Privacy Policy

Privacy Policy

WorldQuest Orlando Resort Privacy Statement

Last updated: 31 August 2026

How We Think About Your Privacy

Protecting your privacy and your personal data is not optional for us — we treat it as an obligation. We work from a few simple principles:

  • Safeguarding personal data is our responsibility.
  • Data is a liability rather than an asset, so we gather and use it only where there is a genuine need.
  • We dislike spam every bit as much as you do.
  • We will never sell, rent out or otherwise distribute your personal data.
  • We will not publish your personal details without your permission.

Laws This Policy Is Built Around

This website, along with our wider business systems and internal computing, is built to meet the following data protection and privacy laws:

  • The EU General Data Protection Regulation (GDPR)
  • The California Consumer Privacy Act 2018 (CCPA)

What We Collect And Why

This section sets out the categories of information we gather and our reasons for gathering each one.

Visitor Tracking

As most websites do, we use Google Analytics to understand how the site is used. It tells us roughly how many people visit, how they arrived, which pages they look at and the route they take through the site.

Google Analytics logs details such as approximate location, device, browser and operating system. None of that identifies you to us personally. It also logs the IP address of your computer, which could identify you, but Google does not give us access to it. We regard Google as a third-party data processor, covered in the section below.

Google Analytics relies on cookies and on the Google tag, which Google documents in its developer guides. If you turn cookies off in your browser, Google Analytics will no longer be able to track any part of your visit.

Separately from Google Analytics, this site may record publicly available information linked to the IP address of the device used to reach it.

Forms And Newsletter Sign-Ups

When you sign up for our email newsletter or send us a form, the details you provide are passed to Revinate, the email marketing platform we use. They stay in that provider’s database for as long as we keep using their service, or until you ask to be taken off the list.

To be removed, use the unsubscribe link in any newsletter we send you, or email us and ask. If you email, please write from the account that is actually subscribed.

Depending on what you ask us for, the details we may collect include:

  • Name
  • Email address
  • Phone
  • Mobile
  • Street address
  • City
  • State
  • Postal code
  • Country
  • IP address

We do not sell your personal information to anyone. We share only a limited amount of data, and only with the processors named below, either to fulfil what you have asked us for or to improve what we offer.

Reservations

When you book a stay, you are handed over to our reservation system, which is operated on our behalf by Sabre (SynXis). The booking and payment details you enter there are processed by that system under its own security controls.

Emails You Send Us

When you write to us through an email link, we simply receive your message — no third-party processor or intermediary sits in between. Your message travels to us over SMTP, and our mail servers use TLS (also referred to as SSL), so the contents are encrypted in transit across the internet and decrypted once they reach our own computers and devices.

Why There Is No “Do Not Sell My Data” Button

We do not sell the personal information of our customers, or of anyone under 16, to third-party data collectors, which is why a “Do not sell my data” opt-out is optional on this site. To repeat the point made above: we collect your data only to fulfil a request or to send you marketing communications you have asked for. If you would like to see or erase your personal information, you can ask us to do that using the contact details on our Contact page.

If You Are Under 16

If you are younger than 16, you must have a parent’s or guardian’s permission before you:

  • submit a form,
  • sign up for one of our offers,
  • subscribe to our email newsletter, or
  • make a reservation.

Seeing Or Deleting What We Hold

To view or delete the personal information we hold about you, email us using the contact details on our Contact page. Please include the email address you gave us, your name, and what you would like us to do.

Companies That Process Data For Us

A number of outside companies process personal data on our behalf. Each has been chosen with care and each meets the legislation described above. If you ask us to delete your personal information, we will pass that request on to them as well:

  • Google — website analytics and tag management
  • Revinate — email marketing
  • Sabre (SynXis) — reservations
  • Meta — Facebook and Instagram advertising
  • Microsoft — website usage analytics
  • Sojern — travel advertising

Cookie Policy

This section explains how we use cookies and comparable technologies. They fall into three groups.

Essential Cookies And Similar Technologies

These keep our website working; without them, parts of the site would simply not function. Session cookies, for instance, keep your experience consistent as you move around the site and adapt it to your connection speed and the device you are on.

Analytics Cookies And Similar Technologies

These tell us how our website is being used so we can make it better. They show us which pages are visited most, help us spot where people struggle to use our services so we can put it right, and let us see broad usage patterns in aggregate.

Advertising And Tracking Cookies And Similar Technologies

We use these to make the advertising you see more relevant to you, by basing online adverts on pages you have browsed before. Cookies stored in your browser record which sites you have visited, and advertising reflecting that activity is then shown to you on other sites using the same ad networks. We may also use these technologies to tailor adverts to your location, the offers you click, and similar interactions with our website.

If There Is A Data Breach

Should personal data held in an identifiable form be stolen from this website’s database, or from the database of any of our third-party processors, we will report the breach to every relevant person and authority within 72 hours of it occurring.

Changes To This Policy

We may revise this policy from time to time to keep pace with legislation and developments in our industry. We will not notify clients or site visitors individually when we do, so we suggest looking over this page now and again to see whether anything has changed. The date at the top of this page shows when it was last revised.

If you give us a valid email address that you can access, we will tell you what personal information we hold associated with it and how you can manage that information.