Privacy Policy
Last updated: 28 May 2026 · Effective: 28 May 2026
Who we are
local-hotel.com is operated by LOCALHOTEL LTD (company number 17229743), registered in England & Wales at 167-169 Great Portland Street, 5th Floor, London W1W 5PF. We're registered with the UK Information Commissioner's Office under registration number ICO_REGISTRATION_NUMBER. Contact: support@local-hotel.com.
What data we collect
- Account data — email, name, hashed password.
- Booking data — hotel choice, dates, guest count, price, refund status, supplier reference.
- Browsing data — searches, hotels viewed, wishlist, price alerts. Used to populate your account history.
- Error reports — if you tell us something on a page looks wrong, we store your message, the page it was about, and (only if you choose to give them) your name and email, so we can come back with a question or say thanks. We keep a salted hash of your IP address — never the address itself — purely to stop abuse of the form. Reports are deleted once handled.
- Event price watches — if you ask us to watch hotel prices for an event, we store the email address you give us (no account needed) solely to send that one alert. Every alert email carries a one-click unsubscribe, and the watch deactivates itself after it fires or once the event has passed.
- Technical data — IP address (rate-limiting, fraud), browser type, request timestamps.
Why we hold it (lawful basis)
- Contract performance — to fulfil bookings you make.
- Legitimate interest — to operate, secure, and improve the service.
- Consent — for non-essential cookies (see Cookie Policy).
- Legal obligation — accounting records (6 years), security incident response.
Who we share it with (sub-processors)
We pass a minimum subset of data to:
- LiteAPI — booking supplier. Receives guest name, dates, hotel, and a payment confirmation token when payment is taken via their hosted payment SDK. (DPA on file.)
- Hotelbeds — booking supplier. Receives guest name, dates, hotel, room type, and our internal client reference. Hotelbeds is a B2B wholesaler — payment is collected on our side and settled to them, so they never receive your card details. (DPA on file.)
- Stripe — payment processor (regulated by the FCA). Receives card details directly from your browser; we never see the full PAN. Stripe also stores a customer reference linked to your email when you buy a pass or subscribe. stripe.com/privacy.
- Google — sign-in provider, when you choose it. If you use “Continue with Google”, or accept the optional one-tap prompt we may show when you go to book, Google issues us a signed token carrying your email address, name and profile picture, and Google learns that you visited this site. The one-tap prompt only appears if you accepted the Preferences cookie toggle; declining leaves the ordinary sign-in button, which loads nothing until you click it. policies.google.com/privacy.
- Resend — transactional email sender. Receives email address + message content (booking confirmations, password resets, etc.). DPA on file.
- Our hosting provider — to run the app and store data at rest.
- Goatcounter — privacy-first, cookieless web analytics. Receives a hashed IP address (one-way salt, rotated every 8 hours and never retained beyond that window) plus the page URL, referrer and user-agent string for each pageview. No cookies, no cross-site tracking, no profile-building. goatcounter.com/help/gdpr.
Each has a Data Processing Agreement with us. None sell your data. We'll update this list before adding any new sub-processor and email registered users 30 days ahead.
How long we keep it
- Account data: until you delete your account.
- Booking records: 7 years (UK accounting requirement).
- Browsing data (searches, viewed hotels): 12 months from last activity.
- Server logs: 90 days.
Your rights
Under UK-GDPR you have the right to:
- Access — download your full data via your account page (Article 15).
- Portability — export is a machine-readable JSON file (Article 20).
- Erasure — delete your account at any time. We will hard-delete all rows we hold. Confirmed bookings retained by suppliers (LiteAPI, Hotelbeds) and your Stripe customer record remain with those processors under their own DPAs — required for compliance, fraud prevention, and dispute handling (Article 17(3)(b) and (e)). Contact the supplier directly to request deletion from their side.
- Rectification — edit your name and email on your account page.
- Restriction / objection — email support@local-hotel.com and we'll action within 30 days.
- Complaint to the ICO — ico.org.uk if you're unhappy with how we handle your data.
International transfers
Some sub-processors (e.g. Resend) store data outside the UK. We rely on Standard Contractual Clauses + UK Addendum for those transfers, as required under UK-GDPR Article 46.
Marketing communications
We send transactional emails (booking confirmations, refund updates, password resets) as part of fulfilling your booking — these are not marketing and you cannot opt out while you hold an active booking with us, because we need to reach you about it.
We only email you about prices if you asked us to. There is an unticked box at sign-up, separate from accepting these terms, and leaving it unticked changes nothing about your account. If you tick it we record when you did and the exact wording you agreed to (PECR / UK-GDPR Art. 6(1)(a)).
That permission covers three things and nothing else: price drops in places you follow, the cities you search for when something worth knowing changes there, and now and then what people have actually paid through the site. No general mailing list, no third-party advertising, and nothing sold or shared. Every one of those emails carries a one-click unsubscribe, and you can change your mind on your account page at any time.
Price watching is its own thing and needs an account. When you ask us to watch a price, the alert you get is the service you asked for rather than marketing, so it is sent whether or not you ticked the box above — and it stops when you stop watching.
Automated decisions and profiling
We do not make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects (UK-GDPR Article 22). Rate-limit and fraud checks are advisory inputs to human review, not automatic account decisions.
Children
We don't knowingly collect personal data from anyone under 18. Account creation requires confirmation that you are 18 or older (see our Terms of Service). If we learn that we have collected data from a child, we will delete it.
If something goes wrong (incident notification)
If a personal-data breach is likely to result in a high risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware (UK-GDPR Article 33) and notify affected users without undue delay (Article 34). Our internal first contact in an incident is support@local-hotel.com.
Security
Passwords are hashed with bcrypt (cost factor 12). All traffic is HTTPS-only with HSTS preload. We use CSRF protection on all mutating endpoints, rate limiting on sensitive endpoints, and standard browser security headers (CSP, X-Frame-Options).
Changes
We'll email registered users 30 days before any material change to this policy. Minor wording fixes are pushed silently — see the "Last updated" date above.