Digital Audit - Hyatt Hotels Corporation
Domain: Digital (Digital / Technology nexus) Entity scope: Hyatt Hotels Corporation (NYSE: H; Chicago; Delaware-incorporated), an asset-light hotel management and franchise company. Hyatt’s own technology acts are in scope. Individual hotel owners/franchisees and the controlling Pritzker family’s separate ventures are attributed to those owners/franchisees/family ventures, not Hyatt-corporate. Directionality: the serious case is Hyatt providing technology/data to the Israeli state (not a hotel operator’s activity); Hyatt procuring from Israeli-domiciled vendors is a weaker customer-side relationship and is recorded as such. Only genuinely Israeli-domiciled vendors count as Israeli-origin; Israeli-founded but foreign-domiciled firms are flagged. Compiled: 2026-06-27 Method: Live web search (≈22 queries) against Hyatt and vendor press, SEC filings, hotel and CX trade press, NICE case-study material, Who Profits, and travel-industry reporting. No model training data.
Enterprise Technology Stack & Vendor Relationships
Hyatt’s documented core enterprise systems run on US- and European-origin platforms, with one current Israeli-domiciled vendor in the contact-centre layer.
In September 2024 Hyatt selected Oracle OPERA Cloud (Oracle, US) as its global property-management system, migrating over 1,000 hotels onto Oracle Cloud Infrastructure1. Its central reservation system is Sabre SynXis (Sabre, US), selected in July 2023 to replace Hyatt’s proprietary “Reserve” platform; Sabre’s Hospitality Solutions unit, which includes SynXis, was sold to the private-equity firm TPG in 2025, after Hyatt’s contract was in place23. Guest messaging runs on Medallia Zingle (Medallia, US), deployed across more than 1,000 properties from February 20224; cloud infrastructure on Amazon Web Services (US)5; and CRM on Salesforce (US) alongside Hyatt’s proprietary “Envision” platform6. (A prior draft’s claim of a 2020 Hyatt–Amadeus distribution agreement could not be verified in live search and is not carried forward.)
The one Israeli-domiciled vendor identified is NICE Ltd (Ra’anana, Israel; incorporated in Israel, dual-listed NASDAQ/TASE), which supplies Hyatt’s global contact centre. This relationship is current and documented: NICE published a Hyatt CXone case study in December 2025 (CXone Expert knowledge management and CXone Copilot across 250+ agents in the Americas), and Hyatt received NICE’s “AI Trailblazer of the Year” award in June 202578. This is a customer-side procurement of commercial contact-centre and workforce-engagement software from an Israeli vendor - Hyatt is the customer; there is no evidence of Hyatt providing technology or data to NICE or to any Israeli state body, and no documented nexus between this commercial contract and Israeli military or state-surveillance activity. (A prior draft recorded the NICE link as an unverified 2019 marketing reference; live evidence supersedes that as a confirmed, current relationship.)
No public evidence was identified of any Hyatt relationship with the US-domiciled, Israeli-founded firm Verint, or with the Israeli-domiciled/Israeli-founded vendors Check Point, Wiz, CyberArk, or Claroty9.
Surveillance, Biometrics & Retail Technology
Hyatt’s guest privacy policy states it may collect biometric information on a consent basis subject to applicable law, including the Illinois Biometric Information Privacy Act10. The one identified biometric vendor is Daon (its VeriFLY mobile health pass, adopted in March 2021 for COVID-era documentation), an Irish-American company (Fairfax, VA / Dublin) - not Israeli11. No public evidence was identified of Hyatt deploying any Israeli-origin facial-recognition or video-analytics vendor (Oosto/AnyVision, BriefCam, Corsight) at its properties, nor of Israeli-origin predictive-analytics, social-media-monitoring, or workforce-surveillance tooling; Hyatt’s documented analytics (Medallia, cloud platforms) are oriented to guest experience and revenue management45.
Cloud Infrastructure, Data Residency & Sovereign Cloud Participation
Hyatt operates no hotels in Israel and no public evidence was identified of Hyatt operating, leasing, or co-locating data-centre infrastructure there12. Hyatt is a hospitality operator, not a cloud or infrastructure provider, and is not a party to Project Nimbus - the Israeli government cloud contract held by Amazon Web Services and Google. That Hyatt is an AWS customer does not connect it to AWS’s separate Israeli-government work513. No public evidence was identified of Hyatt providing data-sovereignty or resilience services to any state institution. Hyatt does not publish a GDPR Article 28 sub-processor list, so any Israeli-origin sub-processor within its stack is not identifiable from public records - an evidence gap.
Defence, Intelligence & Security Sector Technology Relationships
No public evidence was identified of any contract, partnership, or service agreement between Hyatt and the Israeli Ministry of Defence, the IDF, or Israeli intelligence agencies. Hyatt is a hospitality operator, not a technology vendor; no instance was identified of Hyatt-deployed technology being repurposed for military, intelligence, or law-enforcement surveillance in Israel or the occupied territories, and Hyatt develops no offensive-cyber or weapons capability. The directionally serious Digital case - provision of technology or data to the Israeli state - is not present.
AI, Algorithmic & Autonomous Systems
No public evidence was identified of Hyatt providing AI, machine-learning, or autonomous decision-support systems to any Israeli state, military, or security body. Hyatt’s documented AI/analytics activity is commercial - guest personalisation, revenue management, and the NICE CXone Copilot/Expert tooling in its contact centre57. No public evidence was identified of Hyatt AI/ML models being trained on civilian-surveillance, biometric, or intelligence datasets from Israel or the occupied territories; autonomous or lethal systems are outside Hyatt’s business.
Technology Ecosystem & R&D Footprint
No public evidence was identified of Hyatt operating any R&D facility, innovation lab, or accelerator in Israel; its technology functions are US-headquartered. Hyatt’s material acquisitions - Apple Leisure Group (2021, US), Two Roads Hospitality (2018, US/Asia-Pacific), and Mr & Mrs Smith (2023, UK booking platform) - involve no Israeli-origin technology1415. No strategic investment in Israeli technology startups or venture funds, and no patent, licensing, or co-development arrangement with Israeli research institutions (Technion, Hebrew University, Weizmann), was identified.
Civil Society Scrutiny & Regulatory History
A site-restricted search of the Who Profits database returned no dedicated Hyatt Hotels Corporation company entry; Hyatt appears only in passing within another company’s profile, not as a subject company16. No technology-grounds BDS or divestment campaign targeting Hyatt was identified (the only organised boycott history is a Unite Here labour dispute unrelated to Palestine)17. Hyatt’s documented technology-related regulatory history consists of two payment-card data breaches (2015 and 2017, malware on hotel payment systems), neither with any identified Israel nexus1819. No export-control, BIS, or OFAC action involving Hyatt technology procurement or services in connection with Israeli state entities was identified.
End Notes
Footnotes
-
https://www.oracle.com/news/announcement/hyatt-selects-opera-cloud-property-management-system-global-properties-2024-09-17/ ↩
-
https://investors.sabre.com/news-releases/news-release-details/hyatt-selects-sabre-enhance-central-reservation-system ↩
-
https://www.hoteldive.com/news/sabre-sells-hospitality-solutions-tpg/746619/ ↩
-
https://www.businesswire.com/news/home/20220203005166/en/Medallia-Zingle-Brings-Real-Time-Guest-Engagement-Platform-to-More-Than-1000-Hyatt-Properties-Globally ↩ ↩2
-
https://aws.amazon.com/solutions/case-studies/hyatt-hotels-case-study/ ↩ ↩2 ↩3 ↩4
-
https://www.destinationcrm.com/Webinars/936-Hyatt-Hotels-Corporation-Transforms-the-Customer-Experience-with-Customer-Data-Management.htm ↩
-
https://www.nice.com/press-releases/nice-announces-cx-excellence-award-winners-at-interactions-2025-showcasing-powerful-results-in-ai-driven-customer-service-automation ↩
-
https://world.hyatt.com/content/gp/en/privacy/guest-policy.html ↩
-
https://www.biometricupdate.com/202103/hyatt-adopts-daons-biometric-health-pass-cozera-launches-digital-wallet ↩
-
https://www.business-humanrights.org/en/union-campaign-calls-for-global-boycott-of-hyatt-hotels-cites-health-safety-concerns ↩
-
https://abcnews.go.com/Technology/hyatt-reveals-data-breach-impacted-250-hotels/story?id=36315368 ↩
-
https://krebsonsecurity.com/2017/10/hyatt-hotels-suffers-2nd-card-breach-in-2-years/ ↩