{
  "cells": {
    "grain:m_points_program#vendor-global.airline-aadvantage.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "American's March 2026 policy lists account-profile, payment, partner-transaction, and corporate-program information for enrollment, account use, and management of Program Services.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"American Airlines Privacy Policy\",\"published_revision\":\"Updated March 12, 2026\",\"section\":\"Program Services\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The personal information we collect about you when you enroll in, use, or manage your use of our Program Services may include:",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-aadvantage"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.aa.com/i18n/customer-service/support/privacy-policy.jsp",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-aadvantage.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The March 2026 terms name account audit, voluntary account termination, name change, and the limited deceased-member transfer-document review as verification or documentation events, with the stated matching information or documents.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"AAdvantage terms and conditions\",\"published_revision\":\"Effective March 1, 2026\",\"sections\":[\"2.G Death of an AAdvantage member\",\"6.B Suspension / termination of accounts\",\"6.G Name and address change\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "American Airlines reserves the right to audit any and all accounts at any time, whether with or without notice to the member, to ensure compliance with these Terms, the Conditions of Carriage and applicable tariffs (including validating that the name and date of birth on the AAdvantage ® account matches the name and date of birth in a flight reservation).",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-aadvantage"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.aa.com/i18n/aadvantage-program/aadvantage-terms-and-conditions.jsp",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-aadvantage.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "American's March 2026 policy says Travel Services and Program Services information is generally retained up to seven years after completed travel or membership termination, within its stated necessity and legal criteria.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"American Airlines Privacy Policy\",\"published_revision\":\"Updated March 12, 2026\",\"section\":\"Data retention policy\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We generally retain personal information related to your use of our Travel Services or Program Services for up to seven years after you complete your travel or terminate your membership with us.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-aadvantage"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.aa.com/i18n/customer-service/support/privacy-policy.jsp",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-aadvantage.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The March 2026 terms define an individual member, a narrow approved administrative-support role, the member's responsibility for that use, and a prohibition on third-party online-service account access.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"AAdvantage terms and conditions\",\"published_revision\":\"Effective March 1, 2026\",\"sections\":[\"6.C Program eligibility requirements\",\"6.D Account access, American Airlines data, use of data and privacy\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Only individuals are eligible for AAdvantage ® Program membership, except in connection with the AAdvantage Business℠ program or as expressly permitted by American Airlines.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-aadvantage"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.aa.com/i18n/aadvantage-program/aadvantage-terms-and-conditions.jsp",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-aadvantage.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "American's March 2026 policy describes booking-to-account linkage, its named affiliate/travel/co-brand/service-provider/payment recipient categories, and the fields a partner can access when an AAdvantage login is used on the partner's site or app.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"American Airlines Privacy Policy\",\"published_revision\":\"Updated March 12, 2026\",\"sections\":[\"Information we collect and how we collect it\",\"With whom your information will be shared\",\"AAdvantage account login\",\"Opting out of sharing your information with third parties\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We may link or combine information that we collect about you (such as linking your travel booking to your AAdvantage ® account, or adding saved AAdvantage ® account information to your booking).",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-aadvantage"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.aa.com/i18n/customer-service/support/privacy-policy.jsp",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-mileageplus.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The current MileagePlus rules state that program participation authorizes United to collect, maintain, use, process, and share names, email addresses, physical addresses, account information, and other information under United's Privacy Policy.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"MileagePlus Rules\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":null,\"section\":\"Privacy Policy\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "By participating in the Program, Members authorize United to collect, maintain, use, process and share their information, including, without limitation, names, email addresses, physical addresses, account and other information in accordance with United’s Privacy Policy.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-mileageplus"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-mileageplus.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The rules name password or other security measures for specified transactions and awards, documentary proof for some credit claims, and account validation for changes to a business member's authorized representative.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"MileagePlus Rules\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":null,\"section\":\"Mileage accrual; Claims about Member balances; Award redemption; Members that are not individuals\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Members may be required to supply a password and/or other security measures when conducting certain transactions in writing, by phone or on the internet for security or other purposes.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-mileageplus"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-mileageplus.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The rules state that accrued mileage remains in an account until redemption or forfeiture under six named rule, conduct, law, closure, death, or nonresponse events.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"MileagePlus Rules\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":null,\"section\":\"Mileage expiration\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Mileage accrued in a Member's account shall be maintained in the account until it is redeemed for an award or until it is otherwise forfeited pursuant to (a) these Rules, United’s Contract of Carriage or United’s fare rules, (b) Prohibited Conduct, (c) applicable laws or regulations, (d) Member requested account closure, (e) the death of a Member or (f) the failure of a Member to respond to repeated communication attempts regarding the status of his/her account.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-mileageplus"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-mileageplus.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The rules define individual members, non-individual business members and their authorized representatives, companion travelers, and authorized persons in death or divorce transfers, with stated account-control or responsibility boundaries.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"MileagePlus Rules\",\"published_revision\":null,\"section\":\"General conditions; Mileage accrual; Members that are not individuals\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Only the Member named on the account will be entitled access to account information.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-mileageplus"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-mileageplus.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The rules name audit contractors, defined MileagePlus Partner categories, agreed cross-program mileage-credit contexts, and program-participation information sharing under United's Privacy Policy.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"MileagePlus Rules\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":null,\"section\":\"General conditions; Partners; Privacy Policy; Mileage accrual\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "During the course of an audit or investigation, a Member’s account information may be shared with any third party with whom United has contracted to assist in performing such audit or investigation.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-mileageplus"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-skymiles.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Delta's May 2026 Global Privacy Policy lists identity, contact, SkyMiles-account, program-activity, partner-membership, corporate-association, birth-date, gender, login, and consented lounge-access image data for the SkyMiles/account context.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Delta Global Privacy Policy\",\"published_revision\":\"May 2026\",\"section\":\"2.4 Purposes of Processing — SkyMiles Program and other account information\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Information related to your membership in our Delta Sky Club , the SkyMiles Program or other account, or activities with our SkyMiles Partners , opens in a new window and promotional partners, including:",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-skymiles"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.delta.com/us/en/legal/privacy-and-security",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-skymiles.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Delta's current SkyMiles help page documents MFA for login and password reset, the Identity Verification Form and documentary checks for specified account changes or inaccessible accounts, and both account numbers and passwords for duplicate-account authorization and name validation.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Delta SkyMiles Help\",\"published_revision\":null,\"sections\":[\"Multi-Factor Authentication (MFA)\",\"Name, Date, and Gender Changes\",\"Email and Mailing Address Changes\",\"Merge Duplicate Accounts\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We’ve added verification options to keep your SkyMiles account safe.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-skymiles"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.delta.com/us/en/need-help/support-skymiles",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-skymiles.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Delta states a necessity/record-policy/legal-requirement retention criterion rather than a public fixed period. Its rules say Delta retains the SkyMiles number assigned to basic information after closure, while its help page separately says account deletion permanently removes access to the account and associated data.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Delta Global Privacy Policy\",\"published_revision\":\"May 2026\",\"section\":\"4. Information Retention\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We store your information as necessary for the processing activities described in this notice and to comply with Delta’s record retention policies and legal and regulatory requirements. For information about specific retention periods, please submit your question through Delta’s Privacy Request Form .",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-skymiles"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.delta.com/us/en/legal/privacy-and-security",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-skymiles.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The program rules define an individual-member account, distinguish business-entity and parent/guardian enrollment boundaries, make the member responsible for password confidentiality and use, and prohibit giving another person or third-party service access to the account credentials.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"SkyMiles Membership Guide & Program Rules\",\"published_revision\":null,\"sections\":[\"Conditions of Enrollment\",\"SkyMiles Password\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Only one person may be enrolled per SkyMiles account. Members may not maintain more than one SkyMiles account.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-skymiles"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.delta.com/us/en/skymiles/program-resources/program-rules",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.airline-skymiles.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Delta's May 2026 policy lists nine recipient categories, including authorized representatives, same-booking customers, service and travel partners, other airlines, corporate-travel recipients, payment firms, business-sale counterparties, and government/legal-process recipients. No standalone linked-account terms page was established from the documents read.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Delta Global Privacy Policy\",\"published_revision\":\"May 2026\",\"section\":\"3.1 Information Sharing — In General\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "third parties that provide you with services you request, such as travel segments on other carriers, hotel accommodations, rental cars, SkyMiles Partners, promotional partners, and other Delta Group Companies for the purposes described in and in accordance with this notice.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "airline-skymiles"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.delta.com/us/en/legal/privacy-and-security",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-hilton-honors.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Hilton's July 2026 terms name three required enrollment fields and additional profile fields a member may provide.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Hilton Honors Terms & Conditions\",\"multi_record_provenance\":\"This cell is supported by 7 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective Date: July 15, 2026\",\"section\":\"Hilton Honors Program Personal Information\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Additional personal information that we collect includes information that you provide when you enroll in the Hilton Honors Program or when you manage your profile online. During enrollment, we require that you provide your name, physical address and e-mail address. When you manage your profile online, you have the opportunity to provide additional information about your preferred airline partners and your loyalty program account numbers with them, your room type preferences, your language preferences, your credit card account(s), your preferences for receiving news, offers and information from companies that are part of the Hilton Portfolio, and to create a User ID and password.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-hilton-honors"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.hilton.com/en/hilton-honors/terms/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-hilton-honors.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Hilton's help page documents password-plus-code Enhanced Security for account access.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Enhanced Security authentication\",\"multi_record_provenance\":\"This cell is supported by 5 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Captured 2026-10-04\",\"section\":\"What is Enhanced Security?\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Enhanced Security, also known as two-factor or two-step authentication (2FA), provides an additional level of security when accessing your Hilton Honors account. Along with your password, it requires a second form of verification in the form of a unique code sent to your preferred email address or phone number stored on your account.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-hilton-honors"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.hilton.com/en/help-center/your-account/enhanced-security-authentication/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-hilton-honors.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Hilton's August 2026 statement publishes a purpose-based criterion, a usual contractual/legal period, and a destruction standard.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Hilton Global Privacy Statement\",\"multi_record_provenance\":\"This cell is supported by 4 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Last updated: August 31, 2026\",\"section\":\"9. Data Retention Periods\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We retain personal information about you for the time necessary to fulfill the purpose for which that information was collected, usually for the duration of any contractual relationship and for any period thereafter as legally required or permitted by law. Our retention policies reflect applicable statute of limitation periods and legal requirements. When we destroy your personal information, we do so in a way that prevents that information from being restored or reconstructed.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-hilton-honors"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.hilton.com/en/p/global-privacy-statement/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-hilton-honors.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Hilton's terms define individual-member eligibility and assign account-access security responsibilities to each member.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Hilton Honors Terms & Conditions\",\"multi_record_provenance\":\"This cell is supported by 6 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective Date: July 15, 2026\",\"section\":\"General; Additional Terms of Participation\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Only individuals of majority age in their country, territory, or state of residence may enroll in Hilton Honors and become Members (defined as individuals who have been accepted as Members by Hilton Honors).",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-hilton-honors"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.hilton.com/en/hilton-honors/terms/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-hilton-honors.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Hilton's terms say relevant personal information may be shared with business partners to credit mileage or other program benefits.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Hilton Honors Terms & Conditions\",\"multi_record_provenance\":\"This cell is supported by 16 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective Date: July 15, 2026\",\"section\":\"Hilton Honors Program Personal Information\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "In addition to the uses and sharing described in the Privacy Policy , Opens new tab , we may use and share relevant portions of your personal information in order to administer the Hilton Honors Program. This may include sharing your personal information with our business partners in order to credit you with mileage or other benefits earned through your participation in the Hilton Honors Program.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-hilton-honors"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.hilton.com/en/hilton-honors/terms/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-ihg-one-rewards.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "IHG's July 2026 statement names identity, contact, account, preference, partner-membership, stay, and purchase fields collected for loyalty enrollment and participation.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"IHG Privacy Statement\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective Date: July 2026\",\"section\":\"If you join one of our loyalty programs; If you make a reservation or stay at an IHG-branded hotel\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We collect information from you during your membership in any of our loyalty programs and services, including our core loyalty program, IHG® One Rewards.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-ihg-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.ihg.com/content/us/en/customer-care/privacy_statement",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-ihg-one-rewards.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "IHG's June 2026 terms state that a member requesting a name change through Customer Care should be prepared to provide supporting legal documentation.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"IHG One Rewards Membership Terms and Conditions\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Last updated on 24 June 2026\",\"section\":\"Maintaining Member Information; Protecting Your Account; Eligibility; IHG® Business Rewards Terms and Conditions — Membership\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "For name changes, please contact IHG Customer Care, and please be prepared to provide supporting legal documentation for your name change (such as a driver’s license with your new name, marriage certificate, passport, or other legal documentation).",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-ihg-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.ihg.com/content/us/en/customer-care/member-tc",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-ihg-one-rewards.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "IHG's July 2026 statement uses a purpose-based retention criterion and names longer transactional-record and prospective-litigation exceptions.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"IHG Privacy Statement\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective Date: July 2026\",\"section\":\"Retaining your information in our systems; Retention of Personal Information; CALIFORNIA NOTICE OF FINANCIAL INCENTIVE\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We generally only keep your information for as long as is reasonably required for the purposes explained in this privacy policy. In some cases we keep transactional records (which may include your information) for longer periods if necessary to meet legal, regulatory, tax or accounting needs. We will also retain information if we reasonably believe there is a prospect of litigation. We maintain a data retention policy which we apply to the records we hold.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-ihg-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.ihg.com/content/us/en/customer-care/privacy_statement",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-ihg-one-rewards.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "IHG's June 2026 terms define an individual member role, one-account and registered-guest constraints, and responsibility for account/password access and use.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"IHG One Rewards Membership Terms and Conditions\",\"published_revision\":\"Last updated on 24 June 2026\",\"section\":\"Eligibility; Maintaining Member Information; Protecting Your Account; IHG® Business Rewards Terms and Conditions — Membership; Reward Night and Free Night Beneficiary; Point Transfers; Transfer of IHG One Rewards Points Upon Death; InterContinental Ambassador\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Each Program Member is responsible for restricting access to and maintaining the confidentiality of the Member’s account and password and agrees to accept responsibility for the activities of anyone using the Member’s password.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-ihg-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.ihg.com/content/us/en/customer-care/member-tc",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-ihg-one-rewards.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "IHG's July 2026 statement names loyalty and co-brand partners and service providers, with product, program-operation, and advertising purposes.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"IHG Privacy Statement\",\"multi_record_provenance\":\"This cell is supported by 3 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective Date: July 2026\",\"section\":\"If you join one of our loyalty programs — Who we disclose your information with; If you make a reservation or stay at an IHG-branded hotel; U.S. STATE CONSUMER RIGHTS\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Loyalty partners: to provide you with the products and services that you have requested and, where permitted by law, for the partner to offer its own products and services to you. We also may choose to partner with another company to offer a product, such as a co-branded credit card.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-ihg-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.ihg.com/content/us/en/customer-care/privacy_statement",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-marriott-bonvoy.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "For the loyalty-identity workflow, this cell records six Marriott-listed categories: identifying, demographic, government-ID, financial, loyalty-program, and travel information.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Marriott Group Global Privacy Statement\",\"published_revision\":\"Last Updated: August 5, 2026\",\"section\":\"The Data We Collect\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We collect and process the following types of Personal Data about you:",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-marriott-bonvoy"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.marriott.com/about/privacy.mi",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-marriott-bonvoy.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Within the member-account administration clauses, the September 2026 terms name Member Support security questions and supporting documentation for legal-name changes as verification or confirmation events.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Marriott Bonvoy Loyalty Program Terms and Conditions\",\"published_revision\":\"Updated September 2026\",\"section\":\"1.5 Membership Communications\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Any time a Member contacts Member Support , the Company may ask the Member certain security questions to verify the Member’s identity.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-marriott-bonvoy"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.marriott.com/loyalty/terms/default.mi",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-marriott-bonvoy.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Marriott's August 2026 statement uses purpose, ongoing-relationship, legal-obligation, and legal-position criteria rather than one universal duration.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Marriott Group Global Privacy Statement\",\"published_revision\":\"Last Updated: August 5, 2026\",\"section\":\"Retention\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Statement unless a longer retention period is required or permitted by law.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-marriott-bonvoy"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.marriott.com/about/privacy.mi",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-marriott-bonvoy.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "For the member-account role, the September 2026 terms define individual membership, prohibit joint or shared accounts, require duplicate accounts to be combined, and assign the member responsibility for current, accurate profile information.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Marriott Bonvoy Loyalty Program Terms and Conditions\",\"published_revision\":\"Updated September 2026\",\"sections\":[\"1.4.b Individual Membership\",\"1.4.e Duplicate Accounts\",\"1.4.f Personal Profile\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Only individuals are eligible for Loyalty Program membership, and each individual may maintain only one Membership Account.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-marriott-bonvoy"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.marriott.com/loyalty/terms/default.mi",
      "table": "grain"
    },
    "grain:m_points_program#vendor-global.hotel-marriott-bonvoy.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Marriott's August 2026 sharing section identifies Marriott affiliates and property participants, licensees and co-brand issuers, on-property and travel providers, linked-account and insurance partners, advertising partners, corporate recipients, and service-provider functions.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Marriott Group Global Privacy Statement\",\"published_revision\":\"Last Updated: August 5, 2026\",\"section\":\"How and When We Share Your Data — Linked Accounts and Travel Insurance\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "For example, certain companies allow you to use your loyalty program number or Online Services login to receive or register for their services.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-global",
        "row_key": "hotel-marriott-bonvoy"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.marriott.com/about/privacy.mi",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-amex-membership-rewards.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "American Express's current Additional Card page says a request requires the additional user's legal name, address, date of birth, and SSN or ITIN, with a telephone route when the user has neither identifier.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Additional Card Membership\",\"multi_record_provenance\":\"This cell is supported by 5 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":null,\"section\":\"What information will you need to provide about the Additional Card Member to request an Additional Card?\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You need the Additional Card Member’s legal name, address, date of birth, and Social Security Number (SSN) or International Tax Identification Number (ITIN) to request to add them to your account as an Additional Card Member. If the Additional Card Member does not have an SSN or ITIN, please call the number on the back of your Card.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-amex-membership-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.americanexpress.com/en-us/benefits/additional-card/learn-more/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-amex-membership-rewards.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "At an Additional Card request, American Express says it obtains, verifies, and records information about the additional user; the requester confirms the relationship, accuracy, and consent for identity verification.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Additional Card Membership\",\"multi_record_provenance\":\"This cell is supported by 3 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":null,\"sections\":[\"Why do we need information about your Additional Card Member?\",\"Terms & Conditions\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "To help the United States government fight terrorism and money laundering, American Express obtains, verifies, and records information about Additional Card Members. Therefore, we will ask for your Additional Card Member’s name, address, date of birth, and other personal information.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-amex-membership-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.americanexpress.com/en-us/benefits/additional-card/learn-more/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-amex-membership-rewards.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "American Express states an event-based rule for covered Online Information rather than a fixed duration, with legal, regulatory, litigation, and investigation exceptions.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"American Express Online Privacy Statement\",\"multi_record_provenance\":\"This cell is supported by 3 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective Date: March 26, 2026\",\"section\":\"How do we keep and safeguard your information?\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We take reasonable steps to securely destroy or permanently de-identify Personal Information when we no longer need it. We will keep your Online Information only as long as we must to deliver our products and services, unless we are required by law or regulation or for litigation and regulatory investigations to keep it.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-amex-membership-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.americanexpress.com/us/company/privacy-center/online-privacy-disclosures/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-amex-membership-rewards.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The June 2026 Business Gold agreement defines the Basic Card Member, Company, and Additional/Employee Card Member roles, assigns account and charge responsibility, and states the approval boundary for replacing the Basic Card Member.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Business Gold Card Member Agreement\",\"multi_record_provenance\":\"This cell is supported by 4 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"part\":\"Part 2 of 3\",\"published_revision\":\"As of: 06/30/2026\",\"sections\":[\"Definitions\",\"Joint and Several Liability\",\"Additional Card Members\",\"Replacing the Basic Card Member\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "That means that both the Basic Card Member and the Company are each individually responsible for the Account, including but not limited to the obligation to pay all charges. We may seek payment from either or both the Basic Card Member and the Company.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-amex-membership-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.americanexpress.com/content/dam/amex/en-us/company/legal/cardmember-agreements/public-site-2026-q2-pdf-cmas/sbs-small-business/business-gold-06-30-2026.pdf",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-amex-membership-rewards.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The May 2026 Business Card Privacy Notice identifies everyday-business, service-provider marketing, business-partner, and co-brand sharing contexts and states the associated opt-out boundary.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"American Express Business Card Privacy Notice\",\"multi_record_provenance\":\"This cell is supported by 6 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective Date: May 1, 2026\",\"sections\":[\"How We May Share Your Information\",\"Choices Available to You\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "This Section describes how we may share information that identifies you or your business:",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-amex-membership-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.americanexpress.com/content/dam/amex/us/company/privacy-center/online-privacy-disclosures/Business_Card_Privacy_Notice_2026.05.01.pdf",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-capital-one-rewards.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Capital One Business's March 2026 application guide says a business-card application may typically call for the listed contact, entity, applicant, tax, operational, financial, and ownership/controller information.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"How to apply for and get a business credit card\",\"multi_record_provenance\":\"This cell is supported by 5 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"March 3, 2026\",\"section\":\"Step 3: Gather what you need to apply\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Typically, this may include some or all of the following: Contact information (business mailing address and phone number) Legal name of your business Your Social Security number (SSN) and legal name (if you’re a sole proprietor ) How long your business has been in operation Your role in the business Federal tax ID number (TIN) Industry type (the North American Industry Classification System [NAICS] code) Legal structure (corporation, partnership , nonprofit, LLC or cooperative) Annual revenue Total monthly expenses List of beneficial owners or business controllers (for corporations and partnerships)",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-capital-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.capitalone.com/learn-grow/business-resources/applying-for-business-credit-card/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-capital-one-rewards.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Capital One's May 2026 policy names application, login, account-access, and later online or phone interactions as identity or account-verification events.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Capital One Online Privacy Policy\",\"multi_record_provenance\":\"This cell is supported by 3 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective May 5, 2026\",\"section\":\"How does Capital One use this information? — Verifying your identity\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Verifying your identity , such as conducting identity verification when you apply for our products or services, authenticating your login credentials, verifying your location to allow access to your accounts, and storing security questions for subsequent verification online or over the phone.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-capital-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-capital-one-rewards.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Capital One's May 2026 policy uses a reasonably-necessary criterion and lists service, compliance/audit, complaint/troubleshooting, and legal-claim factors; it publishes no fixed duration in this clause.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Capital One Online Privacy Policy\",\"published_revision\":\"Effective May 5, 2026\",\"section\":\"Data retention and security\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The personal information we collect will be retained for as long as reasonably necessary for the purposes set out in this Privacy Policy and consistent with our retention policies, in accordance with applicable laws.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-capital-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-capital-one-rewards.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Capital One Business's September 2026 account-manager page distinguishes the account manager, authorized user, and primary account holder and states each role's controls or responsibility.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Capital One Business account managers: Delegate tasks\",\"multi_record_provenance\":\"This cell is supported by 3 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"September 17, 2026\",\"sections\":[\"What is a Capital One Business account manager?\",\"What other role types are available?\",\"FAQ\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "An account manager is one of two account user roles that small-business owners (SBOs) can assign to employees who have a Capital One Business employee card .",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-capital-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.capitalone.com/learn-grow/business-resources/capital-one-account-manager/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-capital-one-rewards.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Capital One's May 2026 policy lists seven recipient categories, their stated examples or purposes, aggregate/de-identified sharing, and the policy's U.S.-audience scope and non-Capital-One exclusions.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Capital One Online Privacy Policy\",\"published_revision\":\"Effective May 5, 2026\",\"sections\":[\"What this policy covers\",\"What this policy does not cover\",\"How does Capital One share this information?\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We share information in a variety of contexts. For example, we may share information about you with:",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-capital-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-chase-ultimate-rewards.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Chase's business-card application guide lists business identity, address, structure, tax, revenue, operating-history, and employee-count fields used for most applications.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"How to Fill Out a Business Credit Card Application\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"section\":\"How to fill out a business credit card application\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Here are some details you’ll need for most business credit card applications: Business name : If you’re a sole proprietor without a formal business name, you may include your name as the company name. Business address : Legal business location (can be home address). Business type : This will usually be a sole proprietorship, LLC or corporation. Tax Identification Number : If you don't have an EIN, use your personal SSN (Social Security number). Annual business revenue : The amount of money your business makes per year. Years in business : How long your business has been operating. Number of employees : How many employees you have (if you're the only employee, you can write “one”).",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-chase-ultimate-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.chase.com/personal/credit-cards/education/basics/how-to-fill-out-business-credit-card-application",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-chase-ultimate-rewards.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Chase's online privacy policy names access to account information as an example identity-verification event.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Chase Online Privacy Policy\",\"multi_record_provenance\":\"This cell is supported by 15 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Last updated September 2023\",\"section\":\"Use of Information\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Verifying your identity (such as when you access your account information);",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-chase-ultimate-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.chase.com/digital/resources/privacy-security/privacy/online-privacy-policy",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-chase-ultimate-rewards.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Chase's December 2025 California disclosure ties retention to an ongoing relationship or stated-purpose need, applicable limitation periods, legal retention requirements, and legal claims.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"California Consumer Privacy Act Disclosure and Notice at Collection\",\"published_revision\":\"Last updated December 2025\",\"section\":\"Retention of Personal Information\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We will retain copies of your personal information in a form that permits identification only for as long as: We maintain an ongoing relationship with you (e.g., while you are still receiving services from us); or Your personal information is necessary in connection with purposes set out in this disclosure plus: The duration of any applicable limitation period under applicable law; and where required by applicable law or a retention policy established in accordance with applicable law",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-chase-ultimate-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.chase.com/digital/resources/privacy-security/privacy/ca-consumer-privacy-act",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-chase-ultimate-rewards.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The Ink Business Preferred Ultimate Rewards agreement distinguishes the responsible party from an authorized user and assigns the responsible party responsibility for points use.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Ink Business Preferred with Ultimate Rewards Program Agreement\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"sections\":[\"Important information about the program and this agreement\",\"How you can use your points\",\"Combine points with other Chase cards with Ultimate Rewards\",\"Transfer points to frequent travel programs\",\"Other important information you should know\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "“you” and “your” mean the party or parties responsible",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-chase-ultimate-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.chase.com/inkbusinesspreferred/rewardsagreement",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-chase-ultimate-rewards.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Chase's policy names service providers, affiliates, co-brand companies, corporate-transaction parties, and legal or protective recipients.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Chase Online Privacy Policy\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Last updated September 2023\",\"section\":\"Disclosure of Information\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We may share the information we collect from and about you with our affiliates and other third parties as described below. In particular, we may share your information with: Chase third-party service providers; Chase affiliated websites and businesses in an effort to bring you improved service across our family of products and services, when permissible under relevant laws and regulations; Other companies to bring you co-branded services, products or programs that you have requested; Third parties or affiliates in connection with a corporate transaction, such as a sale, consolidation or merger of Chase businesses; and Other third parties to comply with legal requirements such as the demands of applicable subpoenas and court orders; to verify or enforce our terms of use, our other rights, or other applicable policies; to address fraud, security or technical issues; to respond to an emergency; or otherwise to protect the rights, property or security of our customers or third parties.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-chase-ultimate-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.chase.com/digital/resources/privacy-security/privacy/online-privacy-policy",
      "table": "grain"
    }
  },
  "class": "REFERENCE",
  "content_file_sha256": "85258f33ccab039b6064357ee2eedbb850dd568fb107a48cbac7689e92ef31be",
  "figure_slots": [],
  "generator": "page-generator/1",
  "held": {
    "cells": [],
    "counts": {
      "gap": 0,
      "no_quote": 0,
      "unconfirmed": 0,
      "unresolved": 0
    },
    "is_held": false
  },
  "last_updated": "2026-10-04",
  "route": "/travel-mobility/loyalty-program-identity-verification/",
  "schema": "pp-page-sources.v1",
  "tables": {
    "airline-identity-verification-and-retention": {
      "field_definitions": {
        "identity.data_collected": "Identity or account data the accepted provider record states is collected within its named event, program, jurisdiction, and revision.",
        "identity.verification_events": "A documented event, requested information, actor, and scope in which the accepted provider record states that verification occurs.",
        "retention.rule": "The duration or purpose-based retention criterion, covered record category, trigger, exception, and scope stated by the accepted provider record.",
        "roles_and_responsibility": "The account-holder, member, authorized actor, guest, partner, or other role and responsibility boundary stated by the accepted record.",
        "sharing_or_linkage": "A documented recipient, partner, linked-account relationship, purpose, and scope without an inference of public visibility or legal access."
      },
      "last_updated": "2026-10-04",
      "matrix_id": "m_points_program:airline-identity-verification-and-retention",
      "row_header": "Program",
      "rows": [
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.aa.com/i18n/customer-service/support/privacy-policy.jsp",
              "cell_locator": "vendor-global.airline-aadvantage.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "American's March 2026 policy lists account-profile, payment, partner-transaction, and corporate-program information for enrollment, account use, and management of Program Services."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.aa.com/i18n/aadvantage-program/aadvantage-terms-and-conditions.jsp",
              "cell_locator": "vendor-global.airline-aadvantage.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "The March 2026 terms name account audit, voluntary account termination, name change, and the limited deceased-member transfer-document review as verification or documentation events, with the stated matching information or documents."
            },
            "retention.rule": {
              "cell_citation_url": "https://www.aa.com/i18n/customer-service/support/privacy-policy.jsp",
              "cell_locator": "vendor-global.airline-aadvantage.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "American's March 2026 policy says Travel Services and Program Services information is generally retained up to seven years after completed travel or membership termination, within its stated necessity and legal criteria."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.aa.com/i18n/aadvantage-program/aadvantage-terms-and-conditions.jsp",
              "cell_locator": "vendor-global.airline-aadvantage.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "The March 2026 terms define an individual member, a narrow approved administrative-support role, the member's responsibility for that use, and a prohibition on third-party online-service account access."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.aa.com/i18n/customer-service/support/privacy-policy.jsp",
              "cell_locator": "vendor-global.airline-aadvantage.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "American's March 2026 policy describes booking-to-account linkage, its named affiliate/travel/co-brand/service-provider/payment recipient categories, and the fields a partner can access when an AAdvantage login is used on the partner's site or app."
            }
          },
          "jurisdiction": "vendor-global",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.aa.com/i18n/customer-service/support/privacy-policy.jsp",
          "row_id": "airline-aadvantage",
          "state": "airline-aadvantage"
        },
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
              "cell_locator": "vendor-global.airline-mileageplus.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "The current MileagePlus rules state that program participation authorizes United to collect, maintain, use, process, and share names, email addresses, physical addresses, account information, and other information under United's Privacy Policy."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
              "cell_locator": "vendor-global.airline-mileageplus.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "The rules name password or other security measures for specified transactions and awards, documentary proof for some credit claims, and account validation for changes to a business member's authorized representative."
            },
            "retention.rule": {
              "cell_citation_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
              "cell_locator": "vendor-global.airline-mileageplus.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "The rules state that accrued mileage remains in an account until redemption or forfeiture under six named rule, conduct, law, closure, death, or nonresponse events."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
              "cell_locator": "vendor-global.airline-mileageplus.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "The rules define individual members, non-individual business members and their authorized representatives, companion travelers, and authorized persons in death or divorce transfers, with stated account-control or responsibility boundaries."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
              "cell_locator": "vendor-global.airline-mileageplus.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "The rules name audit contractors, defined MileagePlus Partner categories, agreed cross-program mileage-credit contexts, and program-participation information sharing under United's Privacy Policy."
            }
          },
          "jurisdiction": "vendor-global",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.united.com/en/us/fly/mileageplus/rules.html",
          "row_id": "airline-mileageplus",
          "state": "airline-mileageplus"
        },
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.delta.com/us/en/legal/privacy-and-security",
              "cell_locator": "vendor-global.airline-skymiles.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "Delta's May 2026 Global Privacy Policy lists identity, contact, SkyMiles-account, program-activity, partner-membership, corporate-association, birth-date, gender, login, and consented lounge-access image data for the SkyMiles/account context."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.delta.com/us/en/need-help/support-skymiles",
              "cell_locator": "vendor-global.airline-skymiles.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "Delta's current SkyMiles help page documents MFA for login and password reset, the Identity Verification Form and documentary checks for specified account changes or inaccessible accounts, and both account numbers and passwords for duplicate-account authorization and name validation."
            },
            "retention.rule": {
              "cell_citation_url": "https://www.delta.com/us/en/legal/privacy-and-security",
              "cell_locator": "vendor-global.airline-skymiles.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "Delta states a necessity/record-policy/legal-requirement retention criterion rather than a public fixed period. Its rules say Delta retains the SkyMiles number assigned to basic information after closure, while its help page separately says account deletion permanently removes access to the account and associated data."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.delta.com/us/en/skymiles/program-resources/program-rules",
              "cell_locator": "vendor-global.airline-skymiles.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "The program rules define an individual-member account, distinguish business-entity and parent/guardian enrollment boundaries, make the member responsible for password confidentiality and use, and prohibit giving another person or third-party service access to the account credentials."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.delta.com/us/en/legal/privacy-and-security",
              "cell_locator": "vendor-global.airline-skymiles.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "Delta's May 2026 policy lists nine recipient categories, including authorized representatives, same-booking customers, service and travel partners, other airlines, corporate-travel recipients, payment firms, business-sale counterparties, and government/legal-process recipients. No standalone linked-account terms page was established from the documents read."
            }
          },
          "jurisdiction": "vendor-global",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.delta.com/us/en/legal/privacy-and-security",
          "row_id": "airline-skymiles",
          "state": "airline-skymiles"
        }
      ],
      "scope_label": "3 programs"
    },
    "hotel-identity-verification-and-retention": {
      "field_definitions": {
        "identity.data_collected": "Identity or account data the accepted provider record states is collected within its named event, program, jurisdiction, and revision.",
        "identity.verification_events": "A documented event, requested information, actor, and scope in which the accepted provider record states that verification occurs.",
        "retention.rule": "The duration or purpose-based retention criterion, covered record category, trigger, exception, and scope stated by the accepted provider record.",
        "roles_and_responsibility": "The account-holder, member, authorized actor, guest, partner, or other role and responsibility boundary stated by the accepted record.",
        "sharing_or_linkage": "A documented recipient, partner, linked-account relationship, purpose, and scope without an inference of public visibility or legal access."
      },
      "last_updated": "2026-10-04",
      "matrix_id": "m_points_program:hotel-identity-verification-and-retention",
      "row_header": "Program",
      "rows": [
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.hilton.com/en/hilton-honors/terms/",
              "cell_locator": "vendor-global.hotel-hilton-honors.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "Hilton's July 2026 terms name three required enrollment fields and additional profile fields a member may provide."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.hilton.com/en/help-center/your-account/enhanced-security-authentication/",
              "cell_locator": "vendor-global.hotel-hilton-honors.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "Hilton's help page documents password-plus-code Enhanced Security for account access."
            },
            "retention.rule": {
              "cell_citation_url": "https://www.hilton.com/en/p/global-privacy-statement/",
              "cell_locator": "vendor-global.hotel-hilton-honors.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "Hilton's August 2026 statement publishes a purpose-based criterion, a usual contractual/legal period, and a destruction standard."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.hilton.com/en/hilton-honors/terms/",
              "cell_locator": "vendor-global.hotel-hilton-honors.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "Hilton's terms define individual-member eligibility and assign account-access security responsibilities to each member."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.hilton.com/en/hilton-honors/terms/",
              "cell_locator": "vendor-global.hotel-hilton-honors.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "Hilton's terms say relevant personal information may be shared with business partners to credit mileage or other program benefits."
            }
          },
          "jurisdiction": "vendor-global",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.hilton.com/en/hilton-honors/terms/",
          "row_id": "hotel-hilton-honors",
          "state": "hotel-hilton-honors"
        },
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.ihg.com/content/us/en/customer-care/privacy_statement",
              "cell_locator": "vendor-global.hotel-ihg-one-rewards.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "IHG's July 2026 statement names identity, contact, account, preference, partner-membership, stay, and purchase fields collected for loyalty enrollment and participation."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.ihg.com/content/us/en/customer-care/member-tc",
              "cell_locator": "vendor-global.hotel-ihg-one-rewards.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "IHG's June 2026 terms state that a member requesting a name change through Customer Care should be prepared to provide supporting legal documentation."
            },
            "retention.rule": {
              "cell_citation_url": "https://www.ihg.com/content/us/en/customer-care/privacy_statement",
              "cell_locator": "vendor-global.hotel-ihg-one-rewards.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "IHG's July 2026 statement uses a purpose-based retention criterion and names longer transactional-record and prospective-litigation exceptions."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.ihg.com/content/us/en/customer-care/member-tc",
              "cell_locator": "vendor-global.hotel-ihg-one-rewards.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "IHG's June 2026 terms define an individual member role, one-account and registered-guest constraints, and responsibility for account/password access and use."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.ihg.com/content/us/en/customer-care/privacy_statement",
              "cell_locator": "vendor-global.hotel-ihg-one-rewards.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "IHG's July 2026 statement names loyalty and co-brand partners and service providers, with product, program-operation, and advertising purposes."
            }
          },
          "jurisdiction": "vendor-global",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.ihg.com/content/us/en/customer-care/privacy_statement",
          "row_id": "hotel-ihg-one-rewards",
          "state": "hotel-ihg-one-rewards"
        },
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.marriott.com/about/privacy.mi",
              "cell_locator": "vendor-global.hotel-marriott-bonvoy.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "For the loyalty-identity workflow, this cell records six Marriott-listed categories: identifying, demographic, government-ID, financial, loyalty-program, and travel information."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.marriott.com/loyalty/terms/default.mi",
              "cell_locator": "vendor-global.hotel-marriott-bonvoy.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "Within the member-account administration clauses, the September 2026 terms name Member Support security questions and supporting documentation for legal-name changes as verification or confirmation events."
            },
            "retention.rule": {
              "cell_citation_url": "https://www.marriott.com/about/privacy.mi",
              "cell_locator": "vendor-global.hotel-marriott-bonvoy.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "Marriott's August 2026 statement uses purpose, ongoing-relationship, legal-obligation, and legal-position criteria rather than one universal duration."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.marriott.com/loyalty/terms/default.mi",
              "cell_locator": "vendor-global.hotel-marriott-bonvoy.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "For the member-account role, the September 2026 terms define individual membership, prohibit joint or shared accounts, require duplicate accounts to be combined, and assign the member responsibility for current, accurate profile information."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.marriott.com/about/privacy.mi",
              "cell_locator": "vendor-global.hotel-marriott-bonvoy.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "Marriott's August 2026 sharing section identifies Marriott affiliates and property participants, licensees and co-brand issuers, on-property and travel providers, linked-account and insurance partners, advertising partners, corporate recipients, and service-provider functions."
            }
          },
          "jurisdiction": "vendor-global",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.marriott.com/about/privacy.mi",
          "row_id": "hotel-marriott-bonvoy",
          "state": "hotel-marriott-bonvoy"
        }
      ],
      "scope_label": "3 programs"
    },
    "issuer-identity-verification-and-retention": {
      "field_definitions": {
        "identity.data_collected": "Identity or account data the accepted provider record states is collected within its named event, program, jurisdiction, and revision.",
        "identity.verification_events": "A documented event, requested information, actor, and scope in which the accepted provider record states that verification occurs.",
        "retention.rule": "The duration or purpose-based retention criterion, covered record category, trigger, exception, and scope stated by the accepted provider record.",
        "roles_and_responsibility": "The account-holder, member, authorized actor, guest, partner, or other role and responsibility boundary stated by the accepted record.",
        "sharing_or_linkage": "A documented recipient, partner, linked-account relationship, purpose, and scope without an inference of public visibility or legal access."
      },
      "last_updated": "2026-10-04",
      "matrix_id": "m_points_program:issuer-identity-verification-and-retention",
      "row_header": "Program",
      "rows": [
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.americanexpress.com/en-us/benefits/additional-card/learn-more/",
              "cell_locator": "vendor-us.issuer-amex-membership-rewards.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "American Express's current Additional Card page says a request requires the additional user's legal name, address, date of birth, and SSN or ITIN, with a telephone route when the user has neither identifier."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.americanexpress.com/en-us/benefits/additional-card/learn-more/",
              "cell_locator": "vendor-us.issuer-amex-membership-rewards.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "At an Additional Card request, American Express says it obtains, verifies, and records information about the additional user; the requester confirms the relationship, accuracy, and consent for identity verification."
            },
            "retention.rule": {
              "cell_citation_url": "https://www.americanexpress.com/us/company/privacy-center/online-privacy-disclosures/",
              "cell_locator": "vendor-us.issuer-amex-membership-rewards.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "American Express states an event-based rule for covered Online Information rather than a fixed duration, with legal, regulatory, litigation, and investigation exceptions."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.americanexpress.com/content/dam/amex/en-us/company/legal/cardmember-agreements/public-site-2026-q2-pdf-cmas/sbs-small-business/business-gold-06-30-2026.pdf",
              "cell_locator": "vendor-us.issuer-amex-membership-rewards.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "The June 2026 Business Gold agreement defines the Basic Card Member, Company, and Additional/Employee Card Member roles, assigns account and charge responsibility, and states the approval boundary for replacing the Basic Card Member."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.americanexpress.com/content/dam/amex/us/company/privacy-center/online-privacy-disclosures/Business_Card_Privacy_Notice_2026.05.01.pdf",
              "cell_locator": "vendor-us.issuer-amex-membership-rewards.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "The May 2026 Business Card Privacy Notice identifies everyday-business, service-provider marketing, business-partner, and co-brand sharing contexts and states the associated opt-out boundary."
            }
          },
          "jurisdiction": "vendor-us",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.americanexpress.com/en-us/benefits/additional-card/learn-more/",
          "row_id": "issuer-amex-membership-rewards",
          "state": "issuer-amex-membership-rewards"
        },
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.capitalone.com/learn-grow/business-resources/applying-for-business-credit-card/",
              "cell_locator": "vendor-us.issuer-capital-one-rewards.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "Capital One Business's March 2026 application guide says a business-card application may typically call for the listed contact, entity, applicant, tax, operational, financial, and ownership/controller information."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
              "cell_locator": "vendor-us.issuer-capital-one-rewards.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "Capital One's May 2026 policy names application, login, account-access, and later online or phone interactions as identity or account-verification events."
            },
            "retention.rule": {
              "cell_citation_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
              "cell_locator": "vendor-us.issuer-capital-one-rewards.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "Capital One's May 2026 policy uses a reasonably-necessary criterion and lists service, compliance/audit, complaint/troubleshooting, and legal-claim factors; it publishes no fixed duration in this clause."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.capitalone.com/learn-grow/business-resources/capital-one-account-manager/",
              "cell_locator": "vendor-us.issuer-capital-one-rewards.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "Capital One Business's September 2026 account-manager page distinguishes the account manager, authorized user, and primary account holder and states each role's controls or responsibility."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
              "cell_locator": "vendor-us.issuer-capital-one-rewards.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "Capital One's May 2026 policy lists seven recipient categories, their stated examples or purposes, aggregate/de-identified sharing, and the policy's U.S.-audience scope and non-Capital-One exclusions."
            }
          },
          "jurisdiction": "vendor-us",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.capitalone.com/learn-grow/business-resources/applying-for-business-credit-card/",
          "row_id": "issuer-capital-one-rewards",
          "state": "issuer-capital-one-rewards"
        },
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.chase.com/personal/credit-cards/education/basics/how-to-fill-out-business-credit-card-application",
              "cell_locator": "vendor-us.issuer-chase-ultimate-rewards.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "Chase's business-card application guide lists business identity, address, structure, tax, revenue, operating-history, and employee-count fields used for most applications."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.chase.com/digital/resources/privacy-security/privacy/online-privacy-policy",
              "cell_locator": "vendor-us.issuer-chase-ultimate-rewards.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "Chase's online privacy policy names access to account information as an example identity-verification event."
            },
            "retention.rule": {
              "cell_citation_url": "https://www.chase.com/digital/resources/privacy-security/privacy/ca-consumer-privacy-act",
              "cell_locator": "vendor-us.issuer-chase-ultimate-rewards.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "Chase's December 2025 California disclosure ties retention to an ongoing relationship or stated-purpose need, applicable limitation periods, legal retention requirements, and legal claims."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.chase.com/inkbusinesspreferred/rewardsagreement",
              "cell_locator": "vendor-us.issuer-chase-ultimate-rewards.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "The Ink Business Preferred Ultimate Rewards agreement distinguishes the responsible party from an authorized user and assigns the responsible party responsibility for points use."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.chase.com/digital/resources/privacy-security/privacy/online-privacy-policy",
              "cell_locator": "vendor-us.issuer-chase-ultimate-rewards.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "Chase's policy names service providers, affiliates, co-brand companies, corporate-transaction parties, and legal or protective recipients."
            }
          },
          "jurisdiction": "vendor-us",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.chase.com/personal/credit-cards/education/basics/how-to-fill-out-business-credit-card-application",
          "row_id": "issuer-chase-ultimate-rewards",
          "state": "issuer-chase-ultimate-rewards"
        }
      ],
      "scope_label": "3 programs"
    }
  },
  "template": "matrix",
  "tier": "T1",
  "warnings": []
}
