SH GROUP PRIVACY STATEMENT
OUR COMMITMENT TO PRIVACY
1. Important information and who we are
2. The Personal Data we collect about you
3. How we obtain your Personal Data and Other Data
4. How we use your Personal Data and Other Data
5. Disclosure of Personal Data and Other Data
6. How we keep your Personal Data secure
7. How long we retain your Personal Data for
8. International transfers of your Personal Data
9. Your legal rights
IMPORTANT INFORMATION AND WHO WE ARE
WHO WE ARE
Pursuant to applicable data protection laws, SH Group, 1 Hotels, Baccarat Hotels & Resorts, Treehouse Hotels, The Jeremy Hotel and Princeville Resort are each “data controllers” of your personal data (referred to as “we”, “us”, “our” or collectively, as “SH Group”). In simple terms, this means that we: (i) “control” your personal data, including making sure that it is kept secure; and (ii) make certain decisions on how to use and protect your personal data, but only to the extent that we have informed you about the use or are otherwise permitted by law.
HOW TO CONTACT US OR MAKE COMPLAINTS
GDPR Customer Service Team SH Group
200 W. 41st Street, Suite 8B
New York, NY 10036.
If your inquiry with us is not satisfactorily addressed, you may have the right to make a complaint at any time to the relevant supervisory authority in your country of residence for data protection issues. We always appreciate the chance to deal with your concerns before you approach the relevant supervisory authority, so please contact us in the first instance.
THIRD PARTY SITES AND LINKS
Our website may include links to third party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their processing of your Personal Data. When you leave our website, we encourage you to read the privacy notice of every website you visit.
THE PERSONAL DATA WE COLLECT ABOUT YOU
“Personal Data” are data that identify you as an individual or relate to an identifiable individual.SH Group, 1 Hotels, Baccarat Hotels &Resorts, Treehouse Hotels, The Jeremy Hotel and Princeville Resort collects the following types of Personal Data in both an online and offline context, when providing you with our products and services:
• Postal address
• Telephone number
• Email address
• Credit and debit card number or other payment data
• Financial Information in limited circumstances such as residential services
• Language preference
• Date and place of birth
• Nationality, passport, visa or other government-issued identification data
• Important dates, such as birthdays, anniversaries and special occasions
• Travel itinerary, tour group or activity data
• Prior guest stays, or interactions, goods and services purchased, special service and amenity requests
• Geolocation information
• Aocial media account ID, profile photo and other data publicly available
We will also collect the following types of personal data for the following purposes:
• Images and video and audio data via security cameras located in public areas, such as hallways and lobbies, in our properties
• Guest preferences and personalized data such as your interests, activities, hobbies, food and beverage choices, services and amenities of which you advise us or which we learn about during your visit.
HOW WE OBTAIN YOUR PERSONAL DATA AND OTHER DATA
Personal Data collection is obtained in a variety of ways:
• Online Services. Personal Data is collected through online services either directly or through an affiliate booking website.
• Reservation Process
• Check out process for electronic folio receipts
• Purchase goods or services through the website or ecommerce website
• Communication via email
• Connect or post to social media related to the properties
• Participate in a survey, contest or promotional offer
• Property Visits. Personal Data is collected when guests visit our properties or use on-property services and outlets.
• Concierge services
• Health clubs
• Offline Interactions. Personal Data is collected when individuals attend promotional events that we host or in which we participate, or when you provide your Personal Data to facilitate an event.
• Reservations and Customer Service Centers. Personal Data is collected when you make a reservation over the phone, communicate with us by email, fax or contact customer service.
• These communications may be recorded for purposes of quality assurance and training.
• Other Sources. Personal Data is also collected from other sources, such as public databases, joint marketing partners and other third parties.
• Internet-Connected Devices. Personal Details collected from internet-connected devices available in our properties. For example, a smart assistant device may be available for your use and to tailor your accommodations and experience.
“Other Data” are data that generally do not reveal your specific identity or do not directly relate to an individual. To the extent Other Data reveal your specific identity or relate to an individual, we will treat Other Data as Personal Data. Other Data include:
• Browser and device data
• App usage data
• Data collected through cookies, pixel tags and other technologies
• Demographic data and other data provided by you
• Aggregated data
WE COLLECT OTHER DATA IN A VARIETY OF WAYS
Your browser or device. We collect certain data through your browser or automatically through your device, such as your Media Access Control (MAC) address, computer type (Windows or Macintosh),screen resolution, operating system name and version, device manufacturer and model, language, internet browser type and version and the name and version of the Online Services (such as the Apps) you are using. We use this data to ensure that the Online Services function properly.
Cookies. We collect certain data from cookies, which are pieces of data stored directly on the computer or mobile device that you are using. Cookies allow us to collect data such as browser type, time spent on the Online Services, pages visited, referring URL, language preferences, and other aggregated traffic data. We use the data for security purposes, to facilitate navigation, to display data more effectively, to collect statistical data, to personalize your experience while using the Online Services and to recognize your computer to assist your use of the Online Services. We also gather statistical data about use of the Online Services to continually improve design and functionality, understand how they are used and assist us with resolving questions.
Pixel Tags and other similar technologies. We collect data from pixel tags (also known as web beacons and clear GIFs), which are used with some Online Services to, among other things, track the actions of users of the Online Services (including email recipients), measure the success of our marketing campaigns and compile statistics about usage of the Online Services.
Your IP Address. We collect your IP address, a number that is automatically assigned to the computer that you are using by your Internet Service Provider (ISP). An IP address is identified and logged automatically in our server log files when a user accesses the Online Services, along with the time of the visit and the pages that were visited. We use IP addresses to calculate usage levels, diagnose server problems and administer the Online Services. We also may derive your approximate location from your IP address.
Aggregated Data. We may aggregate data that we have collected, and this aggregated data will not personally identify you or any other user.
HOW WE USE YOUR PERSONAL DATA AND OTHER DATA
We use Personal Data and Other Data to provide you with Services, to develop new offerings and to protect SH Group, 1 Hotels, Baccarat Hotels & Resorts, Treehouse Hotels, The Jeremy Hotel and Princeville Resort and our guests as detailed below. In some instances, we will request that you provide Personal Data or Other Data to us directly. If you do not provide the data that we request, or prohibit us from collecting such data, we may not be able to provide the requested Services. We will let you know if this is ever the case. We use Personal Data and Other Data for the following purposes, and in accordance with the following legal bases.
Purpose/activity: To facilitate reservations, payment, send administrative information, confirmations or pre-arrival messages, to assist you with meetings and events and to provide you with other information about the area and the property at which you are scheduled to visit.
Legal basis: Contractual necessity
Purpose/activity: To support our electronic receipt program. When you provide an email address in making a reservation, we use that email address to send you a copy of your bill. If you make a reservation for another person using your email address, that person's bill will be emailed to you, as well.
Legal basis: Contractual necessity
Purpose/activity: Personalize the Services according to your Personal Preferences. We use Personal Data and Other Data to personalize the Services and improve your experiences, including when you contact our reservations center, visit one of our properties or use the Online Services, to
customize your experience according to your Personal Preferences and
present offers tailored to your Personal Preferences
Legal basis: Consent, Legitimate interests
Purpose/activity: Communicate with you about goods and services according to your Personal Preferences. We use Personal Data and Other Data to send you marketing communications and promotional offers, as well as periodic customer satisfaction, market research or quality assurance surveys
Legal basis: Consent, Legitimate interest
Purpose/activity: Sweepstakes, activities, events and promotions. We use Personal Data and Other Data to allow you to participate in sweepstakes, contests and other promotions and to administer these activities. Some of these activities have additional rules and may contain additional information about how we use and disclose your Personal Data. We suggest that you read any such rules carefully.
Legal basis: Consent
Purpose/activity: We use Personal Data and Other Data for data analysis, audits, security and fraud monitoring and prevention (including with the use of closed circuit television, card keys, and other security systems)
Legal basis: Legal obligation
Purpose/activity: We use Personal Data and Other Data for developing new goods and services, enhancing, improving or modifying our Services, identifying usage trends, determining the effectiveness of our promotional campaigns and operating and expanding our business activities.
Legal basis: Legitimate interest, Consent
Purpose/activity: We use credit card data or other payment data for invoicing purposes
Legal basis: Contractual necessity
DISCLOSURE OF PERSONAL DATA AND OTHER DATA
Our goal is to provide you with the highest level of hospitality and Services, and to do so, we share Personal Data and Other Data with the following:
Owners and Franchisees. We disclose Personal Data and Other Data to Owners of SH Group, 1 Hotels, Baccarat Hotels & Resorts, Treehouse Hotels, The Jeremy Hotel and Princeville Resort branded properties for the purposes described in this Privacy Statement, such as providing and personalizing the Services.
Strategic Business Partners. We disclose Personal Data and Other Data with select Strategic Business Partners who provide goods, services and offers that enhance your experience at our properties or that we believe will be of interest to you. By sharing data with these Strategic Business Partners, we are able to make personalized services and unique travel experiences available to you. For example, this sharing enables spa, restaurant, health club, concierge and other outlets at our properties to provide you with services. This sharing also enables us to provide you with a single source for purchasing packages that include travel-related services, such as airline tickets, rental cars and vacation packages.
Service Providers. We disclose Personal Data and Other Data to third-party service providers for the purposes described in this Privacy Statement. Examples of service providers include companies that provide website hosting, data analysis, payment processing, order fulfillment, information technology and related infrastructure provision, customer service, email delivery, marketing, auditing and other services.
Corporate Reorganization. We may disclose or transfer your Personal Data and Other Data to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transferor other disposition of all or any portion of the SH Group, 1 Hotels, Baccarat Hotels & Resorts, Treehouse Hotels, The Jeremy Hotel and Princeville Resort business, assets or stock (including any bankruptcy or similar proceedings).
OTHER USES AND DISCLOSURES
We will use and disclose Personal Data as we believe to be necessary or appropriate: (a) to comply with applicable law, including laws outside your country of residence; (b) to comply with legal process; (c) to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements; (d) to enforce our terms and conditions; (e) to protect our operations; (f) to protect the rights, privacy, safety or property of the SH Group, 1 Hotels, Baccarat Hotels & Resorts, Treehouse Hotels, The Jeremy Hotel and Princeville Resort, you or others; and (g) to allow us to pursue available remedies or limit the damages that we may sustain. We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data for so long as it is combined.
HOW WE KEEP YOUR PERSONAL DATA SECURE
We use appropriate organizational, technical and administrative measures to protect Personal Data. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of your account has been compromised), please immediately notify us in accordance with the “Contacting Us” section on the website.
HOW LONG WE RETAIN YOUR PERSONAL DATA FOR
We will only retain your Personal Data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In some circumstances we may anonymise your Personal Data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you. For further information on how long we retain your Personal Data for, please contact [email protected]
INTERNATIONAL TRANSFERS OF YOUR PERSONAL DATA
SH Group is an international organization based in the United States.
If you are staying in one of our hotels located in European Economic Area, we may transfer your personal information outside of the European Economic Area to the United States for the purpose of processing transactions and requests related to our services. In such cases, your personal data will be transferred to the United States or to other countries or jurisdictions in which we or our third-party associates may process personal data through the use of Standard Contract Clauses.
If you are browsing or otherwise accessing our websites from the European Economic Area, please be aware that any personal data you provide, and any personal information we automatically collect through your browsing, such as browser data and IP address, will be transferred to the United States. You should be aware that the laws that apply to the use and protection of personal data in the United States or other countries or jurisdictions to which we transfer, or in which we process, personal data may differ from those of your country of residence. If you access our website from jurisdictions outside of the United States, you do so at your own choice and risk and are solely responsible for compliance with local law. While we take steps to safeguard your personal data, the United States has NOT been deemed by the European Commission to ensure an adequate level of protection for personal data. Accordingly, the level of protection provided in the United States or other non-EU countries and jurisdictions from which you may access our websites may not be as stringent as that under EU data protection standards or the data protection laws of some other countries, possibly including your home jurisdiction.
YOUR LEGAL RIGHTS
To the extent your country of residence provides pursuant to applicable data protection laws, you may have certain rights with respect to your personal data, as explained below. To exercise these rights and controls, please contact us at [email protected]
Access: You have the right to ask for a copy of the Personal Data that we hold about you free of charge, however we may charge a ‘reasonable fee’ if we think that your request is excessive, to help us cover the costs of locating the information you have requested. We will respond to your request as soon as possible and (save for in certain circumstances) within one month.
Correction: If there are any inaccuracies in the information we hold about you, please contact us and we will correct them.
Deletion: If you think that we shouldn’t be holding or processing your Personal Data any more, you may request that we delete it. Please note that this may not always be possible due to legal obligations. Restrictions on use: You may request that we stop processing your Personal Data (other than storing it), if: (i) you contest the accuracy of it (unless the accuracy is verified); (ii) you believe the processing is against the law; (iii) you believe that we no longer need your Personal Data for the purposes for which it was collected, but you still need your data to establish or defend a legal claim; or (iv) you object to the processing and we are verifying whether our legitimate grounds to process your Personal Data, override your own rights.
Object: You have the right to object to processing of your Personal Data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your Personal Data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
Request the transfer: If you wish to transfer your Personal Data to another organization (and certain conditions are satisfied), you may ask us to do so, and we will send it directly if we have the technical means. Please note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
Withdrawal of consent: If you previously gave us your consent to allow us to process your Personal Data for a particular purpose, but you no longer wish to consent to us doing so, you can contact us to let us know that you withdraw that consent. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.