Your Privacy Rights
1. What Personal Data does the Company collect?
We collect personal information that you enter on our Site or otherwise volunteer to us when you contact us. You can choose not to provide certain information, but then you might not be able to take advantage of some of our features.
For purposes of this Policy, “Personal Data” means information (whether stored electronically or in paper based filing systems) relating to a living individual who can be identified from that data (or from that data and other information in our possession).
Macerich collects only that Personal Data that is relevant for the purposes for which the data is requested. You can visit our Site without telling us who you are or revealing any Personal Data.
Information You Give Us
But in some circumstances we may ask you for and you may submit Personal Data, which may include information you give us when you contact us through our Site, or by corresponding with us by phone, e-mail, or otherwise. We may collect Personal Data including contact information, such as name, address, email, and phone, and any other information that you may provide us.
Information We Collect About You
When you visit our Site, our web server automatically collects and stores the following information:
• Technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, referring website address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform; and
• Information about your visit, including the full Uniform Resource Locators (URL), clickstream to, through and from our site (including date and time), pages on our Site you viewed; page response times, download errors, duration of page visits, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, and any phone number used to call our customer service number.
This information helps us improve our Site and facilitates your online experience when accessing our Site.
Information We Receive from other Sources
We also receive information about you from third parties who operate other Sites or services we use to provide our products and services to you. We work closely with third parties, including, for example, business partners, promoters, affiliates, and sub-contractors in technical, payment and delivery services, advertising networks, marketing analytics providers, promotions, and search information providers.
2. How does the Company use Personal Data?
Information you give to us
We will use this information:
• to provide you with the information, products, and services that you request from us;
• to carry out our obligations arising from any contracts entered into between you and us, or between you and our promoters, affiliates, or distributors;
• to contact you in the future to provide you with information about other goods and services we offer, or that are offered by our affiliates or third party vendors;
• to contact you in the future with newsletters and email correspondence on behalf of Macerich, our affiliates and our third party vendors;
• to notify you about changes to our service;
• to comply with applicable laws and regulations;
• to allow you to participate in our sweepstakes, contests and promotions;
• to perform data analyses (including anonymization and aggregation of Personal Data);
Information We Collect about You. We will use this information:
• to administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical, and survey purposes;
• to improve our site to ensure that content is presented in the most effective manner for you and for your computer;
• as part of our efforts to keep our site safe and secure.
Information we receive from other sources.
We will combine this information with information you give to us and information we collect about you. We will use this information and the combined information for the purposes set out above (depending on the types of information we receive).
3. Do we share your Personal Data with any Third Parties?
We do not sell your Personal Data to any third parties. We partner with third parties to provide some of the services and products available on our Site and at our events. We sometimes disclose your Personal Data to those third parties, and they sometimes collect your Personal Data in the first instance and provide it to us. All such third parties use your Personal Data only on behalf of Macerich and under the instructions of Macerich on how your information may be used and processed. Macerich and our partners will use your Personal Data for limited purposes as specified in this Policy. Macerich takes reasonable steps to ensure these third parties use your Personal Data only for the purposes for which they have been engaged by Macerich and that they agree to provide protections for your Personal Data that are no less protective than those set out in this Policy.
We may also disclose your personal information to third parties in the following circumstances:
• If we sell or buy any business or assets, in which case we will disclose your Personal Data to the prospective seller or buyer of such business or assets as part of the purchase, transfer, or sale of services or assets;
• If we sell all or substantially all of our assets to a third party, in which case personal information about our customers will be one of the transferred assets;
Whenever we share information with third parties, we will take steps to ensure that the third parties put in place adequate measures to safeguard your Personal Data, and they will be required to use any Personal Data for only the intended purpose for which it was shared.
4. How we store your Personal Data.
Macerich uses reasonable and appropriate measures to protect your Personal Data from loss, misuse and unauthorized access, disclosure, alteration and destruction, taking into due account the risks involved in the processing undertaken and the nature of the Personal Data we collect.
We will keep your personal data for as long as we need it, or as otherwise prescribed by law, for the purposes set out above. This period will vary depending on your interactions with us. We may also keep a record of correspondence with you (for example if you have made a complaint about us or our services) for as long as is necessary to protect us from a legal claim.
You may unsubscribe from any of our online e-mail updates and marketing by following the unsubscribe instructions in the body of any e-mail message we have sent to you. We will take commercially reasonable steps to implement your unsubscribe requests promptly, but you may still receive promotional information form us by mail for up to 60 days, and up to 10 days for e-mail. You may also continue to receive information from those third parties to whom we have previously disclosed your Personal Data.
Please note that when you unsubscribe from our marketing communications, we will keep a record of your email address to ensure we do not send you marketing emails in future.
5. Access to Other Websites
6. Protecting Children’s Privacy
We are strongly committed to protecting the safety and privacy of children who visit our Site. Protecting children is important to Macerich. The Site is not intended for use by children under 13 years of age, and we do not knowingly collect Personal Information from such children. By using the Site, you represent that you are at least 13 years of age.
If you are a parent or guardian who believes we have inadvertently collected your child’s Personal Information, you may contact us to request the removal of such child’s Personal Information from our database at any time by e-mailing us at DataCustSvc@macerich.com or contacting the customer service facility and/or mall office at the applicable center directly. Please note, however, that Personal Information inadvertently collected about a child may remain in back-up storage for some period of time after a request for deletion of that child’s account. This may be the case even though no information about that account remains in our active user databases.
7. Information collected at Macerich Mall Properties
Macerich may use mobile technology to locate customers in Macerich’s mall properties to improve your shopping experience and to assist our merchants in providing services to you. Among the technologies we use are locational beacons that transmit a signal to mobile device with a mobile application. If you use one of the Wi-Fi networks in our malls, we will collect personal information from you in order to log you on to the network, including your email address. We may also collect information about your use of the Wi-Fi, such as the web pages you visit, your MAC or IP address, and your location while using the Wi-Fi. You can choose to opt out of this service at any time, but if you do, you will not have access to our Wi-Fi networks.
Macerich also places video cameras throughout certain Macerich mall properties. Macerich uses these cameras to photograph shoppers and analyze the photographs to determine traffic patterns within our malls and to assess demographic data, which may include age and gender. We use this information to optimize shopping experiences at our properties, and for marketing, strategic and security purposes. Due to the nature of such technology, you are unable to opt out of being photographed or videotaped while on any Macerich mall property.
We also employ in some Macerich malls other mobile data technology to track how shoppers travel through our malls, assess the duration of time they are on our property, count the total numbers of shoppers by hour, by entrance and other zones within the property, and detect whether the shopper is a repeat visitor and the frequency of his or her visits. These technologies use signals broadcast from a smartphone or other mobile device and the unique number assigned to such device when it was manufactured (known as a “MAC address”), together with the time, signal strength and location of the observing sensor. This may be accomplished using Wi-Fi access points from any guest Wi-Fi we may offer at the property, regardless of whether you use such Wi-Fi, and/or via Wi-Fi sensors provided by a Macerich service provider. None of this information constitutes Personal Information. We use such information for marketing, strategic and security purposes.
To avoid any collection of data by means of such mobile device detection technology, you (i) should ensure all mobile devices you may be carrying are fully powered off at all times while on our property AND (ii) opt not to use any guest Wi-Fi service we may make available at the property.
License Plate Recording
At certain of our mall properties, Macerich photographs and records license plate numbers of shoppers who use our parking facilities. Macerich collects that information to assist drivers in locating their automobiles; to monitor available space in parking structures; and in certain locations, to facilitate automatic or cashless parking charges.
Macerich does not regulate how merchants with locations in a Macerich mall might collect or use your Personal Information. For information concerning how a merchant might collect or use your Personal Information, please contact the merchant directly.
8. Your Responsibility
9. Sweepstakes and Promotions
Macerich sometimes offers sweepstakes, contests or other promotions, as well as rewards programs and text messaging programs (collectively, “Promotions”). These can be offered through the Site, at mall properties or by other means. In each case, the Promotions will be governed by a separate set of rules or terms and conditions that, in addition to describing the Promotion, may have eligibility requirements, restrictions, terms and conditions governing the Promotion, use of submissions you make, and disclosures about how your Personal Information may be used. It is your responsibility to read such rules or terms and conditions to determine whether or not you are eligible and want to participate, register and/or enter, according to each Promotion’s rules or terms and conditions. By participating in any Promotion, you will become subject to those official rules or terms and conditions, and you agree to comply with and abide by such rules or terms and conditions, and the decisions of the sponsor(s) identified therein, if applicable, which shall be final and binding in all respects.
10. Additional Policies In Compliance with the EEA Privacy Laws
10.1 GDPR Definitions
“Controller” means the Company which is the organization that determines the purposes for which, and the manner in which, any Personal Data is Processed and used in its business.
“Processor” means any Person Processing Personal Data.
“Person” means a natural person, corporation, association, organization, partnership, or other legal entity.
“Processing” is any activity that involves use of the Personal Data. It includes, without limitation, obtaining, recording or holding the Personal Data, or carrying out any operation or set of operations on the Personal Data including organizing, amending, retrieving, using, disclosing, erasing or destroying it. Processing also includes transferring Personal Data to third parties.
10.2 The legal basis for processing your Personal Data
In order to comply with the GDPR, we are required to set out the legal basis for the processing of your Personal Data. In accordance with the purposes for which we collect and use your Personal Data, as set out above, the legal basis for processing your Personal Data will typically be one of the following:
• our own legitimate business interests, or the legitimate business interests of our third party partners, promoters, affiliates, distributors, suppliers, vendors, and subcontractors, such as, for example, providing direct marketing to our customers of our products and services that we think would be of interest, permitting prospective employees to search and apply for job opportunities, handling inquiries from our promoters, affiliates, distributors, vendors, and customers, or other instances where we have carried out a legitimate interests assessment and have established an existing legitimate interest;
• the performance of a contract that we have in place with you;
• your consent, where appropriate; or
• compliance with our legal obligations, including to meet national security or law enforcement requirements.
10.3 Where we store your Personal Data
The transmission of information via the Internet is not completely secure. Although we take reasonable efforts to protect your Personal Data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.
10.4 Addendum to how long we store your Personal Data
In some cases, there is a legal requirement to keep Personal Data for a minimum period of time. Except in those circumstances, we do not keep your Personal Data for any longer than is necessary for the purposes for which the Personal Data was collected or for which it is to be further processed.
10.5 Your rights with respect to your Personal Data
Subject to certain exceptions, you have the following rights with respect to your Personal Data:
• To receive or access a copy of the Personal Data that we hold about you;
• To request that any inaccurate or incomplete Personal Data be corrected or supplemented;
• To have your Personal Data erased, unless we have a legitimate reason to retain the Personal Data (such as if we are required to do so for legal reasons); and
• To ask us not to process your Personal Data for a particular purpose, including for marketing.
All of these rights are subject to certain conditions and exemptions. For example, Macerich will not be obligated to erase your Personal Data if we need to retain it to protect ourselves in the event of a legal claim.
To exercise any of these rights, please submit a written request to us using the contact information set forth below. The Company reserves the right to charge a fee in dealing with such a request as permitted by applicable law and regulations. You may also opt out of receiving additional marketing information by using the unsubscribe feature in any marketing email we send you.
12. Your California Privacy Rights
13. Contacting us
The Macerich Company
401 Wilshire Blvd., Suite 700
Santa Monica, CA 90401
Attn: Legal Department
Updated April 1, 2019