Last Updated: November 6, 2024
Please read the following statement (“Privacy Statement”) to learn about our privacy practices. This Privacy Statement explains how we collect, use, and disclose data when you visit this website.
Privacy Statement Summary
This is a summary of our Privacy Statement. To review our Privacy Statement in full please click here, or scroll down.
What does this Privacy Statement cover?
This Privacy Statement is designed to describe:
- How and what type of personal data we collect and use
- When and with whom we share your personal data
- What choices you can make about how we collect, use, and share your personal data
- How you can access and update your personal data
What personal data do we collect and use, and how do we collect it?
We collect personal data when:
- You give us the information
- We collect it automatically
- We receive it from others
When you create an account on one of our sites, sign up to receive offers or information, or otherwise use our platform, you give us your personal data. We also collect such information through automated technology such as cookies placed on your browser, with your consent where applicable, when you visit our sites, or download and use our apps, if applicable. We also receive personal data from affiliated companies within Expedia Group, as well as business partners and other third-parties, which help us improve our platform and associated tools and services, update and maintain accurate records, potentially detect and investigate fraud, and more effectively market our services.
When is your personal data shared?
Your personal data may be shared with third parties for several purposes, including: to help provide you information and/or services, assist with your use of our services, communicate with you (including when we send information to you on products and services or enable you to communicate with others), and comply with the law, where applicable, depending on your interaction with the site. The full Privacy Statement below details how personal data is shared.
What are your rights and choices?
You can exercise your data protection rights in various ways. For example, you can opt out of marketing by clicking the “unsubscribe” link in the emails, in your account as applicable, or contacting our customer service. Our full Privacy Statement has more information about the options and data protection rights and choices available to you.
How to contact us
More information about our privacy practices is set out in our full Privacy Statement. You can also contact us as described below in the “Contact Us” section to ask questions about how we handle your personal data or make requests about your personal data.
Lawful bases for processing
In the tables below, you will find the lawful basis we rely on to collect and use your personal data.
In summary, whenever we collect or use your personal data, that collection or use must be based on one of the following criteria:
- Consent: This means you have given your consent for us to do so (e.g., sending you marketing communications where consent is required).
- Legal obligation: This means we have a legal obligation to collect personal data from you such as to comply with applicable laws, protect our and our users’ rights and interest, defend ourselves, and respond to law enforcement, other legal authorities, and requests that are part of a legal process.
- Performance of a contract: This means the personal data is necessary to perform a contract with you (e.g., create and/or manage your campaign(s), process payments, or create an account at your request).
- If we ask you to provide personal data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal data is mandatory or not (as well as of the possible consequences if you do not provide your personal data).
- Legitimate interest: This means the processing is in our legitimate interests and those interests are not overridden by your rights (as explained below),
- Certain countries and regions allow us to process personal data on the basis of legitimate interests. If we collect and use your personal data in reliance on our legitimate interests (or the legitimate interests of any third party), this interest will typically be to operate or improve our platform and communicate with you as necessary to provide our services to you, for security verification purposes when you contact us, to respond to your queries, to undertake marketing, or for the purpose of detecting or preventing illegal activities. Whatever our determination of our specific legitimate interest is for a given use of your personal data, when we assess its appropriateness, we will always assess it against the potential impact on your rights. While the concept of legitimate interest only exists in certain countries and regions, we balance our usage of your personal data against your rights globally.
Categories of Personal Data We Collect And Use
We collect and use personal data for the following purposes:
- Platform Usage Purposes – including to:
- Create, maintain, and update user accounts on our platform and authenticate you as a user.
- Enable and facilitate acceptance and processing of payments and other transactions.
- Help you to use our services faster and more easily through features such as the ability to sign-in using your account within the online services and sites of some of the Expedia Group brands.
- Communications and Customer Service Purposes – including to:
- Respond to your questions, requests for information, and process information choices.
- Contact you (such as by text message, email, phone calls, or messages on other communication platforms) to provide information or for other purposes as described in this Privacy Statement.
- Marketing Purposes – including to:
- Contact you (such as by text message, email, phone calls, or messages on other communication platforms) for marketing purposes.
- Analyze information such as browsing and use the result to optimize advertising and marketing in accordance with your interests and preferences.
- Market Research, Analytics, and Training Purposes to improve our Services– including to:
- Conduct surveys, market research, and data analytics.
- Maintain, improve, research, and measure the effectiveness of our sites, tools, and services.
- Monitor or record chats and other communications with our customer service team and other representatives, such as via email for quality control, training, dispute resolution, and as described in this Privacy Statement.
- Create aggregated or otherwise anonymized or deidentified data, which we may use and disclose without restriction where permissible.
- Security and Compliance Purposes – including to:
- Promote security, verify identity of our partners, prevent, and investigate fraud and unauthorized activities, defend against claims and other liabilities, and manage other risks.
- Comply with applicable laws, protect our and our users’ rights and interest, defend ourselves, and respond to law enforcement, courts, governments, public bodies, other legal authorities, and requests that are part of a legal process.
- Comply with applicable security and anti-terrorism, anti-bribery, customs and immigration, and other due diligence laws and requirements.
We may collect the following categories of personal data for the following purposes:
Personal Data Category | Purposes for collection / use | Sources of Personal Data | Lawful Basis |
---|---|---|---|
Identification data: – including name; email address; telephone number; business and billing addresses (including street and postal code) |
|
|
|
Payment data: – including payment card number; expiration date; billing address, where required |
|
|
|
Geolocation data – including inferred location from IP address |
|
|
|
Communications with us: including emails, phone calls, etc. |
|
|
|
Data you give us: about other people associated with you or your company |
|
|
|
Device data – including device type, unique device identification numbers, operating system, mobile carrier, and how your device has interacted with our online services, including the pages accessed, links clicked, and features used, along with associated dates and times |
|
|
|
Clickstream data - In certain instances, we may use clickstream data to render an illustration of your usage of our site. Clickstream data is the collection of a sequence of events that represent visitor actions on a website. We may reconstruct your site journey modeled on the timing and location of your actions. |
|
|
|
Joint Use of Personal Data
We jointly use, and our Expedia Group companies are joint controllers of your personal data in the following manner:
- We process all the categories of personal data identified in the “Categories of Personal Data We Collect and Use” section jointly for the users identified in the table above.
- The Expedia Group companies, the main brands of which are listed on expediagroup.com process this personal data jointly.
- Expedia, Inc. is the party responsible for managing your personal data. More information about how to contact us regarding this joint use can be found in the “Contact Us” section.
Our Use of Artificial Intelligence
We use artificial intelligence, machine learning, and other automated decision-making for various purposes to deliver our platform and associated services. We may use your personal data for the following purposes:
- To enhance your user experience and keep our site safe.
- To determine the sort order you see on our site,
- To screen the content you upload on our site to ensure they meet our quality or formatting requirements
- To prevent and detect a breach of our terms and conditions or other fraudulent activities to keep our site safe, Automated decisions may be made by putting your personal data into a system and the decision is calculated using automatic processes.
We will rely on our legitimate interests to keep our site safe and to enhance your user experience. We will not engage in automated decision-making that involves a decision with legal or similarly significant effects solely based on automated processing of personal data, unless:
- You explicitly consented to the processing,
- The processing is necessary for entering into a contract, or for its performance, or
- When otherwise authorized by applicable law.
You may have rights in relation to automated decision making, including:
- the ability to request a manual decision-making process instead, or
- contest a decision based solely on automated processing.
If you want to know more about your data protection rights, please see the Your Rights and Choices section below.
Sharing Of Personal Data
We share your personal data as described below and in this Privacy Statement, and as permitted by applicable law.
Recipient of Personal Data | Purpose Category |
---|---|
Expedia Group Companies. We share your personal data within Expedia Group, the main brands of which are listed on expediagroup.com. Expedia Group companies act either as joint data controllers or processors for another Expedia Group company when accessing and processing your shared personal data. |
|
Third-party service providers. We share personal data with third parties in connection with the delivery of services to you and the operation of our business. These third-party service providers are required to protect personal data we share with them and may not use any identifiable personal data other than to provide the agreed services. They are not allowed to use the personal data we share for purposes of their own direct marketing (unless you have separately permitted them to do so). |
|
Recipients in relation to our legal rights and obligations. We may disclose your personal data and associated records to enforce our policies; as necessary to satisfy our tax or other regulatory reporting requirements, including the remission of certain taxes in the course of processing payments; or where we are permitted (or believe in good faith that we are required) to do so by applicable law, such as in response to a subpoena or other legal request, in connection with actual or proposed litigation, or to protect and defend our property, people, and other rights or interests. |
|
Recipients in relations to corporate transactions. We may share your personal data in connection with a corporate transaction, such as a divestiture, merger, consolidation, assignments, or asset sale, or in the unlikely event of bankruptcy. In the case of any acquisition, we will inform the buyer it must use your personal data only for the purposes disclosed in this Privacy Statement. |
|
Your Rights and Choices
You have certain rights and choices with respect to your personal data, as described below:
- You can control our use of non-essential cookies by following the guidance in our Cookie Statement
- You can access, amend, inquire about deletion of, or update the accuracy of, your personal data at any time by contacting us
- If you no longer wish to receive marketing and promotional emails, you may unsubscribe by clicking the ‘unsubscribe’ link in the email. You can also contact us as outlined below in the Contact Us section. Please note that if you choose to unsubscribe from or opt out of marketing emails, we may still send you important transactional and account-related messages from which you will not be able to unsubscribe.
- If we are processing your personal data on the basis of consent, you may withdraw that consent at any time by contacting us. Withdrawing your consent will not affect the lawfulness of any processing that occurred before you withdrew consent, and it will not affect our processing of your personal data that is conducted in reliance on a legal basis other than consent
Certain countries and regions provide their residents with additional rights relating to personal data. These additional rights vary by country and region and may include the ability to:
- Request a copy of your personal data
- Request information about the purpose of the processing activities
- Delete your personal data
- Object to our use or disclosure of your personal data
- Restrict the processing of your personal data
- Opt-out of the sale of your personal data
- Port your personal data
- Request information about the logic involved in our automated decision-making and the result of such decisions
- Object to the use of fully automated decision making, including profiling, with significant legal effect, and request a manual decision-making process instead
- Contest a decision based solely on automated processing
For more information on what data subject rights may be available to you, please click here.
For questions about privacy, your rights and choices, and in order for you, or (where applicable) your authorized agent to make a request to amend or update your personal data, or to inquire about deletion of your personal data, please contact us via the Contact Us section below.
In addition to the above rights, you may have the right to complain to a data protection authority about our collection and use of your personal data. However, we encourage you to contact us first so we can do our best to resolve your concern. You may submit your request to us using the information in the Contact Us section below.
We respond to all requests we receive from individuals wanting to exercise their personal data protection rights in accordance with applicable data protection laws. Should you have the right under applicable law to appeal a decision we have made to not take action on your request, instructions on how to make that appeal will be included in our response to you.
International Data Transfer
The personal data that we process may be accessed from, processed or transferred to countries other than the country in which you reside. Those countries may have data protection laws that are different from the laws of your country. Such cross-border transfer of your personal data is necessary for us to service your transaction with us, and for the purposes outlined in this Privacy Statement.
The servers for our platform are located in the United States, and the Expedia Group companies and third-party service providers operate in many countries around the world. When we collect your personal data, we may process it in any of those countries. Our employees may access your personal data from various countries around the world. The transferees of your personal data may also be located in countries other than the country in which you reside.
We have taken appropriate steps and put safeguards in place to help ensure that any access, processing and/or transfer of your personal data remains protected in accordance with this Privacy Statement and in compliance with applicable data protection law. Such measures provide your personal data with a standard of protection that is at least comparable to that under the equivalent local law in your country, no matter where your data is accessed from, processed and/or transferred to. We will comply with obligations regarding personal data cross-border transfer in accordance with applicable data protection laws, regulations, and conditions set by the competent authorities. This may include fulfilling obligations such as security assessments and/or certifications and signing agreements with overseas recipients in accordance with the standard contract established by the competent authorities.
Some measures we have in place include the following:
- Adequacy decisions of the European Commission confirming an adequate level of data protection in respective non-EEA countries. Please see the latest list of such countries published by the European Commission here.
- Ensuring that the third-party partners, vendors and service providers to whom data transfers are made have appropriate mechanisms in place to protect your personal data. For instance, our agreements signed with our third-party partners, vendors and service providers incorporate strict data transfer terms (including, where applicable, the European Commission's Standard Contractual Clauses issued by the European Commission and/or United Kingdom, for transfers from the EEA/UK), and require all contracting parties to protect the personal data they process in accordance with applicable data protection law. Our agreements with our third-party partners, vendors and service providers may also include, where applicable, their certification under the EU-U.S. DPF and the UK extension to EU-U.S. DPF and/or Swiss-U.S. DPF certification (and any other country specific extension to the DPF adopted from time to time), or reliance on the service provider's Binding Corporate Rules, as defined by the European Commission. In regard to the onward principle of the DPF Frameworks, if Expedia, Inc. learns that a third-party is using or disclosing your personal data in a manner that is contrary to this Policy, we will take reasonable steps to prevent or stop such use or disclosure. Expedia, Inc. may be liable for onward transfers of personal data to third parties in violation of this Policy and the DPF Frameworks.
- Intra-group agreements in place for our group companies which incorporate strict data transfer terms (including, where applicable, in reliance on our DPF certifications (as appropriate to the transfer), with Standard Contractual Clauses issued by the European Commission and/or United Kingdom, for transfers from the EEA/UK) and require all group companies to protect the personal data they process in accordance with applicable data protection law.
- Carrying out periodic risk assessments and implement various technological and organization measures to ensure compliance with relevant laws on data transfer.
Data Privacy Framework
All wholly owned U.S. affiliates of Expedia, Inc. (part of the Expedia Group of brands) have certified to the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF and Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) (“the DPF Frameworks”) and that we adhere to the DPF Framework Principles of Notice, Choice, Accountability for Onward Transfers, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement, and Liability for personal data from the EU, Switzerland, and the United Kingdom. The Federal Trade Commission has jurisdiction over such Expedia Group U.S. affiliates’ compliance with the DPF Frameworks. In addition, Expedia Group maintains intra-group Standard Contractual Clauses where applicable to cover the transfer of EU personal data to the U.S. in the event that any of our certifications to the DPF Frameworks cease to be a valid safeguard for a relevant transfer. Our certifications can be found here. For more information about the DPF Frameworks principles, please visit: https://www.dataprivacyframework.gov.
In compliance with the DPF Frameworks, Expedia, Inc. U.S. affiliates (part of the Expedia Group of brands) commit to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs), the UK Information Commissioner’s Office (ICO), the Gibraltar Regulatory Authority (GRA) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the DPF Frameworks. Under certain circumstances, you may have the possibility to invoke binding arbitration for complaints regarding compliance with the DPF Frameworks not resolved by any of the other DPF mechanisms. Please visit this link for more information: https://www.dataprivacyframework.gov/s/article/ANNEX-I-introduction-dpf?tabset-35584=2.
Expedia, Inc. commits to resolve DPF Principles-related complaints about our collection and use of your personal data. EU and UK individuals and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the DPF Frameworks should first contact us via our Contact Us
section below.
Security
We want you to feel confident about using the Site and we are committed to protecting the information we collect. While no website can guarantee security, we do take reasonable steps to implement appropriate physical, technical and organizational measures to protect the personal data that we collect and process.
Our cybersecurity team develops and deploys technical security controls and measures to ensure responsible data collection, storage, and sharing that is proportionate to the data’s level of confidentiality or sensitivity. We take efforts to continuously implement and update security measures to protect your information from unauthorized access, loss, destruction, or alteration. We hold our data-handling partners to equally high standards.
We have established an information security protection system based on industry best practices and perform regular assessment and certifications. We have also implemented appropriate security measures throughout the entire lifecycle of data collection, storage, processing, use, transmission, and sharing, and have taken certain technical and management measures including but not limited to verification and access controls, VPN, SSL encrypted transmission, and multi factor authentication mechanisms, based on our information classification and processing standards, to ensure the security of systems and services.
We have management and approval mechanisms for employees who may have access to your information and provide regular information security training for employees.
In the event of a personal data security incident that may affect your rights and interests, you will be notified in accordance with applicable data protection laws and regulations. We will also report the relevant incident to the competent regulatory authorities, if required by applicable laws and regulations
Minors
Our website and mobile application are not directed at minors (as defined in applicable data protection laws) and we cannot distinguish the age of persons who access and use these. If a minor has provided us with personal data without parental or guardian consent, the parent or guardian should contact us (see the “Contact Us” section below). If we become aware that personal data has been collected from a minor without parental or guardian consent, we will terminate the minor’s account, where that minor has an account with us.
If you have any questions or concerns regarding our protection of minors’ personal data, or if you (in your capacity as the parent or guardian of the minor) wish to delete or correct the personal data of minors, please contact us via the information provided in our Contact Us section below.
Record Retention
We will retain your personal data in accordance with all applicable laws, for as long as it may be relevant to fulfill the purposes set forth in this Privacy Statement, unless a longer retention period is required or permitted by law. We will deidentify, aggregate, or otherwise anonymize your personal data if we intend to use it for analytical purposes or trend analysis over longer periods of time.
When we delete your personal data, we use industry standard methods to ensure that any recovery or retrieval of your information is impossible. We may keep residual copies of your personal data in backup systems to protect our systems from malicious loss. This personal data is inaccessible unless restored, and all unnecessary information will be deleted upon restoration.
The criteria we use to determine our retention periods include:
- The duration of our relationship with you or other transactions you have made on our platform
- Whether we have a legal obligation related to your personal data, such as laws requiring us to keep records of your transactions with us
- Whether there are any current and relevant legal obligations affecting how long we will keep your personal data, including contractual obligations, litigation holds, statutes of limitations, and regulatory investigations
- Whether your information is needed for secure backups of our systems
Updates to Privacy Statement
We may update this Statement in response to changing laws or technical or business developments. If we propose to make any material changes, we will notify you by means of a notice on this page. You can see when this Privacy Statement was last updated by checking the “last updated” date displayed at the top of this Statement.
Contact Us
All notices should be sent to: Expedia Group Att: Media Solutions Support Team, 1111 Expedia Group Way W., Seattle WA 98119
Questions? Visit “Help and Support” via the Ads Portal login page.