Pandora Privacy Policy

Effective as of October 1, 2019

Pandora operates a personalized Internet radio service and related platform features available through the web at pandora.com, on mobile devices and tablets, in automobiles, and through other consumer electronic devices (the "Pandora Service" or "Service"). As we use it in this policy, "Pandora" refers to Pandora Media, LLC and its subsidiaries. This policy applies to all Pandora-authorized operations of the Service. We may refer to Pandora as "we", "us", or "our". We may refer to you as "listener", "you", or "your". The purpose of this policy is to inform you about the personal information we collect, how we use and share that information, and the ways in which you can control how we use and share that information. By using our Service, you agree to the terms of this policy and you expressly consent to the collection, use, and disclosure of your personal information in accordance with this policy.

1. Information We Receive or Collect From You

Registration Data: When you register, we ask you to provide certain information, which includes your email address, birth year, gender, and zip code (the "Registration Data"), as well as a password for your account.

Payment Information: If you choose to subscribe to fee-based portions of the Service, purchase a subscription to the Service as a gift, or purchase add-on products or services, you will also be asked to provide (at a minimum) your name and payment information ("Payment Information").

Information You Choose to Provide to Pandora: You have the ability to provide a variety of information during your interactions with us and the Pandora Service, such as emails you may send us, ads you respond to, and emails or newsletters that you sign up to receive. Pandora or third parties acting on our behalf receive data from you whenever you provide us with information.

Listening Activity: When you use the Service, we keep track of your listening activity, which may include the number and title of songs you have listened to, the songs that you like (thumb up) or dislike (thumb down), the stations and playlists you create or listen to, the songs you skip, and how long you listen.

Community Posting: You have the ability to post comments, images and information in community networking features available on or accessible through the Service, such as your Pandora Community public profile, artist and album forums, our blog, and our social networking pages. You should be aware that any information you submit in the course of these community activities can be read, collected, or used by other users of these parts of the Service, as further discussed below. We are not responsible for the information you choose to make public in any of the community networking features available on or through the Service.

Technical Information: As is true of many internet-enabled services, Pandora may collect certain technical information through the use of log files and servers. Web and application servers create log files automatically as part of their setup and configuration. Information in a log file may include IP address, browser type, Internet service provider, date/time stamps, Media Access Control (MAC address), file requested, and other usage information and statistics.

Contact Information: If you choose to participate in research studies, or sign up for certain features and/or rewards offered through the Service, you may provide us, and we may collect, your contact information, including your name, mailing address, and phone number ("Contact Information"). The email address you provided as part of your Registration Data is not considered Contact Information for the purposes of this policy.

Device Information: If you access and use the Service from a computer, mobile phone, tablet, automobile, or other electronic device, we may collect information about those devices. For example, our servers receive and store information about your computer and browser, including your Internet Protocol (IP) address, browser type, and other related software or hardware information. If you access the Service from a mobile phone, tablet, automobile, or other electronic device, we may collect and store information such as device type, operating system version and type, unique identifiers (such as mobile advertising, VIN, and MAC address), carrier, and other related information for that device.

Location Information: When you register for the Pandora Service, you provide us with your zip or postal code. We may also collect location information from devices you use while accessing the Pandora Service. Depending on the device and operating system, device-based location information may be derived from GPS and nearby wireless signals such as cell towers, Wi-Fi networks, and Bluetooth beacons. We will not collect your device-based location information unless you have permitted the Pandora app to access location services on your device. You can disable this access at any time in your system settings. Additionally, in some cases, your location within a geographic block may be approximated from the IP address currently assigned to your device.

Voice Data: If you grant microphone access to the Pandora app on your device, we will receive your voice data when you interact with a voice feature on our app. You can perform a search or control Pandora with your voice by tapping on the microphone icon in the search bar, or by using the wake word “Hey Pandora” if you have enabled “Listen for ‘Hey Pandora’” in your app settings. Ad-supported listeners can also use their voice to interact with select audio advertisements, in which case an audible tone will sound when the microphone opens and closes, and an indicator will display on your screen. For more information about Pandora’s voice features, see this FAQ.

Research: If you choose to participate in surveys or other research, we will collect any information you choose to provide us, together with other data about your use of the Pandora Service.

Third-Party Personal Information: Certain features of our Service require you to provide personal information about another person. By providing another person’s personal information to us, you confirm that you have all necessary rights and permissions to provide such information. If you choose to provide this information, we may store and use the information for purposes of providing those features. For example, if you choose to purchase a subscription to the Service for a friend, we may ask for your friend’s name and email address to provide the gift. We will only use this information for the specific reason for which it was provided or for security purposes, such as to prevent fraud. If you believe that one of your contacts has provided us with your personal information and you would like to request that it be removed from our database, please contact us at privacy@pandora.com.

2. Information We Receive or Collect From Third Parties

We may receive or collect information about you from third parties, and combine and store it on our servers with other information we may have already received or collected from you. These third parties include:

Pandora is not responsible for, and will assume no liability, if a business partner or other entity collects, uses, or shares any information about you in violation of its own privacy policy or any applicable laws, rules, or agreements.

Related Companies

: We may also receive information about you from our parent corporation, Sirius XM Radio Inc. ("Sirius XM") and its subsidiaries. For more information about Sirius XM, please see https://www.siriusxm.com/corporate.

3. Information Collection Technologies

Our use of cookies: Pandora uses a technology that is commonly known as "cookies." A cookie is a file our server writes to your hard drive that contains an alphanumeric identifier. We use the identifier in a cookie to help us manage and report on your interaction with the Service. Through cookies, we are able to collect information that we use to improve the Service, keep count of return visits to our website or our advertisers' or partners' websites, collect and report on aggregate statistical information, authenticate your login credentials, or manage multiple instances of the Service in a single browser. We may also collect other data such as the page or site that referred you to the Service, the date and time you visited the Service, and your current IP address. The cookies we place on your hard drive are known as "first-party cookies."

We use both session cookies and persistent cookies. A session cookie expires when you close your browser. A persistent cookie remains on your hard drive for an extended period of time. You may be able to remove persistent cookies by following directions provided in your browser's "help" section. If you do not accept first-party cookies you may still use our Service, but your ability to use some areas of our website, and the ability to stay logged in, will be limited.

Advertisers' and other third parties' use of cookies: Advertisers and third-party advertising partners that deliver ads to you on the Service may place or recognize a unique cookie on your hard drive. These types of non-Pandora cookies are known as "third-party cookies." Advertisers and third-party advertising partners may use third-party cookies in order to collect information about you, which may include how many times you have seen their ads or whether you have interacted with an ad. They may also use third-party cookies to provide you with interest-based advertising. Most major web browsers provide users with the option to accept or reject third-party cookies. The use of third-party cookies is not covered by this privacy policy. We do not have access to or control over cookies placed by advertisers and other third parties. If you would like to review and modify your interest-based advertising settings, visit Your Advertising Choices on Pandora.

Beacons and tracking pixels: Pandora, its third-party advertising partners, and tracking-utility partners employ a technology known as "beacons" or "tracking pixels" (each, a "Beacon"). A Beacon is a one-pixel-by-one-pixel clear image that is embedded in HTML content, and is about the size of a period at the end of a sentence. When HTML content containing a Beacon is rendered, the Beacon transmits information to a server, such as a numeric count, unique identifier, or IP address. Pandora and its partners use Beacons to help us better manage content on our Service. For example, we may place a Beacon in HTML-based emails to let us know which emails recipients have opened, or on a webpage to count the number of unique visitors to that page. The use of a Beacon may also allow us to gauge the effectiveness of certain communications and of our marketing campaigns.

HTML5 and Flash Local Storage: Pandora and its advertising and technology partners may, in some instances, use HTML5 and/or Flash Local Storage (collectively, "Local Storage") to enhance your listening and advertising experiences on the Service. For example, we use Local Storage to keep track of the current song playing in the event your browser window reloads inadvertently, that way we can continue playing that song starting at the same position it was prior to reload. Our advertising and technology partners may use Local Storage to detect your bandwidth speeds for optimal video playback performance. Each browser implements HTML5 Local Storage differently and provides tools for managing content stored within local storage. You can review your browser's privacy settings to manage the content stored within HTML5 Local Storage. Similarly, for more information on how to manage content stored with Flash Local Storage, please review this document provided by Adobe.

4. How We Use Information We Receive or Collect

Generally: Pandora may use your Registration Data and other information or data we receive or collect, as well as data we derive or infer from combinations of the foregoing, for a variety of purposes, such as:

Push Notifications: We may send you push notifications from time to time in order to update you about events and promotions. If you no longer wish to receive these types of communications, you may turn them off at the device level in your app settings. To ensure you receive proper notifications, we will need to collect certain information about your device such as operating system and user identification information.

Email Address: We do not sell or give your email address to other companies for their own marketing purposes without your permission. However, we may use your email address or other Registration Data to provide you with technical support, send you notices about the Service or other promotional offers you have elected to receive, and to serve you with ads that are more relevant to your interests. We may also work with data partners and advertising platforms to help increase the relevance of ads we provide to our listeners. In doing so, we may use information representing an encrypted or hashed value derived from information we have received, such as your email address, in connection with these partners and platforms.

Contact Information: We do not sell or give your Contact Information to companies for their own marketing purposes without your permission. We do use Contact Information, however, to contact you, and to provide you with special offers and other information. If you provided your Contact Information as part of your use of Pandora's Artist Marketing Platform, we may use your Contact Information to update you on new features and functionality made available as part of the Artist Marketing Platform, or the status of your content submission. You may at any time request that we cease using your Contact Information by contacting User Support.

Related Companies: We share information we collect with our parent corporation, Sirius XM and its subsidiaries for the purposes described in our respective privacy policies, and to offer, provide, and improve services and products offered both individually and jointly with other Sirius XM companies. Sirius XM’s privacy policy is available at www.siriusxm.com/privacy. Additionally, we may share your personal information, with our successor in interest in the event of a corporate reorganization, merger, or sale of all or substantially all of our assets.

5. How We Share Information We Receive or Collect With Others

How Your Information Is Shared: Pandora may share information we receive or collect in a variety of ways, such as:

Legal and Security Purposes: We may share your information in order to (i) protect or defend the legal rights or property of Pandora, or the legal rights of our business partners, employees, agents, and contractors (including enforcement of our agreements); (ii) protect the safety and security of Pandora users or members of the public including acting in urgent circumstances; (iii) protect against fraud or to conduct risk management; or (iv) comply with the law, legal process, or legal and government requests.

Sharing of Device Information: Pandora may share information we gather from devices you use to access the Service with its third-party vendors or service providers, manufacturing or distribution partners, or advertising partners. We share this information for a variety of purposes such as mobile listening capping, advertising frequency capping, tracking advertising conversion events, estimating the number of unique users, security and fraud detection, debugging problems with the Pandora Service, and for providing you with more relevant advertisements.

Sharing of Deidentified, Aggregated, or Anonymized Information: : Pandora may share with third parties, advertisers, and/or business partners deidentified, aggregated, or anonymized information we receive or collect, such as demographic information, location information, information about the computer or device from which you access the Service, or information about the your interactions with the Service. We share such information for a variety of reasons, such as to analyze Service usage, improve the Service and your listener experience, improve the serving of advertisements, or for other similar purposes.

Information You Disclose in a Public Profile or in Public Forums: The Pandora Service offers publicly accessible and available profile pages, Pandora Community, community forums (such as artist, song, or advertiser pages), blogs, and pages on social media platforms. You should be aware that any information you provide or post in these areas may be read, collected, and used by others who access them. If your profile is public, any information you place in your user profile, including biographical information, the people you are following, and the people whom you allow to follow you, may be read, collected, and used by others who access them. To request removal of such information from our public forums, contact our User Support team. In some cases, we may not be able to remove your information, in which case we will let you know if we are unable to do so and why. To find out more about how to make your profile private, please see the section below on Pandora Profile Visibility.

Data Transfer: If your personal information is transferred or shared as described in this policy, we will seek assurances from the recipients of such information (prior to the transfer) that they will safeguard the information in a manner consistent with this policy. We ask recipients of such information to enter into a contractual relationship with us that includes confidentiality and non-disclosure clauses, and provides the same level of commitment to and protections of information as provided in this policy.

6. Advertising & Measurement Settings

Opting Out of Behavioral Advertising on the Web: If you are using an iOS-based device and do not want to receive tailored in-application advertisements that relate to your interests, you may be able to limit these advertisements by enabling “Limit Ad Tracking” on your iOS Device following these instructions from Apple.

If you are using an Android-based device and you do not wish to receive tailored in-application advertisements, you can visit Google’s Ads Settings page from a browser on your Android-based device and make your choices there.

Pandora does not control the applicable platform operator-supplied ad settings, which may be updated or removed in accordance with each platform operator’s respective policy. You should contact the platform operator if these options are no longer available.

Opting Out of Third Party Service Measurement and Analytics: As disclosed in this policy, we use third-party providers to aid us in measuring and analyzing service usage. You may opt-out of web-based participation in these measurement services by following the instructions on the following web pages for each respective company: Nielsen and Scorecard Research. To opt-out of participation on mobile and tablet devices, please follow the instructions above listed in the section for Opting Out of Behavioral Advertising on Mobile and Tablet Devices.

7. Managing Your Information

Modification of Your Registration Data: We provide you with the ability to access and modify your Registration Data, which you may do through the Settings section of our Service or by contacting User Support. For detailed instructions on how to modify your Registration Data or to otherwise access this information, visit https://help.pandora.com. We generally respond to help requests within 24 hours of receiving a request, but it may take up to 30 days depending on the volume of requests we receive.

Retention of Your Registration Data and other Information: We will retain and use your Registration Data and the other information we collect about you for as long as your account is active or as needed to provide you Services. We will retain and use this information for the purposes for which it was collected (as specified in this policy or as Pandora discloses to its listeners outside of this policy), including, to provide the Service to you, comply with our legal obligations, resolve disputes, and enforce our agreements.

If you would like to delete your Registration Data, or if you would like more information on cancelling or deactivating your account, see the section below on Cancellation or Deactivation of Accounts.

Your Email Preferences: When you register for the Service, you may elect to receive promotional, marketing, or other similar emails tailored to your interests. You have the option to change this election in your account settings. For information on how to opt in or out of receiving promotional, marketing, or other similar emails from us, visit help.pandora.com.

Additionally, you may also follow the unsubscribe instructions contained in the promotional, marketing, or other similar emails you receive.

We will send you transaction confirmation emails and other Service-related announcements when it is necessary to do so. For instance, if our Service is temporarily suspended for maintenance, we might send you an email. Generally, you may not opt-out of these communications, which are not promotional in nature. If you do not wish to receive them, you have the option to deactivate your account.

Cancellation or Deactivation of Accounts: If you would like to request the cancellation or deactivation of your account, you should contact our User Support team for assistance. Cancellation or deactivation of your account does not ensure complete or comprehensive removal of the content or information you may have posted or otherwise made available publicly on the Service while you were a registered user. You should also contact our User Support team to request the deactivation of a profile you believe is fake or otherwise unauthorized.

Pandora Profile Visibility: When you register for the Pandora Service, your profile and listening activity will be public. When the visibility of your Pandora profile is set to public, the Service automatically publishes your listening activity to your profile. For example, if you create a new station or thumb up a song, that activity will be posted in your Pandora profile for members of the public to view. We provide you with the ability to change the degree of visibility of your Pandora profile. For detailed instructions on how to adjust your Pandora profile visibility settings, visit https://help.pandora.com.

Please note that changes to the visibility of your Pandora profile do not have any impact on the advertising you may see if you use the ad-supported version of the Service.

Cached Profiles on Search Engines: Although we may deactivate your account or make your profile private at your request, Internet search engines such as Google and Bing cache publicly available webpages for a period of time beyond the control of Pandora, and may make your deactivated or formerly public profile available to users of their services on their platforms until such time as they refresh their webpage cache. Please consult with the applicable search engine to determine how you may remove webpages from their webpage cache.

8. Security and Content From Other Websites

Protection of Data From Loss: We have implemented security measures designed to protect against the loss, misuse, and alteration of the information we collect or receive from you. For example, when you enter sensitive information (such as a credit card number) on our order forms, we encrypt the transmission of that information using secure socket layer technology (SSL). However, despite our efforts, no security measures are perfect or impenetrable. If you have any questions about security on our Service, you can contact our User Support team.

Data Integrity: We use the information we collect in ways that are relevant and compatible with the purpose for which that information was collected or provided to us as disclosed in this policy. We will take steps to ensure that all information collected, processed, and/or stored is protected from destruction, corruption, or use in a manner inconsistent with the purpose for which we received it.

Links to Other Websites: Our Service and certain advertisements on our Service include links to other websites whose privacy practices may differ from those of Pandora. If you submit personal information to any of those websites, the privacy statements and practices of those websites govern their use of your information. We encourage you to carefully read the privacy statement of any website you visit.

Use of Framing Techniques: Some of our third-party partners may utilize framing techniques to serve content to and from webpages accessible through our Service while preserving the look and feel of our website. Please be aware that if a third-party partner utilizes framing techniques, you are providing your personal information to this third-party partner and not to Pandora.

9. Our Policies Concerning Children

Pandora prohibits registration by, and does not knowingly collect personal information from, anyone under 13 years of age. In the event we obtain actual knowledge that we have collected information from children under the age of 13, we will take measures to remove such information from our servers. If you believe that we might have any personal information from a child under 13, please contact our Listener Support team.

10. Your Privacy Under State Laws

California Residents: Pursuant to California Civil Code Section 1798.83, this policy sets forth that we only share personal information (as defined in California Civil Code Section 1798.83) with third parties for direct marketing purposes if you either specifically opt-in, or are offered the opportunity to opt-out and elect not to opt-out of such sharing at the time you provide personal information or when you choose to participate in a feature on the Service. If you do not opt-in or if you opt-out at that time, we will not share your personal information with that identified third party for direct marketing purposes.

California Business & Professions Code Section 22575(b) provides that California residents are entitled to know how we respond to "Do Not Track" browser settings. Like many other websites and online services, we do not currently alter our practices when we receive Do Not Track signals as there is no consensus among industry participants as to what "Do Not Track" means in this context. To find out more about "Do Not Track," you may wish to visit https://www.allaboutdnt.com/.

Nevada Residents: If you are a resident of Nevada, you may apply limits to the sale of certain personal information to third parties for resale or licensing purposes, subject to applicable law. Pandora does not sell your personal information for such use. You are entitled to register your preference for limits on such sales in the future by sending an email to privacy@pandora.com, with the subject line, "Nevada Do Not Sell Request" along with your first and last name, zip code, and whether you are a former or current Pandora listener. If you are a former or current Pandora listener, in order to process your request, your email address must match the email address on your account.

11. Transfer of Information of International Listeners

If the Pandora Service is offered outside of the U.S., the information you submit to us may be transferred to the U.S. and other countries to be processed by us or our service providers in order to provide the Service to you or for such other purposes as set forth in this policy. If you are not a resident of the U.S., you hereby consent and agree that we may collect, process, use, and store your information, as discussed in this policy, outside your resident jurisdiction, including in the U.S. Please be aware that U.S. law and the laws of other countries where we may store and process your information may offer different levels of protection for information than may be available in your country.

12. Changes to our Privacy Policy

We will continue to evaluate this policy against new technologies, business practices, changes in law, and our listeners' needs, and may make changes to the policy accordingly. Please check this page periodically for updates. If we make any material changes to this policy, we will post the updated terms of the policy on the Service, and provide you notice of such chances, which may include notice by email through a message sent to the email address you use to access the Service, or posting a message on the Service.

Any material changes to this policy will be effective upon the earlier of thirty (30) calendar days following our dispatch of an email notice to you or thirty (30) calendar days following our posting of notice of the changes on the Service. These changes will be effective immediately for new users of the Service. Please note that at all times you are responsible for updating your information to provide us with your most current email address. In the event that the last email address that you have provided us is not valid, or for any reason is not capable of delivering to you the notice described above, our dispatch of the email containing such notice will nonetheless constitute effective notice of the changes described in the notice. If you do not wish to permit changes in our use of your information, you must notify us prior to the effective date of the changes that you wish to deactivate your account. Continued use of the Service following notice of such changes shall indicate your acknowledgement of such changes and agreement to be bound by the terms and conditions of such changes.

13. Governance

Enforcement: Pandora will conduct compliance audits of our relevant privacy practices to verify adherence to this policy. Further, we will conduct follow up investigations to verify that attestations and assertions regarding our privacy practices are accurate. You may inquire about an inaccuracy or make a complaint about a potential violation to us via the contact information provided below. We do engage in training to support implementation and compliance of our privacy practices; any employee that we determine is in violation of this policy may be subject to disciplinary action.

Dispute Resolution: Questions or concerns regarding our use or disclosure of information may be directed to our User Support team. Pandora will investigate and attempt to resolve complaints and disputes regarding use and disclosure of information in accordance with the principles contained in this policy. For complaints that cannot be resolved between Pandora and the complainant, Pandora agrees to cooperate with the respective data protection authorities located in the applicable country (or their authorized representatives) and participate in any dispute resolution procedures established by such authorities.

TRUSTe Privacy Seal The TRUSTe certification applies to the following properties: www.pandora.com and the Pandora Radio mobile application. In order to view our relationship with TRUSTe please visit the validation page visible by clicking on the TRUSTe seal. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact TRUSTe at https://feedback-form.truste.com/watchdog/request.

TRUSTe

14. Contact Us

If you have any questions about this privacy policy, or the privacy practices of Pandora, contact us at privacy@pandora.com, or write to us at Attn: User Support, Pandora Media, LLC, 2100 Franklin St, Suite 700, Oakland, CA 94612 USA.

We may provide translations of this policy for the convenience of our listeners. This policy was written in English, and to the extent the translated version of this policy is inconsistent with the English version, the English version will control. We reserve the right to correct translation errors or other issues caused by offering translations of this policy.