Your personal information allows us to provide the products and services you have asked for, as well as enabling us to improve those products and services by understanding your interests and preferences. By understanding what you like (and what you don't) we are able to personalise your experience, show relevant adverts and improve your stay.
Grange Hotels ("we", "our", "us") is the data controller when you provide information to any of the hotels listed on www.grangehotels.com
When you interact with our products and services we collect information about you and that particular interaction. Generally this may include:
- Your personal details
- Contact information, and preferences
- Sensitive information, for example when you tell us about dietary requirements, disabilities, and religious beliefs
- Information about your use of our hotels, and other services when you stay with us
Images of you in areas of our hotels covered by CCTV
- We use CCTV in our properties for the purposes of safety and crime detection and monitoring. We only store the information collected by CCTV for a period of time which allows us to assist regulatory bodies and law enforcement agencies. This information is kept in secure environments and access is restricted to qualified security personnel.
- We have signs in place at main entry points informing people that CCTV is in operation and images are being monitored and recorded for the purposes of crime prevention and public safety
- Conversations you have when you call our reservations or sales teams
- Information about anyone you're travelling with or meeting, if that information is provided to us
- Information about the devices you use to interact with us
- Where you provide information to us about other people, you need to make sure you have their permission to do so.
In the course of providing services to you, we may collect information that could reveal your racial or ethnic origin, physical or mental health, or religious beliefs. Such information is considered “sensitive personal data” under GDPR and other data protection laws. We only collect this information where you have given your explicit consent, it is necessary, or you have deliberately made it public.
For example, we may collect this information in the following circumstances:
- If you request special assistance during a stay, this could reveal information about your health (for example if you ask for a wheelchair). If you inform us about specific dietary requirements you may have, this could potentially indicate that you have specific religious beliefs or food intolerance or allergies. Also, when you provide us with your travel document details, your nationality may imply your racial or ethnic origin.
If you do not allow us to process any sensitive personal data, this may mean we are unable to provide all or parts of the services you have requested from us.
We collect information you provide to us directly and indirectly when interacting with our products and services, including when you stay with us.
1. You provide information directly to us
This may include when you:
- Book a room online, over email or on the phone
- Create, use or manage an online account
- Sign up to our loyalty programmes
- Visit our website or use our apps
- Fill out our online forms or registration cards
- Visit our hotels or use our hotel services, like room service or gym and spa facilities
- Access hotel internet
- Use our restaurants/bars
- Use social media login functionality
- Interact with us in online forums, by email, text, or on social media
- Post reviews of your stay or interaction with us
- Complete our market research/customer surveys
- Enter competitions or promotions
- Requests, complaints and/or disputes
2. You provide information via our processors
There may be situations where we use data processors - companies who act on our behalf - to collect your information for us. These processors can only use your information in accordance with our instructions and for the purposes in this Policy.
3. You provide information via our websites and partner websites
4. You provide information via Travel agents and partners
We collect information about you when it is provided to us by third parties. This might include online travel agents, travel websites, and other partners. This could be when you make bookings, review your stay online, or where you interact with anyone who promote our brands. You should always read the privacy policies of travel companies or other third parties you use, as they will use your information in accordance with their own privacy policies.
When you, or someone on your behalf, make a booking using travel agent, booking platform or other third party to use our services, they may pass us information about your booking, including information about anyone else on that booking. The same would be true where you use a third party to make enquiries about our products or services.
Where you interact with third parties who promote our services for us, these third parties may pass us your information.
When you post comments, reviews, or engage in discussions and polls about our products and services, we may receive this information from the platform you interacted with or from our partners who monitor how our brands are performing.
We may also obtain information about you from our partners and other companies that have your permission to share your information both online and offline, like insight providers.
Sometimes we may want to improve our products and services by getting a better understanding about our customers and their preferences. In these situations we may ask reputable insight providers to provide us information that may identify you. However, this would only be where you have specifically consented to that third party providing your information to us.
Where we do receive information about you from other sources, we may combine it with information we already hold about you and use it in accordance with this Policy.
We may receive updated information about you from organisations that provide services to you. For example, we might be updated if you move home so that we can keep our records up to date or receive updated bank details to ensure that you can continue to use our products and services. Alternatively, we may be updated if your flight is late, so that we can anticipate your arrival more accurately.
The reason we use your information will often be obvious from the way you interact with us. For example, if you book a room at one of our hotels, we would use that information to administer your stay with us. However, our uses of your information may not always be so obvious. You can find out more below. When you provide your information to us, we may use it to:
Use of Personal Information
Legal basis for processing (Where there is more than one, the exact grounds will depend on the activity – Click links to see the section above for an explanation of each)
- Provide you with the products and services you have requested, including administering your booking, responding to any enquiries, complaints or requests you may have C, LI, A
- To manage our relationship with you C, LI, A
- Allow you to participate in loyalty programmes C, LI, A
- Send you market research surveys C, LI
- Tailor our service to your preferences, where you tell us about them C, LI, A
- Make decisions about what direct marketing to show you based on how you have interacted with us LI
- Improve our products and services online and offline, including our websites and apps LI
- Allow you to interact with us online and offline, in forums, on social media and elsewhere C, LI, A
- Monitor the use of our products and services and content LI, LO
- Verify your identity LI, A
- Provide linked services, like joint promotions with partners C, LI, A
- Conduct analysis, system testing and statistical research LI, LO
- Comply with legal obligations on us LI, LO
- Detect ad blockers and other technologies that affect the services we provide C, LI, A
- Manage our hotels efficiency, including regulating the use of utilities, lighting and heating, based on occupancy LI
- Send you product or service related communications, service messages C, LI, A, LO
- Send you direct marketing, where you have consented C, LI
- Allow social sharing functionality C, LI, A
- Keep guests safe and ensure the security of our hotels LI, LO
- Conduct data matching and audience insight activities LI
- Detect ad blockers LI
- Ensure the acceptable use of our services LI, LO
- Facilitate payments and credit checks C, LI, A, LO
- Facilitate the restructuring or sale of all or part of our business C, LI, A, LO
- Investigate and respond to disputes C, LI, LO
- Provide you with help and support where it may be required. For example, we contact you to provide assistance if you do not complete the booking process or experience technical difficulties, where we have your contact details LI, A
Legal Basis For Using Your Information
All organisations need a legal reason to use your personal information. We are conscious of our legal responsibilities as a “data controller” and we shall endeavour to ensure that the personal information we obtain and use will always be held, used, transferred and otherwise processed in accordance with our legal obligations. If we don't have a reason, we can't use your personal information. There are a number of legal grounds that enable data processing. It's quite complicated but below are the most relevant grounds you should be aware of.
(C) With your consent
(A) To fulfil a contract
We also process your personal information in order to fulfil a contract we have with you. For example, when you book a stay with us, we will process your information to administer that stay.
(LI) For a legitimate interest
Sometimes we may use your information to help achieve our business objectives but only where that activity doesn't negatively affect your rights. For example, we might use your information to analyse occupancy rates of our hotels and adjust room rates.
(LO) To comply with legal obligations
There may be situations where we need to use your information to comply with legal obligations. For example, we are required by law to keep records of who is in our hotels in case there is an emergency, so we can make sure you're safe.
Similarly, CCTV footage are recorded and retained for at least a month to prevent crime, to comply with licensing requirements and to enhance personal safety.
The company is required to obtain the name, addresses, contact details and dates when guests use the restaurants, food and beverage and bar facilities. This information is being collected to assist the NHS Test and Trace service for tracing close recent contacts of anyone testing positive for corona virus. It will be given to NHS Test and Trace on request in the event that it is required for contact tracing purposes. Collected information will be securely stored at the premises and destroyed within a period of eight weeks. We will not use this information for any other purpose, including direct marketing.
We sometimes make decisions about what your interests are based on the way that you interact with us and the information we hold about you, this is called profiling. For example, if you regularly stay at a particular hotel or frequently choose a specific room or pillow type, then we might use this information to improve your experience by pre-selecting certain features of your stay for you, so you don't need to. Understanding your preferences and personalising your experience in this way allows us to deliver the very best service possible.
Our websites are designed to respond to “Do not track signals” of user’s browser/device settings.
In addition to sending you information about the products and services you use (product communications) and in-life communications while you stay with us, where we have your permission we may send you direct marketing communications about our products, services, events and offers, as well as those of our commercial partners that we think you'll be interested in.
Direct marketing communications may be sent by post, email, telephone, SMS and MMS, through social media (such as Whatsapp, Instagram, Twitter, and Facebook), messages including push notifications to your mobile devices, and via other electronic means such as when you visit our websites or use our apps. This may also include any websites and apps of our partners who are in our advertising networks.
We may send you direct marketing while you have an ongoing relationship with us and for a reasonable time after you have used one of our products or services.
You will be able to opt-out of direct marketing by following the instructions in the communications you receive or changing your device settings. Alternatively, where you have an account with us, you will be able to log-in and change your marketing preferences.
Product related communications and in-life updates
We may use your information to send you newsletters, bulletins, and other in-life communications (about your stay), and triggered communications where you make changes to your account or other information about products and services you have signed up for.
For example, we may send you email or text messages about an upcoming stay with us in order to help you plan your visit and give you the best experience possible. You'll be able to opt-out of these.
Service communications will be sent to you regarding products and services you interact with. These are important messages relating to the products and services we provide to you.
Data matching and audience insights
Sometimes we may compare our customer database with our commercial customers or partners databases either directly with each other or by using an independent third party. This helps us understand if customers are on both databases, and allows us to plan joint marketing activities, and promotions. Additionally, we may match databases for business planning/continuity purposes.
We may use marketing permissions we hold to contact those customers for promotions that relate to data matching exercises.
We will only share personal information for data matching purposes where we have an agreement in place with the commercial customer or partner. This ensures that they comply with their data protection obligations, protect the information we share and limit the use of any shared information.
We may provide commercial customers and partners with information about the effectiveness of campaigns they run and as well as the potential reach of future campaigns by providing aggregated reports of customer segments. This is called audience insights and helps us plan promotions and other marketing campaigns. Your personal information is not shared for this activity.
We may use your information to improve the products and services we offer. For example, we may look at the preferences our guests have when they stay with us to offer more relevant personalisation to customers.
When you visit our websites we may check (by using script, code, cookies or other technical means) if you are using ad-blocker or other privacy tools. If we do detect one of these tools, we may ask you or ask your browser to ask you, if you would give us permission to ignore those settings and continue to serve adverts and/or collect your information using cookies and similar technologies.
Information about your device and use of ad blockers may be stored or associated with your device and used to reinsert adverts and to understand how ad blockers and other privacy tools are being used by our visitors.
Our website may, from time to time, contain links to other websites which are outside of our control and are not covered by this Policy. Please note that we are not responsible for the collection, use, maintenance, sharing or disclosure of data and information by such parties. We do not accept any responsibility or liability for other sites' privacy policies. If you access other websites using the links provided, we encourage you to read the privacy policies of websites you visit before submitting any personal information.
Grange Hotels strive to protect the privacy of the information that you share with us. We have undertaken reasonable efforts to implement security measures designed to protect all data we collect against unauthorised access. We utilise the industry standard security measures available through your browser, so that it is unlikely that your information can be read as it travels over the Internet.
Unfortunately, no data transmission over the internet can be guaranteed to be 100% secure. As a result, although we strive to protect your information, we cannot ensure or warrant the security of the information that you submit to us via the Site and you do so at your own risk. We also implement measures to protect your personal information off-line.
If we provide a service that is dependent on age or residency we have an obligation to verify relevant information. Where relevant, we may pass your information to a third party for this purpose.
Your information may be used to take payment for products and services and may be used to verify credit details, related to payments. Currently, we do not take card details over the telephone or by email, instead guests are requested to either use our secure link or make payment via bank transfers.
Your information will be disclosed where we are obliged by law to do so. We may also disclose your information where we are allowed by law to protect or enforce our rights or the rights of others and for the detection and prevention of crimes, such as fraud.
If you post or send offensive or inappropriate content anywhere on or to any of our websites or apps, or otherwise engage in disruptive behaviour on any of our websites or apps, we may use the information that is available to us about you to stop such behaviour. This may involve responding to or informing relevant third parties and law enforcement agencies about the content and your behaviour.
When you complete our registration forms or use our services, we may transfer your information to our processors - companies that carry out activities on our behalf, only on our instructions - outside the European Economic Area (EEA) to countries that may not have data protection rules that provide the same level of protection to your personal information as countries in the EEA. However, we will only transfer your information if we have appropriate measures in place to ensure the protection of your information in accordance with applicable data protection legislation.
When you give us information about other individuals, you confirm that you have authority to act for them and have made them aware of the potential transfer of their information outside the EEA.
If you contact us by phone or on chat the conversation may be recorded and listened to for training and quality purposes.
Our websites and apps provide plug-ins to social media websites, including Facebook, Twitter, Google, Yahoo and LinkedIn.
If you make use of, or log-in to, the social media features on our websites or apps, we may (depending on your privacy settings) access, use and store information about you, including, but not limited to: your name, e-mail address, gender, location, profile, picture, contacts, and any other information you have chosen to make available.
Where you provide your information to us we may share it with our group companies and affiliates, advertising networks and partners, commercial partners (including but not limited to owners of hotel businesses we manage or to whom we have licensed a brand and/or hotel system), and sharing with our suppliers.
What sharing takes place will depend on the activity that your information is being used for. Your information will only be shared and used in accordance with this Policy and where an agreement is in place to ensure that your information is protected. We won't sell your personal information without your consent
1. Sharing with advertising partners
When you visit our websites or apps we may pass information about you and any devices you are using to our advertising network partners to enable them to deliver relevant adverts and tell advertisers that adverts have been delivered and seen.
2. Sharing with our processors
There may be situations where we use data processor companies who act on our behalf to process your information for us. These processors can only use your information in accordance with our instructions and for the purposes in this Policy.
3. Sharing with commercial partners
We may share your information with third parties for their own purposes, including direct marketing, where we have told you about this and you have given permission. As above, this may include sharing information with owners of hotel businesses we manage and/or to whom we have licensed a brand and/or hotel systems.
4. Sale of our business
If we restructure or sell all or part of our business or business operations, we may transfer your information as part of that activity, including, but not limited to, where we transfer or cease to manage (or license the use of a brand) at a hotel. Where this is the case your information will be used in accordance with this Policy unless you are notified otherwise.
1. Updating your information
If you have an online account with us, please ensure that the information you provide (e.g. any contact information) is correct and that you review and update it regularly. Alternatively, you can tell us when you check-in that your information has changed and we will update it for you.
2. Controlling direct marketing
A customer may allow Grange Hotels to provide them with information about products and services that Grange Hotels, or third parties that Grange Hotels have selected, which may be of interest to them. Grange Hotels will only do this where a customer has agreed to receive such information. You agree to receive marketing information:
- From Grange Hotels about our products and services by choosing not to opt-out on your registration form for a Grange Hotels website or service.
- From Grange Hotels about similar products and services where you provide your details in the course of purchase or negotiations for the purchase of a product or service.
- From third parties about their products and services by choosing to opt-in on your registration form for a Grange Hotels website or service.
3. Controlling other communications
You can control the communications you receive from us, such as product related communications, by logging into your account, by following the instructions in any relevant communication.
4. Controlling profiling
If you would like to opt-out of profiling, you can do this in your account preferences or by contacting us using the details below or by updating your preferences in your account, where this feature is available.
If you would prefer not to have your information used for data matching purposes you can contact us using the details below.
1. Requesting copies of your information
You may request a copy of your personal information which we may hold about you. You may also ask us to correct any such personal information which you think is incorrect and incomplete. This right may be restricted by law where disclosing information may result in the personal information of other individuals being disclosed and it would be unreasonable to do so.
2. Withdrawing consent
Where we may rely on consent to use your information, you have the right to withdraw that consent for that processing activity at any time. However, we may have the right to rely on an alternative legal basis for the processing activity and will inform you of that.
If you do withdraw consent we may not be able to provide you with the product or service you have requested.
1. Your rights
Under GDPR, you may have the right to object, erase, or restrict our processing of your information - for example, where we process your personal information because this is in our legitimate interests, you may object to this. We will carefully consider your request as there may be circumstances which require us to, or allow us to, continue processing your data.
The request must be in writing and must contain the following:
- Your name and postal address.
- Details of your request.
Any details which may help us locate the information which is the subject of your request, for example:
- Booking reference and dates.
- GH Rewards membership number.
You must also provide:
- A professionally certified copy of your passport or driving licence, so that we can verify your identity.
- Your signature and the date of the request.
- If you are applying on behalf of another person then signed authority from the individual or the organisation is required.
Please send your request to:
Data Protection Officer
58 Rochester Row London UK SW1P 1JU
2. Personal information from Children
We do not provide services to children, nor do we market to children. We do not knowingly collect personally identifiable information from children under 18 without permission from a parent or guardian. If you are a parent or legal guardians and think that your child under 18 has given us information, you can contact us at email@example.com
3. GDPR – The fees to access the personal data
We must provide a copy of the requested information free of charge. However, we can charge the requestor a 'reasonable fee' when a request is manifestly unfounded, mischievous, vexatious, specious or excessive, particularly if it is repetitive.
We may also charge a reasonable fee to comply with requests for further copies of the same information. This does not mean that we can charge for all subsequent access requests.
The fee will be based on the administrative cost of providing the information.
4. Complaining to the regulator
If you have any comments, concerns or complaints about our usage of your information we would ask that you contact us first, so that we can try and resolve any matter.. However, where we are unable to assist, you are able to complain to the Information Commissioner's Office in the United Kingdom or the data protection regulator in your country of residence, who will be able to liaise with the UK Information Commissioner in the UK.
5. Retention of your information
We will retain your information for as long as necessary for the uses set out in this Policy or while there is a legitimate business reason for doing so. We will destroy your personal information as early as practicable and in a way that the information may not be restored or reconstructed. If you ask us to delete your information before this time, we may not be able to do so for technical, legal, regulatory or contractual constraints. For example, where you wish to be suppressed from direct marketing, we would need to retain your information for this purpose.
Where you ask for your account to be closed, we will do this as soon as possible subject to any terms and conditions relating to the account. Your information will be retained in order to comply with legal and regulatory obligations as well as for analysis, to prevent fraud, collect any monies owed, and to resolve disputes.
You can search for and review postings about job opportunities on our Careers page. However, to apply for a position, you must navigate and review the privacy statement specific to that website.
We would like to inform you that Grange Hotels are being managed by Globalgrange Limited. If you have made a booking at one or more of these hotels or have recently made an enquiry, a copy of your customer data has now been transferred for further communication purposes to Globalgrange Limited, registered in England and Wales with company registration number 01503192.
Your right of access, rectification or removal of your personal data from Globalgrange Limited's database at any time remain upheld, and you may do so by simply sending a written request to DPO, Globalgrange Limited, 58 Rochester Row, London, UK, SW1P 1JU.
However, we will retain your personal data in order to facilitate any bookings you might wish to make in the future at any of our hotels. Personal data will continue to be processed by us in accordance with this Policy
What are cookies?
What cookies do we use?
1. Essential cookies
These make our websites work. They remember what dates you want to stay with us, what sort of room you want and that you are logged in to your account. They also allow us to collect information about your use of our websites and apps, enabling us to improve the way they work. Analytics cookies also allow us to see if there are any technical issues on our websites and if you are experiencing any issues using our websites. They also allow us to look at usage statistics and performance.
We use Google Analytics to help us understand how you use our services. For more information on Google Analytics, please visit Google's website.
- Cookie List; __utma; __utmb; __utmc; __utmz; _ga; GALX; GAPS;
Other Cookies; guest_id; original_referer; external_referer; .twitter.com (these cookies are created by Twitter. In this case they are present because a Twitter widget or button is being used on the Grange Hotels website)
2. Functional cookies
These cookies collect information about the language you have requested the site display content in, remembering your username so you can log-in more quickly, text size, location you are in and generally allow us to customise your experience. Nobody likes having to repeat themselves and these cookies help with that.
- Cookie list: Session; cart; cwn; cbt
3. Tracking and advertising cookies and similar technologies
We use these types of cookies and similar technologies to provide adverts that we think may be more relevant to your interests. This can be based on your browsing activity and is known as Online Behavioural Advertising or OBA. Cookies are placed on your browser, which remembers what websites you've been to. Advertising based on what you have been viewing is then displayed.
4. Web beacons and tracking pixels
These technologies help us to count users on a web page, and see if a cookie has been activated. They allow us to see how popular content is and if an email has been delivered to a recipient, opened and links clicked on. We use this information to track how successful campaigns have been.
5. Flash cookies
Sometimes we may use flash players to deliver special content, such as video clips. This uses Local Shared Objects or flash cookies to remember settings.
6. Device Fingerprinting
Sometimes we may use a device's browser information to identify that device, conduct analysis, help detect and prevent fraud and present content correctly.
What other purposes do cookies and similar technologies are used for:
- Allow you access to our websites;
- Permit your internet connection to our websites;
- Allow our servers to record information about your device (such as IP address, browser type, location, hardware and software information;
- Collect unique device identifier (UDID), geo-location and other transactional data to validate free trials when you use a mobile device;
- Assess content usage;
- Provide relevant content;
- Sell third party advertising and enable frequency capping;
How to delete cookies?
Deleting your cookie settings is also relatively easy but the process does differ between browsers. Here’s how to delete cookies in the most popular browsers.
You can find this and further information about cookies at http://www.aboutcookies.org
You can also control which companies set cookies on your devices by visiting the following pages. Please note that you will need to turn off any ad blockers or privacy tools to see what cookies are being set:
1. Internet Advertising Bureau (IAB)
Your Online Choices is an industry programme that allows you to control which companies can set cookies and show you advertising. It provides you an easy way of opting out several advertising networks.
2. The Network Advertising Initiative control page
This control page also allows you to control OBA from the advertising networks they represent.
3. The Digital Advertising Alliance's control page
This control page also allows you to control cookies.
You can stop web beacons being set, although you cannot decline receiving them in emails. For information about managing these, please visit https://ico.org.uk/for-the-public/online/cookies/
From time to time we may make changes to this Policy. This might be in relation to changes in the law, best practice, changes to the services we provide or collection and use of your personal information. We will always display clearly when the Policy was last updated and where appropriate, notify you of any relevant changes.
By downloading our apps, we will require access to the following services on your device: UDID, MAC address, or other applicable device identifier and location. Other services may also be required in order for the apps to function. This information may be used to validate credentials and provide push notifications to your devices.
If you would like to get in touch with us, please contact
- By Email: firstname.lastname@example.org
- By Post: The Data Protection Officer, Globalgrange Limited, 58 Rochester Row, London, UK, SW1P 1JU
This policy was last updated on 4th Jul 2020