U.S. Supplemental Privacy Policy

Last Revised: October 30, 2025

This U.S. State Supplemental Privacy Policy and Notice (“Supplemental Policy”) applies only to information collected about individuals (“Consumer(s),” “you,” “your”) residing in states with comprehensive privacy legislation that requires provision of a privacy notice including in California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Virginia, and Utah, (collectively “U.S. Privacy Laws”) and supplements the information contained in the Website and Mobile App Privacy Policy.

This Supplemental Policy describes Einstein Noah Restaurant Group, Inc., Bruegger’s Enterprises, Inc., Noah’s New York Bagels Company, Inc., and Manhattan Bagel Company, Inc. (together “Bagel Brands” “We,” “Us,” and “Our”) practices regarding the collection, use, and disclosure of Personal Information we collect through our websites, apps, and other online and offline services and provides instructions for submitting data subject requests. Some portions of this Supplemental Policy apply only to consumers of particular states, and we have indicated where those portions are state-specific.

If you are unable to review or access this Supplemental Policy due to a disability, you may contact us at data_privacy@bagelbrands.com or einsteinbros.com/contact/, to access this Supplemental Policy in an alternative format.

Definitions Specific to this Policy

• “Consumer” means a natural person who resides in states with U.S. Privacy Laws and to whom we offer information, goods, or services. For purposes of this Supplemental Policy, this term includes natural persons who reside in California and engage with us as part of business-to-business transactions.

• “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or household. Personal Information includes “personal data” (or equivalent terms) as that term is defined by U.S. Privacy Laws. Personal Information also includes “Sensitive Personal Information,” as defined below.

• “Sell,” “Sale,” or “Sold” means renting, releasing, or transferring an individual’s Personal Information to a Third Party for money or other valuable consideration.

• “Sensitive Personal Information” means Personal Information that reveals a Consumer’s: 1) Social security, driver’s license, state identification card, or passport number; 2) Account log-in, financial account number, debit card number, or credit card number in combination with any required security or access code, password, or credentials allowing access to the individual’s account; 3) Precise geolocation; 4) Racial or ethnic origin; 5) Religious beliefs; 5) Union membership; 6) Contents of email or text messages, unless we are the intended recipient; 7) Genetic data; 8) Biometric information used to uniquely identify the Consumer, and 9) Health, sex life, or sexual orientation. Sensitive Personal Information also includes “sensitive data” as that term is defined in by U.S. Privacy Laws.

• “Share,” “Shared,” or “Sharing” means transferring an individual’s Personal Information to a Third Party for cross-context behavioral advertising or targeted advertising purposes, whether or not for money or other valuable consideration.

• “Third Party” means a person or organization which is not a Consumer, Vendor, or an entity owned or controlled by us and as defined by U.S. Privacy Laws.

• “Vendor” means a “service provider,” “contractor,” or “processor” which collects, stores, or otherwise handles data for us, as those terms are defined by U.S. Privacy Laws.

Other terms used in this Supplemental Policy may be defined under U.S. Privacy Laws and they shall have the meanings described in those statutes. If there are variations between such definitions in different laws, you will be covered by the definition that applies in your state. For example, if you are a California consumer, terms defined in the California Consumer Privacy Act (“CCPA”) shall apply to you if they are used in this Supplemental Policy.

The Personal Information We Collect and Disclose

The chart below shows the categories of Personal Information we may collect and have collected in the past 12 months; examples of Personal Information in each category; types of sources from which each category of Personal Information is collected; the business purposes for which each category of Personal Information is collected and processed; and the types of Vendors or Third parties with whom that category of Personal Information is disclosed, Sold, or Shared and has been disclosed, Sold, or Shared in the past 12 months. As this chart shows, we may Share or Sell Personal Information to Third Parties or disclose certain Personal Information to Vendors for business purposes

Category of Personal Information Examples Sources from Which This Personal Information is Collected Business Purposes for Collection Types of Vendors or Third Parties with Whom This Personal Information is Shared, Sold or Disclosed
Unique Identifiers Real name, signature, alias, address, unique personal identifier, online identifier, IP address, email address, account name, advertising ID, loyalty or gift card ID -Directly from you by telephone, our websites, our mobile apps
-Social media
-Other individuals
-Rewards programs
-Analytics providers
-Vendors
-Franchisees
-Business partners
-Provide information, products and services
-Security, credit or fraud prevention
-Provide customer service and assess satisfaction
-Personalize customer experience
-Improve products and services
-Improve marketing and customer communications
-Comply with legal requirements
Disclosed:
-Service providers
-Contractors
-Stored value account administrator
-Franchisees
-Affiliates
Shared or Sold:
-Online advertising partners
-Analytics providers
-Vendors
-Business partners
Contact and Financial Information Name, address, telephone, email, credit card number, debit card number, or any other financial information -Directly from you by telephone, our websites, our mobile apps
-Claims management
Providers
-Franchisees
-Gift card provider
-Complete transactions
-Other services and discounts
-Process claims
-Prevent fraud
-Track purchase history
Disclosed:
-Card processor and service providers
-Contractors
-Vendors
-Franchisees
-Gift card provider
Shared or Sold:
-None
Characteristics of Protected Classifications Name, address, telephone, email, credit card number, debit card number, or any other financial information -Directly from you by telephone, our websites, our mobile apps
-Claims management
Providers
-Franchisees
-Gift card provider
-Complete transactions
-Other services and discounts
-Process claims
-Prevent fraud
-Track purchase history
Disclosed:
-Card processor and service providers
-Contractors
-Vendors
-Franchisees
-Gift card provider
Shared or Sold:
-None
Characteristics of Protected Classifications Age, gender, race, marital status -Survey data from analytics provider -Consumer classifications for marketing and analytics Disclosed:
-Service providers
-Contractors
Shared or Sold:
-None
Commercial Information Records of products or services purchased, or considered, or other purchasing or consuming histories or tendencies -Directly from you via our website, telephone, mobile app, in-person
-Direct communication
with you
-Other individuals
-Rewards programs
-Social media interaction with you
-Marketing agencies
-Franchisees
-Business partners
-Provide you with goods and services
-Invite participation in
surveys and feedback
-Customer service communications
-Improve promotions
-To provide rewards to loyalty club members
Disclosed:
-Service providers
-Rewards administrator
-Franchisees
-Contractors
-Stored value account administrator
Shared or Sold:
-Business partners
-Marketing providers
-Analytics providers
-Social media
-Affiliates
-Vendors
Internet or Other Electronic Activity Browsing history, search history, and information regarding a consumer’s interaction with an internet website application, or advertisement -Directly from you via our website
-Direct communication
with you
-Social media interaction with you
-Marketing agencies
-Provide you with information, goods and services
-To provide rewards to loyalty club members
-Invite participation in
surveys and feedback
-Customer service communications
-Improve promotions
-To monitor click through rate
Disclosed:
-Service providers
-Contractors
Shared or Sold:
-Business partners
-Marketing providers
-Analytics providers
-Social media
Geolocation Data Device location -From your digital device
-Direct communication
with you
-Provide you with goods and services
-Customer service communications
-Improve promotions
Disclosed:
-Service providers
Shared or Sold:
-Business partners
-Marketing providers
-Analytics providers
-Social media
Professional or Employment-Related Information Work history, Industry -Survey data from analytics provider -Customer service communications
-Improve promotions
Disclosed:
-Service providers
-Contractors
Shared or Sold:
-None
Education Information Education level -Survey data from analytics provider -Customer service communications
-Improve promotions
Disclosed:
-Service providers
-Contractors
Shared or Sold:
-None
Inferences Drawn from Other Categories to Create a Profile Profile reflecting preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes, knowledge of food preferences -Directly from you via our website
-Direct communication with you
-Social media interaction with you
-Survey data from analytics provider
-Marketing
agencies
-Provide you with goods and services
-Customer service communications
-Improve promotions
-To understand other data points on people
Disclosed:
-Service providers
Shared or Sold:
-Business partners
-Marketing providers
-Analytics providers
-Social media
-Affiliates
-Online advertising partner

Sensitive Personal Information We Collect and Disclose

Category of Sensitive Personal
Information
Sources
From Which This
Sensitive Personal
Information is Collected
Business
Purposes for Collection
Types of Vendors or Third Parties with Whom This Sensitive Personal Information is Shared, Sold or Disclosed
Account log-in, financial account, debit card number, plus an access code -Directly from you
you via our website
-Complete transactions
-Offer services and discounts
-Prevent fraud
Disclosed:
-Service Providers
-Contractors
Shared or Sold:
-None
Racial or Ethnic Origin -Survey data from analytics provider -Customer service communications
-Improve promotions (e.g. before specific religious holidays)
Disclosed:
-Service Providers
-Contractors
Shared or Sold:
-None

As needed, we may also disclose the Personal Information described above in the following situations:

• To protect our rights, defend or pursue a legal claim, or investigate or prosecute illegal activities
• To government or judicial authorities to comply with a subpoena, court order, governmental inquiry, legal process, legal obligation, or to protect the rights, property, or safety of other users or the public
• To a successor entity or purchaser upon a merger, consolidation, or other corporate reorganization in which we participate, a sale of all or a portion of our assets, or pursuant to a financing arrangement. In this situation, we will seek assurances that the successor entity or purchaser will process personal information collected by us in accordance with this Policy.

We may also aggregate and/or anonymize Personal Information and analyze those data for statistical or any other purposes permitted by law.

Retention of Data

We intend to retain each category of Personal Information described above only for as long as necessary to fulfill the purpose for which it was collected, or a related and compatible purpose consistent with the average Consumer’s expectation, and to comply with applicable laws and regulations. We consider the following criteria when determining how long to retain Personal Information: why we collected the Personal Information; the nature of the Personal Information; the sensitivity of the Personal Information; our legal obligations related to the Personal Information, and risks associated with retaining the Personal Information.

Opt Out Preference Signals

We recognize opt-out preference signals that we are required to recognize for compliance with applicable law. Where required by U.S. Privacy Laws, we treat such opt-out preference signals as a valid request to opt-out of Sale, Sharing, and processing for purposes of targeted advertising, as applicable, for the browser or device through which the signal is sent and any consumer profile we have associated with that browser or device, including pseudonymous profiles. Further, if we know the identity of the consumer from the opt-out preference signal, we will also treat the opt-out preference signal as a valid request to opt out of Sale and Sharing for such consumer. Consumers may use opt-out preference signals by downloading or otherwise activating them for use on supported browsers and setting them to send opt-out preference signals to websites they visit. However, our sites do not respond to “Do Not Track” signals sent by browsers, which are different from the opt-out preference signals described above.

Your Rights to Your Personal Information

Consumers who reside in states with U.S. Privacy Laws have certain rights with respect to the collection and use of their Personal Information, subject to certain exceptions. Please read this section carefully as some rights vary by state.

Right to Know.

You have the right to request that we disclose to you:
• The categories of Personal Information we have collected about you;
• The categories of sources from which the Personal Information is collected;
• The purposes for which the categories of Personal Information are collected, used, Sold, and Shared;
• The categories of Third Parties to whom we have disclosed Personal Information;
• The categories of Personal Information we have Sold or Shared and the categories of Third Parties who whom the Personal Information was Sold or Shared; and
• The categories of Personal Information we have disclosed for a business purpose and the categories of persons to whom it was disclose to.

Right to Access.

You have the right to request to obtain the specific pieces and categories of Personal Information we have collected about you. Residents of Oregon also have the right to obtain a list of the specific Third Parties to whom we have disclosed Personal Information.

Right to Delete.

You have the right to request that we delete certain Personal Information that we have collected.

Right to Correct.

You have a right to request that we correct any inaccurate Personal Information we may retain about you. Please note this right does not apply to Iowa and Utah residents.

Right to Data Portability.

You have the right to request the Personal Information we have collected about you in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the Personal Information to another entity without hindrance. You may not exercise this right more than two times in a calendar year.

Right to Opt-Out of the Sale and Sharing of Your Personal Information or Use of Your Personal Information for Targeted Advertising.

You have the right to opt-out of the Sale of your Personal Information and the right to opt-out of the Sharing of your Personal Information and processing of Personal Information for targeted advertising purposes.

We Sell and Share Personal Information, and process Personal Information for targeted advertising purposes. In the past twelve months, we have Sold or Shared the categories of Consumer Personal Information as listed in this Supplemental Policy to improve marketing and customer communications, improve promotions, and provide you with information, and to understand other data points on people. As a Consumer, you have the right to opt-out of the Sale and/or Sharing of your Personal Information and of the processing of Personal Information for the purpose of targeted advertising. We do not knowingly Sell or Share Personal Information of Consumers under 16 years of age.

If you would like to request that We do not Sell or Share, or process for targeted advertising purposes Personal Information collected via cookies or other online tracking technologies, click here to open our Cookie Preference Center and then click “Reject All.” To request that We do not Sell or Share or process for targeted advertising purposes other types of Personal Information we may collect about you, click here, email help@bagelbrands.com, or call us at 1-800-962-6786, option 3. The link will take you to an interactive webform that you can complete and submit to make a request to opt out; if you use the telephone number, you will be guided through a process that will allow you to submit a request.

If you use an authorized agent to submit your request to opt-out, We will request that the agent provide Us with proof that he, she, or they has been authorized by you to act on your behalf.

If you opt-out of the sale of your Personal Information, we will wait at least 12 months before asking you if we may Sell or Share your Personal Information. You have the right to opt-in to the sale of your Personal Information after you have opted out. If you would like to opt-in to the Sale or Sharing or processing of your Personal Information for targeted advertising purposes via cookies and other online tracking technologies, you can click here to open our Cookie Preference Center and set your preferences. If you would like to opt-in to the Sale or Sharing or processing for targeted advertising purposes of other types of Personal Information we may collect about you, please email us at data_privacy@bagelbrands.com, or call us at 1-800-962-6786, option 3. Opting-in is a two-step process in which you will first clearly request to opt-in, and then separately confirm that choice.

Right to Limit the Use of Your Sensitive Personal Information.

California residents have the right to instruct us to limit the use and disclosure of your Sensitive Personal Information to only that which is necessary to perform the services or provide the goods reasonably expected by an average Consumer or for specific business purposes defined by the CCPA. However, we do not use Sensitive Personal Information for purposes beyond those authorized by the CCPA.

Right to Withdraw Consent. You may have the right to withdraw your consent to our processing of your Sensitive Personal Information.

Right to Opt-Out of Profiling: You have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects (which means a decision that results in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services). Residents of Minnesota also have the right to question the results of profiling. Please note, however, that we do not use Personal Information for profiling in furtherance of decisions that produce legal or similarly significant effects.

Right to Non-discrimination. You have a right to exercise the above rights and we will not discriminate against you for exercising these rights. Please note that a legitimate denial of a request to access, delete, or opt-out is not discriminatory, nor is charging a fee for excessive or repetitive requests, as permitted by the U.S. Privacy Laws.

Instructions to Exercise your Rights. If you would like to request that We do not Sell or Share, or process for targeted advertising purposes Personal Information collected via cookies or other online tracking technologies, click here to open our Cookie Preference Center and then click “Reject All.” To request that We do not Sell or Share or process for targeted advertising purposes other types of Personal Information we may collect about you, or to make any of the other types of data requests listed above, please click here, email us at data_privacy@bagelbrands.com, or call us at 1-800-962-6786, option 3. The link will take you to an interactive webform that you can complete and submit to make a request to exercise your Rights. You may also authorize an agent to make a request to exercise your Data Subject Rights on your behalf, and your authorized agent may do so by the same means listed above. For requests to exercise your right to know, access, correct, delete, and data portability we will also verify your identity before processing your request, using the process set out in the “Verification Process” section below.

Right to Appeal. You have the right to appeal our decisions about your data subject requests. If you choose to appeal a decision, your request will move from IT Dept to our Legal Department for review. If you would like to appeal a decision regarding your data request, please click here, email us at data_privacy@bagelbrands.com or call us at1-800-962-6786, option 3]. Please state that your request is an “Appeal,” and describe the date and nature of your original request.

Verification Process

When you submit a request to exercise your Data Subject Rights to know, access, correct, delete, or data portability, we may ask you to provide information that will enable us to verify your identity.

If you designate an authorized agent to exercise your rights on your behalf, we may require that you or the authorized agent do the following:

• Verify your identity with us directly.
• Provide proof of your signed written permission for the authorized agent to submit a request on your behalf.

We may deny a request from an authorized agent on your behalf if the authorized agent does not submit proof that he, she, or it has been authorized by you to act on your behalf if we request such proof.

Personal Information of Minors

Our online content is not intended for children or minors under the age of sixteen years. Accordingly, we do not knowingly store information from minors under the age of sixteen years except as required pursuant to applicable law. If you believe that a child has submitted personal information to us, please contact us at data_privacy@bagelbrands.com or 1-800-962-6786, option 3, and we will delete the information.

Financial Incentives For Consumers

Certain of Our companies (but not all) offer a loyalty/rewards program (each, a “Rewards Program”) as a financial incentive to consumers who allow Us to retain and share their Personal Information we collect as described in this Policy. These incentives generally include complimentary or discounted products, and other special offers. For more information on Our Rewards Programs, including to learn how to sign up for a Rewards Program, visit https://bagelbrands.com/loyalty-program-terms-and-conditions/.

If you participate in a Rewards Program we may Sell/Share or process for targeted advertising the following categories of Personal Information: unique identifiers, such as, real name, email address, or loyalty card ID; contact information, such as name, telephone number and email address; characteristics of protected classifications, such as age; and commercial information, such as records of products or services purchased, or considered, or other purchasing or consuming histories or tendencies. We may disclose, Sell, or Share these categories of Personal Information with online advertising partners, analytics providers, vendors, and business partners.

When exercising your rights under this Supplemental Policy, if you request that we delete all Personal Information that we have about you, this will effectively prevent access to your Rewards Program account and/or your participation in our Rewards Programs and, correspondingly, we must treat such an election as a withdrawal from all of Our companies’ Rewards Programs, and your account for the Rewards Programs will be terminated.

You have the right to withdraw from the Rewards Program at any time and may do so by making a request to “delete all personal information you have about me” at https://www.bagelbrands.com/privacy-policy/request/ or email data privacy@bagelbrands.com. Upon termination of your Rewards Program account, (1) all points, rewards and other offers associated with your account will be deemed forfeited, for which no consideration will be given, and (2) if your account has a U.S. dollar funds balance loaded on the account, your funds balance will be transferred by us from your account to a substitute funds access code which will be sent separately by us to you by email.

We estimate the average value of a Rewards Program is $10 per year (which may be higher or lower as to a specific Rewards Program). We arrived at such value by estimating the approximate retail value of complimentary or discounted products provided through a Rewards Program.

Additional California Privacy Rights

Shine the Light Request. California Civil Code Section § 1798.83 permits users of our website who are California residents to request certain information regarding our disclosure of personal information to other parties for their direct marketing purposes. To make such a request, please send an email to us at data_privacy@bagelbrands.com with the subject “Shine the Light Request.”

Disclosure for Nevada Consumers

We may sell “Covered Information” as defined under Nevada law, but we generally do not disclose or share “Personal Information” as defined under Nevada law for commercial purposes. Under Nevada law, you have the right to direct us to not sell your Covered Information to third parties, as defined under Nevada law. To exercise this right, if applicable, you or your authorized representative may contact us at data_privacy@bagelbrands.com.

Changes to Our Supplemental Policy

Bagel Brands reserves the right to amend this Supplemental Policy at our discretion and at any time. When we make changes to this Supplemental Policy, we will post an updated policy on our website with the revised date.

Additional Information

If you would like additional information regarding our Supplemental Policy, please contact us at data_privacy@bagelbrands.com or einsteinbros.com/contact/, or at
Einstein Noah Restaurant Group, Inc.
1720 S. Bellaire St.
Attn: Skybox
Denver 80222

Return to the start of our Supplemental Policy