Compliance frameworks, security audits, and quality certifications this company maintains.
Grubhub's payment processing infrastructure is PCI DSS Level 1 certified, ensuring that credit card and payment data from millions of diners placing orders through the Grubhub marketplace is handled to the highest payment security standards.
Grubhub maintains SOC 2 Type II certification, with annual third-party audits verifying that its platform infrastructure, data handling, and operational security controls meet the Trust Services Criteria for security and availability.
Grubhub complies with the EU General Data Protection Regulation for its European operations, maintaining data processing agreements, user consent mechanisms, and data subject rights workflows to protect personal data of diners and restaurant partners.
Grubhub supports California Consumer Privacy Act compliance, providing California diners with rights to access, delete, and opt out of the sale of their personal data collected through the Grubhub and Seamless platforms.
Accessibility
ADA Title III
CompliantGrubhub's consumer app and website are designed to meet ADA Title III accessibility requirements, ensuring the food ordering experience is accessible to users with disabilities through screen reader support and accessible interface design.
Regulatory
FDA Food Safety
CompliantGrubhub complies with FDA food safety labeling requirements, working with restaurant partners to display calorie counts and allergen information for menu items on the Grubhub marketplace in jurisdictions where such disclosure is mandated.
Grubhub's platform and data collection practices restrict ordering accounts to users 13 and older, and the platform does not knowingly collect personal information from children under 13 in compliance with the Children's Online Privacy Protection Act.
Grubhub's information security management practices align with ISO/IEC 27001 standards, covering risk management, access controls, incident response, and data protection across its technology and operations infrastructure.
Grubhub designs its food delivery application and web platform to meet WCAG 2.1 AA accessibility standards, ensuring users with disabilities can independently browse restaurant menus, place orders, and track deliveries using Grubhub.
Grubhub complies with the California Consumer Privacy Act for personal data collected from California-based diners, restaurants, and delivery partners, providing required privacy notices and data subject rights for personal information processed through the Grubhub platform.