EMPIRE STATE BUILDING PRIVACY POLICY
Last Updated: July 18, 2025
Welcome to the Empire State Building! We hope you will find everything you need on this website to plan your next trip to our iconic property. As you make your plans, we want you to know that we take your privacy very seriously. This Privacy Policy explains how we collect, use, disclose, and otherwise process your personal information in connection with our www.esbnyc.com website (the “Site”) and the services (“Services”) offered through this Site. This Privacy Policy also explains how we process information collected when you visit the Empire State Building or otherwise interact with us.
PRIVACY HIGHLIGHTS
This summary provides key points from our Privacy Policy. You can find more details about any of these topics by clicking the respective links in our Table of Contents.
What personal information do we collect?
When you visit our Site or otherwise interact with us, we collect and process personal information to assist you with finding the information you need to plan your next trip, purchasing tickets or other Services for your visit. We also collect and process personal information so we can share information we think you will find beneficial, and to help us improve and administer our Site and Services. When you visit the Empire State Building, we collect personal information in relation to your visit, and to keep you and other visitors safe.
With whom do we share your personal information?
We do not sell your personal information. We may share information with our service providers and with other third parties, including advertisers, as defined in this Policy.
How do we keep your information safe?
We have administrative, technical and physical safeguards in place to protect your personal information. However, no electronic transmission is 100% secure; and, as such, we cannot guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to circumvent our security efforts and improperly access your information.
What are your privacy rights?
Depending on where you are located geographically, applicable privacy laws may give you certain rights regarding your personal information. See the section below entitled “What are your privacy rights?” for details on those rights and how to exercise them.
Table of Contents
Who are we?
What is personal information?
How do we collect personal information from you?
What personal Information do we collect from you and how do we use it?
Cookies and other technologies
With whom do we share your personal information?
Legal bases for processing and sharing your personal information
Cross-border transfer
How do we store and protect your personal information?
How long do we retain your personal information?
What are your privacy rights?
Children’s privacy
Use of Chatbots
Links to other websites and services
How to exercise your privacy rights
Contact us
Changes to the Policy
Who are we?
ESRT Observatory TRS, LLC (“ESRT”, “we”, “our”, “us”) is the legal entity that manages and operates the Empire State Building and this Site. When we collect your personal information through this Site or our Services, we are acting as a “Controller” of your data. A “Controller” is an entity that determines the purposes and means of processing of your personal information.
What is Personal Information?
When we use the term “personal information” in this Privacy Policy, we mean any data or information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular natural person or household or any other data or information that constitutes “personal data”, “personal information,” or “personally identifiable information” as those terms are defined under applicable privacy laws.
How do we collect personal information from you?
We collect information in three ways: (1) we collect the information you provide to us, (2) we automatically collect certain information (for example, through our Site) and (3) we collect information from third parties. Each of these collection practices is described further below.
What personal information do we collect from you and how do we use it?
We collect the information you provide to us. During your visit to our Site or the Empire State Building, you may choose to provide us with certain information in order to:
- Buy Tickets or Register for Events. You may purchase tickets or register for various Services through our Site. In order to process your purchase requests, we will collect information from you, including: your name, email address, telephone number, country of residence, postal code and any payment information necessary for processing. Please note that we use third party payment processors, such as Ventrata to process credit card payments made to us. In such instances, we do not retain any personally identifiable financial information in connection with credit card payments, such as full credit card numbers. Rather, all such information is provided directly by you to our third-party processor. The payment processor’s use of your personal information is governed by their privacy policy. To view Ventrata’s privacy policy, please click here.
When you make purchases through our Site, you will receive a confirmation containing a link to a site with other promotional offers we think may be of interest to you based upon your purchase. This site is hosted and managed entirely by a third party (Get Your Guide or “GYG”) and we are not responsible for your interaction with the GYG site or the information you may choose to share with them. Since we do not share your information with GYG, any information you choose to share with them is solely subject to the terms of their Privacy Policy and Terms of Services. - Stay Connected. You may choose to sign up for our latest news, updates, and other special offers. In doing so, we collect the following types of information: name, email address, birthdate, zip code and telephone number. You may also voluntarily elect to opt-in to receive SMS alerts with similar news, updates and special offers.
- Enroll in our Ambassador Loyalty Program. If you are interested in enrolling in our Ambassador Loyalty Program, https://ambassador.esbnyc.com/, we will collect your name, email address, telephone number, country and postal code. Our Ambassador Loyalty Program is administered by a third-party service provider, Uptop. You may also voluntarily elect to opt-in to receive Ambassador Program emails or SMS alerts with similar news, updates and special offers.
- Submit a Tower Lighting Partner Application. If you are interested in requesting tower lighting, our application form contains various questions to help us better understand the nature of your request (e.g., is this a personal or organizational request, date and color of lighting, etc.). The information you provide will be used to evaluate whether, and how, your request may be granted. In order to communicate with you concerning this request, we also ask that you provide us with basic contact information.
- Submit a Brand Partnership Form. If you are interested in partnering with us, you will be asked to provide information concerning your brand’s vision for partnership. This information will help us determine the nature of your request. In order to communicate with you concerning this request, we also ask that you provide us with basic contact information.
- Submit a Licensing Application Form. If you are interested in licensing our intellectual property (e.g., trademarked name or image), you will be asked to provide information to help us determine the nature and duration of your intended use. In order to communicate with you concerning this request, we also ask that you provide us with basic contact information.
- Submit an Influencer Application Form. If you are interested in becoming a social media influencer for us, you will be asked to provide certain information to help us determine the benefits of partnering with you. You will be asked to share your social media account handles so we can explore the nature of your presence. In order to communicate with you concerning this request, we also ask that you provide us with basic contact information.
- Contact Us. If you contact us through the “Contact Us” form provided, you will be asked to provide certain information to help us assist you with your stated inquiry. In order to communicate with you concerning this request, we also ask that you provide us with basic contact information.
We utilize video surveillance and other fraud monitoring tools (collectively, “Security Equipment”) on our premises, which may capture biometrics, such as facial recognition information, to create a safer environment for our staff and visitors, and to deter, prevent, investigate, and/or prosecute any illegal activity that may occur on our premises. Our video systems record digital images but do not record audio. Information from the Security Equipment (“Security Information”) is accessible only to a limited number of our employees, or to third-party service providers or law enforcement, engaged to assist with security-related tasks. These third-party service providers may have access to Security Information only where strictly required to perform their tasks, and are not allowed to use the Security Information for any other purposes; and we may provide Security Information to law enforcement for investigations, to prevent fraud, or for safety and security purposes. Security Information is not shared or exchanged with third parties for anything of monetary value or any form of profit.
We automatically collect certain information. When visiting our Site, we automatically collect information about your computer hardware and software. This information can include: your IP address, browser type, domain names, access times and referring website addresses. This information is used for the operation of the Site, to maintain quality of the service, and to provide general statistics regarding use of our Site and Services.
We use cookies to allow us to personalize your visits, keep track of your preferences and learn about the way in which you use our Site. A cookie is a small file that is placed on your computer when you visit our Site and allows is to recognize you as a user. We employ both “Essential” and “Non-essential” cookies. Essential cookies are necessary to the effective operation of our Site and make the interaction between you and the Site faster and easier. Non-essential cookies are not required for a website to function but are used for other purposes, such as analytics or advertising.
We also use web beacons, which allow us to count users who have visited our Site (and particular pages on the Site) and to recognize users by accessing our cookies. In addition, a web beacon can be used in HTML-formatted email to determine responses to our communications and measure their effectiveness.
We participate in behavioral-based advertising. This means that, if you permit targeting cookies in the cookie management tool, a third-party will place a cookie on your browser, or use a web beacon, to collect information about your use of our Site and Services so that they can provide advertising about products and services tailored to your interests. That advertising may appear on our Site or on other websites you visit.
We may also use services hosted by third parties, such as Google Analytics, a web analytics service provided by Google, Inc., to assist in providing our Services. Google Analytics uses cookies and other tracking technologies to help us analyze how users use the Site. The information generated by the cookie or other tracking technology about your use of the website (including your IP address) will be transmitted to, and stored by, Google on their servers. Google will use this information for the purpose of evaluating your use of the Site, compiling reports on Site activity for us and providing other services relating to Site activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. By using the Services, you consent to the processing of data about you by Google in the manner and for the purposes set out above. To opt out of tracking by Google Analytics, click here.
Your browser settings may also allow you to transmit a “Do Not Track” signal when you visit various websites. Like many websites, our Site does not use or respond to “Do Not Track” signals in your web browser. To learn more about “Do Not Track” signals, you can visit http://www.allaboutdnt.com/.
We also collect information from third parties.
We may also collect information about you from social media or other publicly available sources. When an individual interacts with our Site through various social media networks, such as when someone “Likes” us on Facebook or follows us or shares our content on Google, Facebook, X, or other social networks, we may receive some information about individuals that they permit the social network to share with third parties. The data we receive is dependent upon an individual’s privacy settings with the social network, and may include your profile information, profile picture, gender, username, user ID associated with your social media account, age range, language, country, and any other information you permit the social network to share with third parties. Individuals should always review and, if necessary, adjust their privacy settings on third-party websites and social media networks and services before sharing information and/or linking or connecting them to other services. We use this information to operate, maintain, and provide to you the features and functionality of the Site, as well as to communicate directly with you, such as to send you email messages about Services that may be of interest to you.
We may share information collected about you in the following ways:
- With service providers. We work with certain third parties who provide services to us, such as managing visitor/customer information, managing our marketing and promotions activities, managing certain information technology systems, and conducting other activities of the kind described elsewhere in this Privacy Policy on our behalf. In such cases, we may disclose your personal information to such service providers, who act as processors of your data on our behalf. We do not authorize any of these service providers to make any use of your information other than for our benefit.
- With analytics service providers and advertisers. We permit third parties to use cookies, web beacons, and similar tracking technologies on our Site. Such parties may collect information about how you use our Site and other websites over time and across different services. This information may be used to, among other things, analyze and track data, determine the popularity of certain content, and better understand your online activity. Information collected in this fashion may be used for targeted marketing purposes – namely, to deliver advertisements targeted to your interests and preferences. To learn about your choices regarding this sharing of your information please see “How to exercise your privacy rights” section below.
- With third parties for legal reasons. We would share information about you if we reasonably believe that disclosing the information is needed to: (i) comply with any valid legal process, governmental request, or applicable law, rule, or regulation; (ii) investigate, remedy, or enforce potential violations of our Terms of Use or Privacy Policy; (iii) protect the rights, property, and safety of us, our users, or others; or (iv) detect and resolve any fraud or security concerns.
- With third parties as part of an acquisition or liquidation. If we are involved in a merger, asset sale, financing, corporate divestiture, reorganization, or acquisition of all or some portion of our business to another company, or if we undergo liquidation or bankruptcy proceedings, we may share your information with that company before and/or after the transaction closes or the proceedings are completed.
- Aggregated or de-identified information with third parties. We also share with third parties, such as advertisers, aggregated or de-identified information and we may permit our third-party providers to further use, sell, license, distribute, or disclose de-identified data. Aggregated or de-identified information does not identify you and, as such, is not considered personal information.
Legal bases for processing and sharing your personal information
We process your personal information and share it with third parties for the purposes described in this Policy, based on the following legal grounds:
- With your consent. We ask for your consent to process or share your information for specific purposes and you have the right to withdraw your consent at any time. For example, we ask for your consent to provide you with certain promotional information.
- For our legitimate interests. We process and share your information for our legitimate interests and those of third parties while applying appropriate safeguards that protect your privacy. For example, we process and share your information in order to help us:
- maintain and improve our Site and Services;
- welcome you to the Empire State Building and provide you services during your visit;
- perform analytics and research aimed at improving the accuracy, effectiveness, usability, or popularity of the Site and Services;
- improve the content and features of the Site and Services or develop new content and features;
- promote the Site and Services;
- communicate with you and provide you offers concerning the Site and Services;
- detect, prevent, or otherwise address fraud, abuse, security, or technical issues with the Site or Services;
- protect against harm to our, our customers’ or the public’s, rights, property, or safety as required or permitted by law;
- enforce legal claims, including investigation of potential violations of applicable Terms of Use for the Services.
- To fulfill our contractual obligations. We process and share your information where necessary to provide a Service you have requested. For example, we process your payment information when you purchase a ticket to visit the Empire State Building.
- To comply with legal obligations. We process and share your information when we have a legal obligation to do so. For example, if we are legally required to respond to an enforceable subpoena or governmental request.
Cross-border transfer
We transfer, process, and store information about you on servers located in the United States. Therefore, if you are located outside of the United States, your information will be transferred to, stored, or processed in the United States, whose data protection, privacy, and other laws may not provide the same level of protection as those in your country of residence. For example, government entities in the United States and other countries may have certain rights to access your personal information. If we transfer your information outside of your country of residence in this way, we will take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this Policy. By using our Site, you understand and consent to the collection, storage, processing, and transfer of your information to our facilities in the United States and to those third parties with whom we share it as described in this Notice.
How do we store and protect your personal information?
We take reasonable precautions, including the implementation of administrative, technical and physical safeguards, to protect your information. Please keep in mind that the internet is not a 100% secure medium for communication, and we cannot guarantee that the information collected about you will always remain private when using our Site. As a result, while we strive to protect your personal information, we cannot guarantee the security of information you transmit to us, and you do so at your own risk.
How long do we retain your personal information?
We will usually store the personal information we collect about you for no longer than necessary to fulfill the purposes for which it was collected, and in accordance with our legitimate business interests and applicable law. However, if necessary, we may retain personal information for longer periods of time, until set retention periods and deadlines expire. For instance, where we are required to do so in accordance with legal, tax and accounting requirements set by law, regulation or government authority.
To determine the appropriate duration of the retention of personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of personal information and if we can attain our objectives by other means, as well as our legal, regulatory, tax, accounting and other applicable obligations.
Once retention of the personal information is no longer necessary for the purposes outlined above, we will either delete or deidentify the personal information or, if this is not possible (for example, because personal information has been stored in backup archives), then we will securely store the personal information and isolate it from further processing until deletion or deidentification is possible.
What are your privacy rights?
In accordance with applicable privacy law, and depending upon the jurisdiction in which you reside, you may have some or all of the following rights in respect of your personal information:
Right of access. You may have the right to obtain: (i) confirmation of whether, and where, we are processing your personal information; (ii) information about the categories of personal information we are processing, the purposes for which we process your personal information and information as to how we determine applicable retention periods; (iii) information about the categories of recipients with whom we may share your personal information; and (iv) a copy of the personal information we hold about you.
Right of portability. You may have the right, in certain circumstances, to receive a copy of the personal information you have provided to us in a structured, commonly used, machine-readable format that supports re-use, or to request the transfer of your personal information to another person.
Right to rectification or correction. You may have the right to obtain rectification or correction of any inaccurate or incomplete personal information we hold about you.
Right to deletion or erasure. You may have the right, in some circumstances, to require us to delete or erase your personal information.
Right to restriction. You may have the right, in some circumstances, to require us to limit the purposes for which we process your personal information if the continued processing of the personal information in this way is not justified, such as where the accuracy of the personal information is contested by you.
Right to opt-out. You may have the right to opt-out of certain processing activities. For example, you may have the right to opt-out of the use of your personal information for targeted advertising purposes, or to “sell” or “share” your personal information with third parties in certain contexts.
Right to control over automated decision-making or profiling. You may have the right to direct us not to use automated decision-making or profiling for certain purposes.
Right to withdraw consent. If you have provided consent for the processing of your personal information, you may have the right to withdraw your consent. If you withdraw your consent, this will not affect the lawfulness of our use of your personal information before your withdrawal.
Right to appeal. In the event that we decline to take action on a request exercising one of your rights set forth above, you have the right to appeal our decision.
You may also have the right to not receive retaliatory or discriminatory treatment in connection with a request to exercise the above rights. To exercise any applicable rights, please refer to the “How to exercise your privacy rights” section below.
Children’s Privacy
Our Site and Services are not directed to, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 18. If an individual is under the age of 18, they should not provide us with any personal information either directly or by other means. If a child under the age of 18 has provided personal information to us, we encourage the child’s parent or guardian to contact us to request that we remove the personal information from our systems. If we learn that any personal information we collect has been provided by a child under the age of 18, we will promptly delete that personal information.
Use of Chatbots or Artificial Intelligence
We may use automated chat features, or “chatbots” to communicate with you. This feature is hosted by a third-party service provider (Satisfi Labs). Any information you provide to us through the chatbot will be processed and stored by the service provider as part of the services it provides to us. Information collected by a chatbot is used only for the purposes outlined in this Policy, such as to answer a specific user question. We recommend that users not submit personal information through the chatbot features unless specifically prompted to do so. We may recommend products or services based on your questions submitted through the chatbot.
Links to other websites and services
Our Services may include links to third-party websites, such as to our third-party payment processing partner. Except where we post, link to or expressly adopt or refer to this Privacy Policy, this Policy does not apply to, and we are not responsible for, any personal information practices of third-party websites, online services or the practices of other third parties. To learn about the personal information practices of third parties, please visit their respective privacy notices.
How to exercise your privacy rights
Please submit a request as set forth in the “Contact Us” section below. Before processing your request, we may need to verify your identity and confirm you are entitled to the applicable privacy rights. In certain circumstances, we may decline a request to exercise the rights described above, particularly where we are unable to verify your identity or locate your information in our systems. If we are unable to comply with all or a portion of your request, we will explain the reasons for declining to comply with the request. We will respond to your request as required under applicable privacy laws, generally within a month or 45 days, unless we require more time, in which case we will provide you notice.
In certain circumstances, you are permitted to use an authorized agent to submit requests on your behalf through the designated methods set forth above where we can verify the authorized agent’s authority to act on your behalf.
Contact us
If you wish to exercise any of your privacy rights or have any questions about this Notice, please contact us at:
By mail at: Attn: Privacy
Empire State Realty Trust Inc.
111 West 33rd Street
12th Floor, New York, NY 10120
Changes to the Policy
We may update this Policy from time to time. When we make changes, we will change the date at the beginning of this Policy. If we make material changes to this Privacy Policy, we will take reasonable efforts to notify individuals by email to their registered email address, by prominent posting on our Site, or through other appropriate communication channels. All changes shall be effective from the date of publication unless otherwise provided.