← Back to blog
2 August 2026

Shine the Light: Why We Don’t Share Your Data for Third-Party Marketing

Privacy matters long before check-in. When you book a stay, browse a hotel website, or reach out with a question, you want confidence that your information will be handled responsibly. Shine the Light is a useful way to talk about that expectation, and the good news is simple: we do not share personally identifiable information with third parties for their direct marketing purposes.

That approach helps guests avoid unwanted marketing based on information they provided in the course of planning or managing their stay. It also supports a more straightforward privacy experience by keeping the focus on using information to serve guests, operate the website, and respond to requests. In this article, you will learn what Shine the Light means, why not sharing data for third-party marketing benefits guests, what kinds of information may be collected for business purposes, and how California privacy rights work in practice.

What Does "Shine the Light" Mean?

Shine the Light refers to California disclosure rules that relate to sharing personal information with third parties for their own direct marketing purposes. In plain language, the concept is about transparency: if a business shares certain personal information for another company’s marketing, consumers may have rights to know more about that practice.

Here, the policy is direct and easy to understand: personally identifiable information is not shared with third parties for their direct marketing purposes. Because of that policy, the business is exempt from California’s Shine the Light disclosure requirements.

For guests, that means your information is not being passed along so another company can market to you for its own purposes.

Why Not Sharing Data for Third-Party Marketing Matters

When a company chooses not to share guest information for third-party marketing, it creates immediate privacy benefits.

1. It reduces unwanted marketing exposure

If personally identifiable information is not shared for another company’s direct marketing, guests face less risk of receiving promotions based on that sharing.

2. It supports trust

Travel planning often involves sensitive details, from contact information to reservation-related data. A clear policy against sharing personally identifiable information for third-party marketing helps reinforce trust.

3. It keeps data use tied to guest service

A privacy program is easier to understand when information is used for defined business and service purposes rather than for unrelated outside marketing campaigns.

4. It aligns privacy with guest expectations

Most guests reasonably expect their information to be used to manage reservations, support website functionality, respond to inquiries, and maintain security. They do not expect it to be shared so an outside party can market its own products or services.

How Personal Information May Be Used

Not sharing data for third-party marketing does not mean personal information is never collected or used. It means the use of that information is tied to specific business or commercial purposes.

Personal information may be used for purposes such as:

This distinction matters. Using information to complete a reservation, support a guest, or secure a website is fundamentally different from sharing personally identifiable information with third parties for their own direct marketing purposes.

What Categories of Personal Information May Be Collected

To understand privacy practices clearly, it helps to look at the categories of information that may be collected within the last 12 months.

Categories collected

The following categories were identified as collected:

Category Collected
A. Identifiers Yes
B. Personal information listed in the California Customer Records statute Yes
C. Protected classification characteristics under California or federal law Yes
F. Internet or other similar network activity Yes

Categories not collected

The following categories were identified as not collected:

Category Collected
D. Commercial information No
E. Biometric information No
G. Geolocation data No
H. Sensory data No
I. Professional or employment-related information No
J. Non-public education information No
K. Inferences drawn from other personal information No

This kind of category-based disclosure gives guests a clearer view of how privacy practices are structured.

What Information Has Been Disclosed for a Business Purpose

In the preceding 12 months, the following categories of personal information were disclosed for a business purpose:

Those disclosures may be made to service providers and third parties such as subsidiaries and affiliates, as well as non-affiliated third parties with whom we partner to offer products and services to you.

That is separate from selling personal information or sharing personally identifiable information for third-party direct marketing.

A Clear Point on Selling Personal Information

The privacy notice states two related points clearly:

  1. In the preceding 12 months, no personal information has been sold.
  2. Because it is our policy not to sell your personal information, no opt-out mechanism is provided for sale of personal information.

For readers comparing privacy terms, this is an important distinction:

Clear definitions help guests understand what is happening with their data and, just as importantly, what is not happening.

What This Means for California Privacy Rights

If you are a California resident, the privacy framework includes additional rights regarding personal information.

Right to access your information

You have the right to request disclosure of certain information about the collection and use of your personal information during the 12-month period preceding your request.

That may include:

Right to request deletion

You have the right to request deletion of some or all of the personal information collected from you, subject to certain exceptions.

A deletion request may be denied in whole or in part if retaining the information is necessary to:

  1. Complete the transaction for which the information was collected, provide a requested good or service, take actions reasonably anticipated within the context of an ongoing business relationship, or otherwise perform a contract
  2. Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible
  3. Debug products to identify and repair errors that impair existing intended functionality
  4. Exercise free speech, ensure another consumer’s right to exercise free speech rights, or exercise another right provided by law
  5. Comply with the California Electronic Communications Privacy Act
  6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to applicable ethics and privacy laws, where deletion may likely render impossible or seriously impair the research’s achievement, if informed consent was previously provided
  7. Enable solely internal uses that are reasonably aligned with consumer expectations based on the relationship
  8. Comply with a legal obligation
  9. Make other internal and lawful uses of that information that are compatible with the context in which it was provided

Right to opt out of sale

California consumers have the right to direct a business not to sell personal information at any time. However, because the policy is not to sell personal information, no mechanism is provided to exercise that right.

Non-discrimination

There is also a commitment not to discriminate against consumers for exercising CCPA rights. Unless permitted by the CCPA, services will not be denied, prices will not be changed, and a different level or quality of services will not be provided based on the exercise of privacy rights.

How to Submit a Privacy Request

A verifiable consumer request to disclose or delete personal information may be submitted by email to email@hoteldomain.com.

A few important requirements apply:

Practical Privacy Takeaways for Guests

If you want the short version of Shine the Light, here it is:

You can also take a few simple steps to manage your privacy effectively:

  1. Review privacy notices carefully before providing personal information.
  2. Use the contact method provided if you want to request access to or deletion of your information.
  3. Provide enough detail in your request to help verify identity and process the request efficiently.
  4. Keep privacy in context by distinguishing among selling data, sharing for direct marketing, and disclosing for business operations.

Privacy, Trust, and the Guest Experience

Privacy is part of hospitality. Guests expect a smooth reservation process, responsive support, secure systems, and clear communication. They also expect responsible handling of the information they share.

A policy against sharing personally identifiable information for third-party direct marketing supports that expectation. It draws a clear line around how data is handled and reinforces a practical principle: guest information should serve the guest relationship, not unrelated outside marketing.

For readers interested in related topics, it is also helpful to explore broader privacy rights, website accessibility practices, and site navigation resources such as the page sitemap at www.holidayinnorlando.com/page-sitemap.xml.

Conclusion

Shine the Light matters because it gives guests a simpler answer to a complicated privacy question. When personally identifiable information is not shared with third parties for their direct marketing purposes, guests gain clarity, stronger expectations of privacy, and greater confidence in how their information is handled.

That policy works alongside other privacy commitments, including clear disclosure of collected categories of information, business-purpose uses, California access and deletion rights, and a stated policy not to sell personal information.

If you would like to exercise your California privacy rights, submit a verifiable consumer request to email@hoteldomain.com. For more information on related privacy practices, review the broader privacy materials and website resources available to guests.