ABOUT THIS POLICY
This Policy, more specifically, is intended to provide individuals with information about how we collect, use, disclose, retain, and safeguard certain types of personal information about them such as through:
- Use of our websites, including mobile websites, applications (collectively, the "Site")
- Visits to our property or attendance at one of our events
- Phone and email communications
- Social media interactions, such as through Instagram, Facebook, Twitter, Pinterest, LinkedIn, YouTube
- Viewing our online advertisements or emails
It also describes options certain individuals may have concerning their personal information. For the purpose of this Policy, an individual or consumer may include individuals such as our guests, visitors to our property or Site, and other individuals, as required under applicable law.
PERSONAL INFORMATION WE COLLECT
As described below, we may collect or have collected in the preceding 12 months the following categories of personal information. We may add to the categories of personal information we collect and the purpose(s) we use it. In those cases, we will inform and update this section of the Policy.
- Identifiers - such as real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver's license number, or other similar identifiers.
- Other elements - such as name, signature, characteristics or description, address, telephone number, education, bank account number, credit card number, passp terms ort number.
- Characteristics of protected classifications under California or federal law - such as race, religion, and age.
- Commercial information - such as products and services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. This may include information about the reason you are staying with us, a special event, date(s) of your visit, food preferences, or vehicle information. It also may include information you provide about the Hotel, staff, or other information when you agree to voluntarily participate in a survey.
- Education information - such as information that is not publicly available personally identifiable information as defined in the Family Educational Rights and Privacy Act (20 U.S.C. section 1232g, Sec. 1232g; 34 C.F.R. Part 99).
- Internet or other electronic network activity - such as browsing history, search history, a consumer's interaction with an internet website, application, or advertisement, as well as activity on Wi-Fi.
- Biometric information - such as an individual's physiological, biological, or behavioral characteristics used or is intended to be used singly or in combination with each other or with other identifying data, to establish individual identity.
- Geolocation data - such as location information while using our Site.
- Audio, electronic, visual, thermal, olfactory, or similar information - such as identifiable information obtained about you from voicemail messages, while speaking with our service representatives, including on the telephone, and captured by video cameras and other security equipment. For example, for the protection of our staff, guests, and visitors, the Hotel may use closed circuit television and other security measures that can capture or record images of staff, guests, and visitors in public and common areas throughout the property.
- Professional or employment-related information.
- Consumer profile - such as inferences drawn from any of the information identified above to create a profile about a consumer reflecting the consumer's preferences, characteristics, and behaviors.
- Sensitive information - means a consumer's social security, driver's license, state identification card, or passport number; account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; precise geolocation; racial or ethnic origin, religious or philosophical beliefs, or union membership; the contents of a consumer's mail, email, and text messages unless the business is the intended recipient of the communication; genetic data; the processing of biometric information for the purpose of uniquely identifying a consumer; personal information collected and analyzed concerning a consumer's health; and personal information collected and analyzed concerning a consumer's sex life or sexual orientation.
Personal information does not include certain categories of information, such as publicly available information from government records, and deidentified or aggregated consumer information. Additionally, personal information does not include (i) protected health information as defined under the privacy and security regulations issued under the Health Insurance Portability and Accountability Act, 45 CFR Parts 160 and 164, or (ii) medical information governed by the California Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1).
We retain your personal information for as long as necessary for the purpose that we collected it, such as to arrange for your stay, provide you information about updates, promotions, and events at the Hotel, or to manage the employment relationship, and in accordance with the Hotel's data retention schedule, unless we have or deidentified or deleted your personal information in response to a request to delete. We may retain your personal information for longer if it is necessary to comply with our legal obligations or reporting obligations, resolve disputes, collect fees, etc., or as permitted or required by applicable law. We may also retain your personal information in a deidentified or aggregated form so that it can no longer be associated with you. To determine the appropriate retention period for your personal information, we consider various factors such as the amount, nature, and sensitivity of your information; the potential risk of unauthorized access, use or disclosure; the purposes for which we process your personal information; applicable legal requirements.
PURPOSES WE COLLECT & USE PERSONAL INFORMATION
We collect and use your personal information for the following business or commercial purposes. We may change or add to the purposes we collect personal information. In that case, we will inform you and obtain your consent when required by law.
Reservation and On-property. When you inquire about our Hotel and amenities, visit the hotel, make a reservation, check-in, or stay at our Hotel, we may collect and use your name, address, contact information, your preferences, payment information, along with the details of your stay (arrival and departure day and time, vehicle information and information regarding others traveling or staying with you), where applicable. This information enables us to respond to questions you may have, arrange for your stay, and to provide the services that come with your reservation or that you request. We also use such data for marketing, service improvements, analytics, security, and service personalization.
Corporate meetings or events. In the case of a corporate meeting or event, we may collect and use the personal information obtained in connection with that meeting or event for purposes similar to those described above, subject to any specific contract obligations.
Surveys. When you participate in one of our voluntary surveys, we collect and may use that information to enhance our business functions, as well as other purposes such as analytics, marketing, and to help the Hotel serve you better.
Promotions & Sweepstakes. When you decide to enter one of our sweepstakes, contests and other promotional offerings which are completely voluntary, we may collect and use the information to run the sweepstakes, contests and other promotional offerings, as well as for other purposes, such as marketing activities.
Social Media and Other Online Platforms. When you decide to engage with the Hotel through one or more of the Hotel's social media or other accounts, we may collect and use your user generated content, such as profile pictures or posts collected from social media or other online account participation and engagement with Hotel owned accounts for reasons similar to those described above, including marketing, analytics, and improving the Hotel's services. A complete outline of the Hotel's terms and conditions for user generated content and reuse on Portola Hotel & Spa's channels including affiliated restaurants is available here.
Reviews and Comments. Should you choose to add a comment or review on our Site, the name and email address you enter with your comment will be saved to this Site's database, along with your computer's IP address and the time and date that you submitted the comment. This information is only used to identify you as a contributor to the comment section of the respective post and is not passed on to any of the third-party data processors detailed below. Only your name and email address that you supply will be shown on the public-facing website. Your comments and the associated personal data will remain on the Site until we see fit to either remove the comment or remove the blog post, subject to any applicable obligations we may have at law or in this Policy. You should avoid entering personally identifiable information to the actual comment field of any comments that you submit on the Site.
Forms and Email Newsletter Submissions. If you choose to subscribe to our email newsletter or submit a form on our Site, the email address that you submit to us will be forwarded to a third-party marketing platform service company. Your email address will remain within their database for as long as we continue to use the third-party marketing company's services for the sole purpose of email marketing, subject to any applicable obligations we may have at law or in this Policy. You may unsubscribe using the unsubscribe links contained in any email newsletters that we send you or by requesting removal via email. When requesting removal via email, please send your email to us using the email account that is subscribed to the mailing list.
Other purposes. In addition to the specific purposes above, the Hotel also may collect and use your personal information for the following purposes:
- To provide you with information, products, or services you request from us.
- To fulfill or meet the reason for which the information is provided, such as to confirm or modify your reservation with the Hotel, process a payment, or arrange for an amenity at the Hotel.
- To contact you and/or provide you with email alerts and other notices concerning our products, services, events, or news that may be of interest to you. For example, we may send you announcements, surveys, and newsletters using any communications preferences you have expressed. We may provide these communications via email, postal mail, online advertising, social media, telephone, text message (including SMS and MMS), push notifications, in-app messaging, and other means. Of course, if at any time you no longer wish to receive such communications, you have the option of unsubscribing from our mailing list for that communication.
- To engage in marketing activities, such as direct marketing activities through email. You may stop such email communications at any time by contacting us at [email protected] or by selecting "unsubscribe" in the e-mail marketing message.
- To communicate with you in social media. If you connect your social media services or other accounts to our services, we may use this information to make your experiences with us more personal or share and use it as described elsewhere in this Policy.
- To ensure your information is accurate and to personalize our communications to you. For example, we may aggregate your personal information with data from various sources for purposes of keeping information up to date.
- To carry out our obligations and enforce our rights including those arising from any reservations or contracts made by or entered into with you including for billing, payment, and collections.
- To review, improve, and monitor our website, applications, online services, and overall guest experience, including to provide customization to meet the specific needs.
- To provide customer service and engage in quality control activities concerning our products and services.
- For testing, research, analysis and product and service development. We may use data, including public feedback and surveys, to conduct research and for the development of the Site and the services, products, and information we provide.
- To respond to law enforcement requests and as required by applicable law, court order, governmental regulations, or other lawful processes.
- As described to you when collecting your personal information.
- As necessary or appropriate to protect the rights, property, security, and safety of our guests, our employees, our consumers, our information systems, and the public. This may include health and related information such as in the case of an accident or injury that occurs on our property or to comply with health authorities and best practices.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us is among the assets transferred.
SOURCES OF PERSONAL INFORMATION WE COLLECT
- You. We may collect personal information that you provide during your interactions with us, such as through our Site, by email, or when you communicate with our staff online, by phone, via email/text, or at our property. We may also collect information when you attend an event, or participate in a sweepstakes, contest, promotion, or program we sponsor. We also collect information through certain online tracking tools, such as browser cookies, flash cookies, and web beacons. We also may collect personal information from content you generate or provide to us. A complete outline of the Hotel's terms and conditions for user generated content and reuse on Portola Hotel & Spa's channels including affiliated restaurants is available here. You may authorize certain third parties, such a www.VisitCalifornia.com, to share your information with us to enable direct marketing communications to you.
- Social media and related services. We may obtain personal information from social media and similar platforms and services and users of social media and similar platforms and services you when you engage in certain activities on social media, such as visiting our Facebook or Instagram page. This Site may offer social media sharing features or other integrated tools, which let you share actions you take on this Site with other media, and vice versa. These features may collect information about your IP address and which page you are visiting on our Site, and they may set a cookie or employ other tracking technologies. The use of such features enables the sharing of information with your friends or the public, depending on the settings you establish with the third party that provides the social sharing feature. Social media sharing features and widgets are either hosted by a third party or hosted directly on our Site. Your interactions with those features are governed by the privacy policies of the companies that provide them. For more information about the purpose and scope of data collection and processing in connection with social media sharing features, please visit the privacy policies of the third parties that provide these features.
- Travel, reservation, booking services or agents, and other service providers. When in the process of making arrangements to stay with us, you might use third party travel, reservation, or booking services or agents, or other service providers, such as call centers, that provide your information to us to check for availability, pricing, as well as to make a reservation. For example, if you decide to make an online reservation at the Site, you will be linked to a reservation interface and a third-party booking engine ("Booking Engine"), currently provided by SynXis. While it may appear to be part of the Hotel's Site, the Booking Engine is in fact provided by a third party and is governed by its privacy practices.
- Credit Card Companies, Financial Institutions, and other Payment Sources. We may obtain personal information about you in the course of processing and collecting payment from you from credit card companies, banks, and other payment sources.
- Employers and Meeting Planners. You may work for, be a part of, or otherwise have a connection with an organization who is sponsoring an event at the Hotel which you are scheduled to attend. The organization or their meeting planners may provide your personal information to us for purposes of organizing and coordinating that event.
- Related Entities and Affiliates. We may collect information about you from our related parties and affiliates, including joint ventures.
- News outlets, social media, surveys, and certain third parties. In the course of performing our services or marketing activities, we or third parties on our behalf may conduct research, surveys, and other activities resulting in the collection of personal information about you.
SELLING, SHARING, & DISCLOSURES OF PERSONAL INFORMATION
We do not sell or share your personal information to third parties and we do not have actual knowledge that we have sold personal information of minors under age 16. With limited exceptions, we may use and disclose your sensitive personal information for purposes that, with limited exceptions, are necessary in order to provide products and services to you and which are reasonably expected by the average consumer.
We may, however, disclose your personal information with services providers and contractors who help us run the Hotel and provide the products and services you request and expect. For example, we may disclose your personal information to arrange for parking services, entertainment venues and events, payment processing, marketing and advertising, photography, information and communication services, billing and collection, and related services.
We may disclose personal information to protect the security, property, assets, or legal rights of the Hotel.
We may also disclose your personal information if necessary to: (1) comply with federal, state, or local laws; (2) comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities; (3) cooperate with law enforcement agencies concerning conduct or activity that we reasonably and in good faith believe may violate federal, state, or local laws; or (4) exercise or defend legal claims.
We may disclose your email address and certain system activity data to re-marketing service companies in cases where you have abandoned your cart without making a purchase. We do this as a reminder in case you wanted to complete the purchase. The re-marketing service companies will send an email invite to complete the transaction.
Lastly, we may transfer to a third-party personal information as an asset that is part of a merger, acquisition, bankruptcy, or other transaction in which the third party assumes control of all or part of our business.
During the past 12 months, we disclosed the following:
|Categories of Personal Information Disclosed||Categories of Third Parties to Whom Disclosed|
Characteristics of protected classifications under California or federal law
|Audio, electronic, visual, thermal, olfactory, or similar information|| |
|Sensitive Personal Information|| |
|Professional or employment-related information|| |
|Internet or other electronic network activity|| |
SITE VISIT TRACKERS
Like most websites, this Site uses Google Analytics (GA) to track user interaction. We use this data to determine the number of people using our Site, to better understand how they find and use our web pages and to track their journey through the Site.
Although GA records data such as your geographical location, device, internet browser and operating system, none of this information personally identifies you to us. GA also records your computer's IP address, which could be used to personally identify you, but Google does not grant us access to this.
In addition to Google Analytics, this Site may collect information (held in the public domain) attributed to the IP address of the computer or device that is being used to access it.
Do Not Track. "Do Not Track" is a privacy preference that you can set in your Internet search browser that sends a signal to a website that you do not want the website operator to track certain browsing information about you. However, because our Site is not configured to detect Do Not Track signals from a user's computer, we are unable to respond to Do Not Track requests.
THIRD PARTY DATA PROCESSORS
We use a number of third parties to process personal data on our behalf.
- Essential cookies and similar technologies. These are vital for the running of our services on our Site. Without the use of these cookies, parts of our Site would not function. For example, session cookies allows a navigation experience that is consistent and optimal to user's network speed and choice of device.
- Analytics cookies and similar technologies. These collect information about your use of our Site and enable us to improve the way it works. For example, analytics cookies show us which are the most frequently visited pages. They also help identify any difficulties you have accessing our services, so we can fix any problems. Additionally, these cookies allow us to see overall patterns of usage at an aggregated level.
EMAIL & SMS COMMUNICATIONS
We may collect your email address via cookies and pixels on the Site through the use of trusted third-party partners. These partners may combine your email information with other information they have access to such as mailing address so that we may send relevant marketing offers to you via direct mail. You may stop such email communications at any time by contacting us at [email protected] or by selecting "unsubscribe" in the e-mail marketing message.
OUR SITES & CHILDREN
We do not knowingly collect or solicit personal information from children under 13 years of age. We are concerned about the safety of children when they use the Internet and will never knowingly request personal information from anyone under the age of 13. If the parent or guardian of a child under 13 believes that the child has provided us with any personal information, the parent or guardian of that child should contact us and ask to have this personal information deleted from our files. If we otherwise obtain knowledge that we have personal information about a child under 13 in our files, we will delete that information from our existing files so that it is not in retrievable form.
While we use reasonable measures to protect our Site and your information, the Internet is never 100% secure. The measures we use are reasonable for the type of information we collect. We cannot guarantee use of our Site is 100% secure. We encourage you to use caution when using the Internet.
This Policy is governed by the laws of the State of California, without regard to its conflict of laws principles. Jurisdiction for any claims arising under or out of this Policy shall lie exclusively with the state and federal courts within California. If any provision of this Policy is found to be invalid by a court having competent jurisdiction, the invalidity of such provision shall not affect the validity of the remaining provisions of this Policy, which shall remain in full force and effect.
NOTICE TO SITE USERS LOCATED OUTSIDE THE U.S.
The Hotel operates in accordance with the laws of the U.S. When you access our Site from outside the U.S., we may transfer the personal information that we collect from you to a location outside of your jurisdiction, including the U.S. The data protection laws in these jurisdictions may not provide you with the same protections as those of your jurisdiction. By using this Site, you acknowledge that these laws may provide a different standard of protection and you consent to the transfer of your personal data to other jurisdictions, including the U.S.
If you have additional questions, you may call us at (800) 326-5215 or reach us by email at [email protected]. You can write to us at: Two Portola Plaza, Monterey, CA 93940.
CHANGES TO THIS POLICY
Effective Date: January 1, 2023
From time to time we may change our privacy policies. We will notify you of any material changes to our Policy by posting an updated copy on our Site. Please check our Site periodically for updates.
NOTICE TO CALIFORNIA RESIDENTS
Eraser Law. If you are a California resident under the age of 18, and a registered user of any Site where this Policy is posted, California law permits you to request and obtain removal of content or information you have publicly posted. You may submit your request using the contact information in this Policy. Please be aware that such a request does not ensure complete or comprehensive removal of the content or information you have posted and that there may be circumstances in which the law does not require or allow removal even if requested.
California Consumer Privacy Act. This section concerning the California Consumer Privacy Act ("CCPA Section") applies solely to individuals who are residents of the State of California ("consumers" or "you") as required under the California Consumer Privacy Act, as amended ("CCPA"). This CCPA Section describes our policies and practices regarding the collection, use, and disclosure of personal information we collect about you, including personal information we obtain when you access or use the Site, or through other channels including but not limited to visiting one of our locations, phone and email conversations, attending our events, social media interactions on our websites and other third party websites such as social media sites, viewing our emails, or through our authorized services providers.
Please read this CCPA Section carefully before using the Site or submitting information to us. By accessing or visiting the Site, you indicate your understanding that the collection, use, and sharing of your information is subject to the terms of this CCPA Section.
IF YOU DO NOT CONSENT TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR PERSONAL INFORMATION AS DESCRIBED IN THIS CCPA SECTION, PLEASE DO NOT PROVIDE US WITH SUCH INFORMATION.
Right To Know About Personal Information Collected or Disclosed. We generally describe in the Policy our current and past 12-month practices related to the categories of personal information we collect, how we collect and use the personal information, and how we disclose your personal information. In addition to what is described above, as a California resident, you also have the right to request more information regarding the following topics for the preceding 12 months, to the extent applicable:
- the categories of personal information,
- the categories of sources from which the personal information is collected,
- the business or commercial purpose for collecting, selling, or sharing personal information, if applicable,
- the categories of third parties to whom the business discloses personal information, and
- the specific pieces of personal information the business has collected about you.
Upon receipt of a verifiable consumer request (see below), and as required by the CCPA, we will provide a response to such requests. Any disclosures we provide will only cover the 12-month period preceding the receipt of your verifiable consumer request. With respect to personal information collected on and after January 1, 2022, and to the extent expressly required by applicable regulation, you may request that such disclosures cover a period beyond the 12 months referenced above, provided doing so would not require a disproportionate effort by us.
Right To Request Deletion Of Your Personal Information. You have the right to request that we delete the personal information we collected or maintained about you. Once we receive your request, we will let you know what, if any, personal information we can delete from our records, and we will direct any service providers and contractors with whom we disclosed your personal information to also delete your personal information from their records.
There may be circumstances where we cannot delete your personal information or direct service providers or contractors to delete your personal information from their records. Some of these instances include, but are not limited to, if we need to:
- Complete the transaction for which the personal information was collected, provide a good or service requested by you, or reasonably anticipated by you within the context of our ongoing business relationship with you, or otherwise perform a contract between the Hotel and you.
- Help to ensure security and integrity to the extent the use of the consumer's personal information is reasonably necessary and proportionate for those purposes.
- Debug to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code.
- Engage in public or peer-reviewed scientific, historical, or statistical research that confirms or adheres to all other applicable ethics and privacy laws, when the Hotel's deletion of the information is likely to render impossible or seriously impair the ability to complete such research, if you have provided informed consent.
- To enable solely internal uses that are reasonably aligned with your expectations based on your relationship with the Hotel and compatible with the context in which the consumer provided the information.
- Comply with a legal obligation.
Upon receipt of a verifiable consumer request (see below), and as required by the CCPA, we will provide a response to such requests.
Right to Request Correction. You have the right to request that the Hotel correct any inaccurate personal information we maintain about you, taking into account the nature of that information and purpose for processing it. Upon receipt of a verifiable consumer request (see below), and as required by the CCPA, we will provide a response to such requests.
Right to Non-Discrimination for the Exercise of Your Privacy Rights. We will not discriminate against you for exercising any of your rights under the CCPA, as described above. This includes, but is not limited to: (A) denying good or services to you; (B) charging you different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties; (C) providing a different level or quality of goods or services; or (D) suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services. It also includes an employee's, applicant's, or independent contractor's right not to be retaliated against for the exercise of their CCPA rights.
Submitting Consumer Rights Requests
How to submit. To submit a California Consumer Rights request as outlined in this CA Section, please contact the Hotel by calling us at (800) 326-5215 Monday-Friday from 6am-5pm PST, emailing us at [email protected]. We reserve the right to only respond to verifiable consumer requests to know, delete, or correct. A verifiable consumer request is one made by any individual who is:
- the consumer who is the subject of the request,
- a consumer on behalf of the consumer's minor child, or
- the authorized agent of the consumer.
What to submit. If we request, you must provide us with sufficient information to verify your identity and/or authority to act on behalf of a consumer. In general, we may ask you to provide identifying information that we already maintain about you or we may use a third-party verification service. In either event, we will try to avoid asking you for sensitive personal information to verify your identity. We may not be able to respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. However, making a verifiable consumer request does not require you to create an account with us.
Additionally, you will need to describe your request with sufficient detail to allow us to review, understand, assess, and respond. We will not use the personal information we collect from an individual to determine a verifiable request for any other purpose, except as required or permitted by law.
Our response. We reserve the right to charge a fee to process or respond to your request if it is excessive, repetitive, or manifestly unfounded. If we determine that a request warrants a fee, we will attempt to notify you as to why we made that decision and provide a cost estimate before completing your request. We will endeavor to respond to a verifiable consumer request within forty-five (45) calendar days of receipt, but we may require an extension of up to forty-five (45) additional calendar days to respond and we will notify you of the need for the extension.
Questions. If you have questions about this CA Section, please contact us as described above in the Policy.
4895-0342-7639, v. 1