skip to main content
Book Your Stay
Reservation Details
Your Travel Dates
1
0
3317 Forty Mile Road, Wheatland, California 95692, United States
SIGN INTO WILD CARD REWARDS Hard Rock Hotels
1
0
Book Now

Privacy Policy

Privacy Policy

Effective: December 6, 2019

HR Sacramento FM, LLC (“HR Sacramento,” “we,” “us,” or “our”) values your privacy.  This Privacy Policy (“Policy”) explains how we collect, use, protect, and disclose personally identifiable information and data (“Personal Information”) when you use the Hard Rock Sacramento Casino and Hotel website at https://www.hardrockhotelsacramento.com (“Site”) and associated mobile and other applications and services, including any online reservations you make at the Hard Rock Hotel & Casino-Sacramento at Fire Mountain (the “Hotel and Casino”) (collectively, the “Services”).  This Policy also explains your choices for managing your Personal Information preferences including, when applicable, your rights under the California Consumer Privacy Act (“CCPA”) and the General Data Protection Regulation (“GDPR”).

This Policy is subject to the Terms and Conditions that govern any Services.  By accessing or using the Site or Services, you consent to and agree to be bound by this Policy and, depending on the Service also the relevant Terms and Conditions.  If you are a resident of California, additional provisions may apply to you under the CCPA as set forth on our California Privacy Rights page.  If you are a resident of the European Union, additional provisions may apply to you as set forth in Section 17, Appendix A below.

1. Who Is Collecting Your Information

The Site is operated, and the Services are provided, by HR Sacramento FM, LLC, which is the controller for all Personal Information collected through the Site and Services and at the Hotel and Casino. Personal Information collected through the Site or at the Hotel and Casino may be shared with our owners, licensors, and affiliated entities, including, but not limited to, Hard Rock Cafe International (USA), Inc. and its affiliated entities (collectively, “Hard Rock”) and the Estom Yumeka Maidu Tribe of the Enterprise Rancheria (“Enterprise Rancheria”), which owns the Hotel and Casino, provided that they abide by the terms of this Policy. This Policy applies only to the Site, the Services, and the Hotel and Casino. Other privacy policies may apply to certain other programs made available through the Site such as, but not limited to, the Hard Rock Rewards Program, the Wild Card Rewards offered through the Hotel and Casino, the Hard Rock Social Casino, the booking engines used to make hotel reservations, and third-party job application systems (collectively, the “Other Programs”).  Each of these Other Programs are discussed below.

2. Managing Your Information Preferences

You can review, correct, update, change, or request deletion of the Personal Information you provided to us by using this form.  We will respond to your requests within the time period specified by applicable law, or if no time period is specified, we will use reasonable efforts to respond within thirty (30) days of receipt of the request, subject to any limitations in applicable law.  If you are California resident, please see our California Privacy Rights page for more information on the exercise of rights under the CCPA.  If you are a resident of the European Union, please review Section 17 below.

If you wish to opt-out of receiving email marketing communications, you can use this form or click the unsubscribe mechanism at the bottom of each email.  

Requests relating to the Other Programs must be made through the procedures specified in the privacy policies for those Programs.  For example, as noted in the Job Posting Information section, you must contact iCIMS to access, correct, amend, or delete any Job Posting Information you may have submitted through their tracking system.

3. Information We Collect

Personal Information We Collect Directly From You

We collect Personal Information that you choose to provide us, such as when you register for email communications, reserve a room or use Services at the Hotel and Casino, or when you use one of the Other Programs offered through the Site, such as when you register for the Wild Card Rewards program, register for the Hard Rock Rewards program, designate Hard Rock Sacramento Hotel and Casino as your home casino on the Hard Rock Social Casino, or apply for a job through the Site.  For what information we may collect in connection with each of these Other Programs, please see the respective section below.

By providing us your email address, you consent to receiving emails from us.  You may revoke this consent at any time as described in the section on “Managing Your Information Preferences.”

We may also collect Personal Information (a) in connection with requests for proposals for weddings, meetings, and other special events at the Hotel and Casino by completing forms on the Site; and (b) when you request certain services offered at the Hotel and Casino.  When we collect this type of Personal Information, we will notify you as to why we are asking for Personal Information and how this Personal Information will be used.  Providing this Personal Information is optional; however, if you choose not to provide the requested Personal Information, you may not be able to use some or all of the features of the Site or Services.

From time to time, our Site may request Personal Information from you via surveys, sweepstakes, or contests.  Participation in these surveys, sweepstakes, or contests is completely voluntary.  Contact Personal Information will be used to administer your participation in a contest or sweepstakes, notify the winners, and award prizes.  Survey Personal Information will be collected and used for purposes of monitoring or improving the use, features, and performance of the Site and our other products and services.

Information We Collect Automatically

We may automatically collect the following Personal Information about your use of our Site or Services through cookies and other technologies:  your domain name; your browser type and operating system; web pages you view; links you click; your IP address; your mobile device ID; the length of time you visit our Site or Services; and the referring URL, or the web page that led you to our Site (collectively, “Usage Data”).  We may combine this Usage Data with other information that we have collected about you, including, where applicable, your Personal Information.  Please see the section “Our Use of Cookies and Other Tracking Mechanisms” below for more information.  We use Usage Data to help us understand how people use the Site and Services, and to enhance the Services we offer.

Reservation System

When you make a reservation online at the Site, you will be asked to supply your name, email address, birthdate, telephone number, an employer or company name, and credit card, debit card or other form of payment information (collectively, “Reservation Information”).  The Reservation Information is collected and processed using the ResNet booking engine (“Booking Engine”).  The Booking Engine is subject to change and any such change will be reflected in an updated version of this Policy.

Both HR Sacramento and Hard Rock collect and process Reservation Information from the Booking Engine to complete your reservation, to provide you Services and to provide customer care as needed.  Hard Rock will also track your Reservation Information and stays for purposes of tracking rewards under the Hard Rock Rewards program.

Social Casino

Users of the Hard Rock Social Casino may choose “Sacramento” as their home casino or Sacramento may be auto-assigned to them because they registered via a link provided by HR Sacramento.  Please note that any Personal Information collected through the Hard Rock Social Casino is subject to the Hard Rock Social Casino privacy policy at https://hardrocksocialcasino.com/terms/18/tc.html#_privacy.  Please note HR Sacramento will receive a data feed from Hard Rock Social Casino for data relating to players that are assigned to HR Sacramento as their home casino.  Such data will be used by HR Sacramento in accordance with this Policy.

Wild Card

If you sign up for Wild Card Rewards, your Personal Information is collected by HR Sacramento and shared with Hard Rock under the following privacy policy:  https://www.hardrockhotels.com/privacy.  Hard Rock and HR Sacramento use this information to confirm your eligibility to participate.  You will be assigned a Wild Card Rewards number that is used to track your betting, expenditures, and other transactions (“Transaction Information”) at the Hotel and Casino.  You agree that we may use the information we collect, including Transaction Information, for purposes of administering the Wild Card Rewards and Hard Rock Rewards Programs and for the other purposes specified in this Policy.

Hard Rock Rewards

Hard Rock also offers an overall rewards program that allows members to earn rewards at Hard Rock Hotels and Hard Rock Cafes & Rock Shops.  If you sign up for Hard Rock Rewards, you will be asked to provide your Personal Information.  In addition, Hard Rock will track your transactions at Hard Rock Hotels, including our Hotel and Casino, and other Hard Rock Cafes & Rock Shops to determine your eligibility for rewards.  Any Personal Information collected under Hard Rock Rewards is collected by Hard Rock and shared with HR Sacramento under the following privacy policy:  https://members.hardrock.com/privacy-policy.

Job Postings

This Site or the website at www.hardrockhotels.com (“HRH Site”) may include job postings from time to time for our Hotel and Casino.  You may be given the opportunity to apply for job openings online through an applicant tracking system operated by iCIMS by creating an account and submitting either via this Site or the HRH Site, which is usually received by the human resources department of the hiring company.  If submitted through that tracking system, your resume and other Personal Information (collectively, “Job Posting Information”) will be made available to us or the manager or operator of the hiring hotel if that is a separate entity.  In addition, your Job Posting Information will be stored in that tracking system in an electronic database maintained by iCIMS in the United States on behalf of HR Sacramento and Hard Rock.

In some cases, the Site might list the email address of a contact person at the applicable hiring hotel.  If that hiring hotel is HR Sacramento, any Job Posting Information sent to that email address will be maintained in accordance with this Policy.

All such Job Posting Information may be used for the purpose of assessing your suitability for current and future job vacancies and to pursue your recruiting process.

You will also be required, by the applicant tracking system, to create an account with a user name and password when using an applicant tracking system.  You are solely responsible for maintaining the confidentiality of that user name and password, and for any unauthorized access or use of your user name and password.

If at any time you want your Personal Information or resume to be deleted by us, you need to use this form.  You also need to contact iCIMS directly as stated in the iCIMS privacy policy for any questions or requests regarding their processing of your Personal Information, https://www.icims.com/legal/privacy-policy-Site.

4. How We Use Your Information

We use your Personal Information for the following business purposes:

  • To provide our Site and Services to you, including reservations and services you request at our Hotel and Casino, to communicate with you about your use of our Site and Services, to respond to your inquiries, to process job applications, to fulfill your orders, and for other customer service purposes.
  • To tailor the content and information that we may send or display to you, to offer location customization, personalized help and instructions, and to otherwise personalize your experiences while using our Site or Services.
  • To notify you about marketing and promotional opportunities.  For example, we and Hard Rock may use your information, such as your email address, to send you news and newsletters, special offers, and promotions, or to otherwise contact you about products or information we think may interest you.  We also may use the information that we learn about you to assist us in advertising our Site and related services on third-party websites.
  • To conduct promotions, such as sweepstakes, contests and giveaways, and to administer and operate the Wild Card Rewards and Hard Rock Rewards Programs.
  • To better understand how users access and use our Site and Services, both on an aggregated and individualized basis, in order to improve our Site and Services and respond to user desires and preferences, and for other research and analytical purposes.

5. How We Share Your Information

We may share your Personal Information as follows:

  • Affiliates.  We may disclose the Personal Information we collect from you to Hard Rock and its affiliates; however, if we do so, their use and disclosure of your Personal Information will be maintained by them in accordance with this Policy.
  • Service Providers.  We may disclose the information we collect from you to third-party vendors, service providers, contractors or agents who perform functions on our behalf (“Service Providers”).  For example, we may contract with Service Providers to provide certain services, such as hosting and maintenance, data storage and management, property management, and marketing and promotions.  We only provide our Service Providers with the information or access to information necessary for them to perform these services on our behalf.  Each Service Provider must agree to use commercially reasonable security procedures and practices, appropriate to the nature of the information involved, in order to protect your Personal Information from unauthorized acquisition, access, use, or disclosure.  Service Providers may only use the Personal Information to provide services to Hard Rock and HR Sacramento and are prohibited from using Personal Information other than as authorized by Hard Rock and HR Sacramento under this Policy.
  • Business Transfers.  If we are acquired by, or merged with, another company, if substantially all of our assets are transferred to another company, or as part of a bankruptcy proceeding, or if we are in negotiations with respect to any such transaction, we may transfer, or make available, the Personal Information we have collected from you to the other company or resulting legal entity.
  • In Response to Legal Process.  We also may disclose the Personal Information we collect from you in order to comply with the law, a judicial proceeding, court order, or other legal process, such as in response to a subpoena.
  • To Protect Us and Others.  We also may disclose the Personal Information we collect from you where we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of any applicable Terms and Conditions for Services provided through this Site, at the Hotel and Casino or this Policy, or as evidence in litigation in which we are involved.
  • Aggregate and De-Identified Information.  We may share aggregate or de-identified Personal Information about users with third parties and publicly for marketing, advertising, research, or similar purposes.

Except as noted in this Section 5, we do not disclose Personal Information to third parties, including for their direct marketing purposes, without your consent, except as explained in this Privacy Policy.

6. Retention of Personal Information

We retain Personal Information about you for the time necessary to accomplish the purpose for which such information was collected, usually for the duration of any contractual relationship or as long as you use or are registered for any of the Services and for any period thereafter as legally required or permitted by applicable law.  Our retention policies respect applicable statute of limitation periods and legal requirements.  When we no longer need to use or retain your Personal Information for any business, commercial or lawful purpose, we will endeavor to destroy all records, both physical and electronic, containing your Personal Information.

7. Our Use of Cookies and Other Tracking Mechanisms

We and our Service Providers use cookies, web beacons, and other tracking mechanisms to track information about your use of our Site and Services.  We may combine this information with other Personal Information we collect from you (and our Service Providers may do so on our behalf).

Currently, our systems do not recognize browser “do-not-track” requests.  You may, however, disable certain tracking as discussed in this section (e.g., by disabling cookies), and change your preferences at any time by using the ‘Privacy Settings’ link found in the footer of our Site, but such disabling might impair use of the Site and Services.

Cookies.  Cookies are alphanumeric identifiers that we transfer to your computer’s hard drive through your web browser for record-keeping purposes.  Some cookies allow us to make it easier for you to navigate our Site and Services, while others are used to enable a faster log-in process or to allow us to track your activities at our Site and Services.  For a complete description of the cookies that we use, please see our Cookie Statement.

Disabling Cookies.  In certain jurisdictions, you will be asked to provide consent for your cookies when accessing our website. The request does not always reappear when you revisit the site. You may click to revise your cookie settings.

Third-Party Analytics.  We use automated devices and applications, such as Google Analytics, to evaluate usage of our Site and Services.  These devices and applications may use cookies and other tracking technologies to perform their services.  We use these tools to help us improve our Services, performance, and user experiences.    

8. Advertising and Online Tracking

We may allow third-party companies to serve ads and collect certain anonymous information when you visit the Site.  These companies may use non-personally identifiable information (e.g., click stream information, web browser type, time and date, subject of advertisements clicked or scrolled over) during your visits to the Site and other websites in order to provide advertisements about goods and services likely to be of interest to you.  We are not responsible for, and expressly disclaim any liability related to, the content of these ads or the activities of these third-party companies. 

9. Security

We maintain physical, technical, and administrative safeguards to protect the security of information transmitted to us through this Site or Services.  However, no data transmission over the Internet or other network can be guaranteed to be 100% secure.  As a result, while we strive to protect information transmitted on or through the Site or Services, we cannot and do not guarantee the security of any information you transmit on or through the Site or Services, and you do so at your own risk.  You are also responsible for maintaining the security of any password or user login credentials you are provided in connection with the Site or the Services.

10. Links to Other Websites

Our Site and Services may contain links to other websites, including websites that collect data or solicit Personal Information, or allow others to send you such links.  A link to a third party’s website does not mean that we endorse it or that we are affiliated with it.  We do not exercise control over third-party websites and are not responsible for their privacy and security policies and practices.  You access such third-party websites or content at your own risk.  We encourage users to be aware when they leave this Site and to read the privacy policy of a third-party website before providing any information to the third-party website.

11. Children’s Privacy

The Site and Services are intended for users who are 21 years old or older.  In addition, we never collect or maintain information at our Site from those we actually know are under 13 (or 16 in the case of European Union residents).  If we are notified that we have collected Personal Information from a person under 13 (or 16 in the case of European Union residents), we will delete that Personal Information.  Our Site is a general audience website.

12. Processing in the United States

Please be aware that, depending on your location, your Personal Information and communications may be transferred to and maintained on servers or databases located outside your state, province, or country.  If you are located outside of the United States, please be advised that we store all Personal Information in the United States.  The laws in the United States may not be as protective of your privacy as those in your location.  By using the Site or Services, you agree that the collection, use, transfer, and disclosure of your Personal Information and communications will be governed by the applicable laws in the United States.

13. How to Contact Us

You may address all communications to HR Sacramento FM, LLC, c/o Seminole Hard Rock Support Services, LLC, Attn:  Data Protection Office (DPO), 5701 Stirling Road, Davie, Florida 33314, or email to dataprotection@HardRock.com.  Please include your name, address, and phone number, or email in all communications and state clearly the nature of your request.

14. EU/US Privacy Shield Compliance

HR Sacramento and Hard Rock comply with the EU/US Privacy Shield framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information from European Union members and treaty countries, and the United Kingdom.  We have certified that we adhere to the Privacy Shield Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement and Liability.

If there is any conflict between the policies in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern.  To learn more about the Privacy Shield program and to view our certification page, please visit www.privacyshield.gov/.

In compliance with the EU/US Privacy Shield Principles, Hard Rock and HR Sacramento commit to resolve complaints about your privacy and our collection or use of your personal information.  European Union citizens with inquiries or complaints regarding this privacy policy should first contact HR Sacramento FM, LLC, c/o, Seminole Hard Rock Support Services, LLC, Attn:  Data Protection Office (DPO), 5701 Stirling Road, Davie, Florida 33314, or email to dataprotection@HardRock.com.

Please include your name, address and phone number or e-mail in all communications and state clearly the nature of your request or concern.  If you wish to make a request to access the personal information we collect and store about you, complete this form.

HR Sacramento and Hard Rock Cafe International (USA), Inc. has provided a private sector independent recourse mechanism (located in the United States) to investigate and expeditiously resolve individual complaints and disputes.  This dispute mechanism will cover all personal data except for human resource data.  For more information, visit the website for ICDR®/AAA® EU-U.S. Privacy Shield:  International Centre for Dispute Resolution®, the international division of the American Arbitration Association® (ICDR/AAA) at go.adr.org/privacyshield.html.  The services of ICDR/AAA are provided at no cost to you.  Under certain limited conditions and as a last resort, the individual can invoke binding arbitration.  The Federal Trade Commission has jurisdiction over HR Sacramento’s and Hard Rock’s compliance with the Privacy Shield.

If HR Sacramento or Hard Rock transfers your personal data to a third party, we will ensure the third party is contractually obligated to process your data only for limited, specific purposes consistent with this policy, to apply the same level of protection to that data as the EU-U.S. Privacy Shield Principles, and notify us if it makes a determination that it can no longer meet this obligation.  Upon notice, HR Sacramento and Hard Rock will take reasonable and appropriate steps to stop and remediate unauthorized processing.  In cases of onward transfer to third parties of data received pursuant to the EU-US Privacy Shield, HR Sacramento and Hard Rock are potentially liable.

15. Complaints

If you feel that HR Sacramento has not complied with the policies outlined in this Policy, please contact us at HR Sacramento FM, LLC, c/o, Seminole Hard Rock Support Services, LLC, Attn:  Data Protection Office (DPO), 5701 Stirling Road, Davie, Florida 33314, or email to dataprotection@HardRock.com.  Please include your name, address, and phone number, or email in all communications and state clearly the nature of your request.  The Company will investigate and attempt to resolve complaints and disputes regarding use and disclosure of Personal Information in accordance with the principles contained in this Policy within thirty (30) days of receiving the complaint, unless a shorter period is required by law.  European Union residents may also follow the procedure outlined in Section 14 above under the Privacy Shield.

16. Privacy Policy Changes

We may change this Policy from time to time.  If we decide to change this Policy, we will inform you by posting the revised Policy on the Site.  Those changes will go into effect on the “Revised” date shown in the revised Policy.  By continuing to use the Site or Services, you consent to the revised Policy.

17. Appendix A - Provisions Applicable to European Union Data Subjects

This Appendix outlines certain additional information that HR Sacramento is obligated to provide to data subjects of the European Union as well as certain rights such residents have with respect to the processing of their Personal Information under GDPR.  For European Union residents, the term Personal Information means information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

A. Legal Bases for Processing of Personal Information

We process the personal Information collected for the purposes described in the sections entitled “Information We Collect” and “How We Use Your Information” in our Policy.  The legal bases for our processing activities include processing Personal Information as necessary to comply with our contractual obligations, compliance with our legal obligations, protecting the safety of our employees, guests and others, for our legitimate business interests, and pursuant to your consent.  The particular legal basis for the processing of your Personal Information is based on the purpose for which such information was provided or collected.

For example, we use Personal Information, such as name, address, email and credit card information, as necessary to perform Services, such as making reservations at our Hotel and Casino.  For example, we are not able to provide our Services and products according to our contracts unless you provide us with certain necessary Personal Information.  This collection and processing of the Personal Data is based on Art. 6 para. 1 (b) GDPR (necessary for the performance of a contract with you).

We may also process your Personal Information if we have received your consent, to respond to requests from you or to take actions in our legitimate interest, such as for marketing purposes or to otherwise inform you of our business operations, and to improve our products and services.  Please note that if we rely on consent, you may withdraw your consent at any time, but such withdrawal will not affect the lawfulness of the processing of your Personal Information prior to the withdrawal.

B. Data Retention

See Section 6 for our retention policies.

C. Data Subject Rights

Data subjects of the European Union have the following rights:

  • Access, Correction and Erasure Requests:  You have the right to:
  • contact us to confirm whether we are processing your Personal Information;
  • receive certain information on how your Personal Information is processed;
  • obtain a copy of your Personal Information;
  • request that we update or correct your Personal Information; and
  • request that we delete Personal Information in certain circumstances.
  • Right to Object to Processing:  You have the right to request that we cease processing of your Personal Information based on our legitimate business interests, including profiling, unless we are able to demonstrate a compelling legitimate basis for such processing or we need to process your Personal Information for the establishment, exercise, or defense of a legal claim.  You also have the right to object, at any time, to processing of your Personal Information for direct marketing, which includes profiling to the extent that it is related to such direct marketing.

  • Right to Restrict Processing:  You have the right to request that we limit the processing of your Personal Information:
  • while we are evaluating or in the process of responding to a request by you to update or correct your Personal Information;
  • where such processing is unlawful and you do not want us to delete your data;
  • where we no longer require such data, but you want us to retain the data for the establishment, exercise, or defense of a legal claim; and
  • where you have submitted an objection to processing based on our legitimate business interests, pending our response to such request.
  • Data Portability Requests:  You have the right to request that we provide you or a third party that you designate with certain of your Personal Information in a commonly used, machine-readable format.  Please note, however, that data portability rights apply only to Personal Information that we have obtained directly from you and only where our processing is based on consent or the performance of a contract.

If you believe our processing of your Personal Information violates the GDPR, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection.  You may do so in the EU member state of your habitual residence, your place of work, or the place of the alleged violation.

D. Submitting Requests

EU data subjects can submit requests by completing this form.  We will respond to all such requests within the time frame required under GDPR.  Please note, however, that certain Personal Information may be exempt from such rights pursuant to GDPR.  In addition, we will not respond to any request unless we are able to appropriately verify the requester’s identity.  We may charge you a reasonable fee for subsequent copies of Personal Information that you request.  In addition, if we consider that a request is manifestly unfounded or excessive, we may either request a reasonable fee to deal with the request or refuse to deal with the request.