Privacy Policy
Privacy Policy
Last Updated: October 1, 2023
This Privacy Policy (“Privacy Policy” and “Policy”) applies to the collection and use of Personal Information by XPERIENCE RESTAURANT GROUP (“XRG”, “Company”, or “we,” or “us,” or “our”). It describes the Company’s practices regarding the collection, use, disclosure, and sale of Personal Information when you visit our websites or mobile applications (the “Sites”), when you communicate with us via email, when you visit our restaurants, and when you engage with us offline. It also describes the rights you may have regarding your Personal Information pursuant to applicable privacy laws. Please see the U.S. State Privacy Rights section of this Privacy Policy for more information about these rights and how to exercise them. By accessing the Sites and using our services, you agree to our collection and use of Personal Information as described herein and you agree to our Terms of Use.
For purposes of this Policy, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, or as otherwise defined by applicable law. It does not include de-identified or aggregate information, or public information lawfully available from governmental records.
NOTICE AT COLLECTION: PERSONAL INFORMATION WE COLLECT
We may collect Personal Information such as:
- Personal identifiers: Name, address, email address, telephone numbers, IP address or other unique identifier, birthdate, account password and name; anniversary date; favorite location and restaurant; educational information;
- Financial information: Credit card or payment card information; household income
- Protected class information: Age, military or veteran status;
- Commercial information:Records of purchases, records of reward program participation including points accumulated and redeemed; dates, times and locations of purchases;
- Location information: General location information, using your zip code or IP address and your precise GPS location;
- Internet or other electronic activity information: Device and browser type, your browsing and search history on our Sites, and information regarding your interaction with our Sites and our advertisements. On certain Sites, we use tools to look at mouse movements, clicks, keystrokes, data or text entered, and the pages you visit.
- Professional information: First responder status (to offer you specials);
- Audio, visual, or similar information: Recordings of customer telephone calls, video of you captured on CCTV security cameras installed in our restaurants, customer service interactions, chat transcripts, files you attach, and email, text, or other correspondence;
- Inferences drawn from any of the Personal Information identified above.
Some of the information described above may be considered “sensitive” under the laws of certain jurisdictions (including payment information, account login credentials, and precise geolocation information) (“Sensitive Information”). Whether information is Sensitive Information will depend on the laws of your jurisdiction.
We have collected the same categories of personal information in the 12 months prior to the date of this Privacy Policy
NOTICE AT COLLECTION: PURPOSES FOR COLLECTION OF PERSONAL INFORMATION
We use your Personal Information in the following ways:
- To enable us to process, validate and verify your requests for products and services;
- To facilitate your participation in our rewards program;
- For marketing and advertising, including to alert you to new projects, Sites features, special events and services (e.g., by text message, if you sign up);
- To provide our partners and affiliates with information about you so that they can offer products or services you might be interested in receiving;
- To provide you with information about the Company;
- To conduct surveys to measure your satisfaction with our services;
- To monitor and evaluate our Sites, including to improve their functionality;
- To communicate and conduct business with you or your employer, in the context of business-to-business contacts;
- For internal business analysis, including to develop new features and services to meet customer needs; and
- To facilitate your participation in our rewards program
Additionally, we use Personal Information, including about your use of our Sites, to monitor or improve our Sites; to prevent fraud, activities that violate our Terms of Service or that are illegal; and to protect our rights and the rights and safety of our users or others.
We use Sensitive Information for necessary or reasonably expected purposes – specifically, to provide you with services on our Sites (i.e., to fulfill purchases, allow account logins, and to find the nearest XRG restaurant location) and as authorized by law.
NOTICE AT COLLECTION: PERSONAL INFORMATION SOLD OR SHARED TO THIRD PARTIES IN THE PRECEDING 12 MONTHS
We sell or share the following Personal Information with our affiliates and with third-party partners such as advertising networks, social networks, data brokers, other advertisers, and our affiliates which may not share common branding so that we and/or our third-party partners can deliver targeted ads and other tailored communications to you: Personal Identifiers; Commercial Information; Internet or other electronic activity information; and Inferences.
If you would like to opt-out of the sale or sharing of any of the information described above, please submit an opt-out request through our Data Request Form, or by contacting us at 800-735-3501.
NOTICE AT COLLECTION: RETENTION PERIODS
We retain the categories of Personal Information we collect for the length of time necessary to provide our services and to comply with legal obligations or to protect our legal rights.
SOURCES FROM WHICH WE COLLECT PERSONAL INFORMATION
We collect and obtain Personal Information from:
You. We collect Personal Information that you voluntarily provide to us, for example when you communicate with us via email or other channels, when you visit our Sites, including by submitting orders, reservations, booking events or inquiring about our services; join and participate in our rewards program; purchase or activate gift cards; request information about our restaurants; participate in our surveys; visit our restaurants; or when you voluntarily provide information to us.
Service Providers. We may use third-party service providers or other third-party organizations helping to support our mission that may collect, store, or process your Personal Information on our behalf, such as to complete your request (e.g., completing a transaction or to outsource one or more of the functions described above).
Affiliates. We may get information about you from other companies that are a part of the Z Capital Group, LLC (“ZCG”) family of brands.
Advertising and Marketing Partners. We work with companies that help us deliver, measure, and analyze the effectiveness of our ads. These companies collect information about you when you interact with ads on our platforms and on the websites where our ads are displayed.
DISCLOSURE OF PERSONAL INFORMATION
The following chart describes the categories of Personal Information that we disclosed for a business purpose in the 12 months prior to the date of this Policy:
Categories of Consumers’ Personal Information
- Personal identifiers: Name, address, email address, telephone numbers, IP address or other unique identifier; birthdate, account password and name; anniversary date; favorite location and restaurant.
- Protected class information: Age, military or veteran status.
- Location information
- Commercial information: Records of purchases, records of reward program participation including points accumulated and redeemed.
- Professional information: First responder status (to offer you specials).
- Financial information: Credit card or payment card information
- Internet or other electronic network activity information: Device and browser type, browsing and search history on our Sites, and information regarding interaction with our Sites and our advertisements.
- Audio, visual, or similar information
- Inferences generated from any of the above categories of Personal Information.Categories of Third Parties With Which We Shared Personal Information for a Business Purpose
- Other companies within the ZCG family of brands; agencies, advertisers, advertising networks, social networks, data brokers, and other companies to serve ads; and service providers that provide customer relationship management (CRM) services; assist us in operating, analyzing, and displaying content on our website; provide analytics information; advertise or market our restaurants and services; operate our rewards program; provide website hosting; provide legal and accounting services.
- Other companies within the ZCG family of brands and service providers that provide customer relationship management (CRM) services; advertise or market our restaurants and services; operate our rewards program.
- Service providers that help us provide location-based features, security, cloud-based data storage, analytics, and customer service, host our Sites, and assist with other IT-related functions
- Other companies within the ZCG family of brands; agencies, advertisers, advertising networks, social networks, data brokers, and other companies to serve ads; and service providers that provide customer relationship management (CRM) services; advertise or market our restaurants and services; operate our rewards program.
- Other companies within the ZCG family of brands and service providers that provide customer relationship management (CRM) services; advertise or market our restaurants and services; operate our rewards program.
- Payment service providers and banks who process credit and debit card payments.
- Other companies within the ZCG family of brands; agencies, advertisers, advertising networks, social networks, data brokers, and other companies to serve ads; and service providers that provide data security services and cloud-based data storage; host our Sites and assist with other IT-related functions; provide website hosting; advertise and market our restaurants and services; and provide analytics information.
- Service providers that provide data security, cloud-based data storage, analytics, fraud, legal compliance, and customer service services, host our Sites, and assist with other IT-related functions
- Other companies within the ZCG family of brands; agencies, advertisers, advertising networks, social networks, data brokers, and other companies to serve ads; and service providers that provide customer relationship management (CRM) services; advertise or market our restaurants and services; operate our rewards program.
BUSINESS PURPOSES FOR SUCH DISCLOSURES
We disclosed the aforementioned categories of Personal Information to the categories of third parties identified above for the following purposes: to manage customer, supplier and vendor accounts and relationships; process payments; verify customers’ identities; fulfill orders and transactions; engage in advertising and marketing; operate our IT systems and secure our systems; prevent fraud and other illegal activities; and to obtain professional advice about legal and accounting matters.
ADDITIONAL INFORMATION ABOUT HOW WE MAY SHARE PERSONAL INFORMATION
We share your Personal Information with third parties who may use your Personal Information for their own independent purposes in accordance with their own privacy policies. For example, we share Personal Information with agencies, advertisers, our affiliates and other third parties who provide products/services that may be of interest to you or who serve ads. We work with third-party advertising networks, social networks, data brokers, and other companies to serve ads when you visit our Sites. These companies may use information about your visits to this and other websites in order to provide advertisements about goods and services of interest to you.
We may also share your Personal Information as required or permitted by law to comply with a subpoena or similar legal process or government request, or when we believe in good faith that disclosure is legally required or otherwise necessary to protect our rights and property or the rights, property or safety of others, including to law enforcement agencies, and judicial and regulatory authorities. We may also share your Personal Information with third parties to help detect and protect against fraud or data security vulnerabilities. And we may transfer your Personal Information to a third party in the event of an actual or proposed sale, merger, reorganization of our entity or other restructuring.
PERSONAL INFORMATION SOLD OR SHARED TO THIRD PARTIES IN THE PRECEDING 12 MONTHS
We may sell the following categories of Personal Information (according to the broad definition of “sell” under select state privacy laws) or we may share them for purposes of cross-context behavioral advertising: personal identifiers, commercial information, internet or other electronic activity information and inferences.
In the 12 months prior to the date of this Policy, we sold Personal Information to third party digital advertising networks by allowing such third parties to place cookies or other trackers on our Sites. The data they collected may be used to provide you with personalized content and present you with third party products or services in which you may be interested. For more information about the use of cookies and trackers, see the Cookies and Other Tracking Technologies section below.
We have also sold the following categories of Personal Information to our corporate affiliates so they can offer products and services that you may be interested in receiving: personal identifiers, commercial information, internet or other electronic activity information, and inferences.
COOKIES AND OTHER TRACKING TECHNOLOGIES
Like most websites, our Sites use small data files stored on your computer or mobile device called cookies. Cookies consist of two different types; session and persistent. Session cookies enable us to recognize your actions during the browsing session. Persistent cookies remain stored on your device after you close your browser until they expire or when you delete them.
Cookies and web beacons, typically a one-pixel image, used to pass information from your computer or mobile device to our Sites, enable us to provide you with great customer service, improvements to our website design, product assortments and special promotions by:
- keeping track of what you have in your shopping cart;
- remembering you when you return to visit the Sites;
- identifying the pages you click on during your visit to the Sites;
- the name of the website you visited immediately before clicking onto our Sites; and
- helping track whether our communications are reaching you, measuring their effectiveness and allowing us to better design future communications.
We use this information to improve our Sites, product assortments, customer service, and special promotions. Certain of these cookies are strictly necessary to the access and operation of the Sites and other cookies used are non-essential to the access and operation of the Sites.
We may contract with third parties who may use cookies and web beacons and collect information on our behalf or provide services such as credit card processing, data management, or website troubleshooting and analytics.
We use third party retargeting and remarketing features on our Sites. These technologies allow us to address internet users who previously visited our Sites by delivering personalized advertising on our partners’ websites. For this purpose, the retargeting or remarketing provider will store a cookie on your hard drive. Based on the cookie technology, certain user details will be stored – for example, the advertising you received from us or clicked, the products you viewed, or whether you made a purchase.
Additionally, we also allow third parties to set cookies and other trackers when you visit our Sites which may collect information about your online activities over time and across different websites, applications or other online platforms. These third parties may use such information to, for example, provide analytics information or to offer products or services in which you may be interested, and they may combine information about your activities across different websites, applications or other online platforms to do so. You can opt out of tracking on our website or others for online behavioral advertising by visiting the DAA’s Consumer Choice page at http://www.aboutads.info/choices/.
We use also Google Analytics to evaluate the use of our Sites. Google Analytics uses cookies and other identifiers to collect information, such as how often users visit a website, what pages they visit when they do so, and what other websites they visited prior to visiting a website. To learn more about how Google Analytics collects Personal Information, review Google’s Privacy Policy and its opt-out tool at https://tools.google.com/dlpage/gaoptout.
OTHER MARKETING COMMUNICATIONS
You can opt out of receiving our marketing emails and text messages. To stop receiving our marketing emails, you can follow the “unsubscribe” instructions in any marketing email message you get from us. Even if you opt out of getting marketing emails, we will still send you transactional messages. These include responses to your questions. You can opt out of our marketing text messages by replying “STOP” to MYGUAC (694822).
You can control certain location tracking tools. To control the collection of your precise location on your mobile device or browser, you can adjust your device or browser settings. You can disable location services, disable location access permissions, and turn off Bluetooth and Wi-Fi.
U.S. STATE PRIVACY RIGHTS
You have the following rights, where provided under applicable state law, regarding your Personal Information (each of which are subject to various exceptions and limitations):
Your Right To Request Disclosure of Information We Collect and Share About You
We are committed to ensuring that you know what Personal Information we collect. To that end, you can ask us for any or all of following types of information regarding the Personal Information we have collected about you in the 12 months prior to our receipt of your request:
- Specific pieces of Personal Information we have collected about you;
- Categories of Personal Information we have collected about you;
- Categories of sources from which such Personal Information was collected;
- Categories of Personal Information that the business sold or disclosed for a business purpose about the consumer;
- Categories of third parties to whom the Personal Information was sold or disclosed for a business purpose; and
- The business or commercial purpose for collecting or selling your Personal Information.
Your Right To Request Correction of Personal Information We Have Collected About You
You have the right to request that we correct inaccurate Personal Information collected from you, subject to certain exceptions allowed under applicable law. We will accept, review, and consider any documentation that you provide in connection with your right to correct, provided you make a good-faith effort to provide us with all relevant information available at the time of the request.
Your Right To Request Deletion of Personal Information We Have Collected About You
Upon your request, we will delete the Personal Information we have collected about you, except for situations where the applicable law authorizes us to retain specific information, including when it is necessary for us to provide you with a good or service that you requested; perform a contract we entered into with you; maintain the functionality or security of our systems; or comply with or exercise rights provided by the law. The law also permits us to retain specific information for our exclusively internal use, but only in ways that are compatible with the context in which you provided the information to us or that are reasonably aligned with your expectations based on your relationship with us. We will act on your deletion request within the timeframes set forth below.
Your Right to Ask Us Not to Sell or Share Personal Information We Have Collected About You
You have the right to opt-out of the “sale” of your personal information (defined very broadly to include situations where we provide Personal Information to partners who provide advertising services to us) and the “sharing” of Personal Information in connection with the display of targeted advertising across third party websites. You can direct us not to sell or share your Personal Information by submitting an opt-out request through our Data Request Form, or by contacting us at 800-735-3501. We will act on your request within the timeframes set forth below.
We also honor the Global Privacy Control, a browser-based opt-out signal. We do not respond to other browser-based signals that do not meet applicable state law requirements, which may include older Do Not Track signals.
Your Right to Appeal
You have a right to appeal decisions concerning your ability to exercise your consumer rights.
Exercising Your Rights and How We Will Respond
To exercise any of the rights above, or to ask a question, contact us at 800-735-3501, complete and submit our Data Request Form or use the contact details set out at the end of this Policy.
For requests for access, correction, or deletion, we will first acknowledge receipt of your request within 10 business days of receipt of your request. We provide a substantive response to your request as soon as we can, generally within 45 days from when we receive your request, although we may be allowed to take longer to process your request under certain circumstances. If we expect your request is going to take us longer than normal to fulfill, we will let you know.
For requests to stop the sale or sharing of your Personal Information, we will comply no later than 15 business days after receipt of your request.
We usually act on requests and provide information free of charge, but we may charge a reasonable fee to cover our administrative costs of providing the information in certain situations. In some cases, the law may allow us to refuse to act on certain requests. When this is the case, we will endeavor to provide you with an explanation as to why.
Verification of Identity – Access, Correction, or Deletion Requests
After you submit a request, we will promptly take steps to determine whether your request is a verifiable request. We will verify that you are who you say you are by asking you to confirm certain unique pieces of information relating to your relationship and/or transactions with us.
If we are unable to verify your identity with the degree of certainty required, we will not be able to respond to your request. We will notify you to explain the basis of the denial.
Ensuring Veracity of Opt-Out Requests
If we have a good-faith, reasonable belief that a request to opt-out of the sale or sharing of Personal Information is fraudulent, we may deny the request. Should this occur, we will inform you and explain why we believe the request is fraudulent.
Authorized Agents
You may designate an agent to submit requests on your behalf. If you would like to designate an agent to act on your behalf, you and the agent will need to comply with our verification process:
- Requests to Know, Correct or Delete Personal Information: If the agent submits requests to access, know or delete your Personal Information, the agent will need to provide us with your signed permission indicating the agent has been authorized to submit the opt-out request on your behalf. We will also require that you verify your identity directly with us or confirm with us that you provided the agent with permission to submit the request.
- Requests to Opt Out of Sale or Sharing of Personal Information: If the agent submits a request to opt out of the sale or sharing of your Personal Information, the agent will need to provide us with your signed permission indicating the agent has been authorized to submit the opt-out request on your behalf.
Please note that this subsection does not apply when an agent is authorized to act on your behalf pursuant to a valid power of attorney. Any such requests will be processed in accordance with applicable law pertaining to powers of attorney.
Requests for Household Information
There may be some types of Personal Information that can be associated with a household (a group of people living together in a single dwelling). Requests for access, correction or deletion of household Personal Information must be made by each member of the household. To the extent we collect household information and requests are made pertaining specifically to such information, before responding to a request, we will verify the identity of each member of the household using the verification criteria explained above and will also verify that each household member is currently a member of the household.
Notice at Collection Disclosure. For our notice at collection, see above sections of this privacy policy titled: Personal Information We Collect, Purposes for Collection of Personal Information,Personal Information Sold or Shared to Third Parties in the Preceding 12 Months, and Retention Periods.
Notice of Financial Incentive
We offer a rewards program that provides points and incentives for purchasing items at our restaurants. The points you accumulate through our program can be used to redeem free menu items.
The information we have collected about our rewards program members enables us to deliver personalized offers and value to our customers, which helps us establish a relationship with our customers and is valued by XRG as part of our focus on the customer experience. In determining the value of this data to XRG, we consider the value of what our customers receive in exchange for their participation in the program. As part of our rewards program, our best customers receive approximately $32 per year in such value, on average.
Participation in our reward program is voluntary. After joining our rewards program, if you wish to opt out of the rewards program or wish to opt out of the sale or sharing of your Personal Information to support the program, you can contact our customer contact center by telephone at 800-735-3501 for assistance. For further information, see the XPERIENCE Rewards FAQ.
Non-Discrimination
We will not discriminate against you for exercising any of the rights described herein.
CALIFORNIA SHINE THE LIGHT
California Civil Code Section 1798.83, also known as the “Shine the Light” law, permits California residents to annually request, free of charge, information about certain categories of Personal Information a business has disclosed to third parties for direct marketing purposes in the preceding calendar year. For information, please contact us at webteam@xperiencerg.com.
PERSONAL INFORMATION OF MINORS
Our products and services are not directed to minors under the age of 13. We do not knowingly sell or share the Personal Information of minors under the age of 16.
THIRD PARTY WEBSITES
Our Sites may contain social media buttons or links to third-party websites, which may have privacy policies that differ from our own. We are not responsible for the activities and practices that take place on those social media platforms or third-party websites. We recommend that you review the privacy policies posted on any platform or website that you may access through our Sites.
HOW WE KEEP YOUR PERSONAL INFORMATION SECURE
We implement and maintain reasonable security measures appropriate to the nature of the Personal Information that we collect, use, retain, transfer or otherwise process. Those measures include administrative, physical and technical safeguards to protect the security, confidentiality and integrity of Personal Information. However, data security incidents and breaches can occur due to a variety of factors that cannot reasonably be prevented; therefore, our safeguards may not always be adequate to prevent all breaches of security.
INTERNATIONAL RESIDENTS
Personal Information collected from you, including via our Sites, will be transferred to the United States where the Sites are hosted. You hereby consent to the transfer of your Personal Information to the United States as described in this Privacy Policy. Please do not use the Sites if you do not agree to the transfer and processing of your Personal Information in the United States, which may not provide the same level of protection for your data as your home country.
CHANGES TO THIS POLICY
We will review and update this Policy periodically. We will notify you of material changes to it by posting on our Sites notification that the Policy has been updated and by updating the date of the Policy. Your continued use of the Sites after changes have been posted will constitute your acceptance of this Privacy Policy and any changes.
ACCESSIBILITY
We are committed to ensuring that our communications are accessible to people with disabilities. To make accessibility-related requests or report barriers, please contact us at webteam@xperiencerg.com.
CONTACT US
If there are any questions regarding this Policy or to request a copy of this Policy in another format you may contact us at:
webteam@xperiencerg.com
XRG
11065 Knott Ave, Ste A
Cypress, CA 90630
XRG