VerbatermBetaVerbaterm is in beta. You may encounter bugs, incomplete features, or unexpected results while we improve reliability.

Privacy policy

World of Hyatt

Review these first

Score76.0
Reviewed
Policy typePrivacy policy
Concern findings6
Protections3
Source supportStrong

Source provenance

Verified official source
Retrieved
Last checked
PublishedAutomated refresh

What changedMaterial language shifts detected around personal data, privacy, share your, fee. 118 new line(s), 160 removed line(s).

Snapshot hash 218d2da391a95d24a33ba746995082a8053ef7cdfd5c98aabd332ffe86b649e4

Snapshot of the source text at fetch time, not a live mirror of the policy page.

Plain-English summary

Hyatt's policy outlines several areas of concern regarding personal data handling. It states that personal information, including sensitive data and detailed billing records, can be transferred as part of business sales or acquisitions (risk_flags-0001) and, once transferred through the E-Folio Program, is no longer subject to the company's policy (risk_flags-0003). The company also disclaims responsibility for damages from security incidents (risk_flags-0004). They collect a broad range of personal information, including sensitive and biometric data, and extensive device and online activity (data_use-0002) for targeted advertising (data_use-0003). Data may be shared with other Hyatt and Apple Leisure Group entities, combined with data from other companies for marketing insights, and shared with on-property businesses. Additionally, personal information may be transferred to countries with lower data protection standards. When booking through Hyatt's services for third-party locations, those third parties' privacy policies apply, not Hyatt's.

90% confidence

Ask Verbaterm

Follow up on findings with grounded answers from this review. Not legal advice.

Risk Flags

3 findings

Clauses that indicate potential risks or significant disclaimers for the user.

high95% confidence

Business transfers may include personal information

In the event of business transfers such as selling hotels, assets, or acquisition of the company, personal information collected about you or control of it may be transferred as a business asset.

Why it matters: Your personal information may be transferred to a new entity if the company sells assets or is acquired, meaning a different company might control your data.

As we continue to develop our business, we may sell hotels and other assets, or cease being the manager or franchisor of a Hyatt Location. In those circumstances, we may include the Personal Information collected about you, or control of that Personal Information, as a business asset in any such transfer. Also, in the unlikely event that we, or substantially all of our assets, are acquired, Personal Information collected about you, or control of such information, may be one of the transferred assets.

6 Disclosures of your Personal Information, paragraph 22 · Citation strength: strong

medium90% confidence

Transferred Personal Information no longer subject to this Policy in E-Folio Program

Once Personal Information is transferred to the credit card network operator, credit card issuer, employer, or corporate client, or their subcontractors as part of the E-Folio Program, it is no longer subject to the protections of this Policy.

Why it matters: Your personal information, once transferred to other entities through the E-Folio Program, will be governed by their own arrangements and policies, not this company's Privacy Policy, which could mean less privacy protection.

Once the Personal Information is transferred to the credit card network operator, credit card issuer, your employer or corporate client and/or their respective subcontractors, it is no longer subject to the protections described in this Policy, but rather your own arrangements with your employer or corporate client, the relevant credit card network operator and/or the relevant card issuer.

6 Disclosures of your Personal Information, paragraph 30 · Citation strength: strong

medium90% confidence

No responsibility for security incidents

The company states that security measures cannot prevent all loss, misuse, or alteration of Personal Information and it is not responsible for any damages or liabilities relating to such incidents to the fullest extent permitted by law.

Why it matters: The company disclaims responsibility for damages or liabilities resulting from security incidents, such as data loss or misuse, to the maximum extent allowed by law, which may limit your recourse if your data is compromised.

Nevertheless, such security measures cannot prevent all loss, misuse or alteration of Personal Information and we are not responsible for any damages or liabilities relating to any such incidents to the fullest extent permitted by law.

8.6 Security, paragraph 2 · Citation strength: strong

Data Use and Sharing

2 findings

Clauses that describe how your data is collected, used, and shared by the company, including with third parties.

medium95% confidence

Collection of device, internet, and network activity

The company may collect IP addresses, information from devices connected to their wireless networks, Wi-Fi usage data including websites visited, and use cookies and related technologies to track interactions with their websites, applications, and online content, as well as record user sessions.

Why it matters: The company may collect extensive data about your online activities, including websites you visit, how you interact with their services, and record your sessions, which could be used for detailed profiling and targeted advertising.

rred you to our Website), and whether you click or interact with our digital content and advertising on our Websites and other sites. We may also use technologies to record user sessions on our Websites and Applications.

3 Information We May Collect, paragraph 5 · Citation strength: strong

medium95% confidence

Use of personal information for targeted advertising

The company conducts marketing and sales promotions and serves targeted advertising for products, services, events, or promotions, which may include those from the Hyatt Group and other parties, with advertisements based on information collected by them or third parties, and/or your activities on their or third-party websites.

Why it matters: Your personal information may be used to serve you targeted advertisements from the company and other parties, potentially across different websites, based on your collected data and online activities.

conduct marketing and sales promotions and serve targeted advertising for products, services, events, or promotions you might be interested in, including those provided by the Hyatt Group and by other parties. Where permitted by law, we may work with other companies to serve advertisements or marketing that we think you may find relevant and useful. This may include advertisements displayed on our own Websites or Applications, contained in emails or other communications sent by us, or advertisements from us displayed on other companies' websites.

5 How We Use Your Information, paragraph 10 · Citation strength: strong

Cancellation and Renewal

All clear

Clauses that describe conditions related to service cancellation, account termination, or subscription renewal.

Looking good

No billing surprises spotted

Verbaterm only flags concerns it can cite. No cancellation, auto-renewal, or refund terms needed attention here.

Gotchas

1 finding

Unexpected or less-obvious clauses that could be detrimental to the user.

low90% confidence

Disclaimer of responsibility for linked third-party websites

The company states that its Policy and responsibility are limited to its own information collection practices and it is not responsible for, nor can it ensure, the information collection practices or privacy policies of other websites maintained by third parties or service providers linked from its Websites, nor the content of those websites.

Why it matters: If you navigate to external websites via links on the company's site, their privacy policy and responsibility no longer apply, meaning you are subject to the data practices of those third-party sites.

This Policy, and our responsibility, is limited to our own information collection practices. We are not responsible for, and cannot always ensure, the information collection practices or privacy policies of other websites maintained by third parties or our service providers where you submit your Personal Information directly to such websites. In addition, we cannot ensure the content of the websites maintained by these third parties or our service providers, even if accessible using a link from our Websites. We urge you to read the privacy and security policies of any external websites before providing any Personal Information while accessing those websites.

8.2 Cookies and Other Tracking Technologies, paragraph 11 · Citation strength: strong

Protections

3 findings

Clauses that describe commitments or features that benefit the user.

Protection95% confidence

Right to withdraw consent for sensitive personal information processing

If the company relies on your consent to process your Sensitive Personal Information, you have the right to withdraw that consent at any time.

Why it helps: You maintain control over your most sensitive data, with the ability to revoke permission for its use at any time, enhancing your privacy and autonomy.

If we rely on consent to process your Sensitive Personal Information, you have the right to withdraw that consent at any time.

3 Information We May Collect, paragraph 13 · Citation strength: strong

Protection90% confidence

Option to browse websites without revealing identity

You can visit the company's Websites without logging in or otherwise revealing who you are.

Why it helps: You can explore the website anonymously, which protects your privacy by not requiring you to disclose personal information just to browse.

You can visit our Websites without logging in or otherwise revealing who you are.

7 International Transfers of Personal Information, paragraph 8 · Citation strength: strong

Protection95% confidence

Ability to opt-out of marketing communications

You can always choose whether or not to receive any or all marketing communications by contacting the company or following the “unsubscribe” instructions.

Why it helps: You have control over the marketing communications you receive, allowing you to reduce unwanted emails or messages.

You can always choose whether or not to receive any or all of these communications by contacting us as described in Section 14 below or following the “unsubscribe” instructions contained in the communications.

8.7 Minor Children, paragraph 8 · Citation strength: strong

Report an issue

Flag a citation problem, stale policy text, or incorrect company match.

Verbaterm boundaries

This public review is informational only and is not legal advice. Verbaterm shows only findings tied to the cited source snapshot above.