Last updated: 21 July 2026
Waitlist Ltd trading as Hotel Waitlist provides technology to Hotels that captures expressed booking interest, sends Hotel-approved follow-up and attributes direct bookings. Our privacy programme is designed around the UK GDPR, Data Protection Act 2018 and PECR. EU GDPR applies where the relevant processing falls within its territorial scope.
This page is an operational overview. The Privacy Notice explains use of information, and the binding Data Processing Addendum governs Guest information processed for Hotel clients.
| Context | Waitlist Ltd's usual role |
|---|---|
| Hotel account, billing and contract contacts | Controller |
| Visitors to hotelwaitlist.io and demonstration enquiries | Controller |
| Security and legal-compliance records | Controller |
| Guest waitlist and communication data used for a Hotel | Processor; Hotel is Controller |
| Hotel-specific attribution analytics | Processor, except limited invoice/legal records |
| Effectively anonymised service statistics | Outside data-protection law once individuals cannot be identified |
The exact role depends on the facts. It is documented during Hotel onboarding.
We distinguish a message expressly requested by a Guest from direct marketing. Marketing email, SMS or similar communication is sent only where the responsible Hotel has identified and documented a valid PECR route, such as valid consent or every condition of an applicable soft opt-in. Messages identify the sender and provide an opt-out where required.
The Service can analyse booking preferences, communication engagement and outcomes to recommend or select timing, subject lines and Hotel-approved offers. This is intended to improve relevance and booking conversion and is not intended to make a decision with legal or similarly significant effects on a Guest.
Property-specific learning is performed for the relevant Hotel. Identifiable Guest information is not used for cross-property learning unless expressly configured and supported by a documented lawful, transparent basis. Effectively anonymised and aggregated performance statistics may be used to improve the Service.
We assess new high-risk AI or profiling uses before deployment and support objections to direct-marketing profiling.
Each Hotel agreement includes Article 28 terms covering:
The applicable DPA version must be presented and recorded when a Hotel accepts the Service.
We use contracted providers only where needed to supply functions such as infrastructure hosting, message delivery, support, security and billing. Each provider that Processes Guest information is bound by data-protection obligations appropriate to its role, and we remain responsible as required by the DPA.
Hotel clients receive a current, versioned Subprocessor list and notice of relevant changes. The public list shows each verified legal entity, purpose, processing location and transfer mechanism.
We identify restricted transfers and use a mechanism permitted under UK GDPR, such as UK adequacy regulations, the UK IDTA, or EU SCCs combined with the UK Addendum. We complete the applicable transfer risk/data protection assessment and apply supplementary measures where required. EU transfer requirements are addressed separately where EU GDPR applies.
Our security programme addresses:
Detailed controls are available to Hotel clients through appropriate due diligence. Public claims about protocol versions, encryption algorithms, penetration testing, MFA, certifications and hosting regions are made only when supported by current evidence.
We maintain an incident-response process. Where we act as Processor, we notify the affected Hotel without undue delay after becoming aware of a Guest Personal Data Breach and provide available information and reasonable assistance. The Hotel is responsible for Controller notifications, with our support.
Guests should normally contact the Hotel identified on their form or message because it is the Controller. Requests sent to privacy@hotelwaitlist.io are routed or supported appropriately. We assist Hotels with access, correction, deletion, restriction, portability, objection and consent-withdrawal requests as required by the DPA.
Guest information follows the Hotel's documented retention configuration or instructions. We delete or return it when the Service ends, subject to limited legal, security, backup and suppression requirements. Controller records such as contracts and invoices follow applicable legal and claims periods.
Privacy contact: privacy@hotelwaitlist.io
Waitlist Ltd, company number 17010598
23 Cranley Gardens, London, England, N10 3AA
The UK supervisory authority is the Information Commissioner's Office:
We use the title Privacy Contact for privacy@hotelwaitlist.io. We will identify a Data Protection Officer only if Waitlist Ltd formally appoints one under UK GDPR.