PDF

Privacy Statement

Last Updated: 16/12/2024
Hotels.com, part of the Expedia Group, (“we” or “us”) values you as our customer and recognizes that privacy is important to all of us. This Privacy Statement explains how we collect, use, and disclose personal data when you use our platform and associated services, your rights in determining what we do with the data that we collect or hold about you and tells you how to contact us.
Privacy Statement Summary
This is a summary of our Privacy Statement. To review our Privacy Statement in full, please click here, or scroll down.
What does this Privacy Statement cover?
This Privacy Statement is designed to describe:
  • How and what type of personal data we collect and use
  • When and with whom we share your personal data
  • What choices you can make about how we collect, use, and share your personal data
  • How you can access and update your personal data.
What personal data do we collect and use, and how do we collect it?
We collect personal data when:
  • You give us the personal data
  • We collect it automatically
  • We receive it from others
When you create an account on one of our sites, sign up to receive offers or information, or make a booking using our platform, you give us your personal data. We also collect such personal data through automated technology such as cookies placed on your browser (with your consent where applicable) when you visit our sites or download and use our apps. We also receive personal data from affiliated companies within Expedia Group, as well as business partners and other third parties, which help us improve our platform and associated tools and services, update and maintain accurate records, potentially detect and investigate fraud, and more effectively market our services.
Your personal data may be shared for several purposes, including to help you book your travel/vacation, assist with your travel and/or vacation stay, communicate with you (including when we send information to you on products and services or enable you to communicate with travel providers and/or property owners), and comply with the law. The full Privacy Statement below details how personal data is shared.
You can exercise your data protection rights in various ways. For example, you can opt out of marketing by clicking the “unsubscribe” link in the emails, in your account as applicable, or contacting our customer service. Our Privacy Statement has more information about the options and data protection rights and choices available to you.
More information about our privacy practices is set out in our full Privacy Statement. You can also Contact Us to ask questions about how we handle your personal data or make requests about your personal data.
*****************************

Privacy Statement

Collection and Use of Your Personal Data

In this section, you will find information about:
  • the types of personal data that we collect and use,
  • how we collect and use it,
  • the purposes for which we collect and use it, and
  • the lawful basis we rely on to collect and use it.

Lawful bases for processing:

In the table below, you will find the lawful bases we rely on to collect and use your personal data.
In summary, whenever we collect or use your personal data, that collection or use must be based on one of the following criteria:
  • Consent: this means you have given your consent for us to do so (e.g., sending you marketing communications where consent is required).
  • Legal obligation: this means we have a legal obligation to collect personal data from you or use it for a specific purpose (e.g. using your transaction history to complete our financial and tax obligations under the law).
  • Performance of a contract: this means the personal data is necessary to perform a contract with you (e.g., manage your booking, process payments, or create an account at your request),
    • If we ask you to provide personal data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal data is mandatory or not (as well as of the possible consequences if you do not provide your personal data).
  • Legitimate interest: this means the processing is in our legitimate interests and those interests are not overridden by your rights (as explained below)
    • Certain countries and regions allow us to process personal data on the basis of legitimate interests. If we collect and use your personal data in reliance on our legitimate interests (or the legitimate interests of any third party), this interest will typically be to operate or improve our platform and communicate with you as necessary to provide our services to you, for security verification purposes when you contact us, to respond to your queries, to undertake marketing, or for the purpose of detecting or preventing illegal activities. Whatever our determination of our specific legitimate interest is for a given use of your personal data, when we assess its appropriateness, we will always assess it against the potential impact on your rights. While the concept of legitimate interest only exists in certain countries and regions, we balance our usage of your personal data against your rights globally.

Categories of Personal Data We Collect and Use

We collect and use personal data for the following purposes:
  • Platform Usage and Booking Purposes – including to:
    • Facilitate your booking, verify your identity, and for travel insurance purposes.
    • Book the requested travel (such as flights, cars, cruises, activities, and hotels) or enable vacation property booking.
    • Provide services related to the booking and/or account.
    • Create, maintain, and update user accounts on our platform and authenticate you as a user.
    • Maintain your search and travel history, accommodation and travel preferences, and similar information about your use of Expedia Group’s platform and services, and as otherwise described in this Privacy Statement.
    • Enable and facilitate acceptance and processing of payments (such as collecting or validating your payment details for our various payment models to hold a reservation, secure a booking, enable a travel partner to check the validity of your bank card, expedite the check-out process, or deal with any fee, charge, payment or refund that applies), coupons, and other transactions.
    • Administer loyalty and rewards programs.
    • Collect and enable booking-related reviews.
    • Help you to use our services faster and more easily through features such as the ability to sign in using your account within the online services and sites of some of the Expedia Group brands.
  • Communications and Customer Service Purposes – including to:
    • Respond to your questions, requests for information, and process information choices.
    • Enable communication between you and travel suppliers (such as hotels and vacation property owners).
    • Contact you (e.g. by text message, email, phone calls, mail, push notifications, or messages on other communication platforms) to provide information such as travel booking confirmations and updates, emergency notifications, or for other purposes as described in this Privacy Statement.
  • Marketing Purposes – including to:
    • Contact you (such as by text message, email, phone calls, mail, in-app messaging, push notifications, or messages on other communication platforms) for marketing purposes.
    • Analyze information such as browsing and/or purchase history and use the result to optimize advertising and marketing in accordance with your interests and preferences.
    • Measure and analyze the effectiveness of our marketing and promotions.
    • Administer promotions like contests, sweepstakes, and similar giveaways.
    • Deliver targeted advertising and advertising based on your profile. Our Cookie Statement further explains how we use cookies and similar tracking technology.
  • Market Research, Analytics, and Training Purposes to improve our Services – including to:
    • Conduct surveys, market research, and data analytics.
    • Maintain, improve, research, and measure the effectiveness of our sites and apps, activities, tools, and services.
    • Monitor or record calls, chats, and other communications with our customer service team and other representatives, as well as platform communications between or among partners and travelers for quality control, training, dispute resolution, and as described in this Privacy Statement.
    • Create aggregated or otherwise anonymized or deidentified data, which we may use and disclose without restriction where permissible.
  • Security and Compliance Purposes – including to:
    • Promote security, verify identity of our customers, prevent and investigate fraud and unauthorized activities, defend against claims and other liabilities, and manage other risks.
    • Comply with applicable laws (including tax data sharing laws and obligations), protect our and our users’ rights and interests, defend ourselves, and respond to law enforcement, courts, governments, public bodies, other legal authorities, and requests that are part of a legal process.
    • Comply with applicable security and anti-terrorism, anti-bribery, customs and immigration, and other due diligence laws and requirements.
We collect and use the following categories of personal data for the following purposes:
Personal Data Category
Purposes for collection / use
Sources of Personal Data
Lawful basis (where applicable)
Government issued identification data – including passport, driver’s license, government redress numbers, country of residence, tax identification number (for property owners)
  • Platform Usage and Booking Purposes
  • Security and Compliance Purposes
  • Directly from you
  • From other Expedia Group companies
  • From third parties, such as our business and affiliate partners and authorized service providers
  • Legal obligation relating to booking and/or financial transactions, such as the obligation to maintain books and records or collecting national ID numbers where legally required, including to establish identity of individuals to meet our obligations under applicable laws, including sanctions screening, money laundering and counterterrorism
  • Performance of a contract with you, such as to facilitate and process your booking(s)
Identification data – including name, username, email address, telephone number, as well as home, business, and billing addresses (including street and postal code)
  • Platform Usage and Booking Purposes
  • Communication and Customer Service Purposes
  • Marketing Purposes
  • Market Research, Analytics, and Training Purposes to improve our Services
  • Security and Compliance Purposes
  • Directly from you
  • From other Expedia Group companies
  • Automatically from your device
  • From third parties, such as our business and affiliate partners and authorized service providers
  • Legal obligation relating to booking and/or financial transactions, such as the obligation to maintain books and records, and to establish identity of individuals to meet our obligations under applicable laws, including sanctions screening, money laundering and counterterrorism
  • Performance of a contract with you (and any co-traveler), such as to facilitate and process your booking(s)
  • Legitimate interest (of you or a co-traveler), such as responding to complaints or concerns, or for marketing purposes
  • Consent (including consent of a parent/guardian for the use of child data), where requested on the platform or via customer services
Payment data - including payment card number, expiration date, billing address, financial / bank account number
  • Platform Usage and Booking Purposes
  • Communication and Customer Service Purposes
  • Security and Compliance Purposes
  • Directly from you
  • From other Expedia Group companies
  • From third parties, such as our business and affiliate partners and authorized service providers
  • Legal obligation relating to booking and/or financial transactions, such as the obligation to maintain books and records and to meet our obligations under applicable laws, including sanctions screening, money laundering and counterterrorism
  • Performance of a contract with you (and any co-traveler), such as processing payments
  • Consent, where requested on the platform
Travel related preferences - including favorite destination and accommodation types, special dietary and accessibility needs, as available
  • Platform Usage and Booking Purposes
  • Communication and Customer Service Purposes
  • Marketing Purposes
  • Market Research, Analytics, and Training Purposes to improve our Services
  • Directly from you
  • From other Expedia Group companies
  • Automatically from your device
  • From third parties, such as our business and affiliate partners and authorized service providers
  • Legitimate interest (of you or a co-traveler), such as honoring your preferences, as well as for any individuals accompanying you (e.g., co-travelers, including minors)
  • Consent, where requested on the platform
Loyalty data – including loyalty program membership (for us and/or third-party loyalty programs), loyalty points balance, points earnt and used, loyalty status
  • Platform Usage and Booking Purposes
  • Communication and Customer Service Purposes
  • Marketing Purposes
  • Market Research, Analytics, and Training Purposes to improve our Services
  • Directly from you
  • From other Expedia Group companies
  • Automatically from your device
  • From third parties, such as our business and affiliate partners and authorized service providers
  • Legitimate interest (of you or a co-traveler), such as administering or marketing our loyalty programs and benefits
  • Performance of a contract with you, such as administering our loyalty program(s)
  • Consent, where requested on the platform
Geolocation data – including inferred location from IP address, country selected to use our website, and exact, real-time location (with your consent)
  • Platform Usage and Booking Purposes
  • Communication and Customer Service Purposes
  • Marketing Purposes
  • Market Research, Analytics, and Training Purposes to improve our Services
  • Security and Compliance Purposes
  • Directly from you
  • From other Expedia Group companies
  • Automatically from your device
  • From third parties, such as our business and affiliate partners and authorized service providers
  • Legal obligation, such as complying with tax or pricing requirements and to establish identity to meet our obligations under applicable laws, including sanctions screening, money laundering and counterterrorism
  • Legitimate interest (of you or a co-traveler), such as displaying relevant content in your selected region/language
  • Consent, where requested on the platform
Images, videos and recordings – including videos, images, facial photographs you upload or that we pull from social media accounts that you connect to your profile with us (e.g. when you create an account using social media sign-in)
  • Platform Usage and Booking Purposes
  • Communication and Customer Service Purposes
  • Marketing Purposes
  • Market Research, Analytics, and Training Purposes to improve our Services
  • Security and Compliance Purposes
  • Directly from you
  • From other Expedia Group companies
  • Automatically from your device
  • From third parties, such as our business and affiliate partners and authorized service providers
  • Performance of a contract with you, such as to facilitate a booking or listing
  • Legitimate interest, such as allowing you to have a photo associated with your profile, which may be visible to only you or other third parties, as applicable
  • Consent, where requested
Communications with us – including emails, chat transcripts and recordings of calls with customer service representatives
  • Platform Usage and Booking Purposes
  • Communication and Customer Service Purposes
  • Marketing Purposes
  • Market Research, Analytics, and Training Purposes to improve our Services
  • Security and Compliance Purposes
  • Directly from you
  • From other Expedia Group companies
  • Automatically from your device
  • From third parties, such as our business and affiliate partners and authorized service providers
  • Legal obligation, such as to respond to law enforcement requests (where legally permitted)
  • Performance of a contract with you (and any co-traveler), such as to facilitate customer service interactions
  • Legitimate interest (of you or a co-traveler), such as responding to complaints or concerns
  • Consent (including consent of a parent/guardian for the use of child data), where requested
Site interaction data - including searches you conduct, transactions and other interactions with you on our platform, online services and apps
  • Platform Usage and Booking Purposes
  • Communication and Customer Service Purposes