Last updated: 21 July 2026
Hotel Waitlist is a trading name of Waitlist Ltd, a company registered in England and Wales under company number 17010598. Our registered office is 23 Cranley Gardens, London, England, N10 3AA.
This Notice explains how we use personal information when you:
Privacy contact: privacy@hotelwaitlist.io
We act as a controller for information about our website visitors, prospective hotel clients, hotel account users, billing contacts and business communications.
When a participating hotel uses Hotel Waitlist to collect booking interest, send Guest communications and measure direct bookings, the Hotel normally acts as controller and Waitlist Ltd acts as its processor. The Hotel determines why Guest information is used, which communications are sent and how long Guest information should be retained.
The Guest collection form or message will identify the relevant Hotel and link to the Hotel's privacy notice. Guests should normally contact that Hotel to exercise their rights. We will assist the Hotel and can be contacted at privacy@hotelwaitlist.io.
Depending on how you interact with us, we may use:
Please do not submit health information, identification documents, payment-card details or other special-category information through the waitlist form.
We obtain information:
| Purpose | Information | Our role and usual basis |
|---|---|---|
| Respond to enquiries and demonstrations | Business contact and communication information | Controller; steps before contract and legitimate interests |
| Contract, account and billing administration | Hotel account, contract and invoice information | Controller; contract, legitimate interests and legal obligations |
| Operate Guest waitlists and requested follow-up | Guest contact details, preferences and communications | Processor on Hotel instructions; Hotel determines its lawful basis and PECR position |
| Attribute direct bookings and calculate Commission | Guest interaction, booking identifier/status and relevant revenue | Processor for the Hotel; controller for our invoice and legal records where necessary |
| Secure, support and troubleshoot the Service | Account, technical, log and communication information | Controller or Processor depending on context; legitimate interests, contract and security obligations |
| Improve Hotel-specific performance | Interactions, preferences and outcomes for that Hotel | Processor on Hotel instructions |
| Produce anonymous service statistics | Aggregated information that no longer identifies a Guest or Hotel | Not personal information once effectively anonymised |
| Send our own B2B communications | Business contact details and preferences | Consent or legitimate interests as applicable; PECR considered separately |
| Meet legal and regulatory duties | Relevant account, transaction, security and communication information | Legal obligation and legal claims |
Where we rely on legitimate interests, we assess the purpose, necessity and effect on individuals. You may object where the law provides that right.
A Guest who submits a Hotel waitlist form may request a notification about availability, the booking journey or an approved related offer. The Hotel is responsible for determining whether a message is a requested service communication or direct marketing and for satisfying the applicable UK GDPR and PECR requirements.
Marketing emails or texts are sent only where valid consent or another lawful PECR route applies. Marketing messages identify the sender and provide a simple way to opt out. We maintain suppression information so that opt-outs made through the Service are respected.
Hotel Waitlist may use automated analysis to help a participating Hotel select communication timing, subject lines and Hotel-approved offers that are more likely to be relevant. The analysis may use requested dates or preferences, previous message interactions and aggregated performance information.
This personalisation is intended to improve communications and direct-booking conversion. It is not intended to make decisions that produce legal or similarly significant effects for a Guest. The Hotel remains responsible for its availability, rates and offers.
Guests can object to direct marketing and related marketing profiling at any time by using the unsubscribe method in a message or contacting the Hotel.
Identifiable Guest information is not used to train a model across unrelated hotels unless the relevant Hotel has expressly enabled that use and a lawful, transparent basis has been documented. We may use effectively anonymised and aggregated statistics to improve the Service.
We use essential technologies needed for security, consent choices and core website or Service operation.
Non-essential analytics and marketing technologies are disabled until you make the required affirmative choice through the cookie banner. You can withdraw or change that choice through Cookie Settings.
The cookie manager must display an accurate current table containing each technology's name, provider, purpose, category and duration. Browser settings may also restrict cookies, although doing so can affect functionality.
On participating Hotel websites, the Hotel controls its consent manager and privacy information. Our tag is configured to respect the agreed consent signal.
We disclose information only where necessary to:
We do not sell Guest Personal Data or use it for unrelated third-party advertising.
Current Subprocessors used for Hotel Guest information are identified in the applicable Data Processing Addendum or Subprocessor register. We notify Hotel clients of relevant changes as stated there.
Where information is transferred outside the UK, we use a lawful transfer mechanism. Depending on the destination and circumstances, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the EU Standard Contractual Clauses together with the UK Addendum, or another permitted safeguard or exception. We carry out the assessment required by UK law and apply supplementary measures where appropriate.
Where EU GDPR also applies, we use a transfer mechanism recognised under that regime.
We keep information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and claims requirements.
The verified operational retention schedule is reflected in Hotel contracts and system configuration.
We maintain technical and organisational measures appropriate to the nature and risk of the information we use. These include measures relating to access control, secure transmission and storage, system monitoring, vulnerability management, incident response, business continuity and staff confidentiality.
No internet service is completely secure. Hotel clients can request further security information through the contracting process.
Subject to applicable conditions and exemptions, UK data-protection law may give you rights to:
If your request concerns a Hotel waitlist, contact the Hotel identified on the form or message. You can also contact privacy@hotelwaitlist.io and we will route or assist with the request.
We normally respond within one month after receiving a valid request. We may request information needed to confirm identity and may extend the period where the law permits.
ICO: https://ico.org.uk/make-a-complaint/ · Telephone: 0303 123 1113
The Service is intended for adult hotel bookers. We do not ask children to join a waitlist independently. A parent or guardian may provide occupancy information needed for a family booking, but should not provide unnecessary information about a child.
We may update this Notice to reflect changes in law, the Service or our use of information. We will update the date above and give additional notice where a change materially affects individuals.
Waitlist Ltd trading as Hotel Waitlist