You are here

MemberSite_XML_Dynamic_USA_Hilton-Grand-Vacations-Global-Privacy-Notice



Hilton Grand Vacations Global Privacy Notice

OWNERS & MEMBERS PRIVACY NOTICE 

Effective Date: October 1, 2023

Hilton Grand Vacations Inc. and our HGV Family (collectively, “HGV”, “we”, “us”, or “our”) care about your privacy. This Hilton Grand Vacations Privacy Notice (“Notice”) describes how we collect, use, disclose, and otherwise process Personal Information about our Owners and program Members interacting with the HGV Site (including, but not limited, to https://www.hiltongrandvacations.com/, member.embarcresorts.com and https://theclub.hiltongrandvacations.com/), apps and associated services (the “Site”).

For more information about our privacy practices, you can find our Global Privacy Notice here.

1. INTRODUCTION & WHO WE ARE

This Notice applies to all interactions made by HGV, its subsidiaries, and all our resorts and Collections (the “HGV Family”) with Owners and Members. When we refer to Collections, we generally refer to those resorts which are part of one of our exchange programs, including Hilton Grand Vacations Club, The Hilton Club, Extraordinary Escapes and The Club, as well as those resorts otherwise carrying the Hilton Grand Vacations, Hilton Grand Vacations Club, Hilton Club, Embarc and Hilton Vacations Club branding or properties or vacation owners’ associations managed by HGV.

We have many subsidiaries, affiliates and managed resorts around the world that may act as the data controller of, or process, your Personal Information, including entities that operate outside of the jurisdiction in which it was collected or where you reside. In most cases, the HGV data controller principally responsible for the processing of your Personal Information will be:

  • In respect of your timeshare purchase from us, and unless otherwise indicated, the data controller will be the HGV entity which appears on your purchase agreement;
  • If you elect to finance your timeshare, the data controller with respect to your loan will be the named entity that appears on your relevant financing documents (e.g., your promissory note, instalment agreement, deed of trust etc.);
  • In respect of your participation in our membership programs, the data controller will depend on which membership program you have enrolled in:

    - For Hilton Grand Vacations Club or the Hilton Club, the controller will be Hilton Grand Vacations Club LLC;
    - For Diamond Resort collections and properties including the Club, the controller is Diamond Resorts International Club Inc.;
    - For Extraordinary Escapes program, the controller is Extraordinary Escapes Corporation;_ For Destinations Exchange program, the controller is Destinations Xchange, LLC; and,
    - For any other current or legacy membership program please contact us using the details in Section 12 below for details.

  • In respect of the annual maintenance of your timeshares, including the data controller responsible for collecting your annual fees, this will be either Hilton Grand Vacations Management LLC or Diamond Resorts Management LLC depending on which resort collection you are a Member of.
  • When you stay at a resort, that resort is responsible for Personal Information processed during your stay.

Diamond Resorts Corporation became a wholly owned subsidiary of HGV in 2021. The processing of your Personal Information and/or your associated rights have not changed as a consequence of the 2021 transaction and the information about our data processing activities are reflective of how your Personal information was processed by Diamond Resorts prior to the acquisition by HGV.

If you require further information on the data controller(s) for your jurisdiction, please get in touch using the details in the “Contact Us” section below.

In this Notice we refer to a number of terms as follows:

HGV Family – This means HGV, its subsidiaries, and all our resorts.

HGV Timeshare – This means an ownership interest at a resort, or collection of resorts, owned or operated by the HGV Family.

Owner – When you acquire an HGV timeshare, you become an Owner. When you become an Owner, you will become eligible for participation in one or more of our membership programs and be provided with a membership number. For certain ownership arrangements, you will be automatically enrolled in a relevant membership program, whilst for other ownership arrangements membership must be requested by you. When you are a member of one or our membership programs, you may be referred to as “Member”. References to “Owner” and “Owner Information” in this notice also apply to any membership program for which you are a member.

Personal Information – This means any information that identifies or relates to you as an individual, either on its own or in combination with other information. Personal Information does not include data that has been aggregated or made anonymous such that you can no longer be identified using means reasonably available to us.

Site – This means the HGV Site, apps and associated services we provide to Owners and Members.

2. PERSONAL INFORMATION WE COLLECT

The Personal Information we collect will depend on our relationship with you, how you purchase and/or finance your timeshare, how you engage with our membership programs and the Site, the resort(s) at which you vacation, and in some cases the jurisdiction in which you reside. Below we have set out the various types of Personal Information we may collect depending on your relationship with us.

When you buy a timeshare

Account Information – We collect your name, contact information, membership numbers and contract number for the creation of your account and in order to process your transactions.

Owner Information – In addition to Account Information, when you purchase a HGV Timeshare we collect your social security number or national identification number, information about your nationality and language preferences, and in some instances title preferences if you purchase a deeded interest. If you enroll in membership programs then, we also collect user IDs and passwords for your membership online and app accounts. We will also collect transaction and correspondence details.

Borrower Information – If you apply for financing from us, then in addition to Owner Information and Account Information we may also collect information about you and any co- borrower from your loan application including your income, your home ownership status, your work history, your previous addresses, dates of birth, and bank account information, as well as credit information and payment history.

Payment Information: when setting up your timeshare, we collect your chosen payment method, such as credit or debit card details, bank account information, or direct debit mandate which we use to collect your recurring timeshare and maintenance fees.

Credit Report Information: When you apply for a loan with us to purchase your timeshare we will collect financial information about you, including your Credit History (see the Sensitive Information section below) and will request a copy of your credit report in order to determine whether you are eligible for a particular financial product and to provide you information on products best suited to your situation. We will collect further background information about you and any co-borrower from your credit file. The exact nature of this information may differ depending on your country of residence and the type of financing you receive or apply for, and you may be presented with additional information about our use of Credit Report Information depending on your location (e.g., if you are a US resident, we will provide you with a mandatory disclosure notice under the Gramm–Leach–Bliley Act).

When you use our Site

Online Contact Information – If you submit an online request or participate in an online "click- to-chat" feature, we may ask you to provide your name, contact information and contact preferences.

Payment and Points Information – When you book a property through our Site, we collect your credit or debit card details, bank account information, used or other payment information as required. If you have used points to make your purchase, we collect information about the number of points you have used and the amount you have remaining.

Sweepstakes and Contest Information – If you enter a contest or sweepstakes (even if you do not stay at one of our resorts) we may collect your Account Information and age, if you are a winner of a contest or sweepstakes, then we may also collect your social security number or national identification number.

Forward-to-a-Friend Information and Referral Programs
– From time to time, we may offer a feature that allows you to send an electronic postcard or otherwise share a message with a friend, whether via the Internet, a stand-alone kiosk or mobile device or we may invite you to otherwise participate in a referral program. If you choose to use this feature or participate in our referral programs, we will ask you for the recipient's name and email address or other contact information, along with the text of any message you choose to include, if applicable. By using this feature or participating in such referral programs, you represent that you are entitled to use and provide us with the recipient's name and email address or contact information for this purpose and that you have provided them with the information in this Notice.

Device and Usage Information – We may collect information about your computer or device and Internet or other electronic network activity information. This includes:

  • Device identifiers, such as IP address, WIFI MAC address, and Bluetooth address;
  • Geolocation information such as your mobile device’s Global Positioning System (GPS) technology, other technology (such as wireless transmitters known as beacons) and information about your contacts, depending on your device settings (for more information, see the “Geolocation Data” section below);
  • Information about your online activity, including information collected through the use of standard Internet technologies, such as cookies, pixels, web beacons, logs, and other Internet technologies, as further set forth in our Cookie Statement, and your offline activity, including information about your visit to our resorts or properties; and
  • Through Google Analytics, information about the use of our Site such as how often you visit our Site, what pages you visit, and what other sites you used prior to visiting our Site (for more information, see the “Web Analytics” section below).

Social Plug-ins & Targeted Advertising

Our Site may also support certain third-party services, including social sharing buttons for Facebook, Twitter, Pinterest and Instagram, tweet lists (Twitter) and videos posted on the site (YouTube). These features use third-party cookies that are directly set on your device by these services.

In addition, we may also use third-party platforms, some of which are operated by social networks (in particular Facebook) to show you interest-based ads. We may convert your email address, telephone number or other information into a unique value which can be matched by those third parties with a user on their platform or with other data they may have collected from you. This matching allows interest-based ads to be delivered on those platforms. These platforms may have their own privacy notices or policies, which we strongly suggest you review.

Dynamic Pricing

We use cookies and related technology which may be used to display more personalized pricing information to you. If you consent to the use of such cookies, we may use your location information in combination with other Personal Information to display pricing personalized to you and remember this information for future visits to our Site.

When you stay at our resorts

Guest Information – When you arrive at our front desk, in addition to Account Information, we may collect Personal Information related to your reservation, stay or visit to a property, the purchase and receipt of products or services during a stay, passport number and date and place of issue if you are a Guest at one of our properties outside the United States, payment card number and other card information, and frequent flyer or travel partner program affiliation. If you have an accident on site, we will require a formal report and we will ask you to provide personal details as well as details of the accident. As an Owner we may store and retain certain Personal Information about you and associate this with your Account Information so that you do not have to provide it for future visits, but information such as payment card, health information or preferences (with the exception of where you have been assigned an ADA unit) and local passport requirements will still be collected upon each visit.

Use of Resort Services – We may collect Personal Information in connection with your use of on- property services and activities, such as concierge services, health clubs, spas, activities, childcare services, and equipment rental and your preferences whilst staying at our resorts.

Use of Virtual Concierge Services – For certain properties, we may also make available real-time or virtual “concierge” features, which may be pre-loaded onto a device owned by us, or downloadable to your web-enabled mobile device. For example, you may be able to communicate directly with the resort; order services from the resort, such as room service or valet parking; access our websites; access third-party websites, including local attractions and social media; and book a reservation. The resort will access and use your Personal Information (such as your name, confirmation number, check-in and checkout dates, and room number) in providing these concierge services. If you request or agree to receive SMS (i.e., text message) communications, you will be asked to provide your phone number and carrier. We may also communicate with you by means of third-party digital messaging apps. If we do so, the privacy policies of those services apply.

Family and Visitor Information – We may collect Personal Information about your family or visitors including names, addresses and frequent flyer numbers. If we collect this information from you, on behalf of your family and visitors, you should make sure that the person whose Personal Information you are providing knows that you have done so and that they have read this Notice.

Vehicle and Driver Information –We collect information about vehicles you may bring onto our properties including license plate information, vehicle make and model, and the age of the driver(s) of any rental car. We may use this information if you use our valet parking services.

Loyalty Program Information – We may collect information about participation in any membership or loyalty program (including third-party loyalty programs), including account numbers.

Complaints and feedback – We pride ourselves on the quality of our timeshare products, resorts and customer experiences we provide and as part of this if you provide feedback or raise a complaint, we may associate that feedback or complaint with your Personal Information in case we need to contact you further.

Sensitive Information

Through your interactions with us, both in respect of the acquisition and financing of your timeshare, as well as when you stay at any one of our resorts, we will collect certain Personal Information of a more sensitive nature. This includes Personal Information that is particularly sensitive or which may be subject to special processing conditions in your country of residence (e.g., financial information, health information or ID information).

The sensitive information which we may process about you when you visit our resorts includes:

  • Health information (including medical history, disabilities, and details of any on-site accidents) – For example, as a Guest you may volunteer information relating to any disabilities, medical conditions, allergies and intolerances, or any accessibility requirements you may have. In addition, if an accident occurs then health data will be collected through an incident form; this may include information of a hospital visit (but not doctors reports) and the form typically asks if an accident is related to a Guest’s pre-existing medical history. Photos of injuries may also be collected and in such circumstances, those photographs would constitute sensitive information. This information is transferred to the US as it may need to be reported to insurers.
  • ID information – In addition to the information outlined in Guest Information, in many locations, the passports of Guests are scanned at check-in and the scans are kept for the verification of the Guest’s identity and to comply with local laws.
  • Credit History – Where you have applied for, or are receiving, financing for your timeshare or related timeshare products and services, we will collect information about you and any co- borrower (e.g., your income, your home ownership status, your work history, your previous addresses, dates of birth, and bank account information, as well as credit information and payment history). The exact nature of this information may differ depending on your country of residence and the type of financing you receive or for which you apply. This information is combined to allow us to determine your eligibility for your requested level of finance and we treat this derived information as sensitive Personal Information.
  • Children’s data – Personal Information of children of Guests may be processed either incidentally (e.g., through the use of CCTV at our resorts or participation in on-site activities) or intentionally as part of local laws. For further information please see the “Personal Information about children” section below.

Anonymous, aggregated, and other information

We may also collect certain information about you that is not Personal Information. This may include intellectual property or other company information you share with us, in accordance with any applicable agreements between you or, if applicable, your company including, for example, trademarks, logos and other intellectual property you own.

We also might collect and/or generate anonymized and aggregated information from your use of our Site. We use anonymized and aggregated information in various ways, including to measure your interest in and use of portions or features of our Site. Anonymized or aggregated information is not Personal Information.

3. PERSONAL INFORMATION OBTAINED FROM OTHER SOURCES

We may also obtain Personal Information about you from other sources. The information you provide to third parties is subject to their privacy statements. Such third parties may include the following affiliates and vendors:

Loyalty and membership program providers: If you enroll in certain third-party loyalty or membership programs, then your Personal Information will be collected by the providers of those programs and shared with us. In particular, as part of our long-standing partnership with Hilton Worldwide, we receive data about you from your Hilton Honors membership and may link or associate this information with your HGV Account.

Travel agents: If you use a travel agent (including online travel agencies) to make a reservation for you at our properties then your Personal Information is shared with us by the travel agents.

Exchange companies: Exchange companies provide voluntary exchange opportunities for our Owners to reserve and occupy accommodations outside our portfolio of resorts and conversely provide for owners of such third-party properties to have the opportunity to stay at HGV properties. Your Personal Information is shared to facilitate exchange reservations.

Credit reporting agencies: If you apply for financing with us, we collect certain Personal Information from credit reporting agencies.

Data verification providers: We receive updates from data verification providers, such as the

U.S. Postal Service, that help us to maintain the accuracy of the Personal Information we maintain, such as your correspondence address and your Credit Reporting Information.

Event planners: If you are a participant in a group reservation, we collect Personal Information from the event planners responsible for your event.

Social media: If you choose to participate in HGV-sponsored social media activities or offerings, we may collect certain information from your social media account consistent with your settings within the social media service, such as location, check-ins, activities, interests, photos, status updates and friend list. We may also allow you to enter into contests to provide photos, such as of your stay with us, which you may share with your connections on social media for votes, shared offers or other promotions.

Telemarketing providers: We may receive your contact information from Hilton Worldwide, from our other partners or from other sources, which, where permissible, we may use for telemarketing purposes, electronic mail, text message (including SMS and MMS), push notifications, in-app messaging, and other means.

If someone makes a reservation for you: In the event that someone else makes a reservation for you at our properties, or if you are a Guest of an Owner, we will collect Personal Information about you from that person.

4. HOW WE USE YOUR PERSONAL INFORMATION

The purposes for which we use your Personal Information depend on your relationship with us. In general, we use Personal Information to:

  • process your registration and manage your account (including your payment information and preferences);
  • allow you to complete reservations, use, save and transfer points, make payments, service your requests and administer our relationship with you;
  • fulfill our agreement with you and manage your reservations and associated bookings, including communicating with you about your reservations and any associated bookings;
  • contact you for customer service purposes and to process payment transactions;
  • when you contact us or log on to your account, we will verify your identity or user credentials so that we can protect your information;
  • provide customer service to you and (unless you object) keep your payment card details tokenized on our systems to process your transactions more quickly;
  • provide you with updates and other information regarding your accounts;
  • if we helped you finance your purchase with one of our own lending companies, enable us to perform our legal and regulatory obligations as a responsible lender;
  • to broker credit to you on behalf of a third-party lender;
  • send you information about promotions, our products and services and your membership that may be of interest to you by electronic mail, text message (including SMS and MMS) and (depending on location) by phone;
  • serve to you targeted and personalized advertising about our products and services depending on your location and your privacy choices;
  • provide dynamic pricing and personalized pricing to you;
  • administer contests and sweepstakes and, if you enter, tell you whether or not you have been successful;
  • send you information about our products and services you might be interested in using the details you provided when you entered a contest or sweepstakes;
  • respond to your queries;
  • comply with our legal obligations, policies, and procedures;
  • fulfill other purposes disclosed to you at the time you provide us with your information or otherwise where we are legally permitted to do so;
  • understand your location, including based on your IP address and information you provide to third parties (see the “Mobile app and location-based data” section below for more information);
  • keep our Site safe and secure and to prevent and detect fraud and abuse; and
  • administer and manage our Site including content and layout, Site usage, troubleshooting, data analysis, testing, research, statistical and survey purposes.

5. SHARING OF PERSONAL INFORMATION

We may disclose your Personal Information to the following entities within our group and to our business partners:

HGV Family: We may share Personal Information within the HGV Family, as well as with owners and operators of resorts that we manage or are affiliated with but do not own, resorts that may individually or jointly use the Personal Information to provide you with services, personalization, and for the purposes described above. In addition, when we cease managing a resort that we do not own or end an affiliation relationship, we may provide the resort's owner or manager with certain information about past or future Guests of that resort.

Loyalty and membership program providers: If you enroll in other loyalty or membership programs, then we may share your Personal Information with the providers of those programs.

Business partners: We may partner with other companies to provide you with products, services, or offers based upon your experiences at our properties and may share your information with our business partners accordingly. For example, we may help to arrange flights, rental cars or other services from our business partners and share Personal Information with our business partners in order to provide those services. We may also share your Personal Information, such as your email address, with our corporate travel partners to help them assess compliance with travel policies or participation in special rate plans or to engage in co-branded marketing with our corporate travel partners. We may also work with third parties, such as our airline, cruise and car rental partners, to allow us and our partners to deliver advertisements to our shared customers. Our partners may be able to provide more relevant offers to you based upon anonymous information that we share about your experiences at our properties. Additionally, we may allow third-party partners to recognize you when you visit that partner’s website or app, or to recognize you as one of their customers when you visit our websites or apps so that they may provide more relevant offers to you. We may share your email address with third parties using available security measures that may match it with their own email addresses so that they can send online and email advertisements to you on our behalf. We may also share geolocation information with business partners and service providers to provide information, offers, and services that may be of interest to you.

Exchange companies: You may have a membership with a third-party organization or otherwise have rights to access the benefits and services of a third-party organization, such as Interval International, that allows you to "exchange" your timeshare interests or points for other weeks, products and services, create itineraries by selecting sites, activities, and restaurants from lists that we have personalized for you based on your preferences and third-party data. If you signed up with an exchange company, or otherwise received benefits with an exchange company, when you acquired your timeshare, we may send your Account Information to that exchange company to allow it to administer your account.

Resort services: We may share Personal Information with third-party providers of on-property services such as concierge services, childcare services, spa treatments, golf, or dining experiences.

We may also share Personal Information with the following third-party service providers, agents and subcontractors:

Homeowners’ Associations and related parties: We may share Personal Information with third parties, such as Homeowners Associations, property management providers, and trust companies, to enable them to perform their supervisory and regulatory functions with respect to the management and maintenance of your property and/or ownership interest. In respect of Homeowners’ Associations, HGV typically collects maintenance fees relating to your timeshare on behalf of the Homeowners’ Association and, consequentially, we will need to share certain information about you regarding your maintenance payments.

Finance providers and financial institutions: Where you have elected to finance the purchase of your timeshare with a third-party financial institution, we will share Personal Information relating to your timeshare and membership with that financial provider. In addition, for Owners located in Japan and other non-US regions, we may introduce you to certain third-party financial providers who allow you to make payments in local currency and, where you elect to use such a facility, we will share information relating to those payments with those providers. Those financial institutions will also process your Personal Information for their own purposes and provide a privacy notice relating to such activities.

Co-sponsors of promotions: We co-sponsor promotions, sweepstakes, prize draws, competitions or contests with other companies, and we provide prizes for sweepstakes and contests sponsored by other companies. If you enter one of these sweepstakes or contests, we may share your information with the co-sponsor or third-party sponsor.

Escrow and Title companies and related parties: As part of registering your deeded ownership, we share information with Escrow and local county recorders offices.

Credit Reference Agencies: We share information with credit reference and credit reporting agencies as part of our processing of your Credit Reporting Information. Those agencies may adjust your credit file depending on the information you provide us as part of their wide credit monitoring activities. The type and extent to which we share such information with credit reference agencies will depend on your location and, in some cases, may be further set out in a supplemental privacy notice.

Debt management and claims: As part of our collections and/or foreclosure activities we typically engage the services of third-party claims and debt management companies and may share your information with those companies associated with such activities.

Web Analytics and Other Third-Party Analytics. We use tools to collect information about the use of our Site (e.g., web analytics tools such as Google Analytics collect information such as how often users visit our Site, what pages they visit when they do so, and what other sites they used prior to visiting the Site). The providers of these tools only collect the IP address assigned to you on the date that you visit the Site, rather than your name or other identifying information. The information collected through the use of such tools is not combined with your Personal Information. We also may use other third-party analytics tools to collect similar information about the use of certain online services.

Event planners: If you visit HGV as part of a group event or meeting, information collected for meeting and event planning may be shared with the organizers of those meetings and events, and, where appropriate, Guests who organize or participate in the meeting or event.

Other: We may share Personal Information with any third-party who is restructuring, selling, franchising, licensing or acquiring some or all of our business or assets or otherwise in the event of a merger, re- organization or similar event and in order to comply with any legal or regulatory obligation or request, including by the police, tribunals, regulators, the government or related agencies.

When sending your Personal Information to third parties, we only disclose Personal Information that is necessary for them to provide their services and we have a contract in place that requires them to keep your information secure and, where they are act as our processor, not to use it other than in accordance with our specific instructions.

Third parties that are controllers of your Personal Information may disclose or transfer it to other organizations in accordance with their data protection policies. This does not affect any of your data subject rights.

6. INTERNATIONAL TRANSFERS

HGV is a global company headquartered in the US. Your information will likely be collected by an HGV controller in your country and subsequently transferred to or stored by an HGV controller, our service providers and other third parties including in other countries that may have privacy protections less stringent than in your country. In accordance with applicable law, we implement measures, such as

standard contractual clauses or declarations by regulators or governments (e.g., adequacy decisions) to ensure that any transferred Personal Information remains protected and secure.

Please contact us using the details in the “Contact Us” section of this Notice for more information about the protections that we put in place and to obtain a copy of the relevant documents.

7. RETENTION

We retain the Personal Information we receive for as long as you use our services or as necessary to fulfill the purpose(s) for which it was collected, provide our services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws.

When determining how long this retention period will last once the purpose of processing the Personal Information has been satisfied, we consider the length of time Personal Information is required to:

  • continue to develop, tailor, upgrade, and improve our Site;
  • maintain business records for analysis and/or audit purposes;
  • comply with record retention requirements under the law;
  • defend or bring any existing or potential legal claims; or
  • address any complaints regarding our

8. SECURITY AND LINKS TO OTHER SITES

The security of your Personal Information is important to us. We take reasonable steps to use appropriate technical or organizational measures to protect your Personal Information, including against unauthorized or unlawful processing and accidental loss, destruction, or damage.

By using our Site, or providing Personal Information to us, you agree that we may communicate with you regarding any security, privacy, and administrative issues relating to your use of our Site. If we learn of a security system’s breach, we may attempt to notify you by placing a notice on our Site, by post or by sending an email to you.

Our Site may contain links to third parties' websites. Please note that we are not responsible for the collection, use, maintenance, sharing, or disclosure of data and information by such third parties. If you provide information on and use third-party sites, the privacy notices and terms of service on those sites are applicable. We encourage you to read the privacy notices of websites that you visit before submitting Personal Information.

We may also partner with a limited number of Internet providers to offer Internet access to our Guests. Your use of on-property Internet service is subject to the third-party Internet provider’s terms of use and privacy notice. You can access those terms and policies using the links on the service sign-in page, or by visiting the Internet provider’s website.

9. OTHER IMPORTANT INFORMATION

CCTV and audio recordings

We may utilize CCTV at our properties as part of our legitimate business interests in protecting the safety of our Guests, Members, and our properties. Our CCTV practices are based on an assessment of the data protection interests of affected data subjects against our legitimate interests. This may entail consideration, for example, of the likelihood and impact of unlawful or impermissible conduct on our communities and expectations of privacy in particular facilities or spaces that may be subject to CCTV. Visible signage is displayed at all premises where CCTV is in use and no CCTV is deployed in an area where it would not otherwise be permissible under the relevant law. We may also use closed circuit television and other security measures at our properties that may capture or record images of Guests and visitors in public areas.

We may also collect information related to conversations, including audio recording or monitoring customer service calls and other communications such as in-app messages and SMS (i.e., text messages) and in-person, virtual or telephonic presentations.

Mobile app and location-based data

We provide mobile apps that can be downloaded to your smartphone or mobile device. These apps have a variety of functionalities that enhance the customer experience. In addition to providing services, our apps may collect Personal Information and other information that will be used in accordance with this Notice. We provide a link to this Notice to customers prior to their downloading of any of our apps.

Geolocation data

If you set your devices to allow us to access location information on your device, we may use your mobile device’s Global Positioning System (GPS) technology and other technology (such as wireless transmitters known as beacons) to provide you with information and offers based on the location of your device. Beacons allow us to collect information about your location within participating resorts by communicating with mobile devices that are in range. We may use this location information to enhance your on-property experience by delivering push notifications and other content to your mobile device, providing navigation assistance as you move around our locations, and sending you information and offers about products, services, or activities we believe may be of interest to you. To the extent any location data is combined with Personal Information, that information will be treated as Personal Information in accordance with this Notice. You may prevent or limit collection of location information by changing the settings in your device’s settings.

Card payments

To protect your privacy, please do not send payment card numbers or any other confidential Personal Information to us via email or any other unencrypted method. We will not contact you by SMS/text messaging or email to ask for your payment card details. We will only ask for payment card details by telephone when you are booking a reservation, promotional package or otherwise making a payment toward an HGV product or service you have agreed to purchase. We will not contact you to ask for your account log-in information. If you receive this type of request, you should not respond to it. We also ask that you please notify us of any such a request at Guestexperience@hgv.com.

Personal Information about children

We may process Personal Information, including sensitive information, about children under the age of 18 who stay at our properties as your family members or Guests, both incidentally (such as through the CCTV present in many of our resorts or participation in activities) but also intentionally in accordance with local laws and requirements. In particular, in our Austrian resorts it a requirement for the name and date of birth of all guests, including minors, to be recorded, whilst in many of our other European resorts the names and ages of minors will be listed on the main Guest’s booking.

Our resorts may take photographs of Guests for various purposes; where this includes photographs of children, consent of the parent/guardian will be obtained first.

As individuals must be over the age of 18 to be eligible for a timeshare, financing or to be nominated as an assignee of a timeshare, we do not knowingly process Personal Information about children in this context of our offering of timeshares.

Reviews, Surveys and Inquiries Information

If you submit an online review or inquiry or complete a survey about our collection of resorts or properties, we do not collect Personal Information or sensitive information unless you include it in the review or survey itself.

Information We Send Using Social Media and Marketing Technologies

We partner with companies such as Meta (which operates the Facebook and Instagram platforms) which will serve cookies to you when you visit our Site.

In particular Meta use this information to provide services to us and also for further processing for its own business purposes. We and Meta are joint controllers of the processing involved in collecting and sending your Personal Information to platforms such as Facebook and Instagram, including through the use of Facebook’s “Website Custom Audiences” services (which includes ‘lookalike audience’ targeting). The data from these tools allows us to target advertising to you within Meta’s social media platforms by creating audiences based on your actions on our Site. They also allow Facebook to improve and optimize the targeting and delivery of our advertising campaigns for us.

Meta may also process your Personal Information as our processors, for the purposes of matching, online targeting, measurement, reporting and analytics purposes. These services include the processing that Meta’s platforms carry out when they display our advertisements to you in your news feed at our request after matching contact details for you that we have uploaded to them.

If you are located in the EU, the Facebook company that is a joint controller of your Personal Information is Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland and further information regarding Meta’s use of your Personal Information, can found as follows:

We partner with Google who also provide tools which allow us to understand how users use our Sites and services as well as for the purposes of targeted advertising. The data from these tools allows us to target advertising to you across a range of platforms by creating audiences based on your actions on our Site. They also allow those platforms to improve and optimize the targeting and delivery of our advertising campaigns for us. The majority of this information is serviced through the use of cookies and for further information about these activities please see our Cookie Statement.

Cookies

We may collect Personal Information about your devices and their location, and your use of our Site, including through cookies, pixels, web beacons, logs, and other Internet technologies. For detailed information regarding cookies and related data processing activities please refer to our Cookie Statement. 

10. DO NOT TRACK

Some internet browsers incorporate a “Do Not Track” feature that signals to websites you visit that you do not want to have your online activity tracked. Given that there is not a uniform way that browsers communicate the “Do Not Track” signal, the Site does not currently interpret, respond to or alter its practices when it receives “Do Not Track” signals.

11. YOUR STATE PRIVACY RIGHTS AND ADDITIONAL DISCLOSURES

Depending on the state in which you reside, you may have certain privacy rights regarding your personal data. If you are a California resident, please see our “NOTICE TO CALIFORNIA RESIDENTS” section below. For other state residents, your privacy rights may include (if applicable):

  • The right to confirm whether or not we are processing your personal data and to access such personal data;
  • The right to obtain a copy of your personal data that we collected from and/or about you in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the information to another controller without hindrance, where the processing is carried out by automated means;
  • The right to delete personal data that we collected from and/or about you, subject to certain exceptions;
  • The right to correct inaccurate personal data that we maintain about you, subject to certain exceptions;
  • The right, if applicable, to opt out of the processing of your personal data for purposes of (1) targeted advertising; (2) the “sale” of your personal data (as that term is defined by applicable law); and (3) profiling in furtherance of decisions that produce legal or similarly significant effects concerning you;
  • If we are required by applicable law to obtain your consent to process sensitive personal data, the right to withdraw your consent; and
  • The right not to receive discriminatory treatment by us for the exercise of your privacy

Depending on how the applicable privacy law defines a “sale,” we may sell personal data to third parties. For instance, if you are a resident of Colorado or Connecticut, our use of cookies and tracking technologies constitutes a sale of personal data to third-party advertisers. We also use cookies and other tracking technologies to display advertisements about our products to you on nonaffiliated

websites, applications, and online services. This is “targeted advertising” under applicable privacy laws. We do not use personal data for profiling in furtherance of decisions that produce legal or similarly significant effects concerning individuals.

To exercise your rights, please submit a request here or by calling us at 1-888-905-4482. If legally required, we will comply with your request upon verification of your identity and, to the extent applicable, the identity of the individual on whose behalf you are making such request. To do so, we will ask you to verify data points based on information we have in our records. If you are submitting a request on behalf of another individual, please use the same contact methods described above. If we refuse to take action regarding your request, you may appeal our decision through our interactive webform available here or by calling us at 1-888-905-4482.

12. NOTICE TO CALIFORNIA RESIDENTS

The California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (“CCPA”), requires that we provide California residents with a privacy policy that contains a comprehensive description of our online and offline practices regarding the collection, use, disclosure, sale, sharing, and retention of personal information and of the rights of California residents regarding their personal information. This section of the Privacy Policy is intended solely for, and is applicable only to, California residents. If you are not a California resident, this section does not apply to you and you should not rely on it.

The CCPA defines “personal information” to mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular California resident or household. Personal information does not include publicly available, deidentified or aggregated information or lawfully obtained, truthful information that is a matter of public concern. For purposes of this “NOTICE TO CALIFORNIA RESIDENTS” section we will refer to this information as “Personal Information.”

This Notice does not apply to our employees. A separate privacy notice applies to our employees.

Notice at Collection of Personal Information

We currently collect and, in the 12 months prior to the Last Updated Date of this Privacy Policy, have collected the following categories of Personal Information:

  • Identifiers (name, online identifier, Internet Protocol address, email address, account name/number, Social Security number)
  • Unique personal identifiers (device identifier; cookies, beacons, pixel tags, mobile ad identifiers, or other similar technology; customer number, unique pseudonym or user alias; telephone numbers, or other forms of persistent or probabilistic identifiers that can be used to identify a particular consumer or device)
  • Personal information described in California’s Customer Records statute (California Civil Code § 1798.80(e)) (signature, telephone number, employment, bank account number, credit card number, debit card number, or any other financial information, including income information and credit history, medical information, as well as the categories listed in “Identifiers” category above)
  • Characteristics of protected classifications under California or federal law (age (40 and older), national origin, disability, marital status)
  • Commercial information (records of products or services purchased, obtained or considered; other purchasing or consuming histories or tendencies; or other commercial information, including vehicle information and home ownership information)
  • Biometric information (imagery of face)
  • Internet or other electronic network activity information (browsing history; search history; and information regarding consumer’s interaction with website, application or advertisement)
  • Geolocation data
  • Audio and visual information
  • Professional or employment-related information (including employment history)

We collect Personal Information directly from California residents and from loyalty and membership program providers, exchange companies, credit reporting agencies, data verification providers, event planners, social media networks, telemarketing providers, and third-party booking websites. We do not collect all categories of Personal Information from each source.

In addition to the purposes stated above in the section “HOW WE USE YOUR PERSONAL INFORMATION” we currently collect and have collected the above categories of Personal Information for the following business or commercial purposes:

  • Helping to ensure security and integrity to the extent the use of your Personal Information is reasonably necessary and proportionate for these purposes
  • Debugging to identify and repair errors that impair existing intended functionality
  • Performing services, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, or providing similar services
  • Undertaking internal research for technological development and demonstration
  • Undertaking activities to verify or maintain the quality or safety of a service and to improve, upgrade, or enhance the service
  • Advancing our commercial or economic interests, such as by inducing another person to buy, rent, lease, join, subscribe to, provide, or exchange products, goods, property, information, or services, or enabling or effecting, directly or indirectly, a commercial transaction

Sale, Sharing, and Disclosure of Personal Information

The CCPA defines “sale” as the transfer of Personal Information for monetary or other valuable consideration. Although we do not “sell” Personal Information as that term may be commonly interpreted, we engage in online activities that may constitute a sale or a share of Personal Information under California law. This may include showing you advertisements on other websites.

The following table identifies the categories of Personal Information that we sold or shared to third parties in the 12 months preceding the Last Updated Date of this Privacy Policy and, for each category, the categories of third parties to whom we sold or shared Personal Information:

Category of Personal Information

Categories of Recipients

Identifiers (Internet Protocol address)

Data analytics providers

Unique personal identifiers (device identifier; cookies, beacons, pixel tags, mobile ad identifiers, or other similar technology; customer number, unique pseudonym or user alias; telephone numbers, or other forms of persistent or probabilistic identifiers that can be used to identify a particular consumer or device)

Advertising networks; data analytics providers

We sold or shared Personal Information to third parties to advance our commercial and economic interests.

The following table identifies the categories of Personal Information that we disclosed for a business purpose in the 12 months preceding the Last Updated Date of this Privacy Policy and, for each category, the categories of recipients to whom we disclosed Personal Information.

Category of Personal Information

Categories of Recipients

Identifiers (name, email address, account name/number)

Resorts; loyalty and membership program providers; business partners; promotion providers; event planners; exchange companies; debt management collectors; event planners

Personal information described in California’s Customer Records statute (California Civil Code § 1798.80(e)) (telephone number)

Resorts; loyalty and membership program providers; business partners; promotion providers; event planners; debt management collectors; event planners

Commercial information (records of products or services purchased, obtained or considered; other purchasing or consuming histories or tendencies; or other commercial information)

Resorts; loyalty and membership program providers; business partners; promotion providers; event planners; exchange companies; debt management collectors

Geolocation information

Business partners

We disclosed Personal Information for the following business or commercial purposes:

  • Performing services, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information or providing similar services;
  • Undertaking activities to verify or maintain the quality or safety of a service and to improve, upgrade, or enhance the service; and
  • Advancing our commercial or economic interests, such as by inducing another person to buy, rent, lease, join, subscribe to, provide, or exchange products, goods, property, information, or services, or enabling or effecting, directly or indirectly, a commercial transaction.

We do not knowingly collect, sell, or share Personal Information of consumers under 16 years of age. We do not use Sensitive Personal Information for purposes other than those allowed by the CCPA and its regulations.

Retention

We retain your Personal Information for as long as necessary to fulfill the purposes for which we collect it, such as to provide you with the service you have requested, and for the purpose of satisfying any legal, accounting, contractual, or reporting requirements that apply to us.

Your Rights

California residents have the following rights:

  • The right to know what Personal Information we collected about you, including the categories of Personal Information, the categories of sources from which we collected Personal Information, the business or commercial purpose for collecting, selling, or sharing Personal Information (if applicable), the categories of third parties to whom we disclose Personal Information (if applicable), and the specific pieces of Personal Information we collected about you.
  • The right to request that we delete certain Personal Information we hold about
  • If we sell or share Personal Information, the right to opt out of the sale or sharing of Personal
  • The right to correct inaccurate Personal
  • If we use or disclose sensitive Personal Information for purposes other than those allowed by the CCPA and its regulations, the right to limit our use or disclosure of sensitive Personal
  • The right not to receive discriminatory treatment by us for exercising any of your privacy

How to Submit a Request to Know, Delete, and/or Correct

You may submit a request to know, delete, and/or correct here or by calling us toll free at 1-888-905- 4482.

If you are submitting a request on behalf of a California resident, please submit the request through one of the designated methods discussed above. After submitting the request, we will require additional information to verify your authority to act on behalf of the California resident.

Our Process for Verifying a Request to Know, Delete, and/or Correct

We will comply with your request upon verification of your identity and, to the extent applicable, the identity of the California resident on whose behalf you are making such request. We will verify your identity either to a “reasonable degree of certainty” or a “reasonably high degree of certainty” depending on the sensitivity of the Personal Information and the risk of harm to you by unauthorized disclosure, deletion, or correction as applicable. To do so, we will ask you to verify data points based on information we have in our records concerning you.

Right to Opt Out of Sale or Sharing of Personal Information

If you are a California resident, you have the right to direct us to stop selling or sharing your Personal Information.

You may submit a request to opt out of sales or sharing by clicking here.

Notice of Financial Incentive

From time to time, you may have the opportunity to provide Personal Information in exchange for discounts and price differences. For example, we provide discounts and price differences when you join our loyalty programs, sign up for our mailing list, or provide us with referrals. Categories of Personal Information that we may collect when you subscribe to receive discounts and price differences include your name and email address and/or the name and email address of the person you are referring.

How to Opt-In and Right to Withdraw

Signing up for discounts and price differences through our loyalty programs, newsletter, or referral program is optional. By providing your email address or name and email address and/or the name and email address of the person you are referring, you affirmatively opt in to receiving the financial incentive and to joining our loyalty program and/or mailing list. You have the right to withdraw from the financial incentive at any time. If you opt out of receiving a financial incentive, we will not reduce the value of any financial incentives you previously received from us. If you wish to withdraw from receiving the financial incentive, you may submit such a request at any time by emailing us at privacyhgv@hgvc.com.

How the Financial Incentive is Reasonably Related to the Value of Your Personal Information

The financial incentive or price difference is reasonably related to the value provided by your Personal Information. We take into consideration, without limitation, the anticipated revenue generated from such information, the anticipated expenses which we might incur in the collection, storage, and use of such information, and the anticipated expenses which we might incur related to the offer, provision, and imposition of any financial incentive or price difference. Based on this analysis, the value of your Personal Information that allows us to make these offers and financial incentives is the value of the offer itself.

Shine the Light Law

We do not disclose personal information obtained through our Site to third parties for their direct marketing purposes. Accordingly, we have no obligations under California Civil Code § 1798.83.

13. EUROPE AND THE UNITED KINGDOM

UK and EU residents

Legal bases for processing Personal Information if you reside in the UK or EU

We use Personal Information, as described above, where it is necessary to meet our contractual obligations to you, to meet our legal obligations, or to meet our legitimate interests in providing our services. Our legitimate interests may include providing you and others with a secure environment, analyzing, improving, and better tailoring our products and services, being more efficient, fulfilling any contracts you have with us and helping to prevent fraud.

We also generally rely on our legitimate interests in marketing to you, and providing promotions or administering contests and sweepstakes, where permitted by applicable law. We provide you with choices about how we use your Personal Information, in accordance with applicable law, by allowing

you to opt-out of receiving all such communications (unless they are transactional solely related to the provision of our services to you and have no marketing element) and, where required, by not sending you any such messages without your prior consent. Where applicable, we may also process Personal Information with your consent. Remember that in certain circumstances, and where permitted by applicable law, you may have the right to object to our uses of your Personal Information as further described in the “Your Rights” section of this Notice.

Your rights

If you are resident in the UK or EU, you may have the right to:

  • request confirmation of whether we store, use, or share any of your Personal Information and be informed about third parties with whom your Personal Information has been shared;
  • obtain access to or a copy of your Personal Information;
  • receive an electronic copy of the Personal Information that you have provided to us, or ask us to send that information to another company (the “right of data portability”);
  • restrict our uses of your Personal Information or, as described above, object to those uses or restrict our sharing of your Personal Information;
  • seek correction of inaccurate, partial, untrue, or incomplete Personal Information. In some cases, we may provide self-service tools that enable you to update your Personal Information;
  • request erasure, anonymization, or blocking of Personal Information we hold about you, subject to certain exceptions prescribed by law, when processing is based on your consent or when processing is unnecessary, excessive or non-compliant;
  • object to automated decision-making. We do not envisage that any decisions that have a legal or significant effect on you will be made about you using purely automated means, however, we will update this Notice and inform you if this position changes; or
  • withdraw your consent to our processing of your Personal Information, including sensitive

To exercise any other rights set out above please contact us at privacyhgv@hgvc.com.

Marketing and Opt-out

We may inform you about our products and services or invite you to events via email, online advertising, social media, telephone, text message (including SMS and MMS), push notifications, postal mail, our customer service call center, and other means (including on-property messaging, such as your in-room television).

You may opt-out of receiving marketing messages from us. If you prefer not to receive email marketing materials from us, you may opt-out at any time by using the unsubscribe function in the email you receive from us. Opt-out requests can take up to ten business days to be effective.

To opt out of marketing text messages, reply “STOP” to the message you received.

To opt out of HGV’s telephonic promotional offers, send a message to Guestexperience@hgv.com.

For more information about cookies and interest-based advertising and to learn about how to manage these technologies, please see our Cookie Statement.

Right to complain

If you would like to make a complaint or if you have any questions about how we use or keep your Personal Information, you may contact us using the details in the “Contact Us” section below. In addition, if you believe our processing of your Personal Information violates applicable law, you also may have the right to lodge a complaint with the relevant supervisory authority for your jurisdiction. However, we would ask that you contact us so that we may try to address any privacy concerns you may have.

14. CHANGES TO THIS NOTICE

Any information that is collected via the services is covered by the Notice in effect at the time such information is collected. We reserve the right to change, modify, add, or remove portions of this Notice at any time and at our sole discretion.

If we make any material changes to this Notice, we will notify you of those changes by posting them on our Site or by sending you an email or other notification, as required by applicable law, and we will update the “Last updated” date (at the top of the Notice) to indicate when those changes became effective.

We encourage you to review this Notice periodically to remain informed of how we use and protect your information, and to be aware of any Notice changes. Your continued relationship with us after the posting or notice of any amended Notice shall constitute your agreement to be bound by any such changes. Any changes to this Notice take effect immediately after being posted or otherwise provided by HGV.

15. CONTACT US

If you have any questions or comments regarding this Notice, please contact us at privacyhgv@hgvc.com or at one of the physical addresses set out in the list of global entities at the top of this Notice.

]]>


Hilton Grand Vacations Global Privacy Notice

Content Type: