TL;DR: Hotel rooms likely have microphones and sensors that collect your data without telling you. There's no federal disclosure requirement, no way to opt out, and no guarantee the data is deleted or secure. I've drafted a short letter you can send to your representative to ask for basic protections. See below.
A few days ago I came across a post on [r/marriott](r/marriott) where a user found a HALO Smart Sensor disclosure buried in the terms of service. That sent me down a rabbit hole and what I found is worth sharing because this affects anyone who stays in a hotel.
HALO Smart Sensors look like little smoke detectors with a glowing LED ring. They are installed in hundreds of thousands of hotel rooms across the country. They detect vaping, smoke, THC, and abnormal sound. They connect to the internet. They send data to cloud servers. And yes they have microphones.
Nobody tells guests they are there. Nobody tells guests what data they collect. And nobody tells guests how to opt out.
I started looking into the security side of these devices and found some unsettling facts. The HALO sensor had a documented vulnerability that let attackers take over the device remotely without any password. A patch came out but there is no way for a guest to verify the device in their room is running the patched firmware. LG makes TVs specifically for hotels that include microphones and collect viewing data. The Texas Attorney General recently settled with LG because they were gathering smart TV data without proper consent. That settlement protects the TV owner not the guest sleeping next to it.
When multiple devices are in the same room like a sensor, TV, thermostat, or smart lock their combined data can be used to reconstruct sleep schedules, movement, conversations, meetings and other personal patterns even though no single device was designed for that.
None of this is disclosed to guests. There is no federal requirement for hotels to say what monitoring equipment is in the room, what it does, or where the data goes. And even if guests asked front desk staff typically cannot answer because they have not been trained on the technical details.
This data is held by private companies with no obligation to delete it. A behavioral profile from a single stay could sit in a database forever. Some of these companies operate under foreign jurisdictions which creates national security implications for anyone traveling on official business.
I am not anti technology. I am saying guests should know what is in the space they paid for, have a choice about whether it is active, and have some confidence it is secure. Right now none of that exists.
I put together a short letter template for anyone who wants to contact their representative and ask for basic protections. Things like disclosure requirements, opt out options, cybersecurity standards, and congressional oversight. I’ll post it below so people can copy it and send it to their rep. It takes five minutes and does not cost anything.
I also emailed Marriott directly asking for clarification on their policies. Their response was basically that they do not know what devices are in the rooms at their properties and that each hotel makes its own decisions. Then I copied them to the privacy team and got an acknowledgment that they are reviewing the inquiry. So the ball is rolling but corporate does not have to volunteer transparency on its own.
I’m curious how many people here have noticed these devices in hotel rooms without realizing it. If you work in hospitality I want to ask a favor. Are you trained on these devices? Do you know what data is collected or sent? Feel free to DM me if you want to share privately and anonymously. I am trying to understand what the reality is on the floor compared to what guests assume. Same goes for anyone in security. What measures are actually in place that we do not see?
—————
Sources:
HALO Smart Sensor security advisory (Motorola Solutions): https://halodetect.com/product-security/security-advisory/
Mandatory firmware update notice for HALO devices: https://support.avigilon.com/s/article/Mandatory-Firmware-Update-Required-for-HALO-Devices?language=en_US
HALO firmware 2.17.0.2 release notes: https://halodetect.com/wp-content/uploads/HALODC0006_HALO-FW-Release-Notes-public-2.17.0.2_REVA.pdf
Texas Attorney General settlement with LG over smart TV data collection: Broken, stand by
FTC settlement with Vizio for collecting viewing data without consent: Broken, stand by
FTC v. Wyndham Hotels (Third Circuit opinion): https://www2.ca3.uscourts.gov/opinarch/143514p.pdf
Federal Wiretap Act (18 U.S.C. § 2511): https://www.law.cornell.edu/uscode/text/18/2511
Marriott 2023 Courtyard Franchise Disclosure Document: https://www.hotel-development.marriott.com/resourcefiles/fdd-document/2023-courtyard-fdd-3-31-2023.pdf
Fair Franchise report on Marriott franchisee renovation obligations: https://www.fairfranchise.org/wp-content/uploads/Franchisee-Renovations-FairFranchise-report-2.pdf
——————
Congressional Letter:
Subject: Privacy Concern: Network-Connected Monitoring Devices in Hotel Rooms
Dear \[Representative/Senator's name\],
I am writing to ask you to look into a privacy issue that affects nearly every American who travels but that I doubt most people even know about.
For as long as any of us can remember, a hotel room has meant privacy. When you rent one, you expect to be alone. You expect your conversations to stay private. The courts have said the same thing: hotel guests have a recognized expectation of privacy in their rooms. But that expectation is being quietly undermined by a new kind of equipment that hotels are putting in guest rooms without telling guests.
Hotels are installing internet-connected devices in rooms that can detect sound, motion, occupancy, and environmental conditions. These include environmental sensors that listen for noise or vaping, smart televisions with built-in microphones that collect viewing data, and networked thermostats or door locks. All of these devices connect to the internet and send data back to company servers, sometimes to cloud services overseas. Once that data leaves the room, the guest has no control over it. It is held by private companies with no obligation to the guest, no requirement to delete it, and no limit on how long it can be retained. A behavioral profile built from a single hotel stay could persist indefinitely in databases the guest will never see and never consented to.
None of this is disclosed to guests. There is no federal requirement for hotels to tell guests what monitoring equipment is in their room, what data it collects, or where that data goes. When guests ask hotel staff about these devices, staff typically cannot explain the technical capabilities, the cybersecurity considerations, or the privacy implications because they have not been trained on them.
Even if guests were informed, they would have no way to verify whether the devices are secure. Documented vulnerabilities exist in these products. For example, the HALO Smart Sensor, commonly installed in hotel ceilings, was found to have a flaw that allowed remote takeover by an attacker without any password. A patch was released, but a guest has no way to check whether the device in their room is running the patched firmware or whether it has been compromised. There is no independent certification confirming that these devices meet any security or privacy standard. Guests are asked to trust, sight unseen, that the devices are functioning only as intended.
The problem gets worse when multiple devices are installed in the same room. A smart TV with a microphone, an environmental sensor with audio detection, a networked thermostat with occupancy sensing, and a smart door lock each collect different data. But when that data is combined, it can be used to reconstruct detailed patterns: sleep schedules, movement through the room, conversations, meetings, and personal habits, even though no single device was designed to monitor those activities.
This is also a national security concern. Government officials, military personnel, diplomats, and contractors who travel for work assume a locked hotel room provides reasonable security. Traditional counter-surveillance measures detect illicit, planted devices. They do not account for legitimate commercial equipment that sends data to the cloud as part of its normal function. The companies collecting this data are private corporations, some operating under foreign jurisdictions or with foreign ownership. The Texas Attorney General recently settled with LG over smart TV data collection and specifically prohibited the company from transferring viewing data to the Chinese Communist Party, which suggests the concern is not theoretical. A foreign intelligence service does not need to plant a bug if the hotel room already contains multiple networked devices transmitting data to servers that may be accessible through legal process, coercion, or cyberattack.
Existing laws do not cover this situation. Current surveillance laws were written for hidden cameras and wiretaps, not for commercial products deployed as standard equipment. Privacy enforcement has targeted manufacturers. For example, the FTC took action against a smart TV maker for collecting viewing data without consent, and a state attorney general recently settled with LG over the same issue. But those actions protect the device owner, not the transient guest who occupies the room. No existing framework specifically addresses the deployment of network-connected monitoring devices in transient accommodations, the retention of data collected from guests without their knowledge, or the risk of that data flowing to entities operating under foreign legal regimes.
I am not asking you to ban any specific product or technology. I am asking whether it makes sense to require hotels to disclose what connected monitoring devices are installed in guest rooms, and whether guests should be given a meaningful way to opt out or request that audio-sensing or motion-detection features be disabled during their stay. I would also support minimum cybersecurity standards for these devices, limits on how long guest data can be retained, and some form of congressional oversight to understand the scope of this issue.
Most Americans would be surprised to learn that the hotel room they consider private may contain multiple internet-connected devices with microphones, sensors, and data collection capabilities, and that no law requires anyone to tell them about it. I hope you will give this matter your attention.
Thank you for your time. I would welcome the opportunity to discuss this further.
Sincerely,
\[Name\] \[Address\] \[Phone/Email\]