Effective July 10, 2026. This statement explains the privacy responsibilities that would apply to Bellwether House as a fictional independent hotel concept. The demo does not transmit reservations, payments, contact messages or newsletter sign-ups. Any production operator must publish its own notice based on the systems, partners and laws that actually apply to its business.
Privacy is part of hospitality. A guest should understand what information is requested, why it is needed, who receives it and how long it remains in use. A production service should collect only what is reasonably necessary, protect it throughout its life cycle and provide practical ways for people to exercise their choices.
SCOPE OF THIS STATEMENT
This statement covers information associated with the hotel website, reservation inquiries, guest stays, event or group requests, on-property services, feedback and ordinary business administration. It also describes the responsibilities attached to service providers acting for the hotel, such as reservation technology, payment processing, communications, property operations and security support.
A different notice may apply when a guest chooses to use an independent travel agency, payment wallet, transportation provider, social platform or other third-party service. Those organizations decide how they handle information within their own services. A production hotel should identify the point at which a guest leaves its service and should avoid presenting an outside provider as though it were operated by the hotel.
INFORMATION A GUEST PROVIDES
Information may be supplied when a guest asks about availability, makes or changes a reservation, checks in, requests an amenity, joins a waitlist, submits a message, responds to a survey or arranges a group stay. The exact fields should reflect the request being made rather than a standard demand for every possible detail.
A production operator should explain when a field is required and when it is optional. Sensitive requests, including access needs, dietary needs or other stay preferences, should be recorded only when they are useful for delivering the requested service and should be visible only to staff or providers who need them.
- Identity and contact details, such as name, preferred form of address, mailing address and communication details.
- Stay details, such as arrival and departure dates, room choice, party size, requests and reservation history.
- Payment and transaction details handled through an authorized payment service, including billing status and limited card metadata.
- Preference information voluntarily shared to make a stay more comfortable, such as pillow, room location, dietary or accessibility requests.
- Messages, feedback, survey responses and records of assistance requested from a reservations or guest-services host.
- Business information needed for group stays, event inquiries, invoices, travel coordination or contracted rates.
INFORMATION COLLECTED DURING A STAY
A hotel may create operational records while preparing for and providing a stay. These can include room readiness, key issuance, service delivery, maintenance requests, incident reports, lost-property records and charges posted to a folio. The record should remain factual, limited to the operational purpose and available only to people responsible for that work.
Where a property uses access control, fraud prevention or security systems, the operator should describe the categories of information involved, the areas covered and the applicable retention period. Monitoring should be proportionate to a documented safety purpose and should not extend into spaces where a guest reasonably expects privacy.
A guest may choose to share a preference that is useful on a future visit. A production hotel should distinguish durable preferences from notes needed only for one stay, give staff guidance on respectful wording and provide a way to correct or remove information that is no longer useful.
WEBSITE AND DEVICE INFORMATION
When a production website is requested, standard technical records may include the page visited, date and time, browser or device type, language, referring page, general network information and diagnostic events. These records help deliver pages, balance traffic, diagnose failures and protect the service from misuse.
Approximate location may be inferred from network information at a broad city or regional level. Precise device location should not be requested unless a guest deliberately uses a feature that needs it and receives a clear explanation at the time of the request.
Technical records should not be combined with guest profiles merely because the systems make that possible. A production operator should document which identifiers are essential for security and service delivery, which are optional for measurement and when each category expires.
HOW INFORMATION IS USED
Information should be used for stated hospitality and business purposes. Each purpose should have an accountable owner, a suitable legal basis where one is required and a retention rule connected to the work rather than to indefinite future value.
- Answer availability questions and prepare, confirm, modify or cancel reservations.
- Verify identity where appropriate and support arrival, departure, payment and folio administration.
- Prepare rooms, amenities, access arrangements and other services specifically requested by a guest.
- Communicate material information about a stay, including changes, service interruptions and safety notices.
- Maintain accounting, tax, chargeback and other records required for responsible business administration.
- Protect guests, staff, property and systems; investigate suspected fraud, misuse or security incidents.
- Respond to complaints, accessibility feedback, lost-property reports and requests concerning personal information.
- Measure service quality and website reliability using information reduced to the least identifying form practical.
- Train staff and improve procedures using examples that have been de-identified whenever individual identity is unnecessary.
- Meet lawful obligations and establish, exercise or defend legal claims when reasonably necessary.
RESERVATIONS AND PAYMENT SERVICES
A production reservation flow may rely on specialist providers to display inventory, manage rates, confirm bookings and process payments. The hotel remains responsible for choosing providers carefully, limiting the information sent to them and describing their role in language a guest can understand before information is submitted.
Payment card numbers should be entered directly into a compliant payment service and should not be copied into email, free-text notes or general support systems. Hotel staff should receive only the result and reference information needed to reconcile a transaction, manage a deposit or address a disputed charge.
If a booking begins with a travel advisor or independent booking platform, the hotel may receive the reservation details selected by that provider. The hotel should use those details to deliver the stay and should not assume that permission granted to the booking platform also authorizes unrelated hotel marketing.
COOKIES AND LOCAL STORAGE
Cookies and similar browser storage can remember a session, preserve a security choice, maintain a reservation step or measure whether the website is functioning. A production site should separate essential technologies from optional analytics or advertising technologies and should not load optional categories before the visitor has made the required choice.
Cookie controls should be easy to find after the first visit. Declining an optional category should be as straightforward as accepting it, and changing a choice should not require a person to identify themselves. Browser settings may provide additional controls, although blocking essential storage can prevent a reservation session from working correctly.
- Essential storage supports security, load balancing, accessibility preferences and the steps of a requested transaction.
- Measurement storage helps understand page performance and broad usage patterns when configured to minimize identifiers.
- Preference storage remembers choices such as language or interface settings for a limited period.
- Advertising storage, if ever used, requires a separate explanation, an appropriate choice and contracts that prohibit unrelated reuse.
COMMUNICATION PREFERENCES
Messages necessary to administer a reservation are service communications rather than promotional messages. A guest may still receive confirmation, change, cancellation, payment or safety information needed for the requested stay even when promotional messages are declined.
Promotional email or text should be sent only where the operator has an appropriate basis and a clear record of the choice. Every promotional message should identify the sender and provide a working way to unsubscribe. Preference changes should be honored promptly across the systems responsible for future campaigns.
A request to stop marketing should not erase the minimum suppression record needed to prevent the address from being added again. That record should be used only to respect the choice, not as a route to continued profiling.
WHEN INFORMATION IS SHARED
Information should not be sold as an unrelated asset. It may be disclosed in limited circumstances to complete a guest request, operate the property, comply with law or protect legitimate interests. A production operator should maintain an accurate list of provider categories and review whether each provider still needs the information it receives.
- Reservation, property-management and guest-service providers that support the requested stay.
- Payment, accounting and fraud-prevention providers responsible for authorized transactions and financial records.
- Technology, hosting, security and communications providers working under written instructions and confidentiality duties.
- Professional advisers, insurers and auditors when access is necessary for a defined engagement.
- Public authorities or other parties when disclosure is lawfully required or necessary to address a serious safety or security concern.
- A successor organization involved in a genuine business transaction, subject to appropriate confidentiality and continuity safeguards.
SERVICE PROVIDER RESPONSIBILITIES
Providers acting for the hotel should receive written instructions describing the permitted purpose, security expectations, retention period, incident reporting duties and rules for engaging additional providers. Access should be limited by role and reviewed when responsibilities change.
The operator should conduct proportionate diligence before introducing a provider and should revisit that review when the service, data categories or processing location changes. A recognizable vendor name is not a substitute for understanding how the service is configured and whether optional data uses have been disabled.
When a provider receives a privacy request or identifies a security incident involving hotel information, it should notify the operator without unnecessary delay and preserve the information needed for a complete response.
PURPOSE AND LEGAL BASIS
A production operator should connect each use of information to a recognized basis under the law that applies. Fulfilling a reservation may be necessary to provide the requested stay; accounting records may be required by law; security monitoring may support a legitimate interest that has been assessed against the effect on guests; and some optional communications may depend on consent.
The basis should be selected before the information is used, documented in the operator's internal records and reflected consistently in guest-facing explanations. Consent should not be presented as a condition for a service when the optional use is unrelated to that service, and withdrawing consent should be possible without affecting uses that remain necessary for an existing reservation or legal duty.
When relying on a legitimate interest, the operator should identify the purpose, consider whether a less intrusive method would work and record safeguards that reduce the effect on individuals. That assessment should be revisited when the data, audience, technology or expected outcome changes.
ACCURACY AND RESPONSIBLE NOTES
Guest information should be accurate enough for the work it supports. Staff should confirm material reservation details at appropriate moments, correct known errors and distinguish a fact supplied by the guest from an operational observation or unresolved concern.
Free-text notes require particular care because they can travel across shifts and systems without their original context. Notes should be objective, respectful, relevant to a defined service or safety need and removed when that need ends. Speculation, diagnoses, personal judgments and details unrelated to hospitality operations do not belong in a guest record.
Where an automated rule influences fraud review, room assignment or another meaningful decision, the operator should test the information used by the rule, provide human review where appropriate and offer a practical route to correct an inaccurate result.
AGGREGATED AND DE-IDENTIFIED INFORMATION
A hotel may use totals and trends to plan staffing, understand room demand, reduce service failures or evaluate website performance. Whenever individual identity is unnecessary, the information should be aggregated or de-identified before analysis and access should be limited to the result needed for the decision.
De-identification is a process, not a label. The operator should remove direct identifiers, consider whether unusual combinations could still identify a guest, restrict attempts to reverse the process and reassess the risk before sharing a small or detailed data set.
Information that can reasonably be linked back to a person remains within the privacy program even if a name has been removed. A production notice should not describe pseudonymous identifiers as anonymous when the operator or a provider retains the key needed to reconnect them.
BUSINESS CHANGES
If ownership or operation of the hotel changes, information may need to transfer so reservations can be honored and essential records can continue. Before a transfer, the parties should limit access to people evaluating or completing the transaction, apply confidentiality duties and exclude information that is not necessary for continuity or lawful diligence.
The successor should receive a clear description of existing guest choices, retention limits and unresolved requests. A business change does not automatically authorize a new marketing purpose or remove commitments made when the information was collected.
Where required, guests should be told who is responsible after the change and how to direct questions or exercise rights. If the proposed use is materially different, the successor should provide a new explanation and obtain any choice required before that use begins.
SECURITY AND CONFIDENTIALITY
No system can promise absolute security. A responsible program combines technical, physical and organizational safeguards suited to the sensitivity and volume of the information. Controls should include access management, secure configuration, encryption where appropriate, logging, tested backups, staff training and a documented incident response process.
Staff access should follow job responsibilities and should end promptly when it is no longer needed. Shared accounts and exports to personal devices should be avoided. Sensitive information should not be placed in free-text fields when a protected, purpose-built field is available.
Security events should be assessed by people with authority to contain the issue, determine what information was affected, meet notification duties and correct the underlying weakness. Lessons from an incident should result in updated controls rather than a temporary workaround.
DATA RETENTION
Information should be kept only for the period connected to the purpose for which it was collected. Reservation and financial records may require a defined legal or accounting period, while a declined inquiry, temporary service note or website diagnostic record may need a much shorter period.
A production operator should maintain a retention schedule covering active systems, archives, exports and backups. When a record reaches the end of its period, it should be deleted, securely destroyed or irreversibly de-identified unless a documented legal hold requires preservation.
Retention should not be extended simply because storage is inexpensive. Longer retention increases the effect of mistakes and security incidents and makes it harder to give an accurate account of where information remains.
YOUR PRIVACY CHOICES
Depending on the relationship and applicable law, a person may ask the production operator to take action concerning personal information. The operator should publish a reliable request channel, explain any limits and respond within the required period. A request should not result in discriminatory service or a different price unless a lawful program clearly permits it.
- Confirm whether personal information is being handled and request access to eligible information.
- Correct information that is inaccurate or incomplete.
- Request deletion where no retention duty or other permitted exception applies.
- Receive eligible information in a portable form or ask that it be transferred where available.
- Object to or restrict particular uses in circumstances recognized by applicable law.
- Withdraw consent for a future use when consent is the basis for that use.
- Opt out of promotional communications and manage optional cookie categories.
VERIFYING AND RESPONDING TO REQUESTS
The operator may need enough information to confirm that a request concerns the correct person and records. Verification should be proportionate to the sensitivity of the request; it should not demand a copy of an identity document when a less intrusive method is adequate.
An authorized representative may submit a request where permitted. The operator may ask for evidence of authority and may confirm the request directly with the person unless the law provides otherwise. Information supplied for verification should be used only to process and document the request.
If a request cannot be completed, the response should explain the reason, identify any appeal or complaint route and describe the portions that can still be fulfilled. Requests and outcomes should be logged so the operator can identify recurring failures in its systems or procedures.
COMPLAINTS AND ACCOUNTABILITY
A privacy complaint should reach a person with enough authority and system access to investigate it. The review should identify what happened, which records and providers were involved, whether an immediate correction is possible and whether the same issue could affect other guests.
The response should acknowledge the concern, explain the outcome in accessible language and identify any internal appeal or external complaint route that applies. The operator should avoid requiring a guest to repeat sensitive details to multiple departments merely because responsibilities are divided internally.
Metrics such as overdue requests, repeated corrections, provider incidents and unresolved preference changes should be reviewed by management. Accountability means using those results to change contracts, training, interfaces or procedures when the current control is not working.
CHILDREN'S INFORMATION
The website and reservation services should be directed to adults arranging travel. A production hotel should not knowingly create a marketing profile for a child. Details about a child that are necessary for occupancy, safety or a requested family service should be supplied by the responsible adult and used only for that purpose.
If information has been collected from a child in a way that is inconsistent with the service or applicable law, the operator should investigate promptly and delete or correct the record as appropriate.
INTERNATIONAL PROCESSING
Hotel systems and specialist providers may operate in more than one jurisdiction. Before transferring information, a production operator should identify the destination, determine whether a recognized transfer mechanism is required and apply contractual and technical safeguards appropriate to the risk.
A guest should be able to learn the general location categories involved and how to ask about the safeguards used. Cross-border processing does not reduce the operator's responsibility to honor the notice and respond to valid requests.
CHANGES TO THIS STATEMENT
A production statement should be reviewed when systems, partners, uses or legal obligations change. The effective date should be updated when a revision is published. Material changes should be explained prominently and, where required, presented before the new use begins.
Archived versions should be retained so the operator can determine which notice applied at a particular time. An update should not be used to claim permission for an unrelated use of information already collected.
QUESTIONS AND CONTACT
This local concept does not receive or store privacy requests. In a production release, the operating hotel would identify the legal entity responsible for the information, provide a monitored privacy contact and list any regulator or appeal route required by applicable law.
Questions should be answered in clear language and routed to people who can investigate across reservation, property, payment and communications systems. A complete response is more useful than directing a guest from one vendor to another.