the Company’s information systems. 13. Improve safety of employees, job applicants, customers and the public with regard to use of Company property and equipment. 14. Evaluate an individual’s appropriateness for a participation position at the Company, or promotion to a new position. 15. To respond to and manage any legal claims against the Company and/or its personnel, including civil discovery in litigation. 16. To facilitate other business administrative functions and strategic activities, such as risk management, information technology and communications, financial management and reporting, workforce and succession planning, mergers and acquisition activities; and maintenance of licenses, permits and authorization applicable to Company operations.  For information on the sources of personal information we collect and the categories of third parties to whom we may disclose personal information, please visit the Company’s Privacy Policy at https://cava.com/privacy.

To carry out the purposes outlined above, the Company may disclose information with third parties or service providers, such as background check vendors, third-party staffing vendors and information technology vendors, outside legal counsel, and state or federal governmental agencies.

The Company does not sell or share, as those terms are defined under applicable law, the above categories of Personal Information of employees and job applicants. The Company may add to the categories of personal information it collects and the purposes for which it uses personal information. By applying for a position or becoming an employee of CAVA, you agree to be subject to the Terms of Use at https://cava.com/terms, which are incorporated into this notice and made a part hereof.

California Resident Individual Rights Requests. Individuals who are residents of the State of California have certain individual rights. These rights and how to exercise them are described more fully in the Company’s Privacy Policy at https://cava.com/privacy.

We reserve the right to amend this Notice at any time without advance notice.

If you have questions about this notice, you may call 1-844-707-6841 or e-mail [email protected].

Last Updated: December 28, 2022