Pandora

Pandora is an American music streaming and automated music recommendation internet radio service powered by the Music Genome Project and headquartered in Oakland, California.

This page is not published. While you can access it via its direct link, it is not yet displayed on the website.

Transparency

Does the policy require users to be notified in case of a data breach? No

0/7

Decided May 18, 2020 (revision history). This question accounts for 8% of the final score.

Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.

Possible Options

No0/7
Yes, eventually5/7
Yes, within 72 hours7/7
N/A (the service collects so little personal data that notification would not be possible)7/7

Note

This policy does not require the service to alert users in the event of a breach

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Is the policy's history made available? Only the date it was last modified

3/5

Decided May 18, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

No0/5
Only the date it was last modified3/5
Yes, with revisions or a change-log5/5

Citation

Last updated: January 1, 2020

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Will affected users be notified when the policy is meaningfully changed? Yes

5/5

Decided May 18, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

No0/5
Yes5/5
N/A (no personal data—or contact information—collected)5/5

Citation

We will continue to evaluate this policy against new technologies, business practices, changes in law, and our listeners' needs, and may make changes to the policy accordingly. Please check this page periodically for updates. If we make any material changes to this policy, we will post the updated terms of the policy on the Service, and provide you notice of such changes, which may include notice by email through a message sent to the email address you use to access the Service, or posting a message on the Service. Any material changes to this policy will be effective upon the earlier of thirty (30) calendar days following our dispatch of an email notice to you or thirty (30) calendar days following our posting of notice of the changes on the Service. These changes will be effective immediately for new users of the Service. Please note that at all times you are responsible for updating your information to provide us with your most current email address. In the event that the last email address that you have provided us is not valid, or for any reason is not capable of delivering to you the notice described above, our dispatch of the email containing such notice will nonetheless constitute effective notice of the changes described in the notice. If you do not wish to permit changes in our use of your information, you must notify us prior to the effective date of the changes that you wish to deactivate your account. Continued use of the Service following notice of such changes shall indicate your acknowledgement of such changes and agreement to be bound by the terms and conditions of such changes.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the policy outline the service's general security practices? Somewhat

1/3

Decided May 18, 2020 (revision history). This question accounts for 4% of the final score.

The policy provides only a very vague overview of its security practices.

Possible Options

No0/3
Somewhat1/3
Yes2/3
Yes, including audits2.5/3
N/A (no personal data collected)3/3
Yes, including independent audits3/3

Citation

We have implemented security measures designed to protect against the loss, misuse, and alteration of the information we collect or receive from you. For example, when you enter sensitive information (such as a credit card number) on our order forms, we encrypt the transmission of that information using secure socket layer technology (SSL). However, despite our efforts, no security measures are perfect or impenetrable. If you have any questions about security on our Service, you can contact our User Support team. We use the information we collect in ways that are relevant and compatible with the purpose for which that information was collected or provided to us as disclosed in this policy. We will take steps to ensure that all information collected, processed, and/or stored is protected from destruction, corruption, or use in a manner inconsistent with our policies or the purpose for which we received it. Our Service and certain advertisements on our Service include links to other websites whose privacy practices may differ from those of Pandora. If you submit personal information to any of those websites, the privacy statements and practices of those websites govern their use of your information. We encourage you to carefully read the privacy statement of any website you visit. Some of our third-party partners may utilize framing techniques to serve content to and from webpages accessible through our Service while preserving the look and feel of our website. Please be aware that if a third-party partner utilizes framing techniques, you are providing your personal information to this third-party partner and not to Pandora.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Collection

Does the service collect personal data from third parties? Yes

0/10

Decided May 18, 2020 (revision history). This question accounts for 12% of the final score.

This includes the use of data brokers and independent verification authorities (such as background check providers).

Possible Options

Yes0/10
Only for critical data7/10
No10/10

Citation

We may receive or collect information about you from third parties, and combine and store it on our servers with other information we may have already received or collected from you. These third parties include: - Service providers that provide or make available advertising, features and functionality, and content on or through the Service. - Advertising entities such as advertisers and advertising agencies that collect and maintain information on their customers. These third parties may provide Pandora with certain information about those customers for the purposes of serving advertisements and/or marketing offers to their customers on the Pandora Service. - Marketing companies and data providers that create, maintain, and distribute professional marketing lists or segments, or maintain and distribute other marketing, or similar data. - Governmental or quasi-governmental agencies or organizations that provide or make available, to the public, census and demographic data. - Third-party social media websites, applications, or services that you use, when we allow those websites, applications, or services to interact through the Service to provide personalized services to you. In some cases, those websites, applications, or services may automatically provide us with information about you to facilitate personalization unless you use the controls available on those websites, applications, or services to opt-out of such sharing. - People who store or post information about you on the community features of the Pandora Service, or by your enabling connectivity with another website, application, or service where friends or other listeners store such information. For instance, your friends may store information about you in places such as their friend lists, address books, or photos on our Service or other websites, applications, or services such as social media applications with which the Pandora Service interacts. Pandora is not responsible for, and will assume no liability, if a business partner or other entity collects, uses, or shares any information about you in violation of its own privacy policy or any applicable laws, rules, or agreements.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Is it clear why the service collects the personal data that it does? Yes

10/10

Decided May 18, 2020 (revision history). This question accounts for 12% of the final score.

This question deals with transparency. Even if the service uses data for reasons that aren't ideal for privacy, provided they list all of those uses, the service can still receive full credit for this question. However, if they are not explicit about their uses (by employing language like "such as"), a lower score is assigned.

Possible Options

No0/10
Somewhat4/10
Mostly7/10
Yes10/10
No personal data is collected10/10

Citation

Pandora may use your Registration Data and other information or data we receive or collect, as well as data we derive or infer from combinations of the foregoing, for a variety of purposes, such as: - To facilitate the creation of and secure your account on the Pandora Service. - To provide and improve the Pandora Service, and to develop new products and services. - To customize and personalize the advertising and other content we deliver to you both on the Service and on other services offered by our publishing partners. We use this information to provide you with relevant and interesting advertising and other content. - To measure and analyze Service usage and enhance the listener experience on our Service. We use tracking information to determine how well each page and station performs overall, based on aggregate listener demographics and traffic patterns to those pages and stations. This helps us continue to build a better Service for you. - To fulfill your requests for certain products and services, such as distributing electronic newsletters and enabling you to participate in and renew paid services, surveys, and public forums. - To send you information that you requested or agreed to receive. - To alert you to the latest developments and features on our Service and to notify you of administrative information, such as security or support and maintenance advisories. - To invite you to participate in events or special promotions related to artists or products we think you may like or in which you may be interested. - To pay artists and rights owners for tracks you hear, by reporting aggregated or deidentified listening information to copyright owners and licensing agencies. - To conduct and support research and publication around the art and science of sound and music, and the connections they inspire, as well as other areas of technological advancement pertinent to our products and services.

We may send you push notifications from time to time in order to update you about events and promotions. If you no longer wish to receive these types of communications, you may turn them off at the device level in your app settings. To ensure you receive proper notifications, we will need to collect certain information about your device such as operating system and user identification information.

We do not sell or give your email address to other companies for their own marketing purposes without your permission. However, we may use your email address or other Registration Data to provide you with technical support, send you notices about the Service or other promotional offers you have elected to receive, and to serve you with ads that are more relevant to your interests. We may also work with data partners and advertising platforms to help increase the relevance of ads we provide to our listeners. In doing so, we may use information representing an encrypted or hashed value derived from information we have received, such as your email address, in connection with these partners and platforms.

We do not sell or give your Contact Information to companies for their own marketing purposes without your permission. We do use Contact Information, however, to contact you, and to provide you with special offers and other information. If you provided your Contact Information as part of your use of Pandora's Artist Marketing Platform, we may use your Contact Information to update you on new features and functionality made available as part of the Artist Marketing Platform, or the status of your content submission. You may at any time request that we cease using your Contact Information by contacting User Support.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the policy list the personal data it collects? Yes, generally

7/10

Decided May 18, 2020 (revision history). This question accounts for 12% of the final score.

All general categories of collected personal data are listed, though not all types of personal data are explicitly mentioned (for example, the list might use a phrase like 'such as' when listing types of personal data).

Possible Options

No0/10
Only summarily3/10
Yes, generally7/10
Yes, exhaustively10/10
N/A (no personal information is collected)10/10

Citation

When you register, we ask you to provide certain information, which includes your email address, birth year, gender, and zip code (the "Registration Data"), as well as a password for your account.

If you choose to subscribe to fee-based portions of the Service, purchase a subscription to the Service as a gift, or purchase add-on products or services, you will also be asked to provide (at a minimum) your name and payment information ("Payment Information").

You have the ability to provide a variety of information during your interactions with us and the Pandora Service, such as emails you may send us, ads you respond to, and emails or newsletters that you sign up to receive. Pandora or third parties acting on our behalf receive data from you whenever you provide us with information.

When you use the Service, we keep track of your listening activity, which may include the number and title of songs you have listened to, the songs that you like (thumb up) or dislike (thumb down), the stations and playlists you create or listen to, the songs you skip, and how long you listen.

ou have the ability to post comments, images, and information in community networking features available on or accessible through the Service, such as Pandora Community, your public profile, artist and album forums, our blog, and our social networking pages. You should be aware that any information you submit in the course of these community activities can be read, collected, or used by other users of these parts of the Service, as further discussed below. We are not responsible for the information you choose to make public in any of the community networking features available on or through the Service.

As is true of many internet-enabled services, Pandora may collect certain technical information through the use of log files and servers. Web and application servers create log files automatically as part of their setup and configuration. Information in a log file may include IP address, browser type, Internet service provider, date/time stamps, Media Access Control (MAC) address, file requested, and other usage information and statistics.

If you choose to participate in research studies, or sign up for certain features and/or rewards offered through the Service, you may provide us, and we may collect, your contact information, including your name, mailing address, and phone number ("Contact Information"). The email address you provided as part of your Registration Data is not considered Contact Information for the purposes of this policy.

If you access and use the Service from a computer, mobile phone, tablet, automobile, or other electronic device, we may collect information about those devices. For example, our servers receive and store information about your computer and browser, including your Internet Protocol (IP) address, browser type, and other related software or hardware information. If you access the Service from a mobile phone, tablet, automobile, or other electronic device, we may collect and store information such as device type, operating system version and type, unique identifiers (such as mobile advertising ID, VIN, and MAC address), carrier, and other related information for that device.

When you register for the Pandora Service, you provide us with your zip or postal code. We may also collect location information from devices you use while accessing the Pandora Service. Depending on the device and operating system, device-based location information may be derived from GPS and nearby wireless signals such as cell towers, Wi-Fi networks, and Bluetooth beacons. We will not collect your device-based location information unless you have permitted the Pandora app to access location services on your device. You can disable this access at any time in your system settings. Additionally, in some cases, your location within a geographic block may be approximated from the IP address currently assigned to your device.

If you grant microphone access to the Pandora app on your device, we will receive your voice data when you interact with a voice feature on our app. You can perform a search or control Pandora with your voice by tapping on the microphone icon in the search bar, or by using the wake word "Hey Pandora" if you have enabled "Listen for 'Hey Pandora'" in your app settings. Ad-supported listeners can also use their voice to interact with select audio advertisements, in which case an audible tone will sound when the microphone opens and closes, and an indicator will display on your screen. For more information about Pandora's voice features, see this FAQ.

If you choose to participate in surveys or other research, we will collect any information you choose to provide us, together with other data about your use of the Pandora Service.

Certain features of our Service require you to provide personal information about another person. By providing another person's personal information to us, you confirm that you have all necessary rights and permissions to provide such information. If you choose to provide this information, we may store and use the information for purposes of providing those features. For example, if you choose to purchase a subscription to the Service for a friend, we may ask for your friend's name and email address to provide the gift. We will only use this information for the specific reason for which it was provided or for security purposes, such as to prevent fraud. If you believe that one of your contacts has provided us with your personal information and you would like to request that it be removed from our database, please contact us at privacy @ pandora.com.

We may receive or collect information about you from third parties, and combine and store it on our servers with other information we may have already received or collected from you. These third parties include:

  • Service providers that provide or make available advertising, features and functionality, and content on or through the Service.
  • Advertising entities such as advertisers and advertising agencies that collect and maintain information on their customers. These third parties may provide Pandora with certain information about those customers for the purposes of serving advertisements and/or marketing offers to their customers on the Pandora Service.
  • Marketing companies and data providers that create, maintain, and distribute professional marketing lists or segments, or maintain and distribute other marketing, or similar data.
  • Governmental or quasi-governmental agencies or organizations that provide or make available, to the public, census and demographic data.
  • Third-party social media websites, applications, or services that you use, when we allow those websites, applications, or services to interact through the Service to provide personalized services to you. In some cases, those websites, applications, or services may automatically provide us with information about you to facilitate personalization unless you use the controls available on those websites, applications, or services to opt-out of such sharing.
  • People who store or post information about you on the community features of the Pandora Service, or by your enabling connectivity with another website, application, or service where friends or other listeners store such information. For instance, your friends may store information about you in places such as their friend lists, address books, or photos on our Service or other websites, applications, or services such as social media applications with which the Pandora Service interacts.

[...]

We may also receive information about you from our parent corporation, Sirius XM Radio Inc. ("Sirius XM") and its subsidiaries. For more information about Sirius XM, please see https://www.siriusxm.com/corporate.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow the user to control whether personal data is used or collected for non-critical purposes? On an opt-out basis, for all non-critical data/uses

3/5

Decided May 18, 2020 (revision history). This question accounts for 6% of the final score.

Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.

Possible Options

No0/5
On an opt-out basis, but only for some non-critical data/uses1.5/5
On an opt-out basis, for all non-critical data/uses3/5
N/A (no data used for non-critical purposes)5/5
On an opt-in basis5/5

Citation

In our effort to provide you with advertisements that may interest you, Pandora and third-party advertising entities use data in the manner disclosed in this policy to provide you with relevant ads. To learn about how the online advertising industry uses information it collects to provide you with relevant ads, and to control whether you want to receive those relevant ads from third-party advertisers, please review the information at the following links: Your Advertising Choices on Pandora [https://www.pandora.com/advertising/preferences/] AdChoices [http://www.youradchoices.com/] Understanding Online Advertising (About Our Ads) [https://www.aboutads.info/consumers]

[...]

As disclosed in this policy, we use third-party providers to aid us in measuring and analyzing service usage. You may opt out of web-based participation in these measurement services by following the instructions on the following web pages for each respective company: Nielsen and Scorecard Research. To opt-out of participation on mobile and tablet devices, please follow the instructions above listed in the section for Opting Out of Behavioral Advertising on Mobile and Tablet Devices.

Note

Nielsen opt-out is at https://www.nielsen.com/us/en/legal/privacy-statement/digital-measurement/#choices, with Scorecard at https://www.scorecardresearch.com/preferences.aspx?&newlanguage=1

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Handling

Does the service allow third-party access to private personal data? Yes, not all parties specified

0/10

Decided May 18, 2020 (revision history). This question accounts for 12% of the final score.

The policy allows sharing personal data with third-parties (not just critical service providers), and does not explicitly list the third-parties.

This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).

Note that whether the policy allows sharing aggregated user data does not affect this question.

If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).

If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).

Possible Options

Yes, not all parties specified0/10
Yes, all parties specified (including non-critical service providers such as advertisers)3/10
Yes, not all parties specified (but only to critical service providers)7/10
Yes, all parties specified (only to critical service providers)8/10
No10/10

Citation

We share information we collect with our parent corporation, Sirius XM and its subsidiaries for the purposes described in our respective privacy policies, and to offer, provide, and improve services and products offered both individually and jointly with other Sirius XM companies. Sirius XM's privacy policy is available at www.siriusxm.com/privacy. Additionally, we may share your personal information, with our successor in interest in the event of a corporate reorganization, merger, or sale of all or substantially all of our assets.

Pandora may share information we receive or collect in a variety of ways, such as: - When you give Pandora permission through an affirmative election (for example, clicking "yes" in response to a message such as "share my email with this advertiser"). - When you participate in community and social networking features on the Pandora Service, such as Pandora Community, forums, listener opinions and reviews, or other forms of communication and interaction which you elect to make public or share on public profiles or in other public forums. - If we contract or partner with third parties to provide specialized services on our behalf, such as credit card processors, customer support, ad servers or other providers of advertising services, platform technology providers, bulk email processors who send out emails on our behalf, or parties who assist us with sweepstakes management and prize fulfillment. These companies are authorized to use your personal information only as necessary to provide these services to Pandora. They are not authorized to use your personal information for their own, unrelated purposes. - Sharing information about the artists, tracks, stations, and playlists you have created or listened to via the Service, or that are associated with your account, if you have elected to share that information publicly. If your Pandora profile is marked as private, your stations may appear in a search, but your profile will not be linked to that station; however, if someone already knows and enters your entire email address into our search system, they will be able to see a list of all the stations created under that email address. - If you elect to take advantage of certain features or services provided jointly by Pandora and third parties, we may share certain information about you with those third parties for account authentication and management, and to enable the Service on their platforms. For example, when you elect to use products, services, features, or functionality, such as Google Now or Pandora for Business, provided by third-party partners, such as Google or Mood Media (respectively), you agree that we may provide certain data about you to those partners in order to enable the product, service, feature, or functionality you intend to use. As another example, when you share information through integrated social networking platforms, such as Facebook, you are agreeing to allow the Pandora service to communicate or "talk" with the other service in order to make the social features available for your use. These service providers may have their own data collection, use, and sharing practices that may also be applicable to your personal information, and that are not covered by this policy. You acknowledge and agree that you are solely responsible for your use of those third-party service providers and that it is your responsibility to review the terms of use and privacy policies of the third-party service providers and the methods they use for changing the privacy or sharing settings on such services. - If you have given permission to a third party for us to share data about you with them. For example, if you participate as a panelist in a survey with an analytics company, you may, as part of your agreement with that company, have authorized that company to receive data from us about you. - To measure and analyze Service usage. For example, we use third-party providers such as Nielsen and ScorecardResearch to measure how long and how frequently you are using the Service. Advertising entities may use these providers to measure the effectiveness of their advertising campaigns. When we use these providers, we provide them with information such as device identifier.

We may share your information in order to (i) protect or defend the legal rights or property of Pandora, or the legal rights of third parties, employees, agents, and contractors (including enforcement of our agreements); (ii) protect the safety and security of Pandora users or members of the public including acting in urgent circumstances; (iii) protect against fraud or to conduct risk management; or (iv) comply with the law, legal process, or legal and government requests.

Pandora may share information we gather from devices you use to access the Service with its third-party vendors or service providers, manufacturers or distributors, or advertising entities. We share this information for a variety of purposes such as mobile listening capping, advertising frequency capping, tracking advertising conversion events, estimating the number of unique users, security and fraud detection, debugging problems with the Pandora Service, and for providing you with more relevant advertisements.

Pandora may share with third parties, advertisers, and/or business partners deidentified, aggregated, or anonymized information we receive or collect, such as demographic information, location information, information about the computer or device from which you access the Service, or information about your interactions with the Service. We share such information for a variety of reasons, such as to analyze Service usage, improve the Service and your listener experience, improve the serving of advertisements, or for other similar purposes.

The Pandora Service offers publicly accessible and available profile pages, Pandora Community, community forums (such as artist, song, or advertiser pages), blogs, and pages on social media platforms. You should be aware that any information you provide or post in these areas may be read, collected, and used by others who access them. If your profile is public, any information you place in your user profile, including biographical information, the people you are following, and the people whom you allow to follow you, may be read, collected, and used by others who access them. To request removal of such information from our public forums, contact our User Support team. In some cases, we may not be able to remove your information, in which case we will let you know if we are unable to do so and why. To find out more about how to make your profile private, please see the section below on Pandora Profile Visibility.

If your personal information is transferred or shared as described in this policy, we will seek assurances from the recipients of such information (prior to the transfer) that they will safeguard the information in a manner consistent with this policy. We ask recipients of such information to enter into a contractual relationship with us that includes confidentiality and non-disclosure clauses, and provides the same level of commitment to and protections of information as provided in this policy.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


When does the policy allow law enforcement access to personal data? When reasonably requested

3/5

Decided May 18, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

Always0/5
Not specified0/5
When reasonably requested3/5
Only when required by a court order or subpoena4/5
N/A (no personal data to share)5/5
Never (special legal jurisdiction)5/5

Citation

We may share your information in order to (i) protect or defend the legal rights or property of Pandora, or the legal rights of third parties, employees, agents, and contractors (including enforcement of our agreements); (ii) protect the safety and security of Pandora users or members of the public including acting in urgent circumstances; (iii) protect against fraud or to conduct risk management; or (iv) comply with the law, legal process, or legal and government requests.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow you to permanently delete your personal data? Yes, by contacting someone

3/5

Decided May 18, 2020 (revision history). This question accounts for 6% of the final score.

Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.

Possible Options

No0/5
Yes, by contacting someone3/5
Yes, using an automated mechanism5/5
N/A (no personal information collected)5/5

Citation

If you would like to request the cancellation or deactivation of your account, you should contact our User Support team for assistance. Cancellation or deactivation of your account does not ensure complete or comprehensive removal of the content or information you may have posted or otherwise made available publicly on the Service while you were a registered user. You should also contact our User Support team to request the deactivation of a profile you believe is fake or otherwise unauthorized.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.



Warnings

Pandora has no warnings published on PrivacySpy. PrivacySpy publishes warnings when it learns a service has announced a data breach or is found misusing user data. If you believe a warning should be published for Pandora, submit one here.


Highlighted Policy Snapshot ALPHA

No highlighted policy snapshot has been created for this privacy policy. To view the policy at its original location, click here.

4.7/10

How we calculate ratings →


Version Added

May 18, 2020

Ratings Updated

May 18, 2020

Warnings

0

Maintained by

doamatto

Original Location
Open in New Tab
Other Versions