Privacy and Security Policy of www.staycobblestone.com
Hotels franchised under Owner’s brands (“Franchised Hotels”) are independently owned and operated. Users Personal Data (defined later in this Policy) collected or maintained directly by the Franchised Hotels is not subject to this policy, unless such information has been shared with Owner, in which case the policy only covers Owner’s collection, use, and maintenance of User’s Personal Data. Owner does not control the collection, use, or access of User’s information by the Franchised Hotels and their staff. The Franchised Hotels are merchants who collect and process credit card information and receives payment for User’s booking. The Franchised Hotels are subject to the merchant rules of the credit card processors they select, which establish credit card security rules and procedures.
By submitting User’s Personal Data to us, User agrees to the transfer to and processing of User’s Personal Data in accordance with the terms of this Policy.
OWNER AND DATA CONTROLLER
Cobblestone Hotels, LLC
980 American Dr
Neenah, WI 54956
Owner contact email: Website@staycobblestone.com
TYPES OF DATA COLLECTED
Our Websites and mobile applications may receive and store information based on User’s browser settings, which may include User’s browser type and operating system, Owner’s various web pages, User views, Internet Protocol addresses, unique device identifiers, and sites visited before viewing Owner’s Website.
If User is using a mobile app, Owner may also receive User’s precise or general geo-location information depending on User’s device settings. Owner’s mobile apps may use User’s device’s Global Positioning System (GPS) or other technology to locate a hotel near User and/or to provide User with other relevant location-based information and/or services. User’s location may be shared with Owner’s business partners to make services or products available to User, such as food delivery or local entertainment. User’s may have the option to opt-out of such sharing through User’s device’s settings but Owner and third-parties may still collect general location information (country, state, city) via IP address or other device information. The last location of User’s mobile device when the mobile app was open may be stored by Owner or third-parties for marketing. To the extent any geo-location data is combined with personal information, that information will be treated as personal information in accordance with this policy.
When User uses Owner’s reservation system, calls the toll-free reservation telephone number, enters the Cobblestone Rewards Program, creates an account with Owner, opts-in to receive offers, or purchases a gift card, Owner collects personally identifiable information, such as User’s name, address, telephone number, e-mail address, accommodation preference, credit card details, birth date, and Cobblestone Rewards member number, as well as various other types of data, such as Usage Data and Cookies (each as defined later in this Policy). Owner may also collect information related to User’s military status or other membership numbers such as associations user is a member of, corporate account number, loyalty program membership number, or group booking number.
When User requests information regarding franchise opportunities from our informational Website, http://www.cobblestonefranchising.com,or elsewhere, Owner may collect information such as User’s contact details, User’s hotel ownership or development experience, the brand User is interested in, and the amount User expects to invest in the franchise.
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Website.
Unless specified otherwise, all Data requested by this Website is mandatory and failure to provide this Data may make it impossible for this Website to provide its services. In cases where this Website specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Users are responsible for any third-party Personal Data obtained, published or shared through this Website and confirm that they have the third party's consent to provide the Data to the Owner.
The Website is not directed to children under the age of 13. Users declare themselves to be adult according to their applicable legislation. Minors may use this Website only with the assistance of a parent or guardian. Under no circumstance persons under the age of 13 may use this Website.
MODE AND PLACE OF PROCESSING THE DATA
Methods of processing
Owner’s reservation system and other databases are maintained in the United States. User’s Personal Data will be collected (or transferred) and maintained in the United States. Once User’s information is received by Owner, it is treated as confidential and protected it through a variety of generally accepted industry standards, such as encryption.
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. Owner does not sell, trade, rent, or release User’s Personal Data to anyone outside of Owner’s company, contractors, affiliates or Franchised Hotels, other than in compliance with this privacy and security policy. Owner and its affiliates use the Personal Data in the ordinary course of business, administer customer service, assist with User’s online experience, contact User regarding their booking, and make other rewards, products and services available. Owner does share User information Franchised Hotels, credit card issuers, and other companies where necessary to complete a transaction. Owner may also use Personal Data to send User promotional communications by mail or e-mail and share Personal Data with third-parties Owner has contracted with for the purpose of communications and the provision of products and services.
The Personal Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Personal Data may be accessible to certain types of persons in charge, involved with the operation of this Website (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as data processors by the Owner. The updated list of these parties may be requested from the Owner at any time by contacting Website@staycobblestone.com or sending notification to Cobblestone Hotels, LLC, Attn: Legal Department, 980 American Drive, Neenah, WI 54596.
Owner maintains a centralized reservations system that will retain User’s personally identifiable information when a reservation is made by way of Owner’s Website, mobile applications, call center, Franchised Hotels and third-party travel agents or travel Websites that connect to Owner’s reservation system. User’s Personal Data is needed to process the transaction made and will be processed primarily in the United States to complete User’s transaction and assist with future transactions for User’s convenience. Only Personal Data that is reasonably required to conclude User’s transaction and assist with the convenience of future transactions is collected and shared, as such sharing is described in this Policy.
Owner may use User’s Personal Data to contact User regarding User’s transaction with it or a Franchised Hotel. Owner may also use User’s Personal Data to send travel-related messages, transaction information, helpful information about the area that User is staying, notifications about special offers and promotions, and customer service or market research surveys, in which participation is optional.
If User is a member of the Cobblestone Rewards Program, User’s Personal Data will be used for administrative tasks necessary for the administration and operation of the Program, including, but not limited to, tracking points earned, accounting for the redemption of points, providing User with Program details, account information, surveys, promotional offers, third party offers and other products and services that are offered only to Cobblestone Rewards Members.
To the extent required or permitted by law, Owner may collect, use and disclose Personal Data in connection with security-related or law enforcement investigations or in the course of cooperating with authorities or complying with legal requirements. Owner may also use Personal Data as permitted by law to perform credit checks, report or collect debts owed, or protect the rights or property of Owner, its employees, the Franchised Hotels, other customers, this Website, or its Users.
Legal basis of processing
The Owner may process Personal Data relating to Users if one of the following applies:
- Users have given their consent for one or more specific purposes. Note: Under some legislations the Owner may be allowed to process Personal Data until the User objects to such processing (“opt-out”), without having to rely on consent or any other of the following legal bases. This, however, does not apply, whenever the processing of Personal Data is subject to European data protection law;
- provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
- processing is necessary for compliance with a legal obligation to which the Owner is subject;
- processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
- processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party;
- Owner has reason to believe that it is necessary to identify, contact or bring legal action against persons or entities who may be causing injury to User, to Owner or to others; or
- in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings).
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing of Personal Data and, in particular, whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Place of Processing
The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located, including the Franchised Hotels.
Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.
If any such transfer takes place, Users can find out more by checking the relevant sections of this document or inquire with the Owner using the information provided in the contact section.
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
- Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
- Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
THE PURPOSES OF PROCESSING
The Data concerning the User is collected to allow the Owner to provide its Services, as well as for the following purposes: Contacting the User, Data transfer outside the EU, Displaying content from external platforms, remarketing and behavioral targeting and Analytics.
Users can find further detailed information about such purposes of processing and about the specific Personal Data used for each purpose in the respective sections of this document.
DETAILED INFORMATION ON THE PROCESSING OF PERSONAL DATA
Personal Data is collected for the following purposes and using the following services:
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Google Analytics with Anonymized IP (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google utilizes the Data collected to track and examine the use of this Website, to prepare reports on its activities and share them with other Google services. Google may use the Data collected to contextualize and personalize the ads of its own advertising network. This integration of Google Analytics anonymizes User’s IP address. It works by shortening Users' IP addresses within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the complete IP address be sent to a Google server and shortened within the US.
Google Analytics uses “Cookies”, which are text files placed on User’s computer, to identify User as a unique user and help analyze how Users use this site. The information generated by the cookie about User’s use of the Website (including User’s IP address) will be transmitted to and stored by Google on servers in the United States. This information is used for the purpose of evaluating User’s use of Owner’s Website, compiling reports on Website activity and providing other services relating to Usage Data. The ad formats utilized through Google may include remarketing on Google’s display and search network.
Remarketing and Behavioral Targeting (Generally)
Third Party Ad Networks
Owner may also work with third parties that use tracking technologies in order to provide tailored advertisements across the Internet. These companies may collect information about User’s activity on Owner’s sites and User’s interaction with Owner’s advertising and other communications and use this information to determine which ads User sees on third party Websites and applications. For further reference, see www.aboutads.info.
Technical Cookies and Cookies Serving Aggregated Statistical Purposes
User can generally set User’s browser to not accept Cookies or to notify User when User is sent a cookie, providing the chance to decide whether or not to accept it. Not accepting Cookies will adversely affect User’s ability to perform certain transactions and functions on Owner’s Websites.
Other Types of Cookies or Third Parties That Install Cookies
Some of our third party providers collect statistics in an anonymized and aggregated form and may not require the consent of the User or may be managed directly by the Owner - depending on how they are described - without the help of third parties.
How to Provide or Withdraw Consent to Installation of Cookies
In addition to what is specified in this document, the User can manage preferences for Cookies directly from within their own browser and prevent – for example – third parties from installing Cookies.
Through browser preferences, it is also possible to delete Cookies installed in the past, including the Cookies that may have saved the initial consent for the installation of Cookies by this Website.
Users can, for example, find information about how to manage Cookies in the most commonly used browsers at the following addresses: Google Chrome, Mozilla Firefox, Apple Safari and Microsoft Internet Explorer.
Notwithstanding the above, the Owner informs that Users may follow the instructions provided on the subsequently linked initiatives by the EDAA (EU), the Network Advertising Initiative (US) and the Digital Advertising Alliance (US), DAAC (Canada), DDAI (Japan) or other similar services. Such initiatives allow Users to select their tracking preferences for most of the advertising tools. The Owner thus recommends that Users make use of these resources in addition to the information provided in this document.
Contacting the User
Owner respects the right of each User to control how his or her Personal Data is used. If User does not want Owner to provide Personal Data to its business partners, or if User does not wish to receive promotional communications from Owner or its affiliates concerning special offers, discounts, or other promotions, use the “Unsubscribe” function in the e-mail received from Owner. User can also change privacy settings in User’s browser.
User can also e-mail Owner at Website@staycobblestone.com or write to Cobblestone Hotels, LLC, Attention: Legal Department, 980 American Drive, Neenah, WI 54956. Please include User’s name, address, e-mail address andCobblestone Rewards number (if applicable) and clearly state the nature of User’s request.
Contact Form on Owner’s Website
By filling in the contact form with User’s Personal Data, the User authorizes Owner’s Website to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form’s header.
Personal Data collected: User’s name, address, telephone number, e-mail address, accommodation preference, credit card details, birth date, and Cobblestone Rewards member number, as well as various types of Data, Usage Data and Cookies (discussed below).
Data Transfer Outside the EU
Owner is allowed to transfer Personal Data collected within the EU to third countries (i.e. any country not part of the EU) only pursuant to a specific legal basis. Owner has centralized certain aspects of its data processing, allowing Owner to better manage our business as a whole. That centralization will result in the transfer of personal information from one country to another. These countries may have data protection laws that are different to the laws of User’s country (and, in some cases, may not be as protective).
Owner’s Website servers are located in the United States, and Owner has business relationships globally. This means that when Owner collects Personal Data it may be processed globally if there is a legal basis to do so. If there is a legal basis, Personal Data of Users shall be transferred from the EU to third countries only if the User has explicitly consented to such transfer, after having been informed of the possible risks due to the absence of an adequacy decision and appropriate safeguards. In such cases, the Owner shall inform Users appropriately and collect their explicit consent via this Website.
To facilitate transferring European Economic Area (EEA) citizens’ Personal Data out of the EEA countries, Owner incorporates the Standard Contractual Clauses approved by the EU Commission into applicable contract agreements to ensure that the necessary levels of protection and care are required of all parties. Information about the European Commission’s Standard Contractual Clauses and a copy of the Standard Contractual Clauses can be found at: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en. Additional information about Owner’s incorporation of the Standard Contractual Clauses in its contract agreements or the data protection measures associated with data transfers can be requested by sending Owner notice at Cobblestone Hotels, LLC, Attention: Legal Department, 980 American Drive, Neenah, WI 54956.
Other Legal Basis for Data Transfer Abroad (This Website)
If no other legal basis applies, Personal Data shall be transferred from the EU to third countries only if at least one of the following conditions is met:
- the transfer is necessary for the performance of a contract between the User and the Owner or of pre-contractual measures taken at the User’s request;
- the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the User between the Owner and another natural or legal person;
- the transfer is necessary for important reasons of public interest;
- the transfer is necessary for establishment, exercise or defense of legal claims;
- the transfer is necessary in order to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent. In such cases, the Owner shall inform the User about the legal bases the transfer is based on via this Website.
Displaying Content from External Platforms
This type of service allows User to view content hosted on external platforms directly from the pages of this Website and interact with them. This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.
Fonts.com Web Fonts (Monotype Imaging Holdings Inc.)
Fonts.com Web Fonts is a typeface visualization service provided by Monotype Imaging Holdings Inc. that allows this Website to incorporate content of this kind on its pages.
FURTHER INFORMATION ABOUT PERSONAL DATA
Sojern employs online Cookies and mobile device IDs to collect travel intent data from users that is pseudonymous. They do not collect information that would personally identify users, such as name, address, email address, social security number, or phone number.
Examples of the type of travel intent data that Sojern collects include destination information, dates and length of stay and number of travelers.
Sojern does not store nor sell any of the data it collects; it processes travel intent data to create travel audiences that power advertising campaigns for clients.
You can read more, as well as opt out here: Sojern Privacy Center
CHILD PRIVACY RIGHTS
Under no circumstances may persons under the age of 13 use this Website.
Users declare themselves to be adult according to their applicable legislation. Minors (under the age of 18) may use this Website only with the assistance of a parent or guardian.
THE RIGHTS OF USERS
Users may exercise certain rights regarding their Data processed by the Owner.
In particular, Users have the right to do the following:
- Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
- Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent. Further details are provided in the dedicated section below.
- Access their Data. Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
- Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
- Restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
- Have their Personal Data deleted or otherwise removed. Users have the right, under certain circumstances, to obtain the erasure of their Data from the Owner.
- Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the Data is processed by automated means and that the processing is based on the User's consent, on a contract which the User is part of or on pre-contractual obligations thereof.
- Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.
Details About the Right to Object to Processing
Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Owner or for the purposes of the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time without providing any justification. To learn, whether the Owner is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to Exercise These Rights or Submit a Complaint
Any requests to exercise User rights can be directed to the Owner at Website@staycobblestone.com or write to Cobblestone Hotels, LLC, Attention: Legal Department, 980 American Drive, Neenah, WI 54956. Please include User’s name, address, e-mail address andCobblestone Rewards number (if applicable) and clearly state the nature of User’s request. These requests can be exercised free of charge and will be addressed by the Owner as early as possible and always within one month.
Owner will work with User to address complaints, which may include contacting applicable authorities as part of the resolution process.
ADDITIONAL INFORMATION ABOUT DATA COLLECTION AND PROCESSING
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Website or the related Services. The User declares to be aware that the Owner may be required to reveal Personal Data upon request of public authorities.
Owner is only responsible for the privacy and security policy and content on this website and Owner’s mobile apps. Staycobblestone.com and its mobile apps may redirect to other websites and mobile apps. Those websites and mobile apps are not covered by this privacy and security policy, and OWNER IS not responsible for the privacy practices or the content of those other websites and mobile apps.
Additional Information About User's Personal Data
System Logs and Maintenance
For operation and maintenance purposes, this Website and any third-party services may collect files that record interaction with this Website (system logs) use other Personal Data (such as the IP Address) for this purpose.
Information Not Contained in This Policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time at Website@staycobblestone.com or write to Cobblestone Hotels, LLC, Attention: Legal Department, 980 American Drive, Neenah, WI 54956. Please include User’s name, address, e-mail address andCobblestone Rewards number (if applicable) and clearly state the nature of User’s request. These requests can be exercised free of charge and will be addressed by the Owner as early as possible and always within one month
How “Do Not Track” Requests Are Handled
Do Not Track Signals: Some web browsers offer a "Do Not Track" ("DNT") signal that is an HTTP header field indicating User’s preference regarding tracking or cross-site user tracking. This Website currently does not recognize “Do Not Track” requests. To determine whether any of the third-party services Owner uses honor the “Do Not Track” requests, please read their privacy policies.
By using Owner’s Website User consents to Owner’s collection and use of User’s Personal Data as described in this policy. Owner reserves the right to modify this privacy and security policy and related business practices at any time by posting updated text on this Website. Any changes to this policy become effective upon posting of the revised policy to this Website. Use of this Website following such changes constitutes User’s acceptance of the revised policy then in effect. Should the changes affect processing activities performed based on the User’s consent, the Owner shall collect new consent from the User, where reasonably required.
It is strongly recommended that User check this page often, referring to the date of the last modification listed at the bottom.
Definitions and Legal References
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Information collected automatically through this Website (or third-party services employed in this Website), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Website, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
The individual using this Website who, unless otherwise specified, coincides with the Data Subject.
The natural person to whom the Personal Data refers.
Data Processor (or Data Supervisor)
Data Controller (or Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Website. The Data Controller, unless otherwise specified, is the Owner of this Website.This Website (or this Application)
The means by which the Personal Data of the User is collected and processed.
The service provided by this Website as described in the relative terms (if available) and on this site/application.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Small sets of data stored in the User's device.
Latest update: December 6, 2019