Privacy policy

Last updated: 2 June 2026

This policy explains how Hot Group Holdings Ltd ("HotHotels", "we", "us", "our") collects, uses and protects your personal data when you visit our website, create an account, or make a booking. It should be read alongside our Cookie policy and Terms of service.

HotHotels is the data controller for the personal data described here. Our registered office is 71–75 Shelton Street, Covent Garden, London WC2H 9JQ. We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.

1. The data we collect

We collect the following categories of personal data:

  • Identity and contact data: your name, email address, phone number and, where relevant, the names of additional guests on a booking.
  • Booking data: the hotels, dates, room types, guest numbers, special requests and references associated with your reservations.
  • Payment data: your billing address and the details needed to take payment. Card numbers are processed by our payment provider and are never stored on our own servers.
  • Account data: your login credentials and saved preferences, if you create an account.
  • Technical and usage data: IP address, device and browser type, and how you use the site, collected through server logs, cookies and analytics tools.
  • Communications: the content of messages you send us and our support correspondence with you.

2. How and why we use your data

We rely on the following legal bases under the UK GDPR:

  • To perform our contract with you (Article 6(1)(b)): to process and manage your bookings, take payment, send confirmations and updates, and provide customer support.
  • For our legitimate interests (Article 6(1)(f)): to operate, secure and improve our service, prevent fraud, and understand how the site is used, balanced against your rights.
  • With your consent (Article 6(1)(a)): to send marketing communications and to set non-essential cookies. You can withdraw consent at any time.
  • To comply with legal obligations (Article 6(1)(c)): for example accounting, tax and fraud-prevention requirements.

3. Who we share your data with

We do not sell your personal data. We share it only as needed to provide our service:

  • Hotel suppliers and the hotels themselves: to fulfil your booking we pass the necessary guest and stay details to the relevant wholesale supplier and on to the hotel.
  • Payment providers: our payment processor handles card payments securely on our behalf.
  • Service providers: trusted partners who help us run the site, including hosting, analytics, email and customer-support tools, acting on our instructions.
  • Professional advisers and authorities: where required by law, or to establish, exercise or defend legal claims.

4. International transfers

Because hotels and suppliers operate worldwide, fulfilling a booking may involve transferring your data outside the UK. Where we do this, we rely on an adequacy decision or appropriate safeguards (such as the UK International Data Transfer Agreement or Standard Contractual Clauses) to protect your data.

5. How long we keep it

We keep your personal data only as long as necessary for the purposes above. Booking and transaction records are retained for the period required by accounting, tax and supplier obligations (typically at least six years for financial records). Account data is kept while your account is active. We delete or anonymise data we no longer need.

6. Your rights

Under the UK GDPR you have the right to:

  • access a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to our processing;
  • data portability; and
  • withdraw consent at any time, where we rely on it.

To exercise any of these rights, contact our Data Protection Officer (details below). You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, though we'd ask you to contact us first so we can try to put things right.

7. Marketing

We only send marketing messages where you have agreed to receive them. You can opt out at any time using the unsubscribe link in any marketing email, or by contacting us. Opting out of marketing does not affect service messages about your bookings.

8. Cookies

We use cookies and similar technologies as described in our Cookie policy. You can manage non-essential cookies through our cookie controls and your browser settings.

9. Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls and PCI-compliant payment providers. No system is completely secure, but we work hard to safeguard your information and to notify you and the regulator of any breach where required.

10. Children

Our service is intended for adults aged 18 and over, and we do not knowingly collect personal data from children. Where a child is a guest on a booking, those details are provided by the adult making the reservation.

11. Changes to this policy

We may update this policy from time to time. The current version is always available here, with the "Last updated" date shown above. We will highlight material changes on the site.

12. Contact us

For any question about this policy or your personal data, contact our Data Protection Officer:

Data Protection Officer, Hot Group Holdings Ltd, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ. Email: privacy@hothotels.co