LEXUS ONLINE PRIVACY STATEMENT

This statement applies to the INTERSECT BY LEXUS – NYC website operated by Lexus, a division of Toyota Motor Sales, U.S.A., Inc. ("Lexus," "we," "us," or "our") online. Last Updated December 7th, 2018. Where product-or-service-specific terms conflict with this Privacy Statement, those terms shall govern.



UPDATED AS OF DECEMBER 7TH, 2018


Lexus, a division of Toyota Motor Sales, USA, Inc. (“we”, “us”, and “our”) is committed to maintaining your confidence and trust as it relates to the privacy of your information. Please read below and learn how we collect, protect, share and use your information as part of our technology platforms, including, without limitation, our websites, web pages, interactive features, applications, Twitter, Facebook and other social media networks, and mobile applications ("Platforms").




INFORMATION WE COLLECT ON OUR PLATFORMS

INFORMATION YOU PROVIDE TO US

We may collect Personal Information (information that can be used to identify you as an individual) such as your name, e-mail, telephone number, home address, social media handles, or demographic information (such as ZIP code, age). To register to receive the INTERSECT BY LEXUS -NYC newsletter, we collect your name and email address.

INTERSECT BY LEXUS – NYC utilizes third party reservation systems which may collect your credit card number and other payment-related information in connection with your reservations for dining and events. We do not receive this financial information.

INTERSECT BY LEXUS – NYC utilizes third-party social media management services to collect and analyze publicly available information on various social media sites. Information that you post on those sites, as well as publicly available information that you post on other pages made available through those sites and on other social media sites, may be used by Lexus for customer satisfaction, customized marketing, marketing analysis, consumer research and other legitimate business purposes.

INFORMATION WE COLLECT AUTOMATICALLY

Usage Information. Whenever you visit or interact with the Platforms, we, as well as any third-party advertisers and/or service providers, may use a variety of technologies that automatically or passively collect information about how the Platforms are accessed and used ("Usage Information"). Usage Information may include browser type, device type, operating system, application version, the page served, the time, the preceding page views and your use of features or applications on the Platforms, such as interactions with friends and group activities. This information helps us keep our Platforms fresh and interesting to our visitors and allows us to tailor content to a visitor's interests. Usage Information is generally non-identifying, but if Lexus associates it with you as a specific and identifiable person, Lexus treats it as Personal Information.

Device Identifier. We automatically collect your IP address or other unique identifier ("Device Identifier") for the Device (computer, mobile phone, tablet or other device) you use to access the Platforms. A Device Identifier is a number that is assigned to your Device when you access a website or its servers, and our computers identify your Device by its Device Identifier. We, and our affiliates, service providers, business partners, and other third parties, including authorized dealers, may use a Device Identifier to, among other things, administer the Platforms, help diagnose problems with our servers; analyze trends, track users' web page movements over time and across different websites, Platforms, or other mobile, online or offline services; to help identify you and your shopping cart and gather broad demographic information for aggregate use.

Cookies; Pixel Tags. The technologies used on the Platforms to collect Usage Information, including Device Identifiers, include but are not limited to: cookies (data files placed on a Device when it is used to visit the Platforms), mobile analytics software and pixel tags (transparent graphic image, sometimes called a web beacon or tracking beacon, placed on a web page or in an e-mail, which indicates that a page or e-mail has been viewed). Cookies may also be used to associate you with social networking sites like Facebook and Twitter and, by using one of their applications either on or otherwise connected to our Platforms (e.g. social media log-in credentials or vehicle configuration shared to social media), you may enable interaction between your activities on the Platforms and your activities on such social networking sites. We, or our vendors, may place cookies or similar files on your Device for security purposes, to facilitate site navigation and to personalize your experience while visiting our Platforms (such as allowing us to select which ads or offers are most likely to appeal to you, based on your interests, preferences, location or demographic information). A pixel tag may tell your browser to get content from another server.

Most browsers allow you to control cookies, including whether or not to accept them and how to remove them. You may set most browsers to notify you if you receive a cookie, or you may choose to block cookies with your browser. However, please be aware that some features of the website may not function properly or may be slower if you refuse cookies. In addition, the offers we provide when you visit us may not be as relevant to you or tailored to your interests. If you block or delete cookies, not all of the tracking that we have described in this Privacy Statement will stop.

We do not respond to Do Not Track signals.

We use cookies provided by or our vendors to collect statistical information about the use of the website. To opt-out, please go to our cookie preference center.

Cookie Settings

To learn more about what Cookies we use, please refer to our Cookie Policy


HOW WE USE THE INFORMATION WE COLLECT

We use the Personal Information we collect about and from you for a variety of legitimate purposes connected to providing the INTERSECT BY LEXUS – NYC experience and Platform to you.

We use your Personal Information provided in connection with customer requests to respond to those questions and requests you make, including delivery of our newsletter when requested.

We use your Personal Information provided in connection with your reservations at the restaurants and for events at INTERSECT BY LEXUS - NYC.

We also use your Personal Information to tailor content, advertisements, and offers we serve you, including by providing more relevant content, advertisements, and offers over time and across multiple devices; as well as for purposes disclosed at the time you provide your Personal Information or otherwise with your consent.


SHARING OF INFORMATION

Except as described in this Statement, we will not provide any of your Personal Information to any third parties without your specific consent. We may share non-Personal Information, such as aggregate data and Usage Information with any third parties. We may also share your information as disclosed at the time you provide your information, as set forth in this Privacy Notice and in the following circumstances:

Third Parties Providing Services on Our Behalf. We may share your Personal Information with third parties that perform functions on our behalf (or on behalf of our partners) such as service providers that host or operate our Platforms, analyze data, process transactions and payments, fulfill orders or provide customer service; advertisers; sponsors or other third parties that participate in or administer our promotions, contests, sweepstakes, surveys or provide marketing or promotional assistance and "powered by" partners or partners in co-branded sites. Your Personal Information may also be used by us or shared with our subsidiaries, affiliates, sponsors, partners, advertisers or other third parties to provide you with product and event information and promotional and other offers.

Program Partners. We may offer special Programs in which you may elect to participate. If you choose to participate in a Program, your Personal Information may also be shared with our Program partners and may be used by our Program partners if you indicate your interest in receiving communications directly from that company. If you elect to receive communications from our business partner, your information will be used by that company in accordance with its policies, and this Privacy Notice will not apply to that company's use of your information. Sometimes the rules, terms and conditions or disclaimers that apply to a particular Program include information on how we may use the Personal Information that you provide to us through your participation in the Program. If there is a conflict between the rules, terms and conditions that apply to a particular Program and this Privacy Notice, those applying to the particular Program will govern. Please review all of the information about a Program before you provide us with any Personal Information.

Your Agreement to Have Your Personal Information Shared. While on our Platforms, you may have the opportunity to opt in to receive information and/or marketing offers from someone else or to otherwise consent to the sharing of your information with a third party, including social networking sites such as Facebook or Twitter. If you agree to have your Personal Information shared, your Personal Information will be disclosed to the third party and the Personal Information you disclose will be subject to the privacy policy and business practices of that third party.

Business Transfers. We may share your Personal Information with our affiliates primarily for business and operational purposes. In the event that Lexus is involved in a bankruptcy, merger, acquisition, reorganization or sale of assets, your information may be sold or transferred as part of that transaction.

Legal Disclosure. We may transfer and disclose your information to third parties to comply with a legal obligation; when we believe in good faith that the law or a governmental authority requires it; to verify or enforce our Terms of Use or other applicable policies; to address or investigate fraud, security or technical issues; to respond to an emergency or threat to public safety; or otherwise to protect our rights or property or security of third parties, visitors to our Platforms or the public.


INFORMATION WE RECEIVE FROM THIRD PARTIES

We may receive information about you from third parties.

Websites. For example, if you are on another website and you opt in to receive information from INTERSECT BY LEXUS – NYC, that website will submit to us your e-mail address and other information about you so that we may contact you as requested.

The following third party applications collect Personal Information directly from you on their own platforms in order to assist us in making the INTERSECT BY LEXUS – NYC experience available to you by providing services exclusively from their platform or websites. As such they are data controllers in common and have their own practices and policies concerning the collection, use and sharing of Personal Information.

Eventbrite. Eventbrite collects your name and email in order to offer tickets for admission for INTERSECT BY LEXUS – NYC events. They process data for these transactions in the United States. Eventbrite processes Personal Information in accordance with the US-EU Privacy Shield certification guidelines. To find out more about Eventbrite’s privacy practices, please refer to their privacy policy.

Resy. The Resy Network, Inc. collects your name and email in order make reservations as INTERSECT BY LEXUS – NYC restaurants and coffee shops. They process data for these transactions in the United States. To find out more about Resy’s privacy practices, please refer to their privacy policy.

Third Party Applications. You may also choose to participate in a third-party application or feature (such as one of our Facebook or Twitter applications or a similar application or feature on a third-party website) through which you allow us to collect (or the third party to share) information about you, including Usage Information and Personal Information such as lists of your friends, "likes," comments you have shared, groups and location. Services like Facebook Connect give you the option to post information about your activities on our Platform to your profile page to share with others within your network. In addition, we may receive information about you if other users of a third-party website give us access to their profiles and you are one of their "connections" or information about you is otherwise accessible through your "connection's" web page, profile page or similar page on a social networking or other third-party website or interactive service.

Other Third Parties. We may also receive information about you from our affiliates, other service providers, business partners, and other third parties. Information from such third parties may have been collected online, offline, or through publicly- or commercially-available sources. We may supplement the information we collect about you through the Platforms with such information from third parties in order to enhance our ability to serve you, to tailor our content, advertisements and other offers to you and/or to offer you opportunities to purchase products or services that we believe may be of interest to you. See the Advertising/Behavioral Targeting; How to Opt-out section above for further information about how you can opt-out of targeted advertising online.


CHOICE AND ACCESS

The Platforms give you choices. If you choose to receive e-mails from us about our restaurant, events and other information, we strive to keep your Personal Information updated and accurate.

Should you wish to receive fewer communications from INTERSECT BY LEXUS – NYC, you can choose to unsubscribe from our newsletter.

If you receive an e-mail, you may opt out at any time by following the opt-out instructions provided in the e-mail or text you receive. Your opt-out request will be processed promptly and in the case of email, within 10 days of the date on which we receive it.

In accordance with our routine record-keeping, we may delete certain records that contain Personal Information you have submitted through the Platforms. We are under no obligation to store such Personal Information indefinitely and disclaim any liability arising out of, or related to, the destruction of such Personal Information. It may not always be possible to completely remove or delete all of your information from our databases without some residual data because of backups and other reasons. We will retain your information as needed to provide you services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes and enforce our agreements. We do not control certain privacy settings and preferences maintained by our social media partners such as Facebook and Twitter. If you wish to make changes to those settings and preferences, you may do so by visiting the settings page of the appropriate social media site.


ADVERTISING/BEHAVIORAL TARGETING: HOW TO OPT-OUT

We may use third-party ad network providers to help present ads on the Platforms, as well as other service providers to evaluate and provide us with information about the use of the Platforms and viewing of our content. We do not share Personal Information with these providers (unless, of course, you give us permission). Such providers may place and access cookies, pixel tags or similar technologies on your Device to serve you ads or other content personalized to your interests, which they infer from your precise location and/or your browsing on the Platforms and other sites you have visited. In doing so, the provider collects or has access to non-Personal Information such as your Usage Information. The use of cookies, pixel tags or similar technologies by these providers is subject to their own privacy policies, not ours.

If you prefer to not receive targeted advertising, you can opt out of some network advertising programs that use your information. To do so, please visit the DAA Opt-Out Page. Please note that even if you choose to opt out of targeted advertising, you will still see advertisements while you're browsing online. However, the advertisements you see may be less relevant to you and your interests. Additionally, many network advertising programs allow you to view and manage the interest categories they have compiled from your online browsing activities. These interest categories help determine the types of targeted advertisements you may receive. The DAA Opt-Out Page provides a tool that identifies its member companies which have cookies on your browser and provides links to those companies.


EU DATA SUBJECT RIGHTS

This section applies to persons who are located in the European Economic Area (“EEA”), which includes the European Union (“EU”) Member States, Lichtenstein, Iceland, Norway and for purposes of this Privacy Statement, the United Kingdom.

Right to Review and Rectify Your Personal Information.

You can update most of your Personal Information by signing up again with us and notifying us of any changes at OfficeofPrivacy@toyota.com

Right to Remove.

We collect your Personal Information for the legitimate business purpose of providing the services and information you request to you. You may remove yourself from our email list by following the unsubscribe instructions at the bottom of the email. To remove Personal Information stored by Eventbrite or Resy, you must sign onto your accounts on those sites and contact the applicable services directly in accordance with their privacy policies.

You may request that we delete your Personal Information that you cannot delete or unsubscribe from directly by contacting us via OfficeofPrivacy@toyota.com and we will review your requests and ask to confirm your identity. However, please be aware that since your Personal Information is required for us to provide the Services to you, asking us to terminate your account profile or remove your data will also terminate your access to the services and your ability to get information regarding INTERSECT BY LEXUS – NYC services and events.

Data Retention

We take steps to delete Personal Information that is no longer necessary to provide the Services We may be required to retain Personal Information by law, or defend against legal claims. We may de-identify and anonymize some data so that it can no longer be attributed to You.

Data Portability

If you are located in the EU or EEA, you have the right, on verified request, to obtain a copy of the Personal Information you previously entered directly, as well as the right to have this data sent by us to another organization.  If you would like us to transmit your Personal Information to another company providing similar services insofar as we are legally required, we will work with them to do so upon request and verification of such request with both the requestor and the company receiving the Personal Information.

Right of Redress

EU and EEA data subjects located in Europe, may, if they wish to, file a complaint regarding our practices by contacting the Data Commissioner’s office in the country in which they reside.


CHILDREN

The Platforms are not directed to children under 16. We do not knowingly collect, use or disclose personally identifiable information from anyone under 16 years of age. If we determine upon collection that a user is under this age, we will not use or maintain his/her Personal Information without the parent/guardian's consent. If we become aware that we have unknowingly collected personally identifiable information from a child under the age of 16, please let us know at OfficeofPrivacy@toyota.com and we will make reasonable efforts to delete such information from our records.


SECURITY OF YOUR INFORMATION AND PHISHING SCAMS

We take information security seriously and use reasonable security measures to help protect your Personal Information. We maintain appropriate technical and organizational measures for protection of the security of your Personal Information, (including protection against unauthorized or unlawful processing and against accidental or unlawful destruction, loss or alteration or damage, unauthorized disclosure of, or access to, Personal Information), confidentiality and integrity of your Personal Information.

However, no electronic data transmission or storage of information can be guaranteed to be 100% secure. Please note that we cannot ensure or warrant the security of any information you transmit to us, and you use the Platforms and provide us with your information at your own risk. When we collect sensitive information on our sites or within our mobile application (such as credit card number or geo-location information), we encrypt the transmission of that information using Secure Socket Layer technology.

Beware of Phishing Scams: There have been noticeable increases in the number of suspicious e-mails claiming that the e-mail recipient has won a Lexus lottery or other promotion. Sometimes the e-mail claims that the recipient has won a new Lexus IS. In order to claim the prize, the e-mail may ask that Personal Information be sent to a Hotmail® or Yahoo® or other e-mail address. Samples of these hoax e-mails can be found at this website.

This type of e-mail solicitation is known commonly as a "phishing" scam, with the primary objective being to obtain one's personal information. This information can then be utilized to steal a person's identity. For example, a "Lexus Lottery" phishing scam is often sent from Chinese (.cn), German (.de) or British (.co.uk) addresses, but can originate from anywhere and look very official even to the most savvy of Internet users.

Lexus will never ask you to send passwords, login names, Social Security numbers, or other personal information through e-mail or U.S. mail, fax or text message. If you receive an e-mail or letter by U.S. mail, fax or text message from Lexus asking you to update your credit card information, do not respond: this is a phishing scam. Recipients of suspicious e-mail like this should delete the message from their inbox and, if possible, update their e-mail filter settings to block e-mails from the e-mail address being used. The Federal Trade Commission and the Antiphishing Workgroup are also good sources of information about these types of security threats and how they may be reported to the authorities.


OTHER SITES

The Platforms may contain links to other sites that we do not own or operate, such as the site for Intersect by Lexus | Dubai and Lexus International, and Eventbrite.com and resy.com, both utilized to allow you to make reservations, as well as links from advertisers, sponsors and/or partners. We do not control, recommend or endorse and are not responsible for these sites or their content, products, services or privacy policies or practices, even though they may use the Lexus name or logo on their site through an agreement with us. These other sites may send their own cookies to your Device, they may independently collect data or solicit Personal Information and they may or may not have their own published privacy policies. You should independently assess the privacy policies and site terms of use for these sites prior to sharing your personal information with them. You should also independently assess the authenticity of any site which appears or claims that it is one of our Platforms (including those linked to through an e-mail or social networking page). The Platforms may make available chat rooms, forums, message boards, and news groups. Remember that any information that you disclose in these areas becomes public information and is not subject to the provisions of this Privacy Statement.


CONSENT TO PROCESSING AND TRANSFER OF INFORMATION

INTERSECT LEXUS NYC is located in the United States and our events take place in the United States. We expect that visitors from the United States and elsewhere might like to come to INTERSECT LEXUS NYC. Our Platforms are also located in the United States and are governed by and operated in, and in accordance with, the laws of the United States. Given that we are an international business, our use of your information necessarily involves the transmission of data on an international basis. If you are located in the EU, EEA, Canada or elsewhere outside of the United States, please be aware that information we collect may be transferred to and processed in the United States in order to provide the services we offer here in the United States.


CHANGES

We may update this Privacy Notice to reflect changes to our information practices. If we make any material changes we will notify you by e-mail (sent to the e-mail address specified in your account) or by means of a notice on our Platforms prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.


CONTACT US

{{!-- Do we want a link here? Not mentioned in document, but again, the old version had a link --}}

To contact us with a question, call us at 1-800-25-LEXUS or mail your inquiry to:
INTERSECT BY LEXUS – NYC
Lexus
P.O. Box 259001 – Mail Drop E3-2D
Plano, TX 75025-9001
United States

You may also obtain an update on our information practices by sending a request to:
INTERSECT BY LEXUS – NYC
Lexus
P.O. Box 259001 – Mail Drop E3-2D
Plano, TX 75025-9001
United States
>


YOUR CALIFORNIA PRIVACY RIGHTS

During 2017, we did not share any personal information about our customers with third parties for their own marketing purposes.