Archived version — 28 May 2026
This is a frozen snapshot of our Privacy Policy kept for the bookings made while this version was in force. The current Privacy Policy is at /legal/privacy.
Privacy Policy
Last updated: 28 May 2026 · Effective: 28 May 2026
Who we are
local-hotel.com is operated by LOCALHOTEL LTD (company number 17229743), registered in England & Wales at 167-169 Great Portland Street, 5th Floor, London W1W 5PF. We're registered with the UK Information Commissioner's Office under registration number ICO_REGISTRATION_NUMBER. Contact: support@local-hotel.com.
What data we collect
- Account data — email, name, hashed password.
- Booking data — hotel choice, dates, guest count, price, refund status, supplier reference.
- Browsing data — searches, hotels viewed, wishlist, price alerts. Used to populate your account history.
- Technical data — IP address (rate-limiting, fraud), browser type, request timestamps.
Why we hold it (lawful basis)
- Contract performance — to fulfil bookings you make.
- Legitimate interest — to operate, secure, and improve the service.
- Consent — for non-essential cookies (see Cookie Policy).
- Legal obligation — accounting records (6 years), security incident response.
Who we share it with (sub-processors)
We pass a minimum subset of data to:
- LiteAPI — booking supplier. Receives guest name, dates, hotel, and a payment confirmation token when payment is taken via their hosted payment SDK. (DPA on file.)
- Hotelbeds — booking supplier. Receives guest name, dates, hotel, room type, and our internal client reference. Hotelbeds is a B2B wholesaler — payment is collected on our side and settled to them, so they never receive your card details. (DPA on file.)
- Stripe — payment processor (regulated by the FCA). Receives card details directly from your browser; we never see the full PAN. Stripe also stores a customer reference linked to your email when you buy a pass or subscribe. stripe.com/privacy.
- Resend — transactional email sender. Receives email address + message content (booking confirmations, password resets, etc.). DPA on file.
- Our hosting provider — to run the app and store data at rest.
- Goatcounter — privacy-first, cookieless web analytics. Receives a hashed IP address (one-way salt, rotated every 8 hours and never retained beyond that window) plus the page URL, referrer and user-agent string for each pageview. No cookies, no cross-site tracking, no profile-building. goatcounter.com/help/gdpr.
Each has a Data Processing Agreement with us. None sell your data. We'll update this list before adding any new sub-processor and email registered users 30 days ahead.
How long we keep it
- Account data: until you delete your account.
- Booking records: 7 years (UK accounting requirement).
- Browsing data (searches, viewed hotels): 12 months from last activity.
- Server logs: 90 days.
Your rights
Under UK-GDPR you have the right to:
- Access — download your full data via your account page (Article 15).
- Portability — export is a machine-readable JSON file (Article 20).
- Erasure — delete your account at any time. We will hard-delete all rows we hold. Confirmed bookings retained by suppliers (LiteAPI, Hotelbeds) and your Stripe customer record remain with those processors under their own DPAs — required for compliance, fraud prevention, and dispute handling (Article 17(3)(b) and (e)). Contact the supplier directly to request deletion from their side.
- Rectification — edit your name and email on your account page.
- Restriction / objection — email support@local-hotel.com and we'll action within 30 days.
- Complaint to the ICO — ico.org.uk if you're unhappy with how we handle your data.
International transfers
Some sub-processors (e.g. Resend) store data outside the UK. We rely on Standard Contractual Clauses + UK Addendum for those transfers, as required under UK-GDPR Article 46.
Marketing communications
We send transactional emails (booking confirmations, refund updates, password resets) as part of fulfilling your booking — these are not marketing and you cannot opt out while you hold an active booking with us, because we need to reach you about it.
We do not currently send marketing emails. If we begin to, we will ask for explicit opt-in consent first (PECR / UK-GDPR Art. 6(1)(a)) and every marketing email will carry a one-click unsubscribe link.
Automated decisions and profiling
We do not make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects (UK-GDPR Article 22). Rate-limit and fraud checks are advisory inputs to human review, not automatic account decisions.
Children
We don't knowingly collect personal data from anyone under 18. Account creation requires confirmation that you are 18 or older (see our Terms of Service). If we learn that we have collected data from a child, we will delete it.
If something goes wrong (incident notification)
If a personal-data breach is likely to result in a high risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware (UK-GDPR Article 33) and notify affected users without undue delay (Article 34). Our internal first contact in an incident is support@local-hotel.com.
Security
Passwords are hashed with bcrypt (cost factor 12). All traffic is HTTPS-only with HSTS preload. We use CSRF protection on all mutating endpoints, rate limiting on sensitive endpoints, and standard browser security headers (CSP, X-Frame-Options).
Changes
We'll email registered users 30 days before any material change to this policy. Minor wording fixes are pushed silently — see the "Last updated" date above.