Devour Tours (City Experiences / Hornblower Group) Privacy Policy

Updated: April 2024

Hornblower Group, Inc. its parents, subsidiaries, and affiliates (“Hornblower Group Family of Companies”) are committed to protecting the privacy of your Personal Information. The Hornblower Group Family of Companies is made up of different legal entities who offer its services and products under different brand names, including, among others, Alcatraz City Cruises, Anchor, Bridgeport Shipyard, City Cruises, City Experiences, City Ferries, Devour Tours, HMS Ferries, Hornblower, Liberty Landing Ferries, Niagara City Cruises, NYC Ferry, Seaward Services, Statue City Cruises, Venture Ashore, and Walks. privacy statement, we are referring to the relevant company in the Hornblower Group Family of Companies responsible for processing your information. If you are in the European Union, UK, or Switzerland, Hornblower Group, Inc. is the “data controller” for cityexperiences.com and is responsible for this website and any personal information that is provided via this website. For all other website domains and services, the relevant company in the Hornblower Group Family of Companies who you submit your personal information to is the data controller. If any terms of this Privacy Policy contradict the terms of any privacy policy of any of our Sites (defined below), then the terms of this Privacy Policy will govern. This policy describes how we treat personal information we collect both online and offline and the choices you have associated with that information. In addition to the Standard Privacy Policy:

If you are located in Canada, please also read our: Canadian Privacy Policy.

If you live in California, please also read our: California Privacy Policy.

If you live in the European Union, UK, or Switzerland, please also read our Special Notice to Individuals in the European Economic Area, the United Kingdom and Switzerland.

If you are located in Australia, please also read our: Australian Privacy Policy.

This Privacy Policy (“Policy”) has been designed with you in mind. How it applies to you will depend on the way in which you interact with us. For example, you might:

i. Purchase a ticket to and/or attend one of our many experience offerings; such as our charter yachts, dining cruises and ferry services or take a guided tour or excursion

ii. communicate with us through any written, electronic, and oral communications;

iii. use one of our websites or mobile applications, and all corresponding webpages and websites that link to or display this Policy (the “Sites”);

iv. create an account or subscribe to our email newsletters;

v. use any other features or content owned or operated by us; or

vi. otherwise communicate with us in relation to our business operations.

These examples and any other interaction, communication, or use of our Sites, facilities, experiences, and/or employees or independent contractors encompass our “Services”. Your choices and rights with respect to each interaction are explained in more detail below. Click on “Learn More” under each icon for more information or scroll down to read the full policy.

What Information We Have and Where We Get It

We collect and store different types of information about you when you create an account, buy tickets, attend our experience offerings, contact us, use our Sites, use apps and social media or otherwise submit Personal Information to us. This information includes, where applicable, Identity, Contact, Financial, Technical, Profile, Audio and Video, Electronic, Usage, Geolocation, Marketing and Communications, Recruitment, and some Health Data. We may also draw Inferences from this information about your interests and preferences. We collect personal information by fair and lawful means and, wherever appropriate, directly from you. LEARN MORE

How We Use Your Information and Why

We will collect and use your information for lots of reasons such as helping you get access to our Services, sharing news, for marketing and as otherwise permitted or required by law. LEARN MORE

Who We Share Your Data With and Why

We may disclose your Personal Information with partners and other third parties associated with our Service. These may include other companies affiliated with Hornblower, IT and system administration service providers, professional advisers, advertising partners, data analytics providers, and others in order to assist in providing our Service to you; We may also disclose to other parties where required or permitted by law. LEARN MORE

Looking After Your Information

The security of your data is important to us and we take steps to try to make sure your information is protected and to delete it securely when we no longer need it. However, perfect security does not exist, and we cannot guarantee the absolute security of your Personal Information. Your Personal Information may be processed in another country, and accordingly, may be accessible to courts, law enforcement and national security authorities in those countries. LEARN MORE

Contact Us

If you have any questions or feedback about this Privacy Policy, please contact us by emailing us at [email protected]. LEARN MORE

STANDARD PRIVACY POLICY

What Information We Have and Where We Get It

Personal Information is any information that relates to you, identifies you personally or could be used to identify you, such as your user ID, name, email address, name, phone number, address and payment account number. The types of Personal Information that we may collect about you include, but are not limited to:

  • We collect information you provide us directly:

We collect information you share with us when you use our Services. For example, when you book charter yacht, dining cruise and ferry services through our Sites or by calling us, we may ask your name, street address, email address, and payment information. When you fill out a booking form with us on our Sites, we may collect your name, email, phone, company name and party information. We may also collect your Personal Information in connection with employment at Hornblower that you leave at our Site.

  • We collect information from you passively:

We may collect information about your use of the Services. For example, we may collect information that your browser sends whenever you visit our Sites or when you access the Sites by or through a mobile device (“Usage Data”). This Usage Data may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data. When you access the Service with a mobile device, this Usage Data may include information such as the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data. We may also use and store information about your location if you give us permission to do so (“Location Data”). We use this data to provide features of our Service, to improve and customize our Services. You can enable or disable location services when you use our Services at any time by way of your device settings. LEARN MORE

  • We collect information about you from our Affiliates and Subsidiaries:

We may get your Personal Information from a company controlled by or under common control with Hornblower.

  • We collect information about you from third parties:

For example, if you use a social media feature with our Sites or post to a social media platform, the social media site will give us some information about you. If we collect information about you from another person, including a family member, friend, or travel agent, who seeks to use our Services on your behalf, that person will be asked to provide us with the same personal information that we would normally collect from you directly to complete your booking. We consider that person to have your consent and authorization to provide us with your personal information for relevant purposes described in the policy, unless and until we are advised otherwise.

How We Use Your Information and Why

  • We use information to provide you with products and services

We will use your Personal Information to provide information or deliver Services that you request and to allow you to participate in interactive features of our Service when you choose to do so. If the applicable information is to be provided or Service is to be performed by a third party, then we will disclose the applicable information to the third party providing the information or performing applicable Services. Your information may be available or provided to third-party service providers and contractors that are contractually obligated to protect your information as disclosed in this Policy.

  • We use information to update you on changes to our services

We will send you administrative or account-related information to notify you about changes to our Service. Such communications may include information about Policy updates, confirmations of your transactions, security updates or other relevant transaction-related information. We process your contact information to send you such communications. Service-related communications are not promotional in nature. You are not able to unsubscribe from such communications, otherwise you may miss important developments relating to your account or the Services.

  • We use information to respond to your requests or questions

We collect any information that you provide to us when you contact us, such as with questions, concerns, feedback, disputes or issues. Without your Personal Information, we cannot respond to you or ensure your continued use and enjoyment of the Services.

  • We use information to send you Marketing and Promotional Communications

We may use your Personal Information to contact you with newsletters, marketing or promotional materials, offers, and other information that may be of interest to you based on the Services that you already purchased or enquired about unless you have opted not to receive such information. You may opt-out of receiving any, or all, of these emails from us by following the unsubscribe link or the instructions provided in any email we send. You may opt of our SMS/texting program by messaging STOP to any SMS message we send. We will not purchase consent, or sell, rent or share consent to opt-in to our mobile SMS/texting program.

  • We use information to improve our services

We will use your information to gather analysis or valuable information so that we can improve our Services and to detect, prevent and address technical issues. We may also use your information to monitor the usage of our Services including without limitation search terms entered, pages visited and documents viewed.

  • We use information to enforce compliance with our policies

When you access or use our Services, you are bound to our Terms of Use which may be found at this link or on the Site you made your purchase on, the applicable Service Terms and Conditions for purchases which may be found at this link or on the Site you made your purchase from, the applicable Rewards Terms if participating in a Rewards program, and this Policy. To ensure you comply with them, we process your Personal Information by actively monitoring, investigating, preventing and mitigating any alleged or actual prohibited, illicit or illegal activities on our Services. We also process your Personal Information to: investigate, prevent or mitigate violations of our internal terms, agreements or policies; enforce our agreements with third parties and business partners; and, as applicable, collect fees based on your use of our Services. We cannot perform our Services in accordance with our terms, agreements or policies without processing your Personal Information for such purposes.

  • We use information to maintain legal and regulatory compliance

Our Services are subject to certain laws and regulations which may require us to process your Personal Information. For example, we process your Personal Information to pay our taxes, to fulfill our business obligations, ensure compliance with employment and recruitment laws or as necessary to manage risk as required under applicable law. Without processing your Personal Information for such purposes, we cannot perform the Services in accordance with our legal and regulatory requirements.

Who We Share Your Data With and Why

We may disclose your Personal Information with partners and other third parties associated with our Services.

  • We will share information within the Hornblower Group family of companies.

Hornblower is a part of a corporate organization that has many legal entities, business processes, management structures and technical systems, the Hornblower Group Family of Companies. Hornblower may share your Personal Information with this organization in order to provide you with the Services and take actions based on your request.

  • We will share information with third parties who perform services on our behalf.

We may employ third-party companies and individuals to facilitate our Services (“Service Providers”), provide the Services on our behalf, perform Service-related services or assist us in analyzing how our Services are used. These third parties have access to your Personal Information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

  • We may share information with third party ticket providers.

We may share information with other third party ticket providers who are providing services. For example, if you purchase a bundle package that includes offerings from a company outside the Hornblower Group Family of Companies (“Ticket Provider”), your personal data may be shared to facilitate your purchase. Once personal information is shared with a Ticket Provider, the information becomes subject to the Ticket Provider’s privacy practices.

  • We may share information if any part of our business is involved in a merger or acquisition.

If Hornblower is involved in a merger, acquisition, or asset sale (each a “transaction”) your Personal Information may be disclosed to evaluate and facilitate the transaction and/or transferred as a business asset. Where required, we will provide notice when your Personal Information is transferred or disclosed in relation to a transaction and becomes subject to different privacy policy protections.

  • We may share information if we think we have to in order to comply with the law or to protect ourselves.

Under certain circumstances, Hornblower may be required or permitted to disclose your Personal Information pursuant to applicable law or in response to valid requests by law enforcement or public authorities (e.g. a court or a government agency). Hornblower may disclose your Personal Information in the good faith belief that such action is necessary or prudent to: • comply with a legal obligation; • protect and defend the rights or property of Hornblower; • prevent or investigate possible wrongdoing in connection with the Service; • protect the personal safety of users of the Service or the public; and • protect against legal liability.

Looking After Your Information

  • We use standard security measures.

The security of your data is very important to us and we take steps to try to make sure your information is protected, but remember that no method of transmission over the Internet or method of electronic storage that is 100% secure. Our security measures include industry-standard physical, technical and administrative measures to prevent unauthorized access to or disclosure of your information, to maintain data accuracy, to ensure the appropriate use of information, and otherwise safeguard your Personal Information. While we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security.

  • We will only retain your data for as long as necessary.

Hornblower will retain your Personal Information only for as long as is necessary for the purposes set out in this Policy. We will retain and use your Personal Information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes and enforce our legal agreements and policies. Hornblower will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer periods.

  • We store information both in and outside the United States.

Your Personal Information, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. If you are located outside United States and choose to provide information to us, please note that we transfer the data, including Personal Information, to United States and process it there.

Hornblower will take reasonable steps to ensure that your Personal Information is treated securely and in accordance with this Policy and no transfer of your Personal Information will take place to an organization or a country unless there are adequate controls in place including the security of your Personal Information. If you do not want your information transferred to or processed or maintained outside of the country or jurisdiction where you are located, you should not use the Services.

  • We may link to third party sites or services we don’t control.

Our Service may contain links to other websites that are not operated by us. If you click a third-party link, you will be directed to that third-party website. We strongly advise you to review the privacy policy of every website you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party websites or services.

  • Our services are not directed to anyone under the age of 18.

We do not knowingly collect Personal Information from anyone under the age of 18 without parental consent. If you are a parent or guardian and you are aware that your Child has provided us with Personal Information, please contact us. If we become aware that we have collected Personal Information from children without verification of parental consent, we take steps to remove that information from our servers.

COOKIES POLICY AND AD CHOICES

We use common tracking technologies.

We or our vendors use several common tracking tools. These may include browser cookies. We use these tools:

  • To recognize new or past customers.

  • To store your password if you are registered on our sites.

  • To improve our website and mobile app.

  • To serve you with advertising content in which we think you will be interested. To do so, we or our business partners may observe your behaviors over time on this website and across third party websites. We may also collect information about your browsing history.

  • To better understand the interests of our customers and our website visitors.

We use cookies and similar tracking technologies to track the activity on our Services.

Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Other tracking technologies are also used such as beacons, tags and scripts to collect and track information and to improve and analyze our Services.

We use the following types of cookies on our Services:

  • Strictly Necessary Cookies – These cookies are essential because they enable you to use our Services. For example, strictly necessary cookies allow you to access secure areas on our Services. Without these cookies, some services cannot be provided. These cookies do not gather information about you for marketing purposes. This category of cookies is essential for our Services to work and they cannot be disabled.

  • Functional Cookies – We use functional cookies to remember your choices so we can tailor our Services to provide you with enhanced features and personalized content. For example, these cookies can be used to remember your name or preferences on our Services. We do not use functional cookies to target you with online marketing. While these cookies can be disabled, this may result in less functionality during your use of our Services.

  • Performance or Analytic Cookies – These cookies collect passive information about how you use our Services, including webpages you visit and links you click. We use the information collected by such cookies to improve and optimize our Services. We do not use these cookies to target you with online marketing. You can disable these cookies.

  • Third-Party Cookies – These are cookies that are provided by third-party service providers and belong in one of the cookie categories described above. These third-party providers process your Personal Information on our behalf pursuant to our instructions and obligations consistent with this Policy.

We may use third-party Service Providers to monitor and analyze the use of our Service.

n example of this is Google Analytics. Google Analytics is a web analytics service offered by Google LLC (“Google”) that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network. For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy?hl=en. Google Analytics Opt-out Browser Add-on provides visitors with the ability to prevent their data from being collected and used by Google Analytics, available at: https://tools.google.com/dlpage/gaoptout.

We do not control, and we are not responsible for, these third party Service Providers’ handling of your Personal Information and each have their own respective Privacy Policy.

For information about any other third-party Service Providers we use to monitor and analyze the use of our Service, please email us at [email protected].

We may use remarketing services to advertise on third-party websites to you after you visited our Services.

We and our third-party vendors use cookies to inform, optimize and serve ads based on your past visits to our Service. One example we use for these purposes is Google Ads. Google Ads remarketing service is provided by Google. You can opt-out of this by visiting the Google Ads Settings page: http://www.google.com/settings/ads.

Another example is Facebook Ads. You can opt-out of this by visiting the Facebook Ad Preferences page: https://www.facebook.com/help/109378269482053.

For information about any other remarketing services we use to advertise on third-party websites to you after you visited our Services, please email us at [email protected].

We may use other tracking tools as well.

To see how our Sites are performing we sometimes use conversion beacons, tags, scripts and pixels, which fire a short line of code to tell us when you have clicked on a particular button or reached a particular page. We also use these tracking technologies to analyze usage patterns on our Site. The use of these technologies allows us to record that a particular device, browser, or application has visited a particular webpage.

You can control cookies and tracking tools

Your browser may provide you with the option to refuse some or all browser cookies. You may also be able to remove cookies from your browser. You can exercise your preferences in relation to cookies served on our Site by taking the steps outlined below:

  • First-Party Cookies – You can enable, disable or delete our cookies through the browser you are using to access our Services. To do this, follow the instructions provided by your browser (usually located within the “Help”, “Tools” or “Edit” settings). Please note, if you set your browser to disable cookies, you may not be able to access secure areas of our Services and parts of the Services may not work properly for you. You can find more information about how to change your browser cookie settings at http://www.allaboutcookies.org .

  • Third-Party Cookies – Modern browsers also allow you to block third-party cookies using the steps described above.

  • Do Not Track – We do not support Do Not Track signals. Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.

Contact Us

Please contact us if you have any questions

Before using our Services, please carefully read our Terms of Use, Service Terms and Conditions, and this Policy. Unless otherwise defined in this Policy, the terms used in this Policy have the same meanings as in our Terms of Use. By using the Services, you agree to the collection and use of your Personal Information in accordance with this Policy, Terms of Use, and, if any purchases are made, any applicable Service Terms and Conditions. If you do not feel comfortable with any part of this Policy, Terms of Use or Service Terms and Conditions, you must not use, access, or purchase our Services. If you have any questions or feedback about this Privacy Policy, please contact us by emailing us at [email protected].

What we will do if there is an update to this Policy

We may update this Policy from time to time. We will notify you of any changes by posting the new Policy on this webpage and updating the effective date. If changes are significant, we will provide a more prominent notice such as email notification if applicable. Please review this Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Canada Privacy Rights

This Canadian Privacy Policy (the “Canadian Policy”) only applies to individuals that access or use our Services while located in Canada.

For the purposes of the Canadian Policy, “Personal Information” means information about an identifiable individual, including where there is a serious possibility that an individual could be identified through the use of that information. It does not include business information, such as the name, title, business address or telephone number of an employee of an organization. “Marketing Purposes” means in order to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you based on the Services that you already purchased or enquired about, if you have consented to receive such materials and/or if otherwise permitted by applicable law.

Unless otherwise stated, all other capitalized terms in the Canadian Policy have the meaning set out in the Standard Privacy Policy.

What Personal Information We Collect

We may receive, use and store the following categories of Personal Information which we have grouped together as follows:

  • Identity Data includes first name, last name, username or similar identifier.

  • Contact Data includes billing address, delivery address, email address and telephone numbers.

  • Financial Data includes bank account and payment card details.

  • Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website. When you access the Service with a mobile device, this Technical Data may include information such as the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.

  • Profile Data includes your username and password, purchases or orders made by you, company engagements made by you such as calls, emails, or web pages visited, your preferences, feedback and survey responses.

  • Audio & Video Data includes audio recordings of your voice if you call us and video footage and photographs that may be taken of the public areas of our premises, to the extent permitted by law.

  • Electronic data includes online chat transcripts, SMS or text message transcripts, or email transcripts between you and Hornblower, and any photographs, video, multimedia, or messages or content you provide on the Sites such as reviews, comments, customer service requests, survey responses, images, testimonials, social media profiles, and other content, to the extent permitted by applicable law.

  • Usage Data includes information about how you use our website, products and services. This Usage Data may include information such as the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

  • Geolocation Data includes your geolocation, to the extent you have configured your device to permit us to collect such information;

  • Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences, as well as inferences about your preferences, characteristics, behavior and attitudes.

  • Recruitment Data includes:

    • Contact details (including names, postal addresses, email addresses and telephone numbers)

    • The information you have provided via our application process, including name, title, address, telephone number, personal email address, date of birth, gender, employment history, qualifications, and previous salary and benefits (if provided).

    • Details of your references, and medical records.

  • We may also collect your Health Data. Specifically, we may collect data about:

    • Any health conditions you have;

    • Your Covid-19 vaccination status; and

    • Your dietary requirements.

  • Inferences may be drawn or created from the above listed information about your interests and preferences

The amount and the type of the information we collect, use, or disclose will be limited, wherever possible, to that which is needed to fulfil the purpose(s) identified below. We collect personal information by fair and lawful means and, wherever appropriate, directly from you.

Why We Collect Personal Information

We collect, use, and disclose Personal Information for the primary purpose of providing Services to you, including and in addition to the following purposes:

Purpose / Activity

Type of data

To register you as a new or prospective customer

(a) Identity (b) Contact

To process and deliver your purchases of our Services including:

(a) Manage payments, fees and charges

(b) Collect and recover money owed to us

(c) To enforce compliance with our Terms and Agreements or Policies

(d) Disclosure to our Service Providers

Identity

Contact

Financial

Transaction

Marketing and Communications

Audio and Video

Health

Electronic

To manage our relationship with you which will include:

(a) Communicating with you about Services you have purchased from us

(b) Notifying you about changes to our terms or privacy policy

(c) Asking you to leave a review or take a survey

(a) Identity

(b) Contact

(c) Profile

(d) Marketing and Communications

(e) Health

(f) Electronic

(i) Inference

To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)

Identity

Contact

Technical

Usage

To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you

Identity

Contact

Profile

Usage

Marketing and Communications

Technical

Geolocation

Inference

To use data analytics to improve our website, products/services, marketing, customer relationships and experiences

(a) Technical

(b) Usage

To send you promotional material and make suggestions and recommendations to you about goods or services that may be of interest to you

Identity

Contact

Technical

Usage

Profile

Geolocation

Inference

Disclosure to law enforcement or other authorities

Identity

Contact

Profile

Usage

Marketing and Communications

Technical

Geolocation

Electronic

Audio and Video

To make decisions about your selection and recruitment for a job

(a) Recruitment

Disclosure relating to mergers and acquisitions

Disclosure within our corporate organisation

(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and Communications

(f) Technical

(g) Geolocation

We may also collect, use and disclose your Personal Information as otherwise permitted or required by applicable law.

How Long We Keep Your Personal Information

As stated earlier in this Policy, we will only retain your Personal Information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Where it is no longer necessary to retain your Personal Information, we will securely delete, or in some circumstances, anonymize your Personal Information (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further statement to you. Any such anonymization would be performed in accordance with, and where allowed by, applicable law.

Disclosure of Personal Information

To provide services and effectively run our business, we may need to share your Personal Information as permitted by law. We may share your Personal Information with the following categories of recipients:

  • Other companies within the Hornblower Group Family of Companies

  • Third party Service Providers who perform services on our behalf to help provide you with Services, including IT and system administration services, marketing service providers, data analytics providers. advertising partners, recruitment agencies.

  • Third party ticket providers who may receive your personal data to provide you Services. For example, if you purchase a bundle package that includes offerings from a company outside the Hornblower Group Family of Companies (“Ticket Provider”), your personal data may be shared to facilitate your purchase. Once personal information is shared with a Ticket Provider, the information becomes subject to the Ticket Provider’s privacy practices.

  • Professional advisers including lawyers, bankers, auditors and insurers.

  • Regulators and other authorities where required by law

  • Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners are permitted to use your Personal Information in the same way as set out in this privacy statement.

We require all group companies and third party Service Providers to respect the security of your Personal Information and to treat it in accordance with the law. We do not allow our third party Service Providers to use your Personal Information for their own purposes and only permit them to process your Personal Information for specified purposes and in accordance with our instructions. Your personal data is subject a Ticket Provider’s privacy policies once the data is transferred. We do not sell the Personal Information we collect about you. We may, however, share your Personal Information with service providers or third parties in accordance with the business purposes set out in this privacy statement.

Consent

We will obtain your consent to the collection, use, and disclosure of your Personal Information where required by applicable laws and regulations. We assume you have consented to our reasonable collection and use of Personal Information consistent with the purposes for which the information was given when you initiate contact with us or voluntarily provide Personal Information to us. We also assume that when you use our Services on behalf of yourself and/or others, that you consent on behalf of you and/or others to the reasonable collection, use and disclosure of Personal Information. When using personal information for a new purpose, we will document that new purpose and ask for consent again. We will not use your personal information without your consent unless it is for the same purpose for which the information was originally collected or compiled, consistent with the purpose for which the information was originally collected or compiled or authorized or required by law to do so.

Transfer of Personal Information Abroad

Hornblower Group is headquartered in the United States and the Sites are hosted in the United States. As a result, your Personal Information may be transferred or stored outside of Canada. Personal Information you provide to us may be accessible to courts, law enforcement and national security authorities of those jurisdictions in which we transfer, store or otherwise process Personal Information.

Your Rights

Depending on your location, individuals in Canada may have certain rights with respect to their Personal Information pursuant to applicable privacy and data protection laws, subject to some restrictions and limitations pursuant to such laws, which may include the right to:

  • access, correct, rectify or update their Personal Information;

  • be informed of (and/or obtain an account of) the existence, use, and disclosure of their Personal Information, and challenge the accuracy and completeness of such information and have it amended as appropriate;

  • withdraw consent to continued collection, use or disclosure of Personal Information, subject to legal or contractual restrictions and reasonable notice;

  • acquire information about our policies and practices with respect to our handling of Personal Information; and/or

  • ask a question or address a challenge concerning compliance with applicable privacy and data protection laws to the person(s) designated as being accountable for our compliance with such laws.

Please note that you may be required to provide appropriate proof of identity in connection with a request to exercise your rights under applicable privacy and data protection laws, including in connection with a request to access or rectify your Personal Information. If you wish to exercise any of the rights set out above, please contact our Data Protection Officer at [email protected].

U.S. STATA SPECIFIC PRIVACY RIGHTS

Information for California Residents

This section describes how we use, disclose, and process your personal information within the scope of the California Consumer Privacy Act of 2018 (“CCPA”) currently in effect through December 31, 2022 and the California Privacy Rights Act of 2020 (CPRA) which will become effective on January 1, 2023. This section supplements the above Privacy Policy and only applies only to California residents.

Personal Information Categories We Collect and How We Use It

The term “personal information” as used in this California Privacy Rights section means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. “Personal information” does not include any publicly available, deidentified, aggregated or anonymized information. We also collect “Sensitive Personal Information” as that term is defined by the CPRA.

Category of Personal Information

Categories of Sources from which Personal Information Collected

Purposes for collection / use

Categories of Third Parties to Whom We Disclose Personal Information

identifiers such as a name, address, unique personal identifier, email, phone number, your device’s IP address, software, and identification numbers associated with your devices

Directly from you

Cookies on our websites

Mobile App Tracking

To provide you with products and services

To communicate with you about changes to our services, provide you with information about services, and request feedback

To respond to your requests or questions

For marketing purposes

To show you relevant ads while you are browsing the internet or using social media

To understand, optimize, develop, and improve our Sites and services

To enforce compliance with our policies

To maintain legal and regulatory compliance

With our affiliate entities

Our Service Providers

Data analytics providers like Google Analytics

Our advertising partners

Third party ticket providers

Demographic and protected classifications, such as gender

Directly from you

For marketing purposes

To show you relevant ads while you are browsing the internet or using social media

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

Data analytics providers like Google Analytics

Our advertising partners

Third party ticket providers

Payment card information

Directly from you

To provide you with products and services

To communicate with you about changes to our services, provide you with information about services, and request feedback

To enforce compliance with our policies

To maintain legal and regulatory compliance

With our affiliate entities

Our Service Providers

commercial information such as records of products or services purchased, obtained, or considered by you

Directly from you

Cookies on our websites

Mobile App Tracking

To provide you with products and services

To communicate with you about changes to our services, provide you with information about services, and request feedback.

To respond to your requests or questions

For marketing purposes

To show you relevant ads while you are browsing the internet or using social media

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

Data analytics providers like Google Analytics

Our advertising partners

Third party ticket providers

Internet or other electronic information regarding your browsing history, search history, the webpage visited before you came to our Sites, length of visit and number of page views, click-stream data, locale preferences, your mobile carrier, date and time stamps associated with transactions, and system configuration information

Directly from you

Cookies on our websites

Mobile App Tracking

Our Service Providers

For marketing purposes

To show you relevant ads while you are browsing the internet or using social media

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

Data analytics providers like Google Analytics

Our advertising partners

your geolocation, to the extent you have configured your device to permit us to collect such information

Directly from you

Cookies on our websites

Mobile App Tracking

To provide you with products and services

To communicate with you about changes to our services, provide you with information about services, and request feedback

For marketing purposes

To show you relevant ads while you are browsing the internet or using social media

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

Data analytics providers like Google Analytics

Our advertising partners

audio recordings of your voice to the extent you call us, as permitted under applicable law

Directly from you

To provide you with products and services

To respond to your requests or questions

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

Video footage of you that may be taken in the public areas of our premises, as permitted under law

Directly from you

Our service providers

To enforce compliance with our policies

To maintain legal and regulatory compliance

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

Online chat or email transcripts to the extent you contact us, as provided by law

Directly from you

To provide you with products and services

To respond to your requests or questions

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

SMS or text transcripts to the extent you opt-in or contact us, as provided by law

Directly from you

To provide you with products and services

To respond to your requests or questions

For marketing purposes

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

User content you provide to us such as comments, testimonials, images, customer service requests, photographs, and other content, as permitted by law

Directly from you

To provide you with products and services

To respond to your requests or questions

To enforce compliance with our policies

For marketing purposes

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

Data analytics providers like Google Analytics

Our advertising partners

Third party ticket providers

professional or employment-related information

Directly from you

Our Service Providers

For employment and hiring purposes

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

inferences about your preferences, characteristics, behavior and attitudes.

Directly from you

Cookies on our websites

Mobile App Tracking

Our Service Providers

For marketing purposes

To show you relevant ads while you are browsing the internet or using social media

To understand, optimize, develop, and improve our Sites and services

With our affiliate entities

Our Service Providers

Data analytics providers like Google Analytics

Our advertising partners

We generally do not collect biometric information, or education-related information. For more information about the Personal Information we collect and how we collect it, please refer to sections 1 and 2 above.

Sharing Personal Information for Business Purposes

We may disclose your Personal Information to another party for a business purpose as outlined in the chart below. When we disclose such Personal Information to a third party Service Provider, we do so pursuant to a contract that describes the purpose for such disclosure and requires the recipient to keep confidential the Personal Information and not to use if for any other purpose other than performing its duties under the contract. If we share your information with a third party ticket provider, then your data may be subject to their privacy policies once the data is transferred. For example, when you purchase bundle packages that includes services with a company outside the Hornblower Group Family of Companies (“Ticket Provider”), we may share your personal data with that company in order to provide the Services purchased. Your personal data is subject to the Ticket provider’s privacy policies once data is transferred.

Category of Personal Information or Sensitive Personal Information

Sharing for an Applicable Business Purposes

Auditing & Ad Impressions

Security & Integrity

Functionality & Debugging

Short-Term / Transient Use, Including Non-Personalized Advertising

Services Performed on Our Behalf

Marketing Services

Research & Development

Quality Control & Improvement of Our Products and Services

identifiers

Demographic or protected classifications,

Payment card information

commercial information

Internet or other electronic information

your geolocation

audio recordings

video recordings

Online chat or email transcripts

SMS or text transcripts

user content

professional or employment-related information

inferences drawn

How Long We Keep Your Personal Information

As stated earlier in this Policy, we will only retain your Personal Information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Where it is no longer necessary to retain your Personal Information, we will securely delete, or in some circumstances, anonymize your Personal Information (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further statement to you. Any such anonymization would be performed in accordance with, and where allowed by, applicable law.

California Privacy Rights

As a California resident, you have rights in relation to your Personal Information; however, your rights are subject to certain exceptions. For instance, we cannot disclose specific pieces of Personal Information if the disclosure would create a substantial, articulable, and unreasonable risk to the security of the Personal Information, your account with us or the security of our network systems.

  • Right Against Discrimination – You have the right not to be discriminated against for exercising any of the rights described in this section. We will not discriminate against you for exercising your right to know, delete or opt-out of sales.

  • Right to Know – You have the right to request in writing: (i) a list of the categories of personal information, such as name, address, email address, that a business has disclosed to third parties during the immediately preceding calendar year for the third parties’ direct marketing purposes, and (ii) the names and addresses of all such third parties. In addition, you have the right to request: (i) the categories of personal information we have collected about you, (ii) the categories of sources from which personal information is collected, (iii) the business or commercial purpose for the information collection, (iv) the categories of third parties with whom we have shared personal information, and (v) the specific pieces of personal information we hold about an individual. You have the right to request a copy of the specific Personal Information we collected about you during the 12 months before your request.

  • Right to Delete – You have the right to request us delete any Personal Information we have collected from you or maintain about you, subject to certain exceptions.

  • Right to Correct – Effective beginning January 1, 2023, if you believe that any of the personal information we maintain about you is inaccurate, under the CPRA you may submit a request for us to correct that information. Upon receipt of a verifiable request to correct inaccurate personal information, we will use commercially reasonable efforts to correct the information as you direct.

  • Right to Limit the Use of Your Sensitive Personal Information – Effective beginning January 1, 2023, you may direct us to limit the use of your sensitive Personal Information to uses that are reasonably necessary to provide our goods and services, or as needed; to ensure security and integrity; for short-term, transient use, including for non-personalized advertising; to maintain or service accounts, provide customer service, process or fulfill orders and transactions, verify customer information, process payments, provide financing, provide analytic services, provide storage, or other similar services; and to verify or maintain the quality or safety of a service or device owned, manufactured, manufactured for, or controlled by us, and to improve, upgrade, or enhance such services or devices.

To assert your right to know, delete, or correct your Personal Information or to limit the use of your Sensitive Personal Information or for any other questions or concerns, please contact us by emailing us at [email protected] or calling us toll-free at 833-311-0971. When making a request regarding your privacy rights, we may ask you to verify your identity. To do so, we may ask you to verify Personal Information we already have on file about you. If we cannot verify your identity from the information we have on file, we may request additional information from you, which we will only use to verify your identity, and for security or fraud-prevention purposes. If you exercise your right to request specific pieces of your personal information, we may require you to sign a declaration under penalty of perjury that you are the consumer whose personal information is the subject of the request.

  • Right to Opt-Out of Selling or Sharing of Your Personal Information– The CCPA broadly defines “personal information” and “selling” such that sharing identifiers and identifiers linked to you for a benefit may be considered a sale. You have the right to opt-out of having your Personal Information sold as defined in the CCPA. We do not sell your Personal Information. However, we do “share” Personal Information collected by cookies such as IP address to third parties for cross-context behavioral advertising purposes. To opt-out of the sharing of your Personal Information for this purpose, please refer to the section of this Privacy Policy entitled, “You can control cookies and tracking tools” or visit our Do Not Sell or Share My Personal Information webpage for more information.

Shine the Light Law

California residents may request a notice from us describing what categories of Personal Information (if any) we have shared with third parties, including our corporate affiliates, for direct marketing purposes during the preceding calendar year. You may request such notice once a year and free of charge. To request a notice, please email us at [email protected]. In your request, please specify that you want a “California Privacy Rights Notice.” We will respond to you with thirty (30) days or as permitted by law.

Notice of Financial Incentive

We may offer our customers a [City Experiences] loyalty program that provides certain perks, such as points that are redeemable for discounts on Services. The loyalty program is free to all customers and rewards you for using our Services. You can find a full description of the Loyalty Program, including the benefits offered, and related legal terms by reading the City Experiences Rewards Terms.We may also provide other programs, such as sweepstakes, contest, or other similar promotional campaigns (collectively, the “Programs”). When you sign up for one of these Programs, we may ask for personal information like your name and email address. Financial incentives, as defined under the “CCPA, include programs, benefits, or other offerings, including payments to consumers as compensation, for the disclosure, deletion, or sale of personal information about them. These Programs may be considered a “financial incentive” under California law because they involve the collection of personal information. When you sign up for one of the Programs and provide your personal information, for example, name and email address, the collection of personal information for the Programs may be considered a financial incentive. In such circumstances, we offer a price difference that is reasonably related to the value of your data to us in connection with the loyalty program or Programs. You may opt-out from participating in a Program at any time by contacting us using the options provided in the applicable Program rules. For full details about the loyalty program, please read the Rewards Terms. Program rules for other Programs will be released as they become available.

Information for Colorado, Connecticut, Utah, and Virginia Residents

This section provides residents of the states of Colorado, Connecticut, Utah, and Virginia with additional information regarding our collection, use and disclosure of their personal information that supplements the disclosures in our Privacy Policy above. This section uses certain terms that have the meaning given to them in the Colorado Privacy Act, Connecticut Personal Data Privacy and Online Monitoring Act, Utah Consumer Privacy Act, and Virginia Consumer Data Protection Act respectively

Personal Information Collected and Purposes of Processing Personal Information

In addition to the disclosures in our Privacy Policy above, we collect the personal information and process the personal information for the purposes detailed in the Personal Information Categories We Collect and How We Use It section above.

Disclosure of Personal Information

In addition to the disclosures in our Privacy Policy above, we disclose and share your personal information as described under Sharing Personal Information for Business Purposes in the section above.

Notice of Rewards Program

Information about our Rewards Programs and the information we collect is detailed in the Notice of Financial Incentives section above

Your U.S. State Privacy Rights

The residents of Colorado, Connecticut, Utah, and Virginia have the following rights with respect to their personal information:

  • To access personal information

  • To correct personal information (Colorado, Connecticut, and Virginia only)*

  • To delete personal information

  • To opt-out of targeted advertising

These rights are further detailed in the Your California Privacy Rights section above. Colorado residents may exercise their privacy rights by following the instructions included in the Your California Privacy Rights section above.

Special Notice to Individuals in the European Economic Area, the United Kingdom and Switzerland

This section only applies to individuals that access or use our Services while located in the EEA, United Kingdom and/or Switzerland (collectively, the “Designated Countries”). We may ask you to identify which country you are located in when you use some of the Services or we may rely on your IP address to identify which country you are located in. When we rely on your IP address, we cannot apply the terms of this section to any individual that masks or otherwise hides their location information from us so as not to appear located in the Designated Countries. If any terms in this section conflict with other terms contained in this Policy, the terms in this section shall apply to users in the Designated Countries.

  • City Cruises Limited (a company incorporated in England and Wales, with company number 00312286) is Hornblower’s representative regarding data privacy matters in the United Kingdom. Its contact details are: Cherry Garden Pier, Cherry Garden Street, Rotherhithe, London, SE16 4TU; [email protected].

  • Walks Agency Limited, a company incorporated in Ireland, is Hornblower’s representative regarding data privacy matters within the European Economic Area. Its contact details are: 114 Lower Baggot Street, Dublin D02 YX75 Ireland; [email protected]. You can direct any questions or complaints about the use or disclosure of your Personal Information to us by contacting us as set out above. We will investigate and attempt to resolve any complaints or disputes regarding the use or disclosure of your Personal Information.

If you are located in Europe and are dissatisfied with the resolution of your complaint, you may contact the applicable data protection authority in your jurisdiction in Europe using the contact details provided at http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm for further information and assistance. Where we need to collect Personal Information by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services or process your job application). In this case, we may have to cancel a product or service you have with us, or not progress your job application. We will notify you if this is the case at the time.

Categories of Personal Information Collected

We may receive, use and store the following categories of Personal Information which we have grouped together as follows:

  • Identity Data includes first name, last name, username or similar identifier.

  • Contact Data includes billing address, delivery address, email address and telephone numbers.

  • Financial Data includes bank account and payment card details.

  • Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website. When you access the Service with a mobile device, this Technical Data may include information such as the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.

  • Profile Data includes your username and password, purchases or orders made by you, company engagements made by you such as calls, emails, or web pages visited, your preferences, feedback and survey responses.

  • Audio & Video Data includes audio recordings of your voice if you call us and video footage and photographs that may be taken of the public areas of our premises, to the extent permitted by law

  • Electronic data includes online chat transcripts, SMS or text message transcripts between you and Hornblower, and any photographs, video, multimedia, or messages or content you provide on the Sites such as reviews, comments, customer service requests, survey responses, images, testimonials, social media profiles, and other content, to the extent permitted by applicable law.

  • Usage Data includes information about how you use our website, products and services. This Usage Data may include information such as the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

  • Geolocation data includes your geolocation, to the extent you have configured your device to permit us to collect such information.

  • Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences, as well as inferences about your preferences, characteristics, behavior and attitudes.

  • Recruitment Data includes:

    • Contact details (including names, postal addresses, email addresses and telephone numbers)

    • The information you have provided via our application process, including name, title, address, telephone number, personal email address, date of birth, gender, employment history, qualifications, and previous salary and benefits (if provided).

    • Details of your references, and medical records.

  • We may also collect your Health Data, which is a Special Category of Personal Information. Specifically, we may collect data about:

    • Any health conditions you have;

    • Your Covid-19 vaccination status; and

    • Your dietary requirements.

  • Inferences may be drawn or created from the above listed information about your interests and preferences

Legal Bases for Processing Your Personal Information

We have set out below, in a table format, a description of all the ways we plan to use your Personal Information, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate. Note that we may process your Personal Information for more than one lawful ground depending on the specific purpose for which we are using that data. Please contact us by emailing us at [email protected] if you need details about the specific legal ground we are relying on to process your Personal Information where more than one ground has been set out in the table below.

Purpose / Activity

Type of data

Lawful basis for processing including basis of legitimate interest

To register you as a new or prospective customer

(a) Identity

(b) Contact

Performance of a contract with you

To process and deliver your purchases of our Services including:

(a) Manage payments, fees and charges

(b) Collect and recover money owed to us

(c) To enforce compliance with our Terms and Agreements or Policies

(d) Disclosure to our Service Providers

Identity

Contact

Financial

Transaction

Marketing and Communications

Audio and Video

Health

Electronic

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to recover debts due to us and promote our Services)

(c) On the basis of your consent

To manage our relationship with you which will include:

(a) Communicating with you about Services you have purchased from us

(b) Notifying you about changes to our terms or privacy policy

(c) Asking you to leave a review or take a survey

(a) Identity

(b) Contact

(c) Profile

(d) Marketing and Communications

(e) Health

(f) Electronic

(g) Inference

(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our Services)

To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)

Identity

Contact

Technical

Usage

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise or sale of business or assets)

(b) Necessary to comply with a legal obligation

To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you

Identity

Contact

Profile

Usage

Marketing and Communications

Technical

Geolocation

Inference

Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)

To use data analytics to improve our website, products/services, marketing, customer relationships and experiences

(a) Technical

(b) Usage

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)

To send you promotional material and make suggestions and recommendations to you about goods or services that may be of interest to you

Identity

Contact

Technical

Usage

Profile

Geolocation

Inference

Marketing and Communications

Geolocation

Electronic

Necessary for our legitimate interests (to develop our products/services and grow our business)

Disclosure to law enforcement or other authorities

Identity

Contact

Profile

Usage

Marketing and Communications

Technical

Geolocation

Electronic

Audio and Video

Necessary to comply with a legal obligation

To make decisions about your selection and recruitment for a job

(a) Recruitment

(a) To take steps prior to entering into a contract with you

(b) Necessary for our legitimate interests (to ensure that we can make recruitment decisions)

Disclosure relating to mergers and acquisitions

Disclosure within our corporate organisation

(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and Communications

(f) Technical

(g) Geolocation

Based on our legitimate interests (to grow and expand our business)

1. Marketing

We strive to provide you with choices regarding certain uses of your Personal Information, particularly around marketing. We may use your Identity, Contact, Technical, Usage, Geolocation and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing). You will receive marketing communications from us if you have requested information from us, purchased goods or services from us, consented to receiving such communications or where we are pursuing a legitimate interest and have a lawful right to do so and, in each case, you have not opted out of receiving that marketing. If you do not want us to use your Personal Information in this way or to disclose your Personal Information to third parties for marketing purposes, please click an unsubscribe link in your emails or emailing us at [email protected]. You can object to direct marketing at any time and free of charge.

2. Opting Out

You can ask us to stop sending you marketing messages at any time by clicking on an unsubscribe link in your emails or emailing us at [email protected] at any time. Where you opt out of receiving these marketing messages, this will not apply to Personal Information provided to us as a result of a product/service purchase, service experience or other transactions.

3. Disclosures of Your Personal Information

To provide services and effectively run our business, we may need to share your Personal Information as permitted by law. We may share your Personal Information with the following categories of recipients:

  • Other companies within the Hornblower Group Family of Companies;

  • Service providers (which may include “service providers” as that term is defined under the General Data Protection Regulation, including IT and system administration services and recruitment agencies;

  • Third party ticket providers who are entities outside the Hornblower Group Family of Companies (“Ticket Providers”), but from whom you purchased services from our Sites.

  • Professional advisers including lawyers, bankers, auditors and insurers;

  • Regulators and other authorities where required by law;

  • Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners are permitted to use your Personal Information in the same way as set out in this privacy statement.

We require all group companies and third party Service Providers to respect the security of your Personal Information and to treat it in accordance with the law. We do not allow our third party Service Providers to use your Personal Information for their own purposes and only permit them to process your Personal Information for specified purposes and in accordance with our instructions. Your personal data is subject a Ticket Provider’s privacy policies once the data is transferred. We do not sell the Personal Information we collect about you. We may, however, share your Personal Information with group companies, service providers, or third parties in accordance with the business purposes set out in this privacy statement.

4. International Transfers

Hornblower Group is headquartered in the United States and the Sites are hosted in the United States. As a result, if you are located in Europe or the United Kingdom your Personal Information may be transferred outside Europe. Personal Information that is voluntarily provided to us may be maintained or accessed in servers or files located in the United States, which some or all of the Designated Countries have not deemed to provide “adequate” privacy safeguards. If you do not consent to having your Personal Information processed and stored in the United States, please do not provide it to us. By voluntarily providing your Personal Information on or via the Sites, you acknowledge and accept that your Personal Information will be transferred, processed and stored in the United States. Some of our third party service providers and group companies are based outside the Designated Countries so their processing of your Personal Information will also involve a transfer of data outside the Designated Countries. Whenever we transfer your Personal Information out of the Designated Countries, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented: We will only transfer your Personal Information to countries that have been deemed to provide an adequate level of protection for Personal Information by the European Commission. Where we use certain providers or transfer data between the Hornblower Group Family of Companies, we may use specific contracts approved by the European Commission which give Personal Information the same protection it has in Europe. For further details, see: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en for the EU, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/ for the UK, and https://www.edoeb.admin.ch/edoeb/en/home/datenschutz/arbeit_wirtschaft/datenuebermittlung_ausland.html for Switzerland. Please contact us at the details set out above if you are located in Europe and want further information on the specific mechanism used by us when transferring Personal Information out of Europe.

5. Data Security

We have put in place procedures to deal with any suspected Personal Information breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

6. Data Retention

As stated earlier in this Policy, we will only retain your Personal Information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Where it is no longer necessary to retain your Personal Information, we will securely delete, or in some circumstances, anonymize your Personal Information (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further statement to you. Any such anonymization would be performed in accordance with, and where allowed by, applicable law. To determine the appropriate retention period for your Personal Information, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorized use or disclosure of your Personal Information, the purposes for which we process your Personal Information and whether we can achieve those purposes through other means, and the applicable legal requirements.

7. Your Legal Rights as a Resident of the Designated Countries

If you are located in the Designated Countries, under certain circumstances, you have rights under data protection laws in relation to your Personal Information. These rights include: Request access to your Personal Information (commonly known as a “data subject access request”): this enables you to receive a copy of the Personal Information we hold about you and to check that we are lawfully processing it. Request correction of the Personal Information that we hold about you: this enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us. Request erasure of your Personal Information: this enables you to ask us to delete or remove Personal Information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your Personal Information where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your Personal Information to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request. Object to processing of your Personal Information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your Personal Information for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms. You have the right not to be subject to automatic decision-making, including profiling. We sometimes use our computers and technology to study your personal information. This helps us to use this information so we know how you use our services, and make suggestions and recommendations to you about goods or services that may be of interest to you. Request restriction of processing of your Personal Information. This enables you to ask us to suspend the processing of your Personal Information in the following scenarios:

  • (a) if you want us to establish the data’s accuracy;

  • (b) where our use of the data is unlawful but you do not want us to erase it;

  • (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or

  • (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Request the transfer of your Personal Information to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Information in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you. Withdraw consent at any time where we are relying on consent to process your Personal Information. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent. If you wish to exercise any of the rights set out above, please email us at [email protected]. We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Information (or to exercise any of your other rights). This is a security measure to ensure that Personal Information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

AUSTRALIAN PRIVACY RIGHTS

The Australian Privacy Policy (“Australian Policy”) supplements the above Standard Privacy Policy and only applies to the management of personal information collected in Australia. We will manage personal Information that is subject to the Australian Policy in accordance with the Australian Privacy Principles (“APPs”) set out in the Privacy Act 1988 (Cth) (“Privacy Act”). For the purposes of the Australian Policy,

“Personal Information” means any information or an opinion about an identified individual, or individual who is reasonably identifiable.

“Sensitive Information” means any personal information about a person’s racial or ethnic origin, political opinion, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual preferences or practices, criminal record or health information.

Unless otherwise stated, all other capitalized terms in the Australian Policy have the meaning set out in the Standard Privacy Policy.

Sensitive Information

We will not ask you to disclose sensitive information (other than health information) to us. If sensitive information (other than health information) is disclosed to us, we will take reasonable steps to de-identify the data or destroy it where we can. Otherwise, Sensitive Personal Information will be dealt with in accordance with the Standard Privacy Policy. We may collect information about your health, where necessary for safety reasons, to facilitate provision of your access to our products and services, and for insurance purposes. Specifically, we may collect data about:

  • Any health conditions you have;

  • Your Covid-19 vaccination status; and

  • Your dietary requirements

Security of information

The security of your information is very important to us. We regularly review developments in security and encryption technologies. Unfortunately, no data transmission over the internet can be guaranteed as totally secure. We take all reasonable steps to protect the information in our systems from misuse, interference, loss, and any unauthorised access, modification or disclosure. If we no longer require your information, and we are legally permitted to, we will take all reasonable steps to destroy or de-identify the information. We take reasonable steps to preserve the security of cookie and personal information in accordance with the Australian Policy. If your browser is suitably configured, it will advise you whether the information you are sending us will be secure (encrypted) or not secure (unencrypted).

Overseas recipients

Some personal information may be transferred to countries outside of Australia in the course of our business. We may share Personal Information overseas for reasons including where we have engaged a service provider or a member of the Hornblower Group Family of Companies to assist us with certain technology or data storage functions. Your Personal Information may be shared with parties located overseas, including in the following countries, and other countries from time to time:

  • Australia;

  • the United States;

  • Canada;

  • the European Union;

  • the United Kingdom;

  • Switzerland;

  • Singapore; and

  • India

When we disclose Personal Information outside of Australia, we will comply with this Australian Policy and the Privacy Act. If you do not agree to the transfer of your personal information outside of Australia, please contact us. In these circumstances, we may be prevented from providing products or services to you.

How do we hold your personal information?

All Personal Information held by us will be handled and stored in accordance with our obligations under the Privacy Act. We will take reasonable steps to:

  • implement practices, procedures and systems in our business that will ensure compliance with our legal obligations and to deal with inquiries or complaints about compliance with our legal obligations;

  • make sure that the Personal Information we collect, use or disclose is accurate, complete and up to date;

  • protect the information from misuse, interference, loss or unauthorised access, modification or disclosure both physically and through security methods; and

  • destroy or permanently de-identify the information if it is no longer needed for any purpose.

Please notify us promptly if you become aware of any breach of security. We will comply with all mandatory notification requirements in respect of security breaches as required by the Privacy Act.

Access your personal information

You are entitled to request access to any of the Personal Information we hold about you. If you would like to request access to your Personal Information, or if you would like to request to receive an electronic copy of your Personal Information for purposes of transmitting it to another company (to the extent this right of data portability is provided to you by applicable law), please contact us at: Email: [email protected] You will not be charged for making a request to access your Personal Information, but to the extent permitted by law, you may be charged for the reasonable time and expense incurred in compiling information in response to your request. For your protection we may need to verify your identity before implementing your request. We will comply with your request within a reasonable period after you make your request.