Privacy Policy
This Privacy Policy (“Privacy Policy” and “Policy”) applies to the collection and use of Personal Information by XPERIENCE RESTAURANT GROUP (“Company”, or “we,” or “us,” or “our”). It describes the Company’s practices regarding the collection, use, disclosure, and sale of Personal Information when you visit our websites or mobile applications (the “Sites”), when you communicate with us via email, when you visit our restaurants, and when you engage with us offline. It also describes the rights residents of California may have regarding their Personal Information. By accessing the Sites and using our services, you agree to our collection and use of Personal Information as described herein and you agree to our Terms of Use.
This Policy does not apply to information we collect about employees, job applicants, and independent contractors, or individuals when acting as representatives (e.g., employees, contractors) of entities with which we do business.
For purposes of this Policy, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. It does not include de-identified or aggregate information, or public information lawfully available from governmental records.
Notice at Collection: Personal Information We Collect
We may collect Personal Information such as:
- Personal identifiers: Name, address, email address, telephone numbers, IP address or other unique identifier, birthdate, account password and name; anniversary date; favorite location and restaurant; educational information; geo location
- Financial information: Credit card or payment card information; household income
- Protected class information: Age, military or veteran status;
- Commercial information: Records of purchases, records of reward program participation including points accumulated and redeemed; dates, times and locations of purchases;
- Internet or other electronic activity information: Device and browser type, your browsing and search history on our Sites, and information regarding your interaction with our Sites and our advertisements;
- Professional information: First responder status (to offer you specials);
- Audio and visual information: Recordings of customer telephone calls, video of you captured on CCTV security cameras installed in our restaurants;
- Inferences drawn from any of the Personal Information identified above.
We have collected the same categories of personal information in the 12 months prior to the date of this Privacy Policy
Notices at Collection: Purposes for Collection of Personal Information
We use your Personal Information in the following ways:
- To enable us to process, validate and verify your requests for products and services;
- To facilitate your participation in our rewards program;
- For marketing and advertising, including to alert you to new projects, Sites features, special events and services;
- To provide our partners and affiliates with information about you so that they can offer products or services you might be interested in receiving;
- To provide you with information about the Company;
- To conduct surveys to measure your satisfaction with our services;
- To monitor and evaluate our Sites, including to improve their functionality;
- For internal business analysis, including to develop new features and services to meet customer needs; and
- To facilitate your participation in our rewards program
Additionally, we use Personal Information, including about your use of our Sites, to monitor or improve our Sites; to prevent fraud, activities that violate our Terms of Service or that are illegal; and to protect our rights and the rights and safety of our users or others.
Notice at Collection: Retention Periods
We retain the categories of personal information we collect for the length of time necessary to provide our services and to comply with legal obligations or to protect our legal rights.
Sources From Which We Collect Personal Information
In the 12 months preceding the date of this Policy, we may have collected your Personal Information when you visited our Sites, including by submitting orders, reservations, booking events or inquiring about our services; joined and participated in our rewards program; purchased or activated gift cards; requested information about our restaurants; participated in our surveys; visited our restaurants; or when you voluntarily provided information to us. We will continue to collect Personal Information from the same sources.
Disclosure of Personal Information For Business Purposes in the Past 12 Months
The following chart describes the categories of Personal Information that we disclosed to third parties for a business purpose in the 12 months prior to the date of this Policy:
Categories of Consumers’ Personal Information
- Personal identifiers: Name, address, email address, telephone numbers, IP address or other unique identifier; birthdate, account password and name; anniversary date; favorite location and restaurant
- Protected class information: Age, military or veteran status.
- Commercial information: Records of purchases, records of reward program participation including points accumulated and redeemed.
- Professional information: First responder status (to offer you specials).
- Financial information: Credit card or payment card information.
- Internet or other electronic network activity information: Device and browser type, browsing and search history on our Sites, and information regarding interaction with our Sites and our advertisements.
- Inferences generated from any of the above categories of Personal Information.
Categories of Third Parties With Which We Shared Personal Information for a Business Purpose
- Service providers that provide customer relationship management (CRM) services; assist us in operating, analyzing, and displaying content on our website; provide analytics information; advertise or market our restaurants and services; operate our rewards program; provide website hosting; provide legal and accounting services.
- Service providers that provide customer relationship management (CRM) services; advertise or market our restaurants and services; operate our rewards program.
- Service providers that provide customer relationship management (CRM) services; advertise or market our restaurants and services; operate our rewards program.
- Service providers that provide customer relationship management (CRM) services; advertise or market our restaurants and services; operate our rewards program.
- Payment service providers and banks who process credit and debit card payments.
- Service providers that provide data security services and cloud-based data storage; host our Sites and assist with other IT-related functions; provide website hosting; advertise and market our restaurants and services; and provide analytics information.
- Service providers that provide customer relationship management (CRM) services; advertise or market our restaurants and services; operate our rewards program.
Business Purposes for Such Disclosures
We disclosed the aforementioned categories of personal information to the categories of third parties identified above for the following purposes: to manage customer, supplier and vendor accounts and relationships; process payments; verify customers’ identities; fulfill orders and transactions; engage in advertising and marketing; operate our IT systems and secure our systems; prevent fraud and other illegal activities; and to obtain professional advice about legal and accounting matters
Additional Information About How We May Share Personal Information
We may also share your Personal Information as required or permitted by law to comply with a subpoena or similar legal process or government request, or when we believe in good faith that disclosure is legally required or otherwise necessary to protect our rights and property or the rights, property or safety of others, including to law enforcement agencies, and judicial and regulatory authorities. We may also share your Personal Information with third parties to help detect and protect against fraud or data security vulnerabilities. And we may transfer your Personal Information to a third party in the event of an actual or proposed sale, merger, reorganization of our entity or other restructuring.
Personal Information We Sold to Third Parties in the Preceding 12 Months
When we engage in digital advertising, we may sell the following categories of personal information (according to the broad definition of “sell” under select state privacy laws) or we may share them for purposes of cross-context behavioral advertising: personal identifiers and internet or other electronic activity information.
In the 12 months prior to the date of this Policy, we sold Personal Information to third party digital advertising networks by allowing such third parties to place cookies or other trackers on our Sites. The data they collected may be used to provide you with personalized content and present you with third party products or services in which you may be interested. For more information about the use of cookies and trackers, see the Cookies and Other Tracking Technologies section below.
We have also sold the following categories of Personal Information to our corporate affiliates so they can offer products and services that you may be interested in receiving personal identifiers.
Cookies and Other Tracking Technologies
Like most websites, our Sites use small data files stored on your computer or mobile device called cookies. Cookies consist of two different types; session and persistent. Session cookies enable us to recognize your actions during the browsing session. Persistent cookies remain stored on your device after you close your browser until they expire or when you delete them.
Cookies and web beacons, typically a one-pixel image, used to pass information from your computer or mobile device to our Sites, enable us to provide you with great customer service, improvements to our website design, product assortments and special promotions by:
- keeping track of what you have in your shopping cart;
- remembering you when you return to visit the Sites;
- identifying the pages you click on during your visit to the Sites;
- the name of the website you visited immediately before clicking onto our Sites; and
- helping track whether our communications are reaching you, measuring their effectiveness and allowing us to better design future communications.
We use this information to improve our Sites, product assortments, customer service, and special promotions. Certain of these cookies are strictly necessary to the access and operation of the Sites and other cookies used are non-essential to the access and operation of the Sites.
We may contract with third parties who may use cookies and web beacons and collect information on our behalf or provide services such as credit card processing, data management, or website troubleshooting and analytics.
We use third party retargeting and remarketing features on our Sites. These technologies allow us to address internet users who previously visited our Sites by delivering personalized advertising on our partners’ websites. For this purpose, the retargeting or remarketing provider will store a cookie on your hard drive. Based on the cookie technology, anonymous user details will be stored – for example, the advertising you received from us or clicked, the products you viewed, or whether you made a purchase.
Additionally, we also allow third parties to set cookies and other trackers when you visit our Sites which may collect information about your online activities over time and across different websites, applications or other online platforms. These third parties may use such information to, for example, provide analytics information or to offer products or services in which you may be interested, and they may combine information about your activities across different websites, applications or other online platforms to do so.
We use also Google Analytics to evaluate the use of our Sites. Google Analytics uses cookies and other identifiers to collect information, such as how often users visit a website, what pages they visit when they do so, and what other websites they visited prior to visiting a website. To learn more about how Google Analytics collects personal information, review Google’s Privacy Policy.
California Privacy Rights
If you are a California resident, you may have separate rights regarding your Personal Information, in accordance with California law.
California Consumer Privacy Act
If you are a California resident, you have the following rights in relation to your Personal Information subject to certain legal limitations.
Your Right To Request Disclosure of Information We Collect and Share About You
We are committed to ensuring that you know what Personal Information we collect. To that end, you can ask us for any or all of following types of information regarding the Personal Information we have collected about you in the 12 months prior to our receipt of your request:
- Specific pieces of Personal Information we have collected about you;
- Categories of Personal Information we have collected about you;
- Categories of sources from which such Personal Information was collected;
- Categories of Personal Information that the business sold or disclosed for a business purpose about the consumer;
- Categories of third parties to whom the Personal Information was sold or disclosed for a business purpose; and
- The business or commercial purpose for collecting or selling your Personal Information.
Your Right To Request Deletion of Personal Information We Have Collected About You
Upon your request, we will delete the Personal Information we have collected about you, except for situations where the CCPA authorizes us to retain specific information, including when it is necessary for us to provide you with a good or service that you requested; perform a contract we entered into with you; maintain the functionality or security of our systems; or comply with or exercise rights provided by the law. The law also permits us to retain specific information for our exclusively internal use, but only in ways that are compatible with the context in which you provided the information to us or that are reasonably aligned with your expectations based on your relationship with us. We will act on your deletion request within the timeframes set forth below.
Your Right to Ask Us Not to Sell Personal Information We Have Collected About You
You can direct us not to sell your Personal Information by submitting an opt-out request through our Data Request Form, or by contacting us at 800-735-3501. We will act on your request within the timeframes set forth below.
Exercising Your Rights and How We Will Respond
To exercise any of the rights above, or to ask a question, contact us at 800-735-3501, complete and submit our Data Request Form or use the contact details set out at the end of this Policy.
For requests for access or deletion, we will first acknowledge receipt of your request within 10 business days of receipt of your request. We provide a substantive response to your request as soon as we can, generally within 45 days from when we receive your request, although we may be allowed to take longer to process your request under certain circumstances. If we expect your request is going to take us longer than normal to fulfill, we will let you know.
For requests to stop the sale of your Personal Information, we will comply no later than 15 business days after receipt of your request.
We usually act on requests and provide information free of charge, but we may charge a reasonable fee to cover our administrative costs of providing the information in certain situations. In some cases, the law may allow us to refuse to act on certain requests. When this is the case, we will endeavor to provide you with an explanation as to why.
Our Commitment to Honouring Your Rights
If you exercise any of the rights explained in this Policy , we will continue to treat you fairly. If you exercise your rights under this Policy , you will not be denied or charged different prices or rates for goods or services, or provided a different level or quality of goods or services than others.
Verification of Identity – Access or Deletion Requests
After you submit a request, we will promptly take steps to determine whether your request is a verifiable request. We will verify that you are who you say you are by asking you to confirm certain unique pieces of information relating to your relationship and/or transactions with us.
If we are unable to verify your identity with the degree of certainty required, we will not be able to respond to your request. We will notify you to explain the basis of the denial.
Ensuring Veracity of Opt-Out Requests
If we have a good-faith, reasonable belief that a request to opt-out of the sale of Personal Information is fraudulent, we may deny the request. Should this occur, we will inform you and explain why we believe the request is fraudulent.
Authorized Agents
You may designate an agent to submit requests on your behalf. The agent must be a natural person or a business entity that is registered with the California Secretary of State.
If you would like to designate an agent to act on your behalf, you and the agent will need to comply with our verification process:
- Requests to Know or Delete Personal Information: If the agent submits requests to access, know or delete your Personal Information, the agent will need to provide us with your signed permission indicating the agent has been authorized to submit the opt-out request on your behalf. We will also require that you verify your identity directly with us or confirm with us that you provided the agent with permission to submit the request.
- Requests to Opt Out of Sale: If the agent submits a request to opt out of the sale of your Personal Information, the agent will need to provide us with your signed permission indicating the agent has been authorized to submit the opt-out request on your behalf
Please note that this subsection does not apply when an agent is authorized to act on your behalf pursuant to a valid power of attorney. Any such requests will be processed in accordance with California law pertaining to powers of attorney
Requests for Household Information
There may be some types of Personal Information that can be associated with a household (a group of people living together in a single dwelling). Requests for access or deletion of household Personal Information must be made by each member of the household. To the extent we collect household information and requests are made pertaining specifically to such information, before responding to a request, we will verify the identity of each member of the household using the verification criteria explained above and will also verify that each household member is currently a member of the household.
Notice of Financial Incentive
We offer a rewards program that provides points and incentives for purchasing items at our restaurants. The points you accumulate through our program can be used to redeem free menu items.
The information we have collected about our rewards program members enables us to deliver personalized offers and value to our customers, which helps us establish a relationship with our customers and is valued by XRG as part of our focus on the customer experience. In determining the value of this data to XRG, we consider the value of what our customers receive in exchange for their participation in the program. As part of our rewards program, our best customers receive approximately $32 per year in such value, on average.
Participation in our reward program is voluntary. After joining our rewards program, if you wish to opt out of the rewards program or wish to opt out of the sale of your Personal Information to support the program, you can contact our customer contact center by telephone at 800-735-3501 for assistance. For further information, see the XPERIENCE Rewards FAQ.
Non-Discrimination
We will not discriminate against a California resident because the California resident exercised any of the rights described herein.
California Shine the Light
California Civil Code Section 1798.83, also known as the “Shine the Light” law, permits California residents to annually request, free of charge, information about certain categories of Personal Information a business has disclosed to third parties for direct marketing purposes in the preceding calendar year. For information, please contact us at webteam@xperiencerg.com.
California Do Not Track
Some browsers have a “do not track” feature that lets you tell websites that you do not want to have your online activities tracked. At this time, our Sites do not respond to browsers’ do not track signals. We observe the Global Privacy Control signal for California residents.
Personal Information of Minors
Our products and services are not directed to minors under the age of 13. We do not knowingly sell the Personal Information of minors under the age of 16.
Third Party Websites
Our Sites may contain social media buttons or links to third-party websites, which may have privacy policies that differ from our own. We are not responsible for the activities and practices that take place on those social media platforms or third-party websites. We recommend that you review the privacy policies posted on any platform or website that you may access through our Sites
How We Keep Your Personal Information Secure
We implement and maintain reasonable security measures appropriate to the nature of the Personal Information that we collect, use, retain, transfer or otherwise process. Those measures include administrative, physical and technical safeguards to protect the security, confidentiality and integrity of Personal Information. However, data security incidents and breaches can occur due to a variety of factors that cannot reasonably be prevented; therefore, our safeguards may not always be adequate to prevent all breaches of security.
International Residents
Personal Information collected from you, including via our Sites, will be transferred to the United States where the Sites are hosted. You hereby consent to the transfer of your Personal Information to the United States as described in this Privacy Policy. Please do not use the Sites if you do not agree to the transfer and processing of your Personal Information in the United States, which may not provide the same level of protection for your data as your home country.
Changes to This Policy
We will review and update this Policy periodically. We will notify you of material changes to it by posting on our Sites notification that the Policy has been updated and by updating the date of the Policy. Your continued use of the Sites after changes have been posted will constitute your acceptance of this Privacy Policy and any changes.
Accessibility
We are committed to ensuring that our communications are accessible to people with disabilities. To make accessibility-related requests or report barriers, please contact us at webteam@xperiencerg.com.
CONTACT US
If there are any questions regarding this Policy or to request a copy of this Policy in another format you may contact us at:
XRG 11065 Knott Ave, Ste A Cypress, CA 90630