We use your personal information in order to fulfil our commitment to providing an unparalleled experience in connection with all of your interactions with HRR (the “Purpose”). As part of that undertaking, we are committed to safeguarding the privacy of the personal information that we gather.
As one of our customers or someone else with whom we interact, you understand and consent that we may collect, use, and share your personal information in accordance with this Policy.
Where you provide to us personal information about another person, you should ensure that person acknowledges this Policy and, in particular, tell him/her how we may use his/her information. You should remind that person to read this Policy in advance and may also give him/her a copy of this Policy.
2. The Application of This Policy
3. Information We May Collect
We collect and process your personal information in order to provide you the best experience possible when you interact with us. The categories of personal information that we may collect include:
- Contact and Identification Information: We may collect information such as your name, contact details (e.g., phone number(s), address, or email) professional title, employer or professional affiliations, passport and visa information and information from other government IDs;
- Payment and Credit Information: We may collect credit card and other payment method details. In limited cases, we may also collect information relating to the credit of customers;
- Location Information: We may automatically collect information about your precise geolocation to the extent permitted by applicable law. We may also collect information about your general location using your IP address and your postal code;
- Demographic Information: We may collect demographic information, such as your gender, nationality, age, and date and place of birth;
- Biometric, Health-related or other Sensitive Personal Information: We may collect Sensitive Personal Information such as health-related or religion information you provide us to fulfil special requests (e.g., health or religious conditions that require specific accommodation or services), or biometric information, such as information used for facial recognition;
- Audio and Visual Information: We may record our customer service calls and security footage of our properties, which may include your voice and/or image;
- Preferences and Inferences: We may collect your preferences or make inferences about you, reflecting what we believe to be your preferences, characteristics, and predispositions, based on other personal information we have; and
There may be instances in which the personal information that you provide to us or that we collect is considered Sensitive Personal Information under the privacy laws of some territories/countries. Depending on the applicable law, “Sensitive Personal Information” can mean personal information from which we can determine or infer an individual’s racial or ethnic origin, political opinions, religious beliefs or other beliefs of a similar nature, membership in a trade union or professional, religious, philosophical, or political association, physical or mental health or condition, medical treatment, genetic data, biometric information, and information about an individual’s sexual orientation. In some very rare instances, financial records, credit card information and location data may constitute Sensitive Personal Information where you are located. If we rely on consent to process your Sensitive Personal Information, you have the right to withdraw that consent at any time. We only process Sensitive Personal Information in your jurisdiction if and to the extent permitted or required by applicable law (e.g., so that we can ensure we tailor our services to you accordingly in terms of food allergies and medical conditions, to ensure we can process card payments). We will seek to protect such information rigorously using the security standards further described below.
When you consent to this Policy you are, to the extent required and permitted under your local law, granting your express and written consent to the processing of any personal information that you provide to HRR that is considered to be Sensitive Personal Information or financial information (except, in some jurisdictions, where we will ask that you grant that consent separately). Save to the extent required by law, you are not obliged to provide HRR with any of your Sensitive Personal Information, and should you choose not to, this will not prevent you from purchasing any products or services from HRR (except in locations where credit card information may constitute Sensitive Personal Information).
4. How We Collect Your Personal Information
We collect the above-referenced categories of personal information from the following categories of sources:
- Directly from you: Much of the personal information we process is information that you or someone acting on your behalf directly provides to us. For example, you may provide us with Contact and Identification Information, Stay and Purchase Information, Payment Information, Demographic Information, and Health-related Information, when you create an account; book a reservation; complete surveys, sweepstakes, contests or promotional offers; contact customer service; use our complimentary Wi-Fi; or contact us via email, text, or chat, over the phone, in person, or through third parties.
- From other businesses or individuals: We work with business and marketing partners and social media platforms that give us personal information about you that they have collected either directly or indirectly from you. We also use features that let your friends and family give us your personal information, for example when a family member or friend checks in on your behalf. We also may receive your personal information from (i) someone acting on your behalf, such as your travel agent or your employer (where your employer books travel for you), (ii) your travel provider, such as an airline, or (iii) your third-party card or loyalty scheme provider.
- From social media: If you post to one of our pages on a social media site, we may receive Contact and Identification Information, Stay and Purchase Information, Internet and Network Activity, and any other personal information contained in your social media posts or profile.
5. How We Use Your Information
Subject to applicable laws, we may collect, use, and disclose your personal information in order to:
- provide, charge for, and manage goods and services;
- provide you with customer support and a better or more personalized level of service;
- allow us to evaluate, analyze, and improve the functionality of our Websites, Applications, or goods and services;
- fulfil contractual obligations to you;
- conduct market research, customer satisfaction and quality assurance surveys;
- conduct marketing and sales promotions and serve targeted advertising for products, services, events, or promotions you might be interested in, including those provided by the HRR Group and by other parties. Where permitted by law, we may work with other companies to serve advertisements or marketing that we think you may find relevant and useful. This may include advertisements displayed on our own Websites or Applications, contained in emails or other communications sent by us, or advertisements from us displayed on other companies’ websites. The advertisements you see may be based on information collected by us or third parties and/or may be based on your activities on our Websites, Applications or third-party websites;
- provide for the safety and security of staff, customers, visitors and others;
- prevent, detect, and investigate fraud, cyber incidents, or other illegal or harmful activity;
- communicate with you about our relationship, such as updates to this Policy or other important legal or business changes;
- administer general record keeping;
- meet legal and regulatory requirements or compliance obligations;
- test and evaluate new products and services;
- process credit applications;
- fulfil other purposes as disclosed to you in accordance with applicable law or with your consent; and
- use certain pieces of personal information to verify your identity if you make requests regarding your personal information pursuant to this Policy. The verification steps and the pieces of personal information that we request may vary depending on the sensitivity and nature of your request.
HRR uses and retains your personal information for as long as is necessary to fulfil the purpose for which it is being processed, and in line with our legal and regulatory obligations and risk management guidelines.
5.1 Basis of Processing
When we process your personal information as one of our guests or someone else with whom we do business, we process that information on the basis of one more of the following legal bases depending on the circumstances: (i) our legitimate interests (as detailed above), (ii) because of legal obligations we are subject to, (iii) because the information is required to fulfil contractual obligations either to you, to anyone involved in making your travel arrangements (e.g., travel agents, group travel organizers, or your employer) and/or to vendors (e.g., credit card companies, airline operators, and third-party loyalty, travel, or discount programs), or (iv) with your consent.
6. Disclosures of Your Personal Information
From time to time, we may disclose your personal information. We would always make that disclosure in accordance with applicable law. In some jurisdictions, data privacy laws may require us to obtain your consent before we disclose your information to third parties. When you consent to this Policy, you are, to the extent required and permitted under your local law, granting your consent to the transfer of your personal information to such third parties for the purpose and to the extent stated in this section and as described herein (except, in some jurisdictions, we will ask that you grant that consent separately).
6.1 HRR Group
We may disclose your information to other organizations within the HRR Group for the purposes described in this Policy, including for providing you with HRR Group services.
6.2 Our Agents, Service Providers, and Suppliers
We may outsource the processing of certain functions and/or information to third parties. When we do outsource the processing of your personal information to third parties or provide your personal information to third-party service providers, we oblige those third parties to protect your personal information with appropriate security measures.
6.3 Reservations and Other Requests at Third-Party Locations
Our services allow you to make requests for reservations and other items or services with third parties. Where you make such a request, we will pass information about your request that you provide to us to the third party. The information we provide to these third parties will be handled in accordance with their own privacy policies and procedures, and not HRR’s.
6.4 Consumer Insights
Where we hold personal information about you, we may disclose this personal information to other companies that may also hold information about you. These companies may combine the information in order to better understand your preferences and interests, thereby enabling them and us to serve you better. If your personal information is used for direct marketing purposes, you have the right to object to that by contacting us using the contact information provided herein.
6.5 On-Property Companies
We may share your personal information with companies and other organizations that own and manage the hotel, spas, restaurants, health clubs, and other outlets in Hana so they can provide you with their services in relation to your stay or visit to such outlet.
6.6 Credit Authorization
When you request credit, your personal information will be used and disclosed to appropriate third parties in accordance with applicable laws for the purpose of determining whether to grant and maintain a line of credit to you.
6.7 Business Transfers
As we continue to develop our business, we may cease being the manager of HRR. In those circumstances, we may include the personal information collected about you, or control of that personal information, as a business asset in any such transfer. Also, in the unlikely event that we, or substantially all of our assets, are acquired, personal information collected about you, or control of such information, may be one of the transferred assets.
Similarly, we may disclose your personal information to a third party whom we acquire in order to facilitate mergers and acquisitions of our business and for the furtherance of the purposes herein.
6.8 Legal Requirements
Subject to applicable laws, we reserve the right to disclose any personal information we have concerning you if we are compelled to do so by a court of law or lawfully requested to do so by a governmental entity or if we determine it is necessary or desirable to comply with the law or to protect or defend our rights or property in accordance with applicable laws. We also reserve the right to retain personal information collected and to process such personal information to comply with accounting and tax rules and regulations and any specific record retention laws.
7. International Transfers of Personal Information
Some of the third-party suppliers to which we transfer your personal information may be based in different locations, some of which may have lower standards of data protection than in your home country/territory. When we do transfer personal information to such third parties, we ensure appropriate safeguards (such as entering into data transfer agreements based on clauses approved by major regulators – such as standard contractual clauses) are in place, and oblige those third parties to protect your personal information with appropriate security measures.
In some jurisdictions, data privacy laws may require us to obtain your consent before we transfer your information from your originating country/territory to other countries/territories. When you consent to this Policy, you are, to the extent required and permitted under your local law, granting your consent to the transfer of your personal information to such other countries/territories for the purpose set forth herein.
8. Interacting With Us Online
If you interact with us online, you may wish to know the following:
8.1 You Can Browse Without Revealing Who You Are
You can visit our Websites without logging in or otherwise revealing who you are.
8.2 Cookies and Other Tracking Technologies
Our Applications may contain software development kits (SDKs) provided by other parties which may collect and transmit information, including for purposes of enabling features in the Applications. We may also collect device advertising identifiers. You can configure your mobile device privacy or advertising settings via your iOS or Android device to limit how apps track certain activity for advertising purposes. Choices you make are device specific.
8.3 Social Media
Our websites may also contain plug-ins and other features that integrate third-party social media platforms into our Websites. You will be able to activate them manually. If you do so, the third parties who operate these platforms may be able to identify you, they may be able to determine how you use this Website and they may link and store this information with your social media profile. Please consult the data protection policies of these social media platforms to understand what they will be doing with your personal data. If you activate these plug-ins and other features, you will be doing so at your own risk.
8.4 Creating a User Profile
You may be able to create a user profile on our Website to, among other things, facilitate your online transactions, and to tailor your experience on our Websites to your interests. This allows us to make more appropriate recommendations to you. We may use the information you provide in your user profile to populate other databases maintained by us and our service providers, as applicable and to the extent permitted by law. By creating a user profile, you are consenting that we may use the personal information you provide for these purposes.
You can view, update or remove any personal information that you have provided to us for inclusion in your user profile by amending your user profile online. If you subsequently elect to remove your user profile (or any personal information in your profile), we reserve the right to use any personal information previously provided by you for inclusion in your user profile for record keeping and quality assurance purposes (unless we are required by law to delete or cease to process or use your personal information). Even if you choose not to create a user profile, you can still use our Websites to search for and purchase services.
8.5 Links to Other Websites
If you visit our Website, you may be seamlessly linked to websites maintained by third parties with whom we have contracted to provide those services. If you click on a link found on our Websites or on any other website, you should always look at the location bar within your browser to determine whether you have been linked to a different website. This Policy, and our responsibility, is limited to our own information collection practices. We are not responsible for, and cannot always ensure, the information collection practices or privacy policies of other websites maintained by third parties or our service providers where you submit your personal information directly to such websites. In addition, we cannot ensure the content of the websites maintained by these third parties or our service providers, even if accessible using a link from our Websites. We urge you to read the privacy and security policies of any external websites before providing any personal information while accessing those websites.
Because the security of your personal information is important to us, we require Transport Layer Security (“TLS”) software in order to encrypt the personal information that you provide to us. When using TLS, your transmission of personal information to us online is encrypted. You can verify whether your personal information is transmitted using TLS encryption by confirming the symbol of a closed lock or solid key inside your browser address bar. You can also verify that your personal information will be encrypted using TLS encryption by making sure that the prefix for the web address listed for that page has changed from “http” to “https”. If you do not see the appropriate symbol and/or the “https” prefix, you should not assume that the personal information that you are being asked to provide will be encrypted prior to transmission.
The personal information we collect from you online is stored by us and/or our service providers on databases protected through a combination of physical and electronic access controls, firewall technology and other reasonable security measures. Nevertheless, such security measures cannot prevent all loss, misuse or alteration of personal information and we are not responsible for any damages or liabilities relating to any such incidents to the fullest extent permitted by law. Where required under law, we will notify you of any such loss, misuse or alteration of personal information that may affect you so that you can take the appropriate actions for the due protection of your rights.
8.7 Minor Children
Our Websites do not sell products or services for purchase by children and we do not knowingly solicit or collect personal information from children. You may only use the Site if you are at least eighteen (18) years of age and can form legally binding contracts under applicable law. The Site is not intended for and should not be used by minors. If you are under the age of eighteen (18) or unable to form legally binding contracts under applicable law, you may contact a hotel directly for assistance.
When you download or register to use one of our applications, you may submit personal information to us such as your name, address, email address, phone number, date of birth, username, password and other registration information, financial and credit card information, personal description and/or image.
Further, when you use our applications, we may collect certain information automatically, including technical information related to your mobile device, your device’s unique identifier, your mobile network information, the type of mobile browser you use and information about the way you use the app.
Depending on the particular app you use and only after you have consented to such collection, we may also collect information stored on your device, including contact information, friends lists, login information (where necessary to allow us to communicate with other apps at your request), photos, videos, location information or other digital content. Further details of the kinds of information we collect is set out in the privacy notice for each individual app.
You always have certain choices regarding what personal information you wish to provide to us. However, if you choose not to provide certain details, some of your experiences with us may be affected (for example, we cannot take a reservation without a name).
If you provide us with your contact details (e.g., postal address, email address, telephone number or fax number), we may contact you to let you know about the products, services, promotions and events offered that we think you may be interested in, to the extent permitted by applicable law. We may also share your personal information with carefully-selected third parties, who may communicate directly with you, to the extent permitted by applicable law. In some jurisdictions, data privacy laws may require us to obtain a separate consent before we do so. You can always choose whether or not to receive any or all of these communications by contacting us as described herein or following the “unsubscribe” instructions contained in the communications.
In some jurisdictions, in addition to you consenting to this Policy, data privacy laws may require us to obtain a separate consent before we send you information that you have not specifically requested. In certain circumstances, your consent may be implied (e.g., where communications are required in order to fulfil your requests and/or where you have volunteered information for use by us). In other cases, we may seek your consent expressly in accordance with applicable laws (e.g., where the information collected is regarded to be Sensitive Personal Information under local regulations).
We will abide by any request from you not to send you direct marketing materials. When such a request is received, your contact details will be “suppressed” rather than deleted. This will help ensure that your request is recorded and retained unless you provide a later consent that overrides it.
11. Updating or Accessing Your Personal Information and Your Other Privacy Rights
With some limited exceptions, you may access and update personal information held about you. If you want to inquire about any personal information we may have about you, any information we may have shared, or about the consequences of exercising any of your rights, you can do so by sending us a written request by letter or email to the addresses set forth herein. Please be sure to include your full name, address and telephone number and a copy of a document evidencing your identity (such as an ID card or passport) so we can ascertain your identity and whether we have any personal information regarding you, or in case we need to contact you to obtain any additional information we may require to make that determination. Where you make more than one request in quick succession, we may respond to your subsequent request by referring to our earlier response and only identifying any items that have changed materially.
Depending on applicable law, you may request that we anonymize, block, correct, delete, and/or stop or restrict processing or using personal information that we hold about you by sending a letter or email to the addresses set forth herein. If we agree that the personal information is incorrect, or that the processing should be stopped, we will delete or correct the personal information. If we do not agree that the personal information is incorrect, we will tell you that we do not agree, explain our refusal to you and record the fact that you consider that personal information to be incorrect in the relevant file(s).
Depending on applicable law, you may also withdraw your consent, exercise your right to data portability and request that the rules on processing of your personal information are explained by sending a letter or email to the addresses set forth herein.
12. Local Privacy Rights
12.1 California Privacy Rights
If you reside in California, you may also make the following more specific requests with respect to your personal information in accordance with applicable law:
- Access – You can request, that we disclose to you the categories of personal information collected about you, the categories of sources from which the personal information is collected, the categories of personal information sold or disclosed, the business or commercial purpose for collecting and selling the personal information, the categories of third parties with whom we share the personal information, and the specific pieces of personal information collected about you over the past 12 months.
- Deletion – You can request that we delete your personal information that we maintain about you, subject to certain exceptions.
As is the case for all consumers regardless of residency, we will not discriminate against you because you exercised any of these rights. Note that for purposes of these rights, personal information does not include information about job applicants, employees and other of our personnel; information about employees and other representatives of third-party entities we may interact with in their business or commercial capacity; or information we have collected as a service provider to our clients.
California residents can exercise these access and deletion rights online or by emailing or calling us using the contact information set forth herein. We may deny certain requests, or fulfil a request only in part, based on our legal rights and obligations. For example, we may retain personal information as permitted by law, such as for tax or other record-keeping purposes, to maintain an active account, and to process transactions and facilitate customer requests.
We will take reasonable steps to verify your identity prior to responding to your requests. The verification steps will vary depending on the sensitivity of the personal information and whether you have an account with us.
California residents may designate an authorized agent to make a request on their behalf. When submitting the request, please ensure the authorized agent is identified as an authorized agent and ensure the agent has the necessary information to complete the verification process.
For purposes of California residents exercising these rights, please note the following regarding how we collect, and use and share your personal information as described in this Policy, including in the previous 12 months:
- We may collect, disclose and use for our business and commercial purposes, the following categories of personal information as set forth in applicable California law: Identifiers; California customer records (such as birthdate, contact information, and payment information); characteristics of protected classifications under California or federal law (such as demographic information like age and gender); commercial information (such as booking history and preferences); biometric information; professional or employment information; education information; Internet or other electronic network activity information; geolocation data; audio, electronic or visual information; and inferences.
- We collect and use the above categories of personal information for the business and commercial purposes described herein.
- We collect these categories of personal information from the sources described herein.
- We may disclose each of these categories of personal information for our business and commercial purposes to the extent permitted by applicable law with the categories of parties described herein.
- We may sell the following categories of personal information: Identifiers; California customer records; demographic information; commercial information; Internet or other electronic network activity; geolocation data; and inferences.
From time to time, we may collect personal information in connection with a promotion, offer, program, or discount. The offers and incentives made available through them are generally related to the value of the relationships that we have with the individuals who participate. Participation is voluntary and you may withdraw at any time by emailing us using the information set forth herein.
If you reside in California, you also have the right to ask us one time each year if we have shared personal information with third parties for their direct marketing purposes. To make a request, please write to us using the contact information provided herein. Indicate in your correspondence that you are a California resident making a “Shine the Light” inquiry.
12.2 Nevada Privacy Rights
If you are a Nevada resident, you can request that we not “sell” your “covered information” (as defined in applicable Nevada law). To make such a request, email us using the information set forth herein. Please use “Nevada Do Not Sell” in the subject line.
12.3 China Privacy Rights
This Policy, as updated from time to time, is inclusive of the laws of the People’s Republic of China.
12.4 Brazilian Privacy Rights
If you reside in Brazil or otherwise subject to the Federal Law nº 13.709/18 (“LGPD”), you are entitled with several rights in respect of your personal information under LGPD, especially the ones provided herein. In addition to the rights granted to you herein, you may also exercise the following rights when applicable:
- Right to Withdraw Consent – You have the right, when the basis for processing is consent, to withdraw the consent at any time, through an easy to use and free of charge procedure.
- Right to Revision of Automated Decision-Making – Under this right, you may request the revision of decisions taken solely on the basis of automated processing of your personal data which affects your interests, including decisions intended to define personal, professional, consumer or credit profile or aspects of your personality, providing clear and adequate information regarding the criteria and procedures used for an automated decision, subject to our commercial and industrial secrecy.
- Right to Petition – You may petition with the Brazilian regulatory authority as well as consumer protection entities regarding the processing of your personal data.
Lawfulness of Processing: We process your personal information, and Sensitive Personal Information, on the legal bases described herein.
Transfers of your data to countries outside Brazil: If your personal information is subject to the LGPD, HRR will take all necessary measures to ensure that transfers out of Brazil are adequately protected as required by applicable data protection law and in accordance with this Policy.
13. Changes to This Policy
Just as our business changes constantly, this Policy may also change. To assist you, this Policy has an effective date set out at the end of this document.
14. Request for Access to Personal Information/Questions or Complaints
If you have any questions about this Policy, about the processing of your data described, or any concerns or complaints with regard to the administration of the Policy, or if you would like to submit a request to exercise your rights in relation to the personal information that we maintain about you, please contact us by any of the following means:
- by calling us at (808) 400-1234;
- by mail to Hana Resort Rentals, LLC, 5031 Hāna Hwy., Hāna, HI 96713, United States; or
While this Policy alone does not create contractual rights, HRR has ensured compliance with some of its legal obligations in some countries/territories in relation to personal information by creating a set of binding standards and policies (known in some countries/territories as binding corporate rules), approved by a number of national privacy regulators. As a result, depending on your circumstances and location, you may be able to enforce your privacy rights using those standards or policies through that regulator or a court. If you would like to know more about these standards and policies, please contact HRR at the address above.
All requests for access to your personal information must be submitted in writing by letter or email. We may respond to your request by letter, email, telephone or any other suitable method.