Privacy Policy
Effective Date: September 2, 2026
Last Updated: September 2, 2026
Fandelay Industries, LLC, a Florida limited liability company (“HomeAway,” “we,” “us,” or “our”), provides this Privacy Policy to explain how we collect, use, disclose, and protect personal information in connection with the HomeAway mobile application (the “App”), the website located at https://homeaway.app (the “Site”), and the related features and services we make available (together, the “Services”).
This Privacy Policy is incorporated into and forms part of our Terms of Use. Please read both documents. By downloading, accessing, or using the Services, you acknowledge that you have read and understood this Privacy Policy.
The Services are intended solely for users located in the United States and for individuals who are at least eighteen (18) years of age. We do not offer the Services to individuals located outside the United States, and we do not knowingly collect personal information from anyone under eighteen. See Sections 11 and 15 below.
1. Who We Are and How to Reach Us
The entity responsible for the personal information described in this Privacy Policy (the “controller” or “business,” as those terms are used in applicable privacy laws) is:
Fandelay Industries, LLC d/b/a HomeAway 5443 Sunseeker Blvd, Greenacres, Florida 33463 Email: support@homeaway.app Attention: Evan Caruso, CEO
2. Summary of Our Practices
This summary is provided for convenience only. It does not replace the detailed disclosures that follow, and the balance of this Privacy Policy controls in the event of any inconsistency.
- We collect the information you give us when you create an account and use the App, information collected automatically from your device, and content you choose to post.
- We collect precise geolocation in the foreground in order to power stadium check-ins and proximity-based sorting. You control this through your device settings.
- We do not sell your personal information for money. We do disclose certain identifiers and device information to Google AdMob so that advertising can be shown to users of the free tier. Under California law, that disclosure is treated as “sharing” for cross-context behavioral advertising, and in some circumstances may be treated as a “sale.” You may opt out. See Section 12.
- HomeAway Premium subscribers are not shown third-party behavioral advertising served by Google AdMob. Promoted business placements within the Suggested Places feature are not third-party advertisements and remain visible to all users, including Premium subscribers.
- We do not knowingly collect information from anyone under 18.
- We do not transfer or store your personal information outside the United States.
- You can delete your content and your account from within the App at any time.
3. Information We Collect
3.1 Information You Provide to Us
We collect the following categories of information directly from you:
- Identifiers
Email address, username or display name, and account identifier. Registration requires an email address and a password; additional identifiers such as a display name or profile photo are optional and are collected only if you choose to provide them. - Account credentials
Your password and, if you use a third-party login, the authentication token returned by that provider. We do not receive or store your password for any third-party login service. - User-generated content
Stadium scorecards, scrapbook entries, photographs and images, posts, comments, reviews, ratings, trip and club records, fantasy contest entries, direct messages, and any other content you submit, upload, or transmit through the Services. - Communications with us
Support tickets, emails, in-app support chat, abuse and moderation reports, and your correspondence with our team. - Survey and feedback responses
Information you provide when you respond to a survey, beta feedback request, or similar prompt. - Photo library content
Images you select from your device photo library for upload. We access your photo library only at the moment you choose to upload, and only for the images you select.
3.2 Information Collected Automatically
When you use the Services, we and our service providers collect the following automatically:
- Precise geolocation
Latitude and longitude derived from your device, collected while the App is in the foreground, to support stadium check-in and proximity-based sorting of nearby venues. We have deliberately disabled background location collection. Precise geolocation is treated as sensitive personal information under California law and as sensitive data under a number of other state laws. See Sections 4 and 12. - Device identifiers
The Identifier for Advertisers (IDFA) on iOS and the Google Advertising ID (GAID/AAID) on Android, together with other device identifiers. On iOS, the IDFA is collected only if you grant permission through Apple’s App Tracking Transparency prompt. - IP address and derived coarse location
- Device and software information
Device type and model, operating system and version, App version, and language and locale settings. - Crash logs and diagnostic data,
collected through Firebase Crashlytics. - Usage and interaction data
Screens viewed, features used, time spent, clickstream and interaction data, and presence or online status. - Cookies, SDKs, pixels, and similar technologies,
as described in Section 6. - Inferences
drawn from the information above regarding your preferences and behavior, used to personalize content and, for users of the free tier, to serve advertising. - Clipboard content
When you open the App after tapping a join-invitation link on our website, the App reads text from your device clipboard to detect a one-time invite token placed there by our website. On iOS 16 and later, the operating system displays a prompt asking you to allow or deny the paste; on Android 12 and later, the operating system displays a brief notification that the App read from the clipboard. We read only plaintext, we check only whether it matches our specific invite-token format, and we clear the clipboard immediately after processing. If the clipboard does not contain an invite token, its contents are discarded in memory and are not stored, logged, or transmitted. This access occurs only when you first open the App following a website visit and does not repeat on subsequent launches unless a new invite token is present.
3.3 Information We Receive From Third Parties
We do not purchase personal information from data brokers and we do not receive personal information about you from advertising networks or analytics providers. We receive limited information from the following sources:
- Third-party login providers
If you sign in using Google, Facebook, X, Yahoo, or Apple, that provider sends us a unique identifier and, depending on the provider and your settings, your email address and display name. What is shared is governed by your settings with that provider. - Apple and Google
We receive subscription status, purchase confirmations, and refund and cancellation notices from the Apple App Store and Google Play. We do not receive your payment card number or full billing details. - Sports data providers
We receive inbound sports data feeds from SportsData.io (schedules, scores, player statistics, venue information) and RotoWire (player news and injury information). These are one-way data feeds; no user-specific information is transmitted to these providers.
3.4 Device Permissions
The App requests the following permissions. You may grant or deny each of them, and you may change your choice at any time in your device settings. Denying a permission may disable the corresponding feature but will not prevent you from using the rest of the App.
- Location
(ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION) — stadium check-in and proximity sorting. - Photos and storage
(READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE) — selecting images to upload and temporary storage during content screening. - Notifications
(POST_NOTIFICATIONS) — push notifications, as described in Section 8. - Vibration
(VIBRATE) — notification alerts. - Billing
(com.android.vending.BILLING) — in-app purchases through Google Play. - Network access
(INTERNET) — core App functionality.
The App does not request access to your camera, your microphone, your contacts list, or your calendar, and it does not collect location in the background. We removed the camera and microphone permissions deliberately as a data-minimization measure.
4. Sensitive Personal Information
California and several other states give heightened protection to certain categories of personal information. Of those categories, we collect only the following:
- Your account log-in in combination with your password or other credentials permitting access to your account.
- Your precise geolocation, meaning data used to locate you within an area smaller than a circle with a radius of 1,850 feet, as that term is defined at California Civil Code section 1798.140(w).
We do not collect Social Security numbers, driver’s license or state identification numbers, passport numbers, financial account or payment card numbers, racial or ethnic origin, religious or philosophical beliefs, union membership, the contents of communications not directed to us, genetic data, neural data, biometric information used to identify you, health information, or information concerning your sex life or sexual orientation.
We use the sensitive personal information we collect only to perform the services you have requested, to authenticate you, to maintain the security and integrity of the Services, and for the other purposes permitted by California Civil Code section 1798.121(a). We do not use or disclose your sensitive personal information for the purpose of inferring characteristics about you. See Section 12.4 for your right to limit the use of sensitive personal information.
5. How and Why We Use Personal Information
We use personal information for the following purposes:
- To provide the Services — operating the App and Site, displaying stadium and venue information, enabling check-ins, scorecards, scrapbooks, trips, clubs, meets, bulletin boards, direct messaging, and fantasy contests.
- To create and maintain your account and to authenticate you.
- To process subscriptions, purchases, and refunds, including through Apple and Google.
- To provide customer service and respond to your questions, reports, and requests.
- To personalize content, features, venue suggestions, and recommendations.
- To send transactional messages, including invites, direct-message alerts, activity completions, and club requests and approvals.
- To send marketing emails and promotional push notifications, subject to the choices described in Section 8.
- To conduct analytics and improve the Services, including diagnosing crashes and errors.
- To conduct research and product development.
- To moderate content and to detect, prevent, and address fraud, security incidents, abuse, spam, harassment, and violations of our Terms of Use, including automated screening of uploaded images through Google Cloud Vision and review of user reports.
- To serve advertising, including targeted or behavioral advertising to users of the free tier through Google AdMob, as described in Sections 6 and 12.
- To create social connections between users — when a referral code is redeemed, we automatically create a friendship between the referrer and the redeemer, making each user’s profile information visible to the other. When a club code is entered, we add the user to the corresponding club.
- To connect you to activities you were invited to — when you tap a join link on our website and then open the App, we read a one-time invite token from your clipboard and use it to automatically add you to the club, trip, contest, or series associated with that invite. The token is used solely for this one-time matching and is cleared from your clipboard immediately afterward.
- To comply with law, to respond to legal process, to establish, exercise, or defend legal claims, and to enforce our agreements.
We do not use your personal information to make decisions that produce legal or similarly significant effects concerning you, and we do not engage in profiling for that purpose.
6. Advertising, Cookies, SDKs, and Tracking Technologies
6.1 Advertising in the App
The free tier of the App is supported by advertising served by Google AdMob. To serve those advertisements, we make available to Google certain identifiers and device information, which may include your advertising identifier, IP address, device information, and information about your use of the App. Google may combine that information with information it holds from other sources in order to select the advertisements you see.
On iOS, we present Apple’s App Tracking Transparency prompt where required, and we do not access your IDFA unless you grant permission. On Android and elsewhere, we present Google’s User Messaging Platform consent flow where required.
HomeAway Premium subscribers are not shown third-party behavioral advertising served by Google AdMob. Promoted business placements within the Suggested Places feature are curated by HomeAway, are not behavioral advertising, and remain visible to all users regardless of subscription tier.
The Site displays first-party promotional placements for local businesses and sponsors on stadium pages. These placements are selected based on the stadium page being viewed and not on your personal information, browsing history, or behavior. No personal information is collected, shared with advertisers, or used for targeting in connection with these placements. We record only anonymous, aggregate click counts for internal reporting purposes. No cookies, pixels, or tracking technologies are used in connection with these placements.
6.2 Software Development Kits in the App
The App integrates the following third-party SDKs:
- Firebase App — core SDK initialization.
- Firebase Authentication — account creation, log-in, and identity verification.
- Cloud Firestore and Firebase Realtime Database — user profiles, scorecards, game data, App configuration, and presence and online status.
- Firebase Cloud Storage — user-uploaded images.
- Firebase Crashlytics — crash reporting and error diagnostics.
- Firebase Cloud Messaging — push notifications.
- Firebase Cloud Functions — server-side processing.
- Firebase App Check — app attestation and abuse prevention, using Apple Device Check and App Attest on iOS and Google Play Integrity on Android.
- Google AdMob with User Messaging Platform — advertising banners and interstitials, and CCPA and App Tracking Transparency consent management.
- Expo Location — geolocation for proximity sorting and geofenced stadium check-in.
- Expo Notifications — local and remote push notification handling.
- Expo Image Picker — photo library access for uploads.
- Expo Secure Store — on-device credential storage using the iOS Keychain and the Android Keystore.
- Expo In-App Purchases — Apple App Store and Google Play subscription handling.
- Expo Updates — over-the-air JavaScript bundle updates.
- React Native Maps — map rendering for stadium locations.
- Turf boolean-point-in-polygon — on-device geospatial boundary detection for stadium geofence check-in verification.
We do not use Google Analytics, Firebase Analytics, the Meta SDK, TikTok, AppLovin, Unity Ads, ironSource, Branch, Adjust, AppsFlyer, Singular, Mixpanel, Amplitude, Heap, or Segment. The usage and interaction data described in Section 3.2 is captured through our own server-side logging and Cloud Functions rather than through any third-party analytics or user-activity tracking SDK.
6.3 Cookies and Local Storage on the Site
The Site at homeaway.app uses cookies for essential site operation, including WordPress session management. The Site displays first-party promotional placements as described in Section 6.1, but we do not use advertising cookies, web beacons, or tracking pixels on the Site in connection with those placements or otherwise. Most browsers let you refuse or delete cookies through their settings. Blocking essential cookies may prevent parts of the Site from working.
6.4 Opt-Out Preference Signals
We intend to honor the Global Privacy Control (“GPC”) and other opt-out preference signals once advertising controls are implemented on the Site. This section will be updated at that time. In the App, opt-out of advertising data sharing is handled through the platform consent mechanisms described in Section 6.1 (Apple’s App Tracking Transparency and Google’s User Messaging Platform).
7. How We Disclose Personal Information
7.1 Service Providers
We disclose personal information to vendors that process it on our behalf, under written contracts that restrict their use of the information to the services they perform for us. Our service providers are:
- Google Cloud Platform — hosting, infrastructure, and logging.
- Google Firebase (Authentication, Cloud Firestore, Realtime Database, Cloud Storage, Cloud Functions, App Check, Crashlytics, Cloud Messaging) — application infrastructure.
- Google Cloud Vision API — automated screening of uploaded images for prohibited content.
- Apple App Store and Apple In-App Purchase — app distribution and subscription billing.
- Google Play Store and Google Play Billing — app distribution and subscription billing.
- Postmark — transactional email, external invitations, and marketing messages.
- SportsData.io — inbound sports data feeds (schedules, scores, player statistics, venues). No user data is shared with this provider.
- RotoWire — inbound player news and injury information feeds. No user data is shared with this provider.
- Intuit QuickBooks — invoicing and payment processing for business customers purchasing promotional placement.
7.2 Advertising Partners
We make identifiers and device information available to Google AdMob for the purpose of serving advertising to users of the free tier. This disclosure is the subject of the opt-out rights described in Section 12.
7.3 Other Users and the Public
Some information is public or visible to other users by design:
- Your display name, profile photo, and public profile content are visible to other users.
- Stadium scorecards and the images attached to them are public by nature and may be published on the Site at homeaway.app as review content.
- Content you post to a club, trip, bulletin board, meet, or other social feature is visible to the other participants in that feature, and to any administrator of it.
- If you enable the public check-in setting, other users can see which games you attended.
- If you redeem a referral code, or another user redeems your code, you will automatically be connected as friends on the App. Your display name, profile photo, and profile information visible to friends will be shared with the other user. You may remove this connection at any time.
- If you enter a club code, you will be added to that club, and your display name and profile information will be visible to other members.
- If you open a join link shared by another user, tap the download or “I already have the app” button on the landing page, and then open the App, you will automatically be added to the associated activity (such as a club). Your display name and profile information will be visible to other members of that activity, and the inviter’s referral code may be automatically applied to your account.
Please do not post anything you would not want to be public. Once content has been made public, others may have copied or reshared it, and we cannot retrieve those copies.
7.4 Legal and Protective Disclosures
We may disclose personal information when we believe in good faith that disclosure is necessary to comply with applicable law, a subpoena, a court order, or other legal process; to respond to a lawful request from a governmental or regulatory authority; to establish, exercise, or defend legal claims; to enforce our Terms of Use; or to protect the rights, property, or safety of HomeAway, our users, or the public.
7.5 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, personal information may be transferred as part of that transaction. We will provide notice before your personal information becomes subject to a materially different privacy policy.
7.6 Affiliates
Fandelay Industries, LLC has no parent company, subsidiaries, or affiliates with which it shares personal information.
7.7 International Transfers
We store and process personal information in the United States and we do not transfer it outside the United States. The Services are offered only to users in the United States.
8. Messages, Notifications, and Your Choices
8.1 Push Notifications
We send push notifications for invitations, direct messages, activity completions, and club requests and approvals, and we may send promotional notifications about features and offers. You can turn push notifications off entirely in your device settings.
8.2 Email
We send transactional email relating to your account, your subscription, security, and your activity. These messages are part of the Services and you cannot opt out of them while you maintain an account. We also send marketing email, which is delivered through Postmark and always contains an unsubscribe link. Unsubscribing from marketing email does not stop transactional email.
8.3 Text Messages
We do not send SMS or text messages.
8.4 Advertising Choices
You can limit interest-based advertising through your device settings: on iOS, by declining the App Tracking Transparency prompt or turning off “Allow Apps to Request to Track”; on Android, by deleting or resetting your advertising ID and enabling “Opt out of Ads Personalization.” You may also exercise the opt-out rights described in Section 12. Turning off personalized advertising does not remove advertising from the free tier; it makes the advertising you see less relevant.
9. Data Retention
We keep personal information for as long as your account is active and for as long as we need it to provide the Services, and afterward only as required to comply with law, resolve disputes, or enforce our agreements.
- Content you delete
You can delete individual records, including scorecards, scrapbook entries, and images, from the context menus in the App. Deleted records are removed from the live Services promptly. - Account deletion
You can delete your account from the Settings screen in the App. When you do, we permanently remove your profile, your messages, and your entries within thirty (30) calendar days. - Content published to the Site
If a scorecard has been published on homeaway.app and you delete it or delete your account, we remove it from the Site within thirty (30) calendar days. - Backups
We maintain rolling Firestore backups for thirty (30) days. Deleted data may persist in an encrypted backup until the backup expires on that rolling schedule, after which it is overwritten. We do not restore deleted user data from backups except to recover from a production incident. - Crash logs and diagnostics
Retained for ninety (90) days via Firebase Crashlytics, then automatically purged. - Server logs
Cloud Functions execution logs are retained for thirty (30) days via Google Cloud Logging. - Moderation records
Reports, flags, and moderation actions are retained for the duration of the associated account plus one (1) year after account deletion. - Records we must keep
We retain transaction and subscription records, security and abuse logs, and records of privacy requests for as long as required by applicable law or as necessary to defend legal claims. - Aggregated and deidentified information
We may retain and use information that has been aggregated or deidentified, and that can no longer reasonably be linked to you, without time limit.
10. How We Protect Personal Information
We maintain a written information security program and administrative, technical, and physical safeguards designed to protect personal information. Those safeguards include:
- Encryption in transit
All traffic between the App and our backend services uses TLS over HTTPS. Firebase SDKs enforce TLS for every connection to Firestore, Authentication, Cloud Storage, the Realtime Database, and Cloud Functions. We operate no unencrypted HTTP endpoints. - Encryption at rest
Data stored in Google Firebase is encrypted at rest using AES-256 with Google-managed encryption keys. - On-device protection
Sensitive credentials such as account identifiers and email addresses are stored in the iOS Keychain or the Android Keystore using hardware-backed encryption. Non-sensitive preferences use standard platform storage. - Access control
Identity verification runs through Firebase Authentication. Approximately 3,900 lines of Firestore Security Rules enforce per-document authorization, so that users can read and write only their own data or data they are explicitly authorized to access, such as conversation participants, club members, or confirmed connections. Users cannot modify sensitive fields such as subscription status from the client. - Privileged access
Administrative operations require a separate server-side authentication check within Cloud Functions. The internal administrative application is not distributed publicly, requires two-factor authentication, and is limited to three domain-restricted and email-restricted accounts with an administrator claim enforced in the backend. Only one account at a time holds Google Cloud CLI access to the production environment. - Change control
Corrective data operations are executed first as dry runs against mock targets, then verified against staging, and only then promoted to production. Thirty days of environment snapshots are maintained to permit rollback. - Application integrity
Firebase App Check adds device attestation using Apple Device Check and App Attest on iOS and Google Play Integrity on Android, to block unauthorized API access from non-genuine app instances. - Payment isolation
Payment processing for subscriptions is handled entirely by Apple and Google. No payment card data ever touches our servers or our application code. - Data minimization
We have removed camera and microphone permissions from the App, disabled background location collection, and delegated all password handling to Firebase Authentication so that credentials are never stored in our own systems. - Monitoring
Firebase Crashlytics captures crash reports with device diagnostics, and Cloud Functions log execution results and errors to Google Cloud Logging. No behavioral analytics or user-activity tracking SDK is installed. - Vendor diligence
Our backend infrastructure runs on Google Cloud Platform, which maintains SOC 2 Type II, ISO 27001, and FedRAMP certifications.
No system is perfectly secure. We cannot guarantee the security of information transmitted to or stored on the Services, and you provide information at your own risk. Please choose a strong, unique password and keep it confidential.
11. Children and Minors
The Services are not directed to children and are intended only for users who are at least eighteen (18) years of age. We do not knowingly collect personal information from anyone under 18, including any child under 13 within the meaning of the Children’s Online Privacy Protection Act, 15 U.S.C. sections 6501 through 6506, and its implementing rule at 16 C.F.R. Part 312. The App is not listed in any “kids” category and is not rated as appropriate for children in the Apple App Store or on Google Play.
We verify your age at registration by asking you to provide your date of birth. The date of birth is evaluated on your device and is not transmitted to our servers or stored; only the verification result is retained. We also rely on the age rating mechanisms provided by Apple and Google.
We do not sell or share the personal information of consumers under 16 years of age. If we learn that we have collected personal information from a person under 18, we will delete it promptly. If you believe a person under 18 has provided us personal information, contact us at the address in Section 1 and we will investigate.
12. Notice to California Residents
This Section supplements the rest of this Privacy Policy and applies to California residents. It is provided under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, California Civil Code sections 1798.100 and following (“CCPA”). Capitalized terms in this Section have the meanings given to them in California Civil Code section 1798.140.
12.1 Categories of Personal Information We Collect, Use, and Disclose
In the preceding twelve months, we have collected the following categories of personal information, as those categories are enumerated at California Civil Code section 1798.140(v):
- Identifiers
— email address, username, account identifier, IP address, device identifier, and advertising identifier. Sources: you, your device, third-party login providers. Purposes: all of those listed in Section 5. Disclosed for a business purpose to: hosting, infrastructure, email, and moderation service providers. Shared with: Google AdMob. - Personal information described in California Civil Code section 1798.80(e)
— name and email address. Sources: you. Purposes: Section 5. Disclosed for a business purpose to: service providers. Shared with: no one. - Commercial information
— subscription status and transaction history. Sources: you, Apple, Google. Purposes: subscription administration and support. Disclosed for a business purpose to: Apple, Google, and our billing service providers. Shared with: no one. - Internet or other electronic network activity information
— usage data, clickstream, interaction data, and App and Site activity. Sources: your device. Purposes: Section 5. Disclosed for a business purpose to: hosting and diagnostics service providers. Shared with: Google AdMob. - Geolocation data
— precise geolocation collected in the foreground. Sources: your device. Purposes: check-in and proximity sorting. Disclosed for a business purpose to: hosting service providers. Shared with: no one. - Audio, electronic, visual, or similar information
— photographs and images you upload. Sources: you. Purposes: Section 5, including content moderation. Disclosed for a business purpose to: storage and moderation service providers. Shared with: no one. - Inferences
— preferences and behavioral inferences drawn from the above. Sources: derived by us. Purposes: personalization and advertising. Disclosed for a business purpose to: service providers. Shared with: Google AdMob. - Sensitive personal information
— account log-in in combination with credentials, and precise geolocation. Sources: you and your device. Purposes: authentication, security and integrity, and the requested services only. Disclosed for a business purpose to: authentication and hosting service providers. Shared with: no one.
We do not collect government identification numbers, financial account or payment card numbers, biometric information, health information, genetic data, neural data, professional or employment information, education information, or information regarding racial or ethnic origin, religion, union membership, citizenship or immigration status, sex life, or sexual orientation.
12.2 Sale and Sharing of Personal Information
We do not sell your personal information for money. However, California law defines these terms broadly. “Sharing” under California Civil Code section 1798.140(ah) means disclosing personal information to a third party for cross-context behavioral advertising, whether or not money changes hands. “Selling” under section 1798.140(ad) includes making personal information available to a third party for other valuable consideration.
We share personal information with Google AdMob for cross-context behavioral advertising, and the advertising revenue we receive is greater for users who have not opted out. We therefore treat this disclosure as both a “sale” and a “sharing” under the CCPA, and we give you the right to opt out of it. The categories involved are identifiers, internet or other electronic network activity information, and inferences. We share these with advertising networks. We have not sold or shared sensitive personal information, and we do not sell or share the personal information of consumers we know to be under 16 years of age.
12.3 Your California Rights
If you are a California resident, you have the following rights:
- Right to know
To request the categories and specific pieces of personal information we have collected about you, the categories of sources, our business or commercial purposes, and the categories of third parties to whom we disclose it. - Right to delete
To request deletion of personal information we have collected from you, subject to the exceptions at California Civil Code section 1798.105(d). - Right to correct
To request correction of inaccurate personal information. - Right to opt out of sale and sharing
To direct us not to sell or share your personal information, including for cross-context behavioral advertising. - Right to limit the use and disclosure of sensitive personal information,
as described in Section 12.4. - Right to non-discrimination
We will not deny you goods or services, charge you a different price, or provide you a different level or quality of service because you exercised a privacy right. We do not offer financial incentives or price differences in exchange for personal information.
To exercise the right to opt out of sale and sharing, use the advertising consent controls provided by your device platform (App Tracking Transparency on iOS, advertising settings on Android), or send a request to the address in Section 1. We do not require you to create an account in order to opt out.
12.4 Limiting the Use of Sensitive Personal Information
We use and disclose sensitive personal information only for the purposes permitted by California Civil Code section 1798.121(a) — performing the services you requested, authenticating you, ensuring security and integrity, and the other enumerated business purposes. Because our use is limited to those purposes, the right to limit is not triggered as to the uses we make today. If you exercise that right, we will not use your precise geolocation for anything other than the check-in and proximity features you request, and we will not use your credentials for anything other than authentication and security.
12.5 How to Submit a Request and How We Verify It
You may submit a request by email to support@homeaway.app or through the in-app support channel. We do not maintain a toll-free telephone number because we operate exclusively online.
We will verify your identity before responding to a request to know, delete, or correct. For most requests, verification consists of confirming that you can access the email address associated with your account, and matching data points in the request against our records. For a request for specific pieces of personal information, we apply a higher standard and may require additional verification. If we cannot verify you, we will let you know and will treat a deletion request as an opt-out request where appropriate.
We will confirm receipt within ten (10) business days and respond substantively within forty-five (45) calendar days, which we may extend by a further forty-five days with notice to you. Opt-out requests are honored within fifteen (15) business days.
Authorized agents. You may designate an authorized agent to submit a request for you. We will require written permission signed by you and will verify your identity directly, unless the agent provides a valid power of attorney.
12.6 Notice of Financial Incentive
We do not offer any financial incentive, loyalty program, referral bonus, or price difference in exchange for personal information.
12.7 Shine the Light
California Civil Code section 1798.83 permits California residents to request information about disclosures of personal information to third parties for their own direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes.
13. Your Privacy Rights — All United States Users
A number of states have enacted comprehensive consumer privacy laws. Rather than distinguish among them, we extend the following rights to every user of the Services in the United States, regardless of where you live and regardless of whether your state’s law applies to us. Where a state law gives you a right broader than the one described here, that broader right controls.
- Confirm and access
To confirm whether we are processing your personal information and to obtain a copy of it. - Correct
To correct inaccuracies, taking into account the nature of the information and the purposes of the processing. - Delete
To delete personal information you provided to us and personal information we obtained about you. - Portability
To obtain a copy of your personal information in a portable and, to the extent technically feasible, readily usable format. - Opt out of targeted advertising
To direct us not to process your personal information for targeted advertising. - Opt out of sale
To direct us not to sell your personal information. - Opt out of profiling in furtherance of decisions producing legal or similarly significant effects
We do not engage in such profiling. - Withdraw consent
to any processing to which you previously consented, including precise geolocation. - Non-discrimination
To exercise these rights without being denied service, charged more, or given a lesser experience.
Submit requests by the methods in Section 12.5. We will respond within forty-five (45) days, extendable once by a further forty-five days where reasonably necessary, with notice to you.
Right to appeal. If we decline to act on your request, we will tell you why, and you may appeal that decision by replying to our response or by writing to us at the address in Section 1 with the subject line “Privacy Appeal.” We will decide the appeal and respond in writing within sixty (60) days, explaining the reasons for our decision. If we deny your appeal, we will provide you a method to contact your state Attorney General to submit a complaint.
Consent for sensitive data. Several state laws require opt-in consent before processing sensitive data, including precise geolocation. We obtain that consent through the device-level location permission prompt before any precise geolocation is collected, and you may withdraw it at any time in your device settings.
14. Third-Party Services and Links
The Services integrate and link to services operated by others, including Apple, Google, the third-party login providers listed in Section 3.3, advertisers, and the websites of venues and businesses. This Privacy Policy does not apply to those services. We do not control them and we are not responsible for their privacy practices. Review their policies before providing information to them.
15. Users Outside the United States
The Services are offered only in the United States and are intended only for users located in the United States. We do not offer the Services in the European Economic Area, the United Kingdom, Canada, or elsewhere, and we make no representation that the Services are appropriate or available for use outside the United States. If you access the Services from outside the United States, you do so on your own initiative and you are responsible for compliance with local law.
16. Data Breach Notification
If we become aware of a security incident affecting your personal information, we will notify you and any applicable regulator as required by law, including Florida’s security-breach statute and the breach-notification laws of your state of residence.
17. Changes to This Privacy Policy
We may update this Privacy Policy. When we do, we will revise the “Last Updated” date at the top and post the revised policy in the App and on the Site. If the changes are material, we will provide notice before they take effect by in-app notice, email to the address associated with your account, or both, and, where required by law, we will obtain your consent. Your continued use of the Services after the effective date of a revised Privacy Policy means you accept it.
18. Contact Us
Questions, requests, and complaints about this Privacy Policy or our handling of personal information should be directed to:
Fandelay Industries, LLC d/b/a HomeAway Attention: Evan Caruso, CEO 5443 Sunseeker Blvd, Greenacres, Florida 33463 Email: support@homeaway.app