Skip to main content

Search the site

Pages, events, partners, news and job postings. Press Enter to see every result.

Privacy policy

What we collect, why we collect it, who can see it and the choices you have.

Interim text, under review

This is an interim text of the privacy policy, in effect from October 3, 2026. The Board of Directors and the association's attorney are completing their review, and any change will be posted on this page.

In short

  • We collect what we need to run the association: membership, applications, events, email and dues.
  • We never sell personal information. The site has no advertising and nothing that follows you across websites; it counts visits to public pages without cookies or your internet address.
  • Only members can open the member directory, and each member chooses which contact details and photo it shows.
  • Letters of recommendation and Board notes are for the Board, and Crisis Fund requests only for the positions the Board chooses. Website support may open letters and notes only to fix a technical problem, and each time it does is recorded.
  • You can change your email choices at any time and ask us for a copy of your information, or to correct or delete it.

1. Who we are

The New York City Association of Hotel Concierges, Ltd. (“NYCAHC”, “we” or “us”) is a New York not-for-profit corporation, exempt from federal income tax under section 501(c)(6) of the Internal Revenue Code. We run this website and are responsible for the personal information described in this policy.

The policy covers the public website, the online application and the pages for letter writers, the member portal, the corporate portal, the Board workspace and the emails they send. Services run by others that we link to, such as Intuit's payment pages, have their own policies.

2. Information we collect

When you visit. Like any website, our server receives your internet (IP) address, a description of your browser, the address of the page you ask for and the time. We use this to deliver pages, keep the site secure and fix problems. The site has no advertising and does not follow you across other websites. Maps and weather forecasts on event pages are drawn by our server, so no map or weather service sees your visit.

Visit counts and error reports. To learn which public pages people read, our server counts each visit to them with Umami: it passes on the page's address without anything after a “?”, the website you came from when it is another site, your screen size, your language and your browser, but not your internet address, and no cookie is set or anything stored in your browser. Pages behind the sign-in, the letter pages and previews are never counted, and nothing is counted when your browser sends a Do Not Track or Global Privacy Control signal. When something on the site goes wrong, a report goes to Sentry with what failed, the page's address with its codes removed, the last steps on the site that led to it (such as the buttons pressed and the pages opened), and your browser and system. The report does not say who was signed in, our server passes it on without your internet address, and email addresses are removed from it.

Newsletter and invitations. If you sign up, we keep your email address and, as a record of your consent, when you signed up, the internet address and browser used to sign up, and the internet address used to confirm.

Applicants. A Concierge application asks for your legal and preferred names, email, mobile and work phones, work address, hotel, title and time in your position, whether your desk is in the main lobby and where in the hotel you work, your years as a Concierge and the hotels you worked at before, your usual weekly schedule, confirmation that you meet the age requirement, the general meetings you attended as a guest, a note on why you want to join, your résumé, a photo and your business card, and it ends with your signature of the Ethics and Professional Standards. A corporate application asks for your name and title, the company's details, category, membership level, description and logo, the corporate member that referred you, if any, and the names and contact details of its one or two representatives.

Letter writers. An applicant chooses the member who will recommend them and gives us the name, title and email of the hotel's general manager or human resources contact. We keep the letter you write or upload and, on the hotel's letter page, your name and title; if you decline to write, the reason you give.

Members and corporate representatives. Your account (email address, password stored only in scrambled form, and two-step verification if you turn it on); your profile (names, title, hotel or company, phone numbers, the languages you list, photo and billing email); your membership (category, status, dates, dues paid through and history) and the Les Clefs d'Or and notary public marks the Board records; your directory choices; your replies to invitations and the guests you name; check-ins and attendance; your yearly certification of the standards; your comments on a proposed corporate member and the job postings you send; the private address of your calendar feed and when it was last used; notifications; your email choices; and your invoices and payments. For a corporate member we also keep the company's listing and logo, its contact for Concierges, the events it proposes, requests to present at meetings, logo-use requests and Trade Show interest.

Guests at events. When you come to an event as a guest, the Board member at the door records your name and email address, so that the general meetings you attended count if you later apply, and the Board may send the event's attendees the association's emails, each of which lets you stop them.

Signatures. When you sign the Ethics and Professional Standards, we keep your typed name, the version of the text and a fingerprint of it, the time, and the internet address and browser you used.

Crisis Fund requests. If you ask the Crisis Fund for help, we receive the reason, an amount if you give one, your own words, any documents you add and how to reach you. Please share only what the Board needs to consider your request. Health details are never required; if you include them, we use them only to consider your request.

Sign-in and security records. For each signed-in session we keep the internet address and browser. Board actions, Board sign-ins and every opening of confidential files and exports are recorded in an audit log with the same details and with the person or address each action concerned. So are the main steps of an application, a letter and a signature, each download of a document, and what website support opens or does while helping someone.

Photos at events. The Board may add photos taken at association events to albums. The copies shown on the site are stripped of location and other hidden details; the original files are kept for the Board.

From others. We also receive information from members who recommend you and hotels that confirm your position; from the association's own records, which the Board brought into the site when it opened: its member and corporate member records, the contacts of our previous email service with their subscription status, their registrations for past events and the other details that service held about a member (such as phone numbers, a home address or a birthday), kept as notes for the Board, and the minutes of general meetings since 2010, which name members, candidates and guests; from Intuit, which tells us when an invoice is paid; and from our email provider, which tells us whether a message was delivered, bounced or marked as spam and, when tracking is on, opened or clicked.

3. How we use it

We use personal information to:

  • run membership: review applications, share candidates' names with the membership for comments as the bylaws provide, vote and keep membership records;
  • organize events: invitations, replies, waitlists, member passes and check-ins, and the attendance the Ethics and Professional Standards ask of members;
  • connect members through the members-only directory, following each member's choices;
  • send emails about your account, your application and your invoices, and the other kinds of email you choose;
  • invoice dues and fees and record payments;
  • consider Crisis Fund requests and pay the help the Board approves;
  • keep the site secure, prevent abuse and fix problems;
  • keep the records the law and the bylaws require, and answer your questions.

We do not sell or rent personal information, share it for advertising or use it to build advertising profiles, and we do not give, sell or otherwise transfer email addresses to anyone outside the association, apart from the service providers named below. The site suggests a membership category from an applicant's answers, but people on the Board make every decision.

4. Who can see it

Other members. Signed-in members see the member directory: each member's name, hotel, title, category, the Board position they hold, the languages they list and the Les Clefs d'Or and notary public marks the Board records and, unless the member turns them off, email, work phone and photo. A mobile number shows only if the member turns it on. Corporate representatives do not see the member directory. Members also see corporate members' approved listings and their contacts for Concierges.

Applicants. Someone applying as a Concierge chooses a member to recommend them and, to find that member, can look up active members by name: the search shows a member's name, title and hotel, never contact details.

Candidates. As the bylaws provide, the names of candidates for membership are shared with the members for comments. New corporate members may also be announced to members for feedback.

Corporate hosts. A corporate member that hosts an event sees how many people replied and attended, and sees their names only if the Board turns that on.

The Board. Every Board position reviews applications and their letters and reads the Board's notes on members; other tasks follow each position's permissions. The Board members who check people in at events see members' photos to recognize them at the door. Crisis Fund requests are read only by the positions the Board chooses (by default, the President and the Treasurer). Every opening of a Crisis Fund request, an application file or a document is recorded.

Website support. Website support looks after the site and the member portal. It can reach what the Board sees, apart from Crisis Fund requests, but opens applications, letters, notes and other personal records only when that is needed to fix a technical problem, and each time it opens an application or the notes on a member is recorded. To help with a problem, it can also view the site as a member sees it and act there for them, but it cannot change their password, two-step verification or devices, sign or vote for them, send or withdraw their application, or open the Crisis Fund. Every such visit, and what is done during it, is recorded.

The public. Only what the association publishes: the Board of Directors page (names, positions and their email addresses, hotels and the photos Board members agree to publish), photographs of members on the public pages, published with their agreement, past presidents, corporate members' listings (name, logo, description, address for guests and website), public events, albums the Board makes public, news and job postings.

Service providers. These companies handle information for us, each under its own terms and privacy policy:

  • OVHcloud US (opens in a new tab) hosts the site and its database in data centers in the United States;
  • Resend (opens in a new tab) sends our emails from the United States and reports on their delivery;
  • Sentry (opens in a new tab) receives the site's error reports, as described above, and keeps them in the United States for a limited time;
  • Umami (opens in a new tab) counts visits to the public pages from what our server sends it, without internet addresses or cookies, and keeps the counts in the United States for a limited time;
  • Intuit (QuickBooks Online and QuickBooks Payments) keeps the association's accounts and invoices and takes payments: we share your name, email and invoice details, card or bank details go directly to Intuit, never to us, and Intuit also uses payment information for its own purposes under the Intuit Global Privacy Statement (opens in a new tab);
  • Backblaze (opens in a new tab) (B2 Cloud Storage) keeps our nightly backups, which are encrypted before they leave our server;
  • Google Workspace hosts the association's mailboxes, such as bod@nycahc.org, so emails you send us and replies to our emails are kept there.

If you add an event to Google Calendar or Outlook with our links, the event's details go to that service, the directions links on event and partner pages open Google Maps or Apple Maps with the address of the place, and the map on an event page links to OpenStreetMap.

When the law requires. We may disclose information to comply with the law or a court order, or to protect people's safety or the association's rights. New York law also lets a member of at least six months inspect the minutes of members' meetings and the list of members' names, addresses and membership class for the association's purposes; the directory settings do not change that right.

5. Cookies and browser storage

The site uses only the cookies it needs to work:

  • nycahc.session_token keeps you signed in. It lasts 3 days, renewed while you use the site (for holders of a Board position and website support, a little over 20 hours from signing in), when you choose “Keep me signed in”, sign in with an emailed link or accept an invitation; otherwise it is deleted when you close your browser and stops working after a day at most.
  • nycahc.dont_remember records that you chose not to stay signed in.
  • nycahc.two_factor keeps a sign-in open for 10 minutes while you enter your two-step verification code.
  • nycahc_qbo_state is used for 10 minutes while the Treasurer connects QuickBooks.
  • nycahc.view_as is set only in website support's own browser while it views the site as someone, for an hour at most.

On the secure site the names of the first three start with “__Secure-”, and nycahc.view_as with “__Host-”. The Board's check-in page keeps pass numbers taken without a connection in the phone's browser storage until they can be sent.

There are no advertising or analytics cookies, and no one tracks you across websites through this site. We honor Do Not Track and Global Privacy Control signals: when your browser sends either, nothing about your visit is counted. The newsletter sign-up and the start of an application are protected from automated sign-ups by checks that run out of sight on our own server, such as how soon a form comes back after the page was shown and how many emails these forms send in an hour. These checks need no puzzle and no cookie, and they share nothing with another company.

In our emails. Images and fonts in our emails load from our website without anything that identifies you. When open and click tracking is turned on at our email provider, it adds a tiny image to our emails and passes their links through its own address, so we learn whether a message was opened and which links were clicked. Turning off images in your email app stops the open count.

6. Your email choices

Messages about your account, your membership, your application and your invoices are always sent. For the rest you choose among three kinds: event invitations and reminders, association news and announcements, and the industry newsletter. Every newsletter and invitation campaign has a link to your preferences and a one-click unsubscribe.

Members and corporate representatives receive association emails until they opt out. Newsletter subscribers confirm their address by email first. Contacts brought over from our previous email service receive our emails only if they were subscribed there. Anyone who unsubscribed can sign up again: once the address is confirmed, the three kinds of email are on again, and the preferences link changes them. A sign-up never brings email to an address that bounced, reported our email as spam or that the Board stopped. Guests who attended an event may receive the emails the Board sends to that event's attendees until they opt out.

7. How long we keep it

  • Declined or withdrawn applications: after 12 months (a period the Board sets), we delete the files, letters, notes, comments and most answers, and keep the names, hotel or company, the names and titles of the letter writers, the decision with the Board's votes and its messages to you, the signature record and the account.
  • Unfinished applications that were never sent are deleted, with their files, two years after they were last changed (a period the Board set); your account stays. An application you withdraw follows the rule above.
  • Membership records, such as membership history, attendance, certifications and invoices, are part of the association's books and records, which the bylaws ask the Secretary to keep, and are kept after a membership ends.
  • Newsletter sign-ups and email choices are kept so that we keep respecting them, including after you unsubscribe.
  • Emails: the text of a message is erased from our system once our email provider accepts it, or 30 days after the last attempt if it never does; the record that it was sent, delivered or opened is kept.
  • Sessions and sign-in links: sessions end as described above, a sign-in link works for 15 minutes and a link to set a new password for 60; expired ones are deleted every night.
  • Server logs are limited in size, and the newest entries overwrite the oldest; the application's own logs are kept for a month at most.
  • Error reports and visit counts are kept by Sentry and Umami for a limited time that their plans set.
  • Crisis Fund requests are kept until the Board decides to delete them.
  • Backups are made every night and kept for up to a year (daily copies for a week, weekly copies for a month, monthly copies for a year), so information deleted from the site leaves the backups within about a year.

Other records, such as the audit log, are kept for as long as the association needs them.

8. How we protect it

We protect personal information with measures that fit its sensitivity:

  • encrypted connections (HTTPS) for the whole site;
  • passwords stored only in scrambled form, optional two-step verification and a lock after repeated failed sign-ins;
  • access by Board position, checked on the server for every page and action;
  • private files served only after a permission check, and an audit log of Board actions and of every opening of confidential files and exports;
  • the words, contact details and documents of Crisis Fund requests, and the keys of connected services, encrypted where they are stored;
  • nightly backups encrypted before they leave the server.

No system is perfectly secure. If a breach affects your personal information, we will tell you and the authorities New York law names as quickly as we can and within 30 days of discovering it, unless law enforcement asks us to wait, by mail or by phone, or by email if you agreed to that.

9. Your choices and rights

In the portal you can update your profile, choose what the directory shows, change your email choices, change the email address you sign in with (a link sent to the new address confirms it), see your signed-in devices and sign them out, set a new password and turn on two-step verification.

You can also ask us, by email to contact@nycahc.org or by mail:

  • for a copy of the personal information we hold about you;
  • to correct it;
  • to delete it, or to stop using it for a purpose.

We answer within 45 days and may need to confirm who you are. We may keep what the law or the bylaws require us to keep, such as membership, financial and signature records, and letters written about an applicant stay confidential to the Board. We handle requests the same way whatever state you live in.

10. Children

The site is meant for adults who work in or with the hotel industry. It is not directed to children, and we do not knowingly collect information from children under 13 or from anyone under 18. If you believe a minor has given us information, write to us and we will delete it.

11. Where information is kept

The association is based in New York, and the site, its database, its backups, its error reports and its visit counts are kept in the United States. Some providers, such as Intuit and Google, may also process information in other countries under their own policies. If you use the site from another country, your information is transferred to and processed in the United States.

12. Changes to this policy

We may update this policy. The date at the top shows the current version. When a change matters to members, we tell account holders by email or in the portal before it takes effect.

13. Contact us

New York City Association of Hotel Concierges, Ltd.
F.D.R. Station, P.O. Box 905
New York, NY 10150-0905

Questions and requests about your information: contact@nycahc.org. The Board of Directors is responsible for this policy: bod@nycahc.org.