Kroger's New Privacy Policy Should Concern Us All

When you download the Kroger app, sign up for a loyalty account, or order groceries online, you’re probably thinking about your shopping list and the sale prices. Reading a 36-page privacy policy is unlikely to be part of the plan.

But that fine print tells you a great deal about how Kroger collects and uses your information. It covers far more than purchase histories: the policy describes collecting location data, tracking activity on its websites, and using cameras that may capture license plates and, in select stores, facial-recognition data. It also describes the information Kroger makes available to other companies, including conclusions it draws about individual shoppers.

For customers concerned about being tracked while buying groceries, these disclosures deserve a closer look. We compared Kroger’s December 2025 privacy policy with the update effective September 9, 2026 to explain what changed, what was already there, and what shoppers should know about how their information is being used.

Grocery purchases may inform credit decisions

The new policy adds a notice about automated decision-making technology in its California disclosures. A business supporting Kroger’s co-branded credit card may use that technology to evaluate a customer’s eligibility, including for underwriting or creditworthiness. Kroger says it may provide certain purchase transaction information for that purpose, where permitted by law.

That use may affect whether a shopper receives a credit-card offer and the terms of that offer, including the credit limit. Kroger says it does not use the technology to make those decisions itself. The business supporting the card would do so.

The policy also changes its position on profiling. In December, Kroger said it did not conduct profiling that would produce legal or similarly significant effects, and therefore did not offer an opt-out for it. The September version removes that statement. It now describes a right to opt out of such profiling, with opportunities to apply for the co-branded credit card as an example.

The California notice separately says shoppers can opt out of the purchase-data use described above. If they do, Kroger says it will not make their information available for that purpose.

Kroger does not explain which purchases would matter to a credit decision, or how they would be weighed. A customer using a loyalty account to save money on groceries should be told clearly if that shopping record may also be used to assess their creditworthiness.

Kroger expanded its facial recognition disclosure

The December policy’s section for other state privacy laws said Kroger might collect facial-recognition data in “select Texas stores.” The September version says “select stores.”

The change removes a geographic qualification from that section, and it's unclear if Kroger is now expanding its use of facial recognition cameras. Both versions already described biometric collection in select locations elsewhere in the policy, and both say Kroger does not collect biometric information in California.

Kroger describes this collection as serving security and crime-prevention purposes and says it posts notices at store entrances where it occurs. But neither version gives shoppers a list of the stores involved. Customers should be able to find out whether their store collects facial-recognition data before they enter it.

Location data and data brokers

In the old California disclosure table, geolocation data was marked “No” under the column for selling and sharing. In the new table, non-precise geolocation is marked “Yes.” Kroger also adds non-precise location data to the categories it may disclose for targeted advertising or as a sale under the other state privacy laws covered by the notice.

This change concerns approximate location, not precise GPS coordinates. Kroger continues to say it does not sell or share precise geolocation in its sensitive-information table. And a disclosure of selling or sharing does not, by itself, establish a cash sale; these terms have specific meanings under privacy law, including certain advertising-related transfers.

The new policy also names data brokers among the recipients of identifiers, customer records, purchase histories, and inferences about shoppers. The previous recipient tables used the term data enrichment providers. This is a change in what Kroger discloses, not proof that every relationship is new.

One footnote says Kroger makes its inferences available to a single data broker for aggregated reporting and insights. What single data broker is receiving these inferences? Unclear, Kroger doesn't disclose that.

Kroger already collects more than purchase histories

Many of the policy’s most intrusive disclosures were already present in December. They include facial-recognition data at select locations, license-plate captures, recordings of customer-service calls, and demographic information such as whether a household includes children. Both versions also describe technology that can record keystrokes, cursor movements, scrolling, and clicks on Kroger’s websites.

Kroger’s collection language is conditional. The policy does not establish that every type of information is collected from every shopper. A shopping trip can, however, generate records of a customer’s online behavior and in-store activity as well as a list of purchases.

The September update adds detail about interactions with AI-powered chatbots and agents. It describes collecting users’ inputs and the systems’ responses, retaining interactions, and using information to improve its offerings. The policy also adds developing, testing, and improving models to its stated uses of information.

License plate readers raise further questions

The new California section adds a notice directing readers to a separate automated license plate recognition policy. That policy, effective June 1, 2025 and published on the Ralphs website, covers select retail locations in California.

It describes collecting vehicle images, license plates, and the date and time of capture. Kroger identifies itself as the owner of the system and the information it collects. Listed uses include supporting law-enforcement investigations. Disclosure outside the Kroger family is restricted, with exceptions that include service providers and certain sharing with law enforcement or other businesses for security, property protection, or legal reasons.

The separate policy gives no fixed retention period. It says information is kept for as long as reasonably necessary for the stated purposes or compatible uses, subject to law. It also does not identify the covered stores. Shoppers are left without a clear account of where the cameras operate or how long a record of their visit may remain available.

Privacy protections depend on where you live

Kroger’s policy describes rights to access, correct, and delete personal information, as well as opt-outs for sales, targeted advertising, and certain profiling. Their availability depends on the applicable state law and the policy’s conditions and exceptions.

Ohio, where Kroger is headquartered, is absent from the policy’s California and other state consumer-privacy rights sections. Kroger does not promise Ohio shoppers the same broad rights described there. That does not mean Ohio customers have no privacy protections or account controls. It means the policy offers no equivalent general commitment to let them inspect, delete, or restrict the use of their shopping data.

Shoppers can start with Kroger’s privacy request page or privacy preference center, or call 1-800-576-4377 and ask to exercise a privacy right. Kroger also says it honors qualifying Global Privacy Control signals, which allow a supported browser or device to communicate a sale or targeted-advertising opt-out where the right applies. Our guide to requesting a Kroger shopper profile is linked below.

What Kroger should change

Kroger should give shoppers a plain-language account of what it collects, who receives it, and how it is used. That account should name the stores using biometric and license-plate systems and explain the role purchase records may play in credit decisions.

The company should also extend access, deletion, and opt-out rights to customers in every state, including Ohio. Grocery purchases should not be used in credit decisions without a shopper’s explicit, informed consent.

A loyalty discount should not require customers to work through a 36-page policy to discover how their shopping record may be used. Kroger should make these choices clear when customers sign up and let them refuse uses that have nothing to do with buying groceries.

Sources

1. The Kroger Co., Privacy Notice, December 10, 2025, pp. 3–4, 8, 17–21, 25–26, and 35–36.

2. The Kroger Co., Privacy Notice, effective September 9, 2026, pp. 3–4, 7–9, 20, 22, 25–26, 28–30, and 32–35. Page references for both notices use PDF page order.

3. The Kroger Co., Automated License Plate Recognition Usage and Privacy Policy, effective June 1, 2025. Applies to select retail locations in California.

4. California Department of Justice, California Consumer Privacy Act. Explanation of sale, sharing, and consumer opt-out rights.

5. The Kroger Co., Privacy Requests and Privacy Preferences.

6. Kroger Hurts Families, How to See Your Secret Kroger Shopper Profile.

Explore Other Articles