Privacy Policy

Effective 24 September 2026 · Version 2026-09-24

This policy explains how [Company legal name] ("we") collects and uses personal data when you use onwardhotel.io. We are the controller of your personal data. We process it in line with the EU General Data Protection Regulation (GDPR), the UK GDPR and other applicable data protection laws, including the California Consumer Privacy Act (CCPA) where it applies.

1. Data we collect

2. Why we use it and our legal basis

PurposeLegal basis
Creating and holding your Reservation, sending the confirmation, voucher and service emails, managing your accountPerformance of a contract
Taking payments, managing subscriptions, refunds and disputesPerformance of a contract; legal obligation (accounting)
Preventing fraud and misuse, securing the serviceLegitimate interests
Measuring and improving the site with aggregated statisticsLegitimate interests
Keeping records required by tax and accounting lawLegal obligation

We don't sell your personal data, and we don't use it for automated decisions that have legal or similarly significant effects on you.

3. Who we share it with

Our service providers process data only on our instructions and under written data processing terms.

4. International transfers

Hotels, our Supplier and service providers may be located outside your country, including outside the EEA/UK. Where we transfer personal data to a country without an adequacy decision, we use safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. Contact us for a copy.

5. How long we keep it

6. Your rights

Depending on where you live, you have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. California residents have the right to know, delete and correct personal information and not to be discriminated against for exercising these rights; we do not sell or share personal information for cross-context behavioural advertising. To exercise any right, email [email protected]. We reply within one month. You may also complain to your data protection authority (for us, [Lead supervisory authority]).

7. Cookies

We use only strictly necessary cookies. See our Cookie Policy.

8. Security

We use encryption in transit (HTTPS), hashed sign-in codes, access controls and payment processing by a PCI DSS Level 1 certified provider. No system is completely secure; we will notify you and the authorities of a personal data breach where the law requires.

9. Children

The service is not intended for anyone under 18, and we don't knowingly collect their data. A Reservation for a travelling minor must be made by a parent or guardian.

10. Changes

We will post any changes here and, if they are significant, notify account holders by email.

11. Contact

[Company legal name], [Registered office address]. Data protection enquiries: [email protected].