This Online Privacy Statement (“Policy”) was last updated on January 24, 2020.
Para la versión en Español de nuestra Declaración de Privacidad, haga clic aquí.
Vistana Signature Experiences, Inc. is an indirect subsidiary of Marriott Vacations Worldwide Corporation, a global vacation company that offers vacation ownership, exchange, rental, and resort and property management, along with related businesses, products and services.
Marriott Bonvoy, Heavenly, Heavenly Spa, WestinWORKOUT, Sheraton, St. Regis, The Luxury Collection, Westin and their respective logos are the trademarks of Marriott International, Inc. (“Marriott”). Vistana Signature Experiences and the programs and products provided under the Vistana brand are not owned, developed or sold by Marriott.
Vistana Signature Experiences, its subsidiaries and managed Owners’ associations (together “Vistana,” “we,” “our,” or “us”) respect your privacy and are committed to protecting it through compliance with this Policy. This Policy describes the type of information Vistana may collect from you or that you may provide when you visit any website, mobile applications, or property owned or operated by Vistana. Vistana collects information about you so that we can provide an experience that is tailored to your preferences. Vistana’s mission is to consistently exceed expectations with respect to the products and services we provide to our business and leisure travelers.
This Policy may not apply to information collected by Vistana offline or through other means, including on any other website operated by Vistana or any third party (including our parent, affiliates and subsidiaries) that do not link to this Policy; or any third party through any application or content (including advertising and credit card processing service providers) that may link to or be accessible from or on Vistana websites.
Vistana is committed to providing information about the collection and use of personal information furnished by or from you while using our websites, products and services. If you create a personal online profile through a Vistana website, you will be offered the choice to decline (opt-out) participation in certain services and promotional benefits provided by Vistana and/or our carefully selected third parties, including Marriott through the Marriott Bonvoy program (“Strategic Marketing Partners”).
Please read this Policy carefully to understand Vistana’s policies and practices regarding your information and how it will be used. By accessing or using Vistana websites, you agree to this Policy. If you do not agree with the policies and practices of Vistana, your choice is to not use our websites. This Policy may change from time to time. Your continued use of the websites after we make changes is deemed acceptance of those changes, so please check the Policy periodically for updates.
The following is an explanation of the information collected by Vistana, its use, and why the use of this information will benefit our visitors’ experience.
INFORMATION COLLECTED ON OUR WEBSITES
COOKIES AND INVISIBLE PIXELS
DIRECT MAIL/OUTBOUND TELEMARKETING
LINKS TO OTHER WEBSITES
ACCESS TO PERSONALLY IDENTIFIABLE INFORMATION
CHILDREN UNDER THE AGE OF 13
DATA TRANSFERS ACROSS INTERNATIONAL BORDERS SECURITY
YOUR CALIFORNIA PRIVACY RIGHTS
YOUR PRIVACY RIGHTS IN MEXICO
PERIODIC REVIEW AND MODIFICATIONS
Vistana may ask for and collect personal information in order to provide a customized experience on our websites. The personal information we collect may include information that you provide by filling in forms on our websites, such as name, postal address, email address and telephone number. With these fill-in forms, you have the ability to choose the information you wish to share with us. You will be informed about how Vistana may use such information, including whether it will be shared with Strategic Marketing Partners. In most cases, the information you provide is added to our database in order for us to provide personally tailored messages which are delivered online and offline.
Vistana may also collect information using automatic data collection technologies to collect certain information about your equipment, as well as your browsing activities and patterns. Our automatic data collection activities are further described in the Cookies and Invisible Pixels section of this Policy.
Vistana may contract with third-party service providers to deliver services and customer solutions. Service providers, which may change or be added from time to time, are required to keep confidential the information received on behalf of Vistana and may not use it for any purpose other than to carry out the services they are performing for Vistana. Situations in which Vistana may disclose your information to others include:
If information is shared as mentioned above, we seek to limit the scope of information that is furnished to the amount necessary for the performance of the specific function. Unless otherwise precluded by legal process, we require third parties to protect your personal information and abide by applicable privacy laws and regulations.
You may choose to create a personal online account with a unique log-in. It is necessary for Vistana to collect certain personal information from you to establish these accounts and allow you to perform various activities within the website. For Owners of Vistana products, you will have to provide additional information to enable you to access your specific ownership information. If you do not wish to share your information, please do not register and set up an online account.
The websites may collect personal information through behavioral tracking. As you navigate through and interact with our websites, Vistana, its vendors and marketing partners may use automatic data collection technologies to collect certain information about your equipment, browsing actions and patterns by using cookies, invisible pixels and web beacons. These help us deliver a better and more personalized service, including by enabling us to estimate our audience size and usage patterns; store information about your preferences, allowing us to customize our websites according to your individual interests; and speed up your searches.
Web Beacons and Invisible Pixels. Vistana uses invisible pixels and web beacons to count how many people visit certain web pages. Information collected from invisible pixels and web beacons is used and reported in the aggregate. Vistana may use this information to improve marketing programs and content.
Cookies. Cookies are used to:
Vistana cookies assign your computer or other device with a unique identifier, which in turn becomes your identification card whenever you return to a Vistana website. Cookies are small data files that most websites store, access and maintain on the hard drive of your computer. Most browsers now automatically accept cookies by default, but they can be set so that all or some cookies are rejected automatically, or are accepted or rejected on a case-by-case basis at the user’s option.
Below we explain the different types of cookies that may be used on our websites. For a full list of the cookies we employ, please see the Cookie Choices section of this Policy.
We also work with vendors to deliver our advertisements directly to those who are traveling or about to travel. For example, when you print your boarding pass online, one of our vendors may drop a cookie on your computer, identifying your computer with a unique identifier and a code indicating your destination. We use this vendor to deliver advertisements to you indicating our available properties in the destination indicated on your boarding pass.
You can disable cookies by setting your preferences at any time in the Advertising Preferences link at the bottom of our website. To see a complete list of the companies that use these cookies and technologies, and to tell us whether or not they can be used on your device, please click here. However, you should also understand that rejecting cookies might affect your ability to perform certain transactions on our websites and our ability to recognize your browser from one visit to the next.
You may also adjust your internet browser to treat cookies in different ways. Depending upon the type of browser you are using, you may be able to configure your browser so that: (i) you are prompted to accept or reject cookies on an individual basis or (ii) you may be able to prevent your browser from accepting any cookies at all. You should refer to the supplier or manufacturer of your web browser for specific details about cookie security.
To learn more about cookies, please visit the following site, which is not affiliated with Vistana: allaboutcookies.org/.
Profile If you connect with a social media service, or log in through a social media service, we may collect information that is publicly available through that service and the basic account information that is automatically passed to us by the service. For example, on Facebook, this could include your name, profile pictures and URL, cover photos, username, user ID, your friends’ user IDs, network, gender, birthday, language and current city.
Social Content We may also collect content that you provide to be published on those social media services, such as your likes and your social media activities, like check-ins or tweets. We also collect such other information as you and the social media service provide to us, including information regarding or provided by your friends. This includes, for example, check-ins, events, travel wishes, interests, posts, locations and photos (including photos you or your friends have been tagged in). If you have turned on your device’s location services, your location may be included in that content.
Social Media Content Sharing The information collected from or about you by social media networks with which you connect are governed by the policies of those social media networks. Be aware that sharing content on a social media service may lead to it being shared to your friends (or contacts on those networks). Please consult the privacy settings on these services to update any of your sharing settings.
From time to time, Vistana may ask you for your email address in order to provide relevant information such as reservation confirmations and offers. Email addresses may be joined with other information provided at our website and may also be augmented with other data sources. By providing your email address to us, you may receive periodic offers and information from Vistana or one of its Strategic Marketing Partners. If you do not want to receive marketing information from Vistana and/or one of our Strategic Marketing Partners in the future, you may opt out of receiving email communication by following the directions posted in the email, or by contacting us in any of the ways outlined in the Contact Us section of this Policy.
Once a visitor has opted out, they can choose to opt in again by changing the preferences selected in their personal online profile or by contacting us in any of the ways outlined in the Contact Us section of this Policy. If you ask us to make these changes for you, we may not be able to change your personal information without deleting your account.
As part of the service that Vistana provides, Vistana may mail, text message or call you to inform you of enhancements, changes in offerings, special events or other relevant information responsive to your interests. If you provide Vistana with your postal address, cellular or telephone number, you may receive periodic mailings or phone calls from us with information on new Vistana products and services or upcoming Vistana special offers/events. You may also receive mailings/calls from one or more of our Strategic Marketing Partners. Vistana complies with Federal and State “Do Not Call” legislation and offers you the option to decline these communications. You can opt out of receiving certain communications from Vistana when setting up an online account, or by submitting your request or contacting us in any of the ways outlined in the Contact Us section of this Policy.
In order to anticipate your needs, Vistana provides links to other websites for your convenience and information. Vistana is not responsible or liable for any content presented by or contained on any third-party website, including but not limited to any advertising claims or marketing practices. Please note that while Vistana will protect your information on Vistana-owned and -operated websites, Vistana cannot control and will not be responsible for the privacy policies of third-party websites, including websites owned or controlled by independent Owners’ associations, vendors, service providers, travel providers that may have a business relationship with Vistana, or other websites not controlled or authorized by Vistana. Third-party websites that are accessed through links on Vistana’s websites have separate privacy and data collection practices and security measures. We have no responsibility or liability for the practices, policies and security measures implemented by third parties on their websites. We encourage you to contact them to ask questions about their privacy practices, policies and security measures before disclosing any personal information. We recommend that you review the privacy statements and policies of linked websites to understand how those websites collect, use and store information.
We respect your privacy and maintain your personal information on a secure server. If you create a personal online profile for which you have a unique log-in, you can review and change your personal information and online communication preferences by logging into that website and visiting your account profile. If you request us to make changes to your personal account, we may not be able to change your personal information without deleting your account.
Occasionally, information you request to be changed or removed will be retained in certain files in order to properly resolve disputes or to troubleshoot problems. In addition, information is never completely removed from our databases due to technical and legal constraints, including stored “back-up” systems. Therefore, you should not expect that all of your personal information will be completely removed from our databases in response to such requests.
Data collected by Vistana is an asset. It is possible that Vistana, its parent, subsidiaries, affiliates, joint venture companies, or any combination of the foregoing, could merge with or be acquired by another legal entity. In such event, you should expect that Vistana may share some or all of the data collected from its visitors with such other entity, provided that such other entity will be notified of the practices which apply to personal information under this Policy.
Our websites are not intended for children under 13 years of age. No one under age 13 may provide any personal information on our websites. We do not knowingly collect personal information from children under 13. If you are under 13, do not use or provide any information on this or any other website owned or operated by Vistana; do not use any of the interactive or public comment features; do not provide any information about yourself to us, including your name, address, telephone number, email address or any screen name or username you may use. If we learn we have collected or received personal information from a child under 13 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 13, please contact us.
Vistana does not currently store data collected through this website in any location outside of the United States. However, if at any time Vistana does store personal information of our customers outside of the United States, the nature of our business and our operations may require us to transfer that personal data to our parent, subsidiaries, affiliates and Strategic Marketing Partners located in countries outside of your own, including into the United States. By providing your personal information on this or any of our parent, subsidiary or affiliate websites, you are acknowledging that such transfer may occur and expressly grant permission to do so. Although the data protection requirements and other laws of these various countries may not be as comprehensive as those in your own country, Vistana will take appropriate steps to ensure that your personal data is protected and handled as described in this Policy.
Vistana recognizes the importance of information security and is constantly reviewing and enhancing our technical, physical, and logical security rules and procedures. Vistana-owned and -operated websites and servers utilize security measures to help protect your personal information against accidental loss, misuse, unlawful or unauthorized access, disclosure and alteration while under our control. Online payment transactions will be tokenized. We also strive to ensure our Strategic Marketing Partners and service providers with which we share your personal information exercise reasonable efforts to maintain its confidentiality and security. Although “guaranteed security” does not exist either on or off the internet, we safeguard your information using appropriate administrative, procedural and technical safeguards, including password controls, firewalls, the use of encryption and tokenization.
Where we have given you or where you have chosen a password for access to certain parts of our websites, you are responsible for keeping this password confidential. We ask that you not share your password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our websites. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on our websites.
1. California Consumer Privacy Act of 2018
The California Consumer Privacy Act of 2018 (“CCPA”) requires that we provide consumers that reside in California (“you,” or “your” as used in this Your California Privacy Rights section) certain information about how we collect, use or disclose your personal information. Under the CCPA, “personal information” is any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular California resident or household. It does not include publicly available data as defined by the CCPA.
Personal information we collect, use, or disclose that is governed by the federal Gramm-Leach-Bliley Act, the California Financial Information Privacy Act, or the federal Fair Credit Reporting Act, such as consumer credit reports or information relating to your financing of a vacation ownership product, is not subject to the CCPA or this section.
Categories of Personal Information that We Collect, Use, and Disclose
The type of personal information we collect, use, and disclose will depend on your interaction or relationship with us. The chart below generally identifies the personal information we collect based on the categories of personal information set forth in the CCPA.
|Categories of personal information as set forth in the CCPA||Personal information we collect|
|Name, Contact Information and other Identifiers: Identifiers such as a real name, alias, address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers.||We may collect information such as your name, address, email address, telephone numbers, date of birth, owner number, and IP address. In more limited circumstances, such as when you purchase or finance a vacation ownership product, we may collect information such as social security number, driver’s license number, or passport number.|
|Customer Records: Paper and electronic customer records containing personal information, such as name, signature, physical characteristics or description, address, telephone number, education, current employment, employment history, social security number, passport number, driver’s license or state identification card number, insurance policy number, bank account number, credit card number, debit card number, or any other financial or payment information, medical information, or health insurance information.||We may collect information such as your name, address, email address, telephone numbers, owner number, and credit or debit card information. In more limited circumstances, such as when you purchase or finance a vacation ownership product, we may collect information such as current employment, employment history, social security number, passport number, driver’s license or state identification, and other financial or payment information.|
|Protected Classifications: Characteristics of protected classifications under California or federal law such as race, color, sex, age, religion, national origin, disability, citizenship status, and genetic information.||We may collect information such as your gender or age. In more limited circumstances, we may collect disability information to provide you with appropriate accommodations or services at our resorts.|
|Purchase History and Tendencies: Commercial information including records of personal property, products or services purchased, obtained, or considered, or other purchasing or use histories or tendencies.||We may collect information such as the products or services you purchased or utilized.|
|Biometric Information: Physiological, biological or behavioral characteristics that can be used alone or in combination with each other to establish individual identity, including DNA, imagery of the iris, retina, fingerprint, faceprint, hand, palm, vein patterns, voice recordings, keystroke patterns or rhythms, gait patterns or rhythms, and sleep, health, or exercise data that contain identifying information.||We may collect voice recordings when we monitor and record telephone calls.|
|Usage Data: Internet or other electronic network activity information, including, but not limited to, browsing history, clickstream data, search history, and information regarding a resident’s interaction with an internet website, application, or advertisement.||We may collect this information as part of your interaction with our websites or mobile application and through advertisements.|
|Geolocation Data: Precise geographic location information about a particular individual or device.||We may collect information such as your postal address, zip code, or the location associated with an IP address or particular device.|
|Audio, Video and other Electronic Data: Audio, electronic, visual, thermal, olfactory, or similar information, such as CCTV footage, photographs, and call recordings and other audio recording (e.g., recorded meetings and webinars).||We may collect voice recordings when we monitor and record telephone calls, photos or videos that are tagged or shared with us through social media posts, or audio, video, or images captured in security footage of our resorts.|
|Professional or employment-related information: Employment history, qualifications, licensing, disciplinary record.||In limited circumstances, such as when you purchase or finance a vacation ownership product, we may collect information such as employment history.|
|Education Information: Information about education history or background that is not publicly available personally identifiable information as defined in the federal Family Educational Rights and Privacy Act (20 U.S.C. section 1232g, 34 C.F.R. Part 99).||We do not collect this information.|
|Profiles and Inferences: Inferences drawn from any of the information identified above to create a profile reflecting a resident’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, or aptitudes.||We may collect or derive information such as your preferences, characteristics, predispositions, and behavior based on other information we have about you.|
We collect these categories of personal information from the sources and for the purposes described in this Policy. We disclose your personal information to third parties, such as our service providers, as described in this Policy. We do not collect personal information directly from children under the age of sixteen (16), but may receive such information from parents and guardians when, for example, making resort or other travel reservations.
Third-Party Cookies & Similar Technologies
We may also use standard internet technology, such as cookies, web beacons, pixels, and other similar technologies (“third-party cookies”), to track your use of our websites. We may include web beacons in promotional email messages or newsletters to determine whether messages have been opened and acted upon. The information we obtain in this manner enables us to customize the services we offer to deliver targeted advertisements and to measure the overall effectiveness of our online advertising, content, programming or other activities. Data that is collected through network advertising or social media third-party cookies may be disclosed by such network advertisers or social media to other network advertisers that allows those advertisers to also display ads to you. See the “Cookies and Invisible Pixels” section of this Policy for more information. While there is currently no industry consensus, we do not consider these additional disclosures to be our sale of personal information under the CCPA. You can click here, however, if you do not want information collected by third-party cookies, or visit www.aboutads.info and www.networkadvertising.org to opt out.
California Resident Rights
If you are a California resident, you have certain rights with respect to your personal information as set forth below.
Request to Delete: You may request that we delete personal information we have collected about you, subject to certain exemptions provided by law.
Request to Know: You may request, subject to certain exemptions, that we disclose to you the categories of personal information collected; the categories of sources of personal information; the business or commercial purposes for collecting and selling your personal information; the categories of third parties with whom we have shared your personal information; the categories of personal information that we have disclosed or shared with a third party for a business purpose; the categories of third parties to whom your personal information has been sold, and the specific categories of personal information sold to each category of third party; and the specific pieces of personal information that we have collected about you in the prior 12 months.
Request to Opt-out of Our Sale of Your Personal Information: We do not sell your personal information.
Submitting Requests: To make a Request to Delete or a Request to Know, please contact us at (844) 980‑2582 or [email protected]. Please include your full name, postal address, email address, and your owner number (if applicable). If you designate an authorized agent to make a request on your behalf, we require you to provide a written and signed authorization of your agent’s permission to exercise your rights on your behalf as provided for in this section. Please include your full name, postal address, email address, and your owner number (if applicable) along with your agent’s full name, postal address, email address, and relationship to you.
If we are not able to verify your identity based on this information, we will take additional steps to verify your identity before responding to your request. We will respond to verifiable requests received from California residents or their authorized agents in accordance with the law, which provides certain exemptions for disclosure or deletion. For example, if you are an owner of a vacation ownership product, we may retain your personal information as permitted by law to maintain and service your ownership and account.
We are not permitted to nor do we discriminate against California residents who exercise their rights under the law. These rights do not apply to personal information we collect about job applicants, independent contractors, or our current or former full-time, part-time and temporary employees and other staff, or information we collect when we act as a service provider.
2. Shine the Light Law
California Civil Code Section 1798.83 provides certain privacy rights to individual customers who are California residents. If you are a California resident and have provided personal information to Vistana, you may request information about our disclosures of certain categories of personal information to third parties, if such disclosures were for the direct marketing purposes of the recipient of that information. Because your privacy is important to us, Vistana does not share your personal information with unaffiliated third parties for the third parties’ direct marketing purposes, except as stated herein. Vistana does share customer information with and among its parent, affiliate and subsidiary companies for the purpose of marketing the various Vistana resorts, vacation and travel products and services, and shares certain information about the Owners of vacation ownership interests with Marriott, as operator of the Marriott Bonvoy™ program and as owner of the Sheraton, Westin, St. Regis and The Luxury Collection brands, and with the external vacation exchange companies (Interval International and/or Resort Condominiums International) that are affiliated with the Vistana resorts. If you want to opt out of sharing this information, please submit your request by writing to the addresses listed in the Contact Us section below.
Civil Code Section 1798.83 provides certain privacy rights to individual customers who are California residents. If you are a California resident and have provided personal information to Vistana, you may request information about our disclosures of certain categories of personal information to third parties, if such disclosures were for the direct marketing purposes of the recipient of that information. Because your privacy is important to us, Vistana does not share your personal information with unaffiliated third parties for the third parties’ direct marketing purposes, except as stated herein. Vistana does share customer information with and among its parent, affiliate and subsidiary companies for the purpose of marketing the various Vistana resorts, vacation and travel products and services, and shares certain information about the Owners of vacation ownership interests with Marriott, as operator of the Marriott Bonvoy program and as owner of the Sheraton, Westin, St. Regis and The Luxury Collection brands, and with the external vacation exchange companies (Interval International and/or Resort Condominiums International) that are affiliated with the Vistana resorts. If you want to opt out of sharing this information, please submit your request by writing to the addresses listed in the Contact Us section below.
The Mexican Federal Law for the Protection of Personal Data Held by Private Parties and its Regulations (“Mexican Privacy Regulations”) provide certain privacy rights to individual customers who are Mexican residents. If you are a Mexican resident, Vistana has appointed Jeff Driscoll with Turistica Cancun, S. de R.L. de C.V. as the person in charge of your personal data.
Vistana does not ask for nor collect personal data considered sensitive by Mexican Privacy Regulations.
You have the right to request access to, rectify, cancel and oppose the management of your personal data (your “ARCO Rights”). Furthermore, you have the right to request the revocation of your given consent, as well as limit the use of your personal data.
In order to exercise your rights, we ask that you send your request in a letter or an email to the addresses below.
For security purposes, and in compliance with the Mexican Privacy Regulations, it is mandatory that all requests be accompanied by the information necessary for us to identify the applicant and, if applicable, his or her legal representative. As a result, your request form should be accompanied with the following documents:
Vistana keeps a record of all the submitted requests. Furthermore, in case the request form should be found incomplete, we have the right to reject your request.
You guarantee that the given information is exact, complete and authentic. Vistana is not responsible for any damage and/or harm caused by falsified information or identity impersonation.
Your request shall be processed in accordance with the manner and time established in the Mexican Privacy Regulations. If applicable, Vistana will provide a response no later than 20 (twenty) business days after we have received your request. The waiting period could be extended by another 20 (twenty) business days if and when it’s justified, and provided we notify you of said extension.
If you request access to your personal data, it shall be given digitally. Only upon express request, and provided you cover any reasonable expenses, will Vistana furnish hard copies and send them to your home address.
This Policy may be revised from time to time. Updated versions will be posted to our websites and date stamped so that you are always aware of when the Policy was last updated.
Vistana provides all visitors with the option to contact us with any further questions or concerns.
You can contact us these ways:
By email: [email protected]
By writing to us at: Vistana Signature Experiences, Inc. Attention: Privacy Office 9002 San Marco Court Orlando, Florida 32819
By calling a customer service representative at: (800) 847-8262
To opt out of receiving communications from Vistana by telephone and be placed on the Vistana Do Not Call list: (800) 611-5701
To delete your Online Account: Please click here to send an email with your request.