Shine the Light: Why We Don’t Share Your Data for Third-Party Marketing
Privacy matters long before check-in. When you book a stay, browse a hotel website, or reach out with a question, you want confidence that your information will be handled responsibly. Shine the Light is a useful way to talk about that expectation, and the good news is simple: we do not share personally identifiable information with third parties for their direct marketing purposes.
That approach helps guests avoid unwanted marketing based on information they provided in the course of planning or managing their stay. It also supports a more straightforward privacy experience by keeping the focus on using information to serve guests, operate the website, and respond to requests. In this article, you will learn what Shine the Light means, why not sharing data for third-party marketing benefits guests, what kinds of information may be collected for business purposes, and how California privacy rights work in practice.
What Does "Shine the Light" Mean?
Shine the Light refers to California disclosure rules that relate to sharing personal information with third parties for their own direct marketing purposes. In plain language, the concept is about transparency: if a business shares certain personal information for another company’s marketing, consumers may have rights to know more about that practice.
Here, the policy is direct and easy to understand: personally identifiable information is not shared with third parties for their direct marketing purposes. Because of that policy, the business is exempt from California’s Shine the Light disclosure requirements.
For guests, that means your information is not being passed along so another company can market to you for its own purposes.
Why Not Sharing Data for Third-Party Marketing Matters
When a company chooses not to share guest information for third-party marketing, it creates immediate privacy benefits.
1. It reduces unwanted marketing exposure
If personally identifiable information is not shared for another company’s direct marketing, guests face less risk of receiving promotions based on that sharing.
2. It supports trust
Travel planning often involves sensitive details, from contact information to reservation-related data. A clear policy against sharing personally identifiable information for third-party marketing helps reinforce trust.
3. It keeps data use tied to guest service
A privacy program is easier to understand when information is used for defined business and service purposes rather than for unrelated outside marketing campaigns.
4. It aligns privacy with guest expectations
Most guests reasonably expect their information to be used to manage reservations, support website functionality, respond to inquiries, and maintain security. They do not expect it to be shared so an outside party can market its own products or services.
How Personal Information May Be Used
Not sharing data for third-party marketing does not mean personal information is never collected or used. It means the use of that information is tied to specific business or commercial purposes.
Personal information may be used for purposes such as:
- To fulfill the reason you provided the information, such as making a hotel reservation
- To provide you with the products and services you request
- To operate, support, personalize, and develop the website
- To create, maintain, customize, and secure your account
- To provide support and respond to inquiries
- To investigate and address concerns and improve responses
- To personalize website experience and deliver content and product and service offerings relevant to your interests, including targeted offers and ads through the website and via email or text message, with your consent where required by law
- To help maintain the safety, security, and integrity of the website, products and services, databases, and other technology assets
- For testing, research, analysis, and product development
- To respond to law enforcement requests and comply with applicable law, court order, or governmental regulations
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of assets
This distinction matters. Using information to complete a reservation, support a guest, or secure a website is fundamentally different from sharing personally identifiable information with third parties for their own direct marketing purposes.
What Categories of Personal Information May Be Collected
To understand privacy practices clearly, it helps to look at the categories of information that may be collected within the last 12 months.
Categories collected
The following categories were identified as collected:
| Category | Collected |
|---|---|
| A. Identifiers | Yes |
| B. Personal information listed in the California Customer Records statute | Yes |
| C. Protected classification characteristics under California or federal law | Yes |
| F. Internet or other similar network activity | Yes |
Categories not collected
The following categories were identified as not collected:
| Category | Collected |
|---|---|
| D. Commercial information | No |
| E. Biometric information | No |
| G. Geolocation data | No |
| H. Sensory data | No |
| I. Professional or employment-related information | No |
| J. Non-public education information | No |
| K. Inferences drawn from other personal information | No |
This kind of category-based disclosure gives guests a clearer view of how privacy practices are structured.
What Information Has Been Disclosed for a Business Purpose
In the preceding 12 months, the following categories of personal information were disclosed for a business purpose:
- Category A. Identifiers
- Category B. Personal information listed in the California Customer Records statute
- Category C. Protected classification characteristics under California or federal law
- Category F. Internet or other similar network activity
Those disclosures may be made to service providers and third parties such as subsidiaries and affiliates, as well as non-affiliated third parties with whom we partner to offer products and services to you.
That is separate from selling personal information or sharing personally identifiable information for third-party direct marketing.
A Clear Point on Selling Personal Information
The privacy notice states two related points clearly:
- In the preceding 12 months, no personal information has been sold.
- Because it is our policy not to sell your personal information, no opt-out mechanism is provided for sale of personal information.
For readers comparing privacy terms, this is an important distinction:
- Disclosing information for a business purpose can support operations, service delivery, security, and related functions.
- Selling personal information is treated differently under California privacy law.
- Sharing personally identifiable information for third-party direct marketing is another separate concept addressed by the Shine the Light policy.
Clear definitions help guests understand what is happening with their data and, just as importantly, what is not happening.
What This Means for California Privacy Rights
If you are a California resident, the privacy framework includes additional rights regarding personal information.
Right to access your information
You have the right to request disclosure of certain information about the collection and use of your personal information during the 12-month period preceding your request.
That may include:
- The categories of personal information collected about you
- The categories of sources from which personal information was collected
- The business or commercial purpose for collecting personal information
- The categories of personal information disclosed for a business purpose
- The categories of third parties with whom personal information is shared
- The specific pieces of personal information collected about you
Right to request deletion
You have the right to request deletion of some or all of the personal information collected from you, subject to certain exceptions.
A deletion request may be denied in whole or in part if retaining the information is necessary to:
- Complete the transaction for which the information was collected, provide a requested good or service, take actions reasonably anticipated within the context of an ongoing business relationship, or otherwise perform a contract
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible
- Debug products to identify and repair errors that impair existing intended functionality
- Exercise free speech, ensure another consumer’s right to exercise free speech rights, or exercise another right provided by law
- Comply with the California Electronic Communications Privacy Act
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to applicable ethics and privacy laws, where deletion may likely render impossible or seriously impair the research’s achievement, if informed consent was previously provided
- Enable solely internal uses that are reasonably aligned with consumer expectations based on the relationship
- Comply with a legal obligation
- Make other internal and lawful uses of that information that are compatible with the context in which it was provided
Right to opt out of sale
California consumers have the right to direct a business not to sell personal information at any time. However, because the policy is not to sell personal information, no mechanism is provided to exercise that right.
Non-discrimination
There is also a commitment not to discriminate against consumers for exercising CCPA rights. Unless permitted by the CCPA, services will not be denied, prices will not be changed, and a different level or quality of services will not be provided based on the exercise of privacy rights.
How to Submit a Privacy Request
A verifiable consumer request to disclose or delete personal information may be submitted by email to email@hoteldomain.com.
A few important requirements apply:
- Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your information.
- You may only make a verifiable consumer request for access twice within any 12-month period.
- Your request must:
- Describe the request with sufficient detail so it can be understood, evaluated, and answered
- Include your name and any email address or phone number you have provided so identity can be verified
Practical Privacy Takeaways for Guests
If you want the short version of Shine the Light, here it is:
- Personally identifiable information is not shared with third parties for their direct marketing purposes.
- No personal information has been sold in the preceding 12 months.
- Personal information may still be collected and disclosed for business purposes tied to reservations, service delivery, website operations, support, security, legal compliance, and improvement.
- California residents have rights to access and request deletion of personal information, subject to certain exceptions.
You can also take a few simple steps to manage your privacy effectively:
- Review privacy notices carefully before providing personal information.
- Use the contact method provided if you want to request access to or deletion of your information.
- Provide enough detail in your request to help verify identity and process the request efficiently.
- Keep privacy in context by distinguishing among selling data, sharing for direct marketing, and disclosing for business operations.
Privacy, Trust, and the Guest Experience
Privacy is part of hospitality. Guests expect a smooth reservation process, responsive support, secure systems, and clear communication. They also expect responsible handling of the information they share.
A policy against sharing personally identifiable information for third-party direct marketing supports that expectation. It draws a clear line around how data is handled and reinforces a practical principle: guest information should serve the guest relationship, not unrelated outside marketing.
For readers interested in related topics, it is also helpful to explore broader privacy rights, website accessibility practices, and site navigation resources such as the page sitemap at www.holidayinnorlando.com/page-sitemap.xml.
Conclusion
Shine the Light matters because it gives guests a simpler answer to a complicated privacy question. When personally identifiable information is not shared with third parties for their direct marketing purposes, guests gain clarity, stronger expectations of privacy, and greater confidence in how their information is handled.
That policy works alongside other privacy commitments, including clear disclosure of collected categories of information, business-purpose uses, California access and deletion rights, and a stated policy not to sell personal information.
If you would like to exercise your California privacy rights, submit a verifiable consumer request to email@hoteldomain.com. For more information on related privacy practices, review the broader privacy materials and website resources available to guests.