H Hotel Waitlist
  • Benefits
  • How It Works
  • Pricing
  • About
Get Started

Privacy Notice

Last updated: 21 July 2026

1. Who we are

Hotel Waitlist is a trading name of Waitlist Ltd, a company registered in England and Wales under company number 17010598. Our registered office is 23 Cranley Gardens, London, England, N10 3AA.

This Notice explains how we use personal information when you:

  • visit hotelwaitlist.io;
  • contact us or book a demonstration;
  • represent a hotel using Hotel Waitlist; or
  • join a participating hotel's waitlist or receive a Hotel Waitlist communication.

Privacy contact: privacy@hotelwaitlist.io

2. Our role

We act as a controller for information about our website visitors, prospective hotel clients, hotel account users, billing contacts and business communications.

When a participating hotel uses Hotel Waitlist to collect booking interest, send Guest communications and measure direct bookings, the Hotel normally acts as controller and Waitlist Ltd acts as its processor. The Hotel determines why Guest information is used, which communications are sent and how long Guest information should be retained.

The Guest collection form or message will identify the relevant Hotel and link to the Hotel's privacy notice. Guests should normally contact that Hotel to exercise their rights. We will assist the Hotel and can be contacted at privacy@hotelwaitlist.io.

3. Information we use

Depending on how you interact with us, we may use:

Hotel and business-contact information

  • hotel and legal-entity name;
  • name, role, business email address and telephone number;
  • account credentials and user permissions;
  • contract, invoice and payment-status information;
  • implementation, integration and support communications;
  • dashboard usage and security logs.

Guest information processed for a Hotel

  • name, email address and telephone number where enabled;
  • requested arrival/departure dates;
  • room, occupancy, rate or offer preferences;
  • the Hotel and booking journey in which interest was expressed;
  • emails or other communications sent, delivered, opened or clicked;
  • opt-in, objection and suppression records;
  • booking reference, coupon/tracking code or pseudonymous identifier;
  • direct-booking date, stay dates, booking status and relevant room revenue;
  • attribution events connecting a Hotel Waitlist interaction to a direct booking;
  • IP address, browser, device and technical tag/event information where lawfully collected.

Please do not submit health information, identification documents, payment-card details or other special-category information through the waitlist form.

Website and demonstration information

  • pages viewed and interactions with our site;
  • browser, device, IP address and approximate location derived from IP;
  • cookie and consent choices;
  • information submitted through contact or demonstration forms.

4. Where information comes from

We obtain information:

  • directly from you;
  • from the participating Hotel;
  • through the Hotel Waitlist tag or form on a Hotel website;
  • from communications sent through the Service;
  • from a Hotel's booking engine or property-management integration;
  • from our website, account and support systems.

5. How and why we use information

PurposeInformationOur role and usual basis
Respond to enquiries and demonstrationsBusiness contact and communication informationController; steps before contract and legitimate interests
Contract, account and billing administrationHotel account, contract and invoice informationController; contract, legitimate interests and legal obligations
Operate Guest waitlists and requested follow-upGuest contact details, preferences and communicationsProcessor on Hotel instructions; Hotel determines its lawful basis and PECR position
Attribute direct bookings and calculate CommissionGuest interaction, booking identifier/status and relevant revenueProcessor for the Hotel; controller for our invoice and legal records where necessary
Secure, support and troubleshoot the ServiceAccount, technical, log and communication informationController or Processor depending on context; legitimate interests, contract and security obligations
Improve Hotel-specific performanceInteractions, preferences and outcomes for that HotelProcessor on Hotel instructions
Produce anonymous service statisticsAggregated information that no longer identifies a Guest or HotelNot personal information once effectively anonymised
Send our own B2B communicationsBusiness contact details and preferencesConsent or legitimate interests as applicable; PECR considered separately
Meet legal and regulatory dutiesRelevant account, transaction, security and communication informationLegal obligation and legal claims

Where we rely on legitimate interests, we assess the purpose, necessity and effect on individuals. You may object where the law provides that right.

6. Guest messages and PECR

A Guest who submits a Hotel waitlist form may request a notification about availability, the booking journey or an approved related offer. The Hotel is responsible for determining whether a message is a requested service communication or direct marketing and for satisfying the applicable UK GDPR and PECR requirements.

Marketing emails or texts are sent only where valid consent or another lawful PECR route applies. Marketing messages identify the sender and provide a simple way to opt out. We maintain suppression information so that opt-outs made through the Service are respected.

7. AI optimisation and profiling

Hotel Waitlist may use automated analysis to help a participating Hotel select communication timing, subject lines and Hotel-approved offers that are more likely to be relevant. The analysis may use requested dates or preferences, previous message interactions and aggregated performance information.

This personalisation is intended to improve communications and direct-booking conversion. It is not intended to make decisions that produce legal or similarly significant effects for a Guest. The Hotel remains responsible for its availability, rates and offers.

Guests can object to direct marketing and related marketing profiling at any time by using the unsubscribe method in a message or contacting the Hotel.

Identifiable Guest information is not used to train a model across unrelated hotels unless the relevant Hotel has expressly enabled that use and a lawful, transparent basis has been documented. We may use effectively anonymised and aggregated statistics to improve the Service.

8. Cookies, tags and similar technologies

We use essential technologies needed for security, consent choices and core website or Service operation.

Non-essential analytics and marketing technologies are disabled until you make the required affirmative choice through the cookie banner. You can withdraw or change that choice through Cookie Settings.

The cookie manager must display an accurate current table containing each technology's name, provider, purpose, category and duration. Browser settings may also restrict cookies, although doing so can affect functionality.

On participating Hotel websites, the Hotel controls its consent manager and privacy information. Our tag is configured to respect the agreed consent signal.

9. Sharing information

We disclose information only where necessary to:

  • the participating Hotel;
  • authorised personnel and contractors;
  • hosting, communications, support, security and billing providers acting under contract;
  • booking-engine or property-management providers used by the Hotel;
  • professional advisers, insurers, auditors or prospective business purchasers subject to appropriate duties; or
  • regulators, courts or public authorities where legally required.

We do not sell Guest Personal Data or use it for unrelated third-party advertising.

Current Subprocessors used for Hotel Guest information are identified in the applicable Data Processing Addendum or Subprocessor register. We notify Hotel clients of relevant changes as stated there.

10. International transfers

Where information is transferred outside the UK, we use a lawful transfer mechanism. Depending on the destination and circumstances, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the EU Standard Contractual Clauses together with the UK Addendum, or another permitted safeguard or exception. We carry out the assessment required by UK law and apply supplementary measures where appropriate.

Where EU GDPR also applies, we use a transfer mechanism recognised under that regime.

11. Retention

We keep information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and claims requirements.

  • Guest information is retained according to the participating Hotel's documented configuration or instructions and is deleted or returned after the Service ends, subject to limited legal, backup and suppression records.
  • Contract, invoice and transaction records are retained for the period required by applicable company, tax and limitation laws.
  • Support and security records are retained according to their operational and risk requirements.
  • Consent and suppression records may be retained as necessary to demonstrate and respect communication preferences.
  • Effectively anonymised statistics may be retained because they no longer identify an individual.

The verified operational retention schedule is reflected in Hotel contracts and system configuration.

12. Security

We maintain technical and organisational measures appropriate to the nature and risk of the information we use. These include measures relating to access control, secure transmission and storage, system monitoring, vulnerability management, incident response, business continuity and staff confidentiality.

No internet service is completely secure. Hotel clients can request further security information through the contracting process.

13. Your rights

Subject to applicable conditions and exemptions, UK data-protection law may give you rights to:

  • be informed about use of your information;
  • obtain access and a copy;
  • correct inaccurate information;
  • request deletion or restriction;
  • receive certain information in a portable format;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing and related profiling;
  • withdraw consent without affecting earlier lawful processing; and
  • raise a concern with the Information Commissioner's Office.

If your request concerns a Hotel waitlist, contact the Hotel identified on the form or message. You can also contact privacy@hotelwaitlist.io and we will route or assist with the request.

We normally respond within one month after receiving a valid request. We may request information needed to confirm identity and may extend the period where the law permits.

ICO: https://ico.org.uk/make-a-complaint/ · Telephone: 0303 123 1113

14. Children

The Service is intended for adult hotel bookers. We do not ask children to join a waitlist independently. A parent or guardian may provide occupancy information needed for a family booking, but should not provide unnecessary information about a child.

15. Changes

We may update this Notice to reflect changes in law, the Service or our use of information. We will update the date above and give additional notice where a change materially affects individuals.

16. Contact

Waitlist Ltd trading as Hotel Waitlist

  • Company number: 17010598
  • Registered office: 23 Cranley Gardens, London, England, N10 3AA
  • Privacy contact: privacy@hotelwaitlist.io

Privacy Notice · Terms of Service · UK Data Protection & Security · Cookie Settings

© 2026 Waitlist Ltd trading as Hotel Waitlist. All rights reserved. Company No. 17010598.