VerbatermBetaVerbaterm is in beta. You may encounter bugs, incomplete features, or unexpected results while we improve reliability.

Privacy policy

Hotels.com

Review these first

Score69.0
Reviewed
Policy typePrivacy policy
Concern findings9
Protections12
Source supportStrong

Source provenance

Verified official source
Retrieved
Last checked
PublishedAutomated refresh

What changedMaterial language shifts detected around cancel, refund, arbitration, personal data. 147 new line(s), 175 removed line(s).

Snapshot hash 050d45ec46827a15f18745880f8a244521b088415f523f3480c9ed2945f10eeb

Snapshot of the source text at fetch time, not a live mirror of the policy page.

Plain-English summary

The company engages in extensive data sharing and processing practices for diverse purposes, including marketing, advertising, loyalty programs, and security. Notably, Expedia Group companies jointly control and use personal data, and selected third-party service providers act as independent data controllers (data_use-3). Travel suppliers may directly contact users for additional personal data (data_use-4), and users are advised to review the suppliers' independent privacy policies. Personal data may be shared with business partners for marketing efforts (data_use-6), and with third-party marketing partners for targeted advertising (data_use-7). Opting out of these data disclosures may lead to a less customized user experience (data_use-8). Social media and other online platforms engaged by the company can combine and match users' personal data to build target audiences for advertisements (data_use-9). Finally, data shared via single sign-on with social media credentials is governed by the respective third-party provider's privacy policy (data_use-10), meaning users should be mindful of these separate policies.

90% confidence

Ask Verbaterm

Follow up on findings with grounded answers from this review. Not legal advice.

Risk Flags

Not clearly stated

Critical issues that users should be aware of, such as significant privacy concerns, data breaches, or limitations on user rights.

Not clearly stated

No cited risk flags — wording is unclear

The document does not contain information on risk flags such as significant privacy concerns, data breaches, or limitations on user rights.

Data Use and Sharing

9 findings

This section outlines how the company collects, uses, and shares personal data, including the types of data collected, the purposes for its use, and with whom it is shared.

medium95% confidence

Expedia Group companies jointly control and use your personal data.

Expedia Group companies jointly use and are joint controllers of your personal data for various purposes identified in the document.

Why it matters: Your personal data is shared and jointly controlled by multiple companies within the Expedia Group, potentially broadening its accessibility and usage beyond a single entity.

tegories of personal data identified in the [Categories of Personal Data and Why We Collect and Use it](https://www.hotels.com/legal/privacy#_Categories_of_Personal) section jointly for the uses identified in that table.

Joint Use of your Personal Data within the Expedia Group, paragraph 2 · Citation strength: strong

low85% confidence

Data from third-party providers may be collected.

The company may collect personal data from third parties who compile and share personal data from various sources.

Why it matters: Your personal data might be collected from third-party data providers who obtain it from multiple sources, including directly from consumers, public records, and other businesses.

We may also collect personal data from third parties who collect and compile personal data and have a lawful basis under data protection law to share it with us. These third parties’ source personal data from multiple sources, including directly from consumers, from public records, and from other businesses.

- Respond to data requests from:, paragraph 5 · Citation strength: strong

medium90% confidence

Non-affiliated third-party service providers act as independent data controllers.

Some third-party service providers process your personal data as independent controllers, not just on behalf of the company, and are responsible for their own compliance with data protection laws.

Why it matters: While third-party service providers are required to protect your personal data, some act independently, meaning they have their own data protection policies that you would need to review separately.

Although some of these third parties process your data on our behalf as our processor, others will process your personal data as a controller (either jointly with us or autonomously) rather than as our processor.

Sharing of Personal Data, paragraph 1 · Citation strength: strong

medium90% confidence

Travel suppliers may contact you for additional personal data.

Travel suppliers may contact you to obtain additional personal data if required to facilitate your booking or provide associated services.

Why it matters: Travel suppliers may directly request additional personal data from you beyond what is initially provided to the company, meaning you might need to share sensitive information with multiple entities.

Please note that travel suppliers may contact you to obtain additional personal data if and as required to facilitate your booking or to otherwise provide the travel or associated services.

Sharing of Personal Data, paragraph 2 · Citation strength: strong

medium90% confidence

Personal data may be shared with business partners for marketing.

If the company promotes a program or offer with a third-party business partner, your personal data will be shared with that partner to assist in marketing or providing the service.

Why it matters: Your personal data may be shared with business partners for marketing purposes, potentially resulting in targeted advertising or communications from those partners.

If we promote a program or offer a service or product in conjunction with a third-party business partner, we will share your personal data with that partner to assist in marketing or to provide the associated product or service.

Sharing of Personal Data, paragraph 2 · Citation strength: strong

medium90% confidence

Personal data is disclosed to third-party marketing partners for targeted advertising.

Your personal data may be disclosed to third-party marketing partners for targeted advertising, which may be considered “sharing” under California law.

Data sale or broad sharing

Why it matters: Your personal data is shared with third-party marketing partners for targeted advertising, which could lead to personalized ads based on your profile and increase the number of entities that hold your data.

We may disclose your personal data to our third-party marketing partners for targeted advertising. This may be considered to be “sharing” of data under California law.

Sharing of Personal Data, paragraph 2 · Citation strength: strong

medium85% confidence

Opting out of data sharing may limit content customization.

By opting out of certain disclosures, the company's ability to customize your experience with relevant content or provide a better travel experience may be limited.

Why it matters: Choosing to opt out of data sharing with third-party marketing partners might reduce the personalization of your experience and the relevance of content or services offered.

You should note that by opting out of these types of disclosures, you may limit our ability to customize your experience with content that may be of interest to you or to provide you with a better travel experience.

Sharing of Personal Data, paragraph 2 · Citation strength: strong

medium90% confidence

Social media and online platforms combine and match personal data for targeting.

Social media and other online platforms may use personal data they hold and combine or match it against personal data received from the company to create target audiences for online advertising.

Why it matters: Your personal data, when shared with social media and online platforms, may be combined with data they already hold about you to create target audiences, potentially exposing you to highly specific advertising.

These social media and other online platforms may also use personal data they hold and combine or match it against personal data received from us to create target audiences, which are audiences that we think would be interested in our online advertising (together with the associated product or service, where applicable).

Sharing of Personal Data, paragraph 2 · Citation strength: strong

medium90% confidence

Personal data shared via single sign-on is governed by third-party privacy policies.

When using single sign-on with social media credentials, information is shared with the third party, and the personal data shared will be governed by that third-party provider’s privacy policy.

Why it matters: When you use social media credentials for single sign-on, the third-party provider's privacy policy will govern the personal data shared, which may differ from the company's policies.

When you access certain features such as a single sign-on that allows you to login with your social media credentials to our online services, you will share information with the third party, such as the fact that you have visited or interacted with us. The third-party provider may combine this information with other information they have about you. The personal data shared will be governed by the third-party provider’s privacy policy (including any personal data we may access via the third-party provider).

Sharing of Personal Data, paragraph 2 · Citation strength: strong

Cancellation and Renewal

Not clearly stated

Details regarding subscription cancellation, auto-renewal processes, and associated terms.

Not clearly stated

No cited billing terms — wording is unclear

The document does not contain information on cancellation processes, auto-renewal terms, or related fees for subscriptions.

Gotchas

Not clearly stated

Potentially overlooked clauses that could have significant implications for users.

Not clearly stated

No cited gotchas — wording is unclear

The document does not overtly disclose any 'gotchas' or hidden clauses that might significantly impact users, such as unexpected fees, strict liability limitations, or difficult-to-find waivers of rights that are not covered in other sections.

Protections

12 findings

Key policies and features that protect user rights, privacy, and security.

Protection85% confidence

Choices available about data collection, use, and sharing.

The Privacy Statement details the choices you can make about how personal data is collected, used, and shared.

Why it helps: Users can understand and potentially control how their personal data is handled by the company.

- What choices you can make about how we collect, use, and share your personal data

This Privacy Statement is designed to describe:, paragraph 1 · Citation strength: strong

Protection85% confidence

Ability to access and update personal data.

The Privacy Statement describes how you can access and update your personal data.

Why it helps: Users are informed on how to maintain the accuracy and completeness of their personal information.

- How you can access and update your personal data.

This Privacy Statement is designed to describe:, paragraph 1 · Citation strength: strong

Protection95% confidence

Opt-out available for marketing communications.

You can opt out of marketing by clicking the “unsubscribe” link in marketing emails, in your account, or by contacting customer service.

Why it helps: Users have control over receiving unwanted marketing communications.

For example, you can opt out of marketing by clicking the “unsubscribe” link in marketing emails, in your account, or contacting our customer service.

- You give us the personal data, paragraph 6 · Citation strength: strong

Protection90% confidence

Legal obligation as a basis for data processing.

Personal data collection or use can be based on a legal obligation, meaning the company has a legal requirement to collect data for a specific purpose.

Why it helps: This ensures that certain data processing activities are legally mandated and are not solely for the company's own discretion.

- Legal obligation: this means we have a legal obligation to collect personal data from you or use it for a specific purpose (e.g. using your transaction history to complete our financial and tax obligations under the law).

Lawful bases for processing:, paragraph 3 · Citation strength: strong

Protection90% confidence

Consent as a basis for data processing.

Personal data collection or use can be based on your explicit consent.

Why it helps: Users retain control over their personal data by requiring their consent for specific processing activities, such as marketing communications.

- Consent: this means you have given your consent for us to do so (e.g., sending you marketing communications where consent is required).

Lawful bases for processing:, paragraph 3 · Citation strength: strong

Protection90% confidence

Clarification on mandatory personal data provision.

If personal data is required for a legal requirement or contract, the company will make this clear and advise on potential consequences if it's not provided.

Why it helps: Users are informed upfront about mandatory data provision and potential impacts, allowing them to make informed decisions.

- If we ask you to provide personal data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal data is mandatory or not (as well as of the possible consequences if you do not provide your personal data).

Lawful bases for processing:, paragraph 4 · Citation strength: strong

Protection85% confidence

Balancing legitimate interests against user rights globally.

When processing personal data based on legitimate interests, the company assesses the appropriateness against the potential impact on user rights, balancing usage globally.

Why it helps: This commitment indicates an effort to respect user data rights even when relying on legitimate interests for processing, providing a safeguard against potential misuse.

Whatever our determination of our specific legitimate interest is for a given use of your personal data; when we assess its appropriateness, we will always assess it against the potential impact on your rights. While the concept of legitimate interest only exists in certain countries and regions, we balance our usage of your personal data against your rights globally.

Lawful bases for processing:, paragraph 6 · Citation strength: strong

Protection90% confidence

Control over non-essential cookies.

You can control the use of non-essential cookies by following the guidance in the Cookie Statement.

Why it helps: Users can manage their privacy regarding tracking technologies beyond what is strictly necessary for service functionality.

- You can control our use of non-essential cookies by following the guidance in our [Cookie Statement](https://www.hotels.com/legal/cookies?pos=HCOM_US&locale=en_US&siteid=300000001).

Your Rights and Choices, paragraph 2 · Citation strength: strong

Protection95% confidence

Ability to amend, delete, or update personal data.

You can access, amend, inquire about deletion of, or update the accuracy of your personal data at any time.

Why it helps: Users are empowered to correct inaccuracies or request the removal of their personal data.

- You can access, amend, inquire about deletion of, or update the accuracy of, your personal data at any time by either logging into your account or contacting us via the [Contact Us](https://www.hotels.com/legal/privacy#_Contact_Us) section below.

Your Rights and Choices, paragraph 2 · Citation strength: strong

Protection95% confidence

Withdrawal of consent for data processing.

If processing is based on consent, you may withdraw that consent at any time.

Why it helps: Users maintain control over their data by being able to revoke consent for processing activities based on that consent.

- If we are processing your personal data on the basis of consent, you may withdraw that consent at any time by contacting us via the [Contact Us](https://www.hotels.com/legal/privacy#_Contact_Us) section below.

Your Rights and Choices, paragraph 2 · Citation strength: strong

Protection90% confidence

Right to complain to a data protection authority.

You may have the right to complain to a data protection authority about the company's collection and use of your personal data.

Why it helps: Provides an external recourse for users to address concerns about their data privacy.

In addition to the above rights, you may have the right to complain to a data protection authority about our collection and use of your personal data.

- Port your personal data, paragraph 4 · Citation strength: strong

Protection90% confidence

Process for appealing data request decisions.

If you have the right to appeal a decision made to not take action on your data request, instructions on how to make that appeal will be included in the response.

Why it helps: Ensures that users have a clear path to challenge decisions made regarding their data requests.

Should you have the right under applicable law to appeal a decision we have made to not take action on your request, instructions on how to make that appeal will be included in our response to you.

- Port your personal data, paragraph 5 · Citation strength: strong

Report an issue

Flag a citation problem, stale policy text, or incorrect company match.

Verbaterm boundaries

This public review is informational only and is not legal advice. Verbaterm shows only findings tied to the cited source snapshot above.