top of page

Privacy Policy

Last Updated: June 2026

Sarah and Anna Rowden Ltd are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, store, process, and share your personal data when you visit our website, book a room, or stay at our hotel.

We operate as a Data Controller under the UK Data (Use and Access) Act 2026 and the UK General Data Protection Regulation (UK GDPR).

 

1. Information We Collect About You

To process your bookings and manage your stay via our integrated Zonal Property Management System (PMS), we collect:

  • Identity Data: Full name, title, date of birth, nationality, and passport or driving licence details (collected at check-in).

  • Contact Data: Email address, telephone number, and billing/home address.

  • Financial Data: Payment card numbers, expiry dates, and security codes.

  • Transaction Data: Details about payments to and from you, and services you purchased from our bar, restaurant, or room service.

  • Technical Data: IP address, browser type, and cookie data when you use our website booking engine. 

 

2. How and Why We Use Your Personal Data

Under the UK GDPR, we must have a "lawful basis" to process your data. We use your data for the following reasons:

  • To Perform a Contract: To process your online reservation, securely take payment, send confirmation emails, and manage your accommodation during your stay.

  • Legitimate Interests: To maintain hotel security, manage bar/restaurant room tabs via our Zonal EPoS system, and handle guest customer service queries.

  • Legal Compliance: To maintain a guest register of non-UK/Commonwealth citizens under the Immigration (Hotel Records) Order 1972, and for financial tax auditing.

 

How we collect your personal information 

We collect personal information about you (and others if their personal information is provided by you) when you:

  1. make or manage a booking either personally or as a guest of another guest;

  2. post material to our website or any social media, including our social media pages or accounts;

  3. complete customer feedback or surveys as part of your stay at our hotel

  4. raise a complaint or dispute with us or are involved in a legally recordable incident at our premises (e.g. in relation to health and safety reporting);

  5. participate in competitions or promotions;

  6. visit or use our website or customer applications in any other way; and

  7. to provide you with in-house services that you have requested.

Any personal information that we obtain from you directly is provided to us on a voluntary basis. However, if you do not give this information to us, you may be unable to make a booking or receive certain other services from us or our partners or communicate with us effectively. Some of the information we request is requested because we are required to request it by law (for example, your identification documents in certain circumstances), or because it is a requirement under our contract with you.

 

3. Data Security and Technology Partners

We take data security seriously. We do not store raw, unencrypted credit card details on our local servers.

  • Zonal PMS & EPoS: Your booking details and room bills are stored securely within our Zonal system, which utilizes industry-standard access controls.

  • Payment Tokenisation: Online transactions are processed using a fully secure, PCI-DSS compliant payment gateway integrated with Zonal. Your payment data is instantly encrypted and tokenised, ensuring we never see or store your full card details.

 

4. Who We Share Your Data With

We do not sell your personal data. We only share your data with trusted third parties necessary to run our business:

  • Technology Providers: Zonal (our PMS/EPoS platform) and our integrated payment gateway provider.

  • Professional Advisors: Our accountants, auditors, and legal representatives.

  • Law Enforcement: Government or regulatory authorities if strictly required by UK law.

 

5. How Long We Keep Your Data

We only retain your personal data for as long as necessary to fulfil the purposes we collected it for. By UK law, we must keep basic transactional and financial records (including contact, identity, and financial data) for 6 years after a transaction for tax purposes.

 

6. Your Legal Rights

Under the UK GDPR, you have rights regarding your personal information, including:

  • Access: The right to request a copy of the personal data we hold about you.

  • Correction: The right to ask us to rectify inaccurate information.

  • Erasure: The right to ask us to delete your data (where we do not have a legal obligation to keep it).

  • Object or Restrict: The right to object to us processing your data for specific reasons.

To exercise any of these rights, please contact us using the details below.

 

7. Contact Details and Complaints

If you have any questions about this Privacy Policy or how we handle your data, please contact our Data Protection Officer:

If you are unsatisfied with our response, you have the right to lodge a complaint at any time with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk).

8. Monitoring 

We record CCTV footage and date and time information when you pass as an area in which we operate CCTV surveillance for the safety of our employees and guests. We also use this data to detect and prevent fraud and other criminal  activities (and in relation to any CCTV footage containing criminal offence or health data, we rely on the corresponding condition for processing under relevant domestic law in ,line with the UK Data (Use and Access) Act 2026 and the UK General Data Protection Regulation (UK GDPR). 

bottom of page