Data Protection Charter v3.0

Privacy & Cookie Policy

Learn how HotelsMint gathers, saves, processes, and protects your personal details and complies with UK GDPR, EU GDPR, and Electronic Money Regulations.

Policy ChaptersScroll Spy
Regulatory basis: UK & EU GDPR
PART 1

Who We Are & This Policy

1.1 Data Controller

Bankitt LTD (company registration number 12780965), trading as "HotelsMint", operates as the primary Data Controller for personal data processed through www.hotelsmint.com and its connected platforms. Our registered office is located at 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF. In respect of financial services (such as digital wallets, virtual payment cards, and fund transfers), we operate in conjunction with our FCA-authorised Financial Services Partner, who acts as an independent Data Controller for processing connected with regulated e-money and payment transaction activities.

1.2 Scope of This Policy

This policy details the processing of personal data across: (a) hotel and accommodation booking services; (b) the HotelsMint digital wallet and transaction services; (c) the guest loyalty rewards programme; (d) the B2B supplier marketplace; and (e) our general website and mobile applications. It complies with UK/EU GDPR requirements and governs the use of cookie and tracking technologies under UK PECR and the EU ePrivacy Directive.

1.3 Hotel Partner Data Limitation

Independent Controller Status Notification

Hotel partner responsibility limitation: When you confirm a lodging reservation with a hotel partner, that property acts independently as a separate Data Controller for the duration of your stay. HotelsMint is not responsible for the data processing practices, internal systems, guest ledger handling, or privacy compliance policies of hotel partners at their respective properties. We advise reviewing each hotel’s individual privacy policy during the booking phase.

PART 2

Personal Data We Collect

2.1 Hotel Booking Services

When using our booking platforms, we collect the following variables:

  • Full name, identity title, and contact details (email address and telephone number).
  • Billing address and payment card details (note that card details are fully tokenised; raw card numbers are never stored on HotelsMint servers).
  • Accommodation selections: Selected hotel property, travel dates, selected room type, names and count of guests, and special requests.
  • Interaction files: Booking and cancellation history and correspondence with client support systems.
  • Loyalty values: Points balance metadata, rewards tier status, and points redemption transactions.

2.2 HotelsMint Wallet & Payment Services

For compliance under the Electronic Money Regulations (EMR) 2011 and Money Laundering Regulations (MLR) 2017:

  • Identity metrics: Full legal name, date of birth, and nationality (KYC validation).
  • Verification files: Government-issued photo identification (passport, national ID card, or driving licence).
  • Proof of residence: A recent utility bill or bank statement (issued within 3 months).
  • Biometrics: Selfie files or video liveness checks to prevent identity fraud (subject to explicit consent).
  • Wealth records: Source of funds declarations for enhanced due diligence accounts.
  • Financial transaction history: Transaction amounts, merchant names, recipient details, transaction references, currencies, and timestamps.
  • Card attributes: Virtual card details (masked in-app; CVV numbers are displayed briefly and never saved).
  • Banking connections: Details of connected bank accounts used for deposits or withdrawals.
  • Anti-fraud telemetry: Device fingerprints, IP addresses, and geolocation to satisfy Strong Customer Authentication (SCA).

2.3 Rewards Programme

To operate the customer loyalty platform, we record:

  • Detailed balance history of earned and redeemed Mint Points.
  • Loyalty tiers, qualification status, and anniversary dates.
  • User preferences and transaction listings associated with partner merchants.

2.4 Supplier Marketplace (Business Users)

For the B2B marketplace, we gather operational attributes:

  • Business name, business registration number, tax identifiers, and VAT registration.
  • Name, job title, and verified direct contact details of corporate representatives.
  • Corporate bank account details for trade settlement.
  • Transaction listings, purchase invoices, purchase orders, and contract parameters.
  • Know Your Business (KYB) checks, including details of beneficial owners.

2.5 Data Collected Automatically

When interacting with the platform, we collect operational telemetry:

  • Connection IP addresses and approximate geolocation.
  • Browser properties (browser version, operating system, and hardware properties).
  • Unique device identifiers.
  • Activity listings: Visited links, clicked buttons, session duration, and the referring website.
  • System logs: Login timestamps and general session history.
  • Cookies and tracking pixels.

2.6 Special Category Data

HotelsMint does not intentionally collect special categories of personal data, except in the following limited situations: 1. Biometric verification: Used for KYC identity checks, requiring explicit consent (Art. 9(2)(a)). 2. Health or belief details: Accessibility needs or dietary requirements provided voluntarily as guest requests. This information is processed solely to accommodate the guest and is forwarded to the hotel property with explicit consent.

PART 3

Lawful Bases & Purposes of Processing

3.1 Contract Performance — Art. 6(1)(b)

We process your personal data where necessary to perform a contract we have entered with you, or at your request prior to entering a contract. This operates for: processing hotel selections, confirmations, modifications, and cancellations; facilitating digital wallet account openings and management; processing payments, card transactions, and bank movements; administering points, tiers, and member rewards; and processing marketplace B2B trade details.

3.2 Legal Obligation — Art. 6(1)(c)

We process personal data to satisfy legal and regulatory rules: fulfilling identity checks (KYC) under MLR 2017; implementing transaction monitoring and Suspicious Activity Report (SAR) reviews under the Proceeds of Crime Act 2002; vetting names against sanctions databases (OFSI); maintaining client funds safeguarding logs (EMR 2011); filing statutory invoices and taxes (HMRC); and complying with regulatory audit trails from the FCA or ICO.

3.3 Legitimate Interests — Art. 6(1)(f)

We process personal data for our legitimate business interests, provided they do not override your fundamental rights: protecting against cyber fraud, financial crimes, and site security threats; performing analytics to enhance service quality; handling legal defences and claims; passing booking records to hotels to complete stay contracts; and sending direct marketing messages to existing customers concerning related offers (using the soft opt-in under PECR rules).

3.4 Consent — Art. 6(1)(a)

In specific situations, we rely on your consent: sending marketing emails and newsletter updates (which can be opted-out from at any time); setting non-essential performance or advertising cookies; and processing biometric checks during identity vetting.

3.5 Special Category Data Vetting

To process biometric KYC data, we establish explicit consent (Art. 9(2)(a)) combined with the substantial public interest in preventing financial crime (Art. 9(2)(g), read with Schedule 1, Paragraph 10 of the UK Data Protection Act 2018). You can withdraw this consent at any time; however, doing so will require us to disable digital wallet features.

PART 4

Sharing Your Personal Data

4.1 Third-Party Sharing Guidelines

We do not sell, rent, or trade your personal data to any third party for their own commercial or advertising purposes. We share customer data only where necessary and under strict confidentiality agreements with the following entities:

  • Hotel partners: We share guest names, contact details, and booking parameters to complete staying contracts (properties act as independent controllers).
  • Payment entities: FCA-authorised banking partners and networks to process payments and maintain safeguarding requirements.
  • Payment processors: PCI-DSS compliant companies that process card details securely.
  • KYC vendors: Vetting services (such as Sumsub, Onfido, or Jumio) to confirm identity files.
  • Compliance verifiers: Sanctions screening and Politically Exposed Persons (PEP) checkers.
  • Public authorities: Tax authorities (HMRC), regulatory authorities (FCA, ICO), and national law enforcement services.
  • Cloud hosts: Storage and hosting infrastructure providers with databases inside the UK and EEA.
  • Communication providers: Client Relations Management (CRM) tools to distribute transaction and update messages.

4.2 Tipping-Off Prohibition

Critical Statutory Notice: Criminal Liability

Anti-Money Laundering Regulations Warning: If HotelsMint files a Suspicious Activity Report (SAR) with the National Crime Agency (NCA) under the Proceeds of Crime Act 2002, Section 333A makes it a criminal offence (carrying penalties up to 5 years' imprisonment) for us to disclose this report or related investigations to you or any third party. If your digital wallet is restricted or bookings are declined without detailed explanation, this legal tipping-off prohibition may prevent us from providing additional details. This is a statutory legal obligation, not a violation of your privacy rights.

PART 5

Cookie Policy

5.1 What Are Cookies?

Cookies are small text documents uploaded to your device when visiting websites. We use cookies, web beacons, tracking pixels, browser local storage, and device fingerprint trackers to monitor traffic, save preferences, and facilitate bookings.

5.2 Our Consent Commitment

Non-essential cookies (such as analytics, functional, or marketing cookies) are disabled by default. They are only placed if you provide active, explicit, and informed consent. You can edit or withdraw consent at any time using the Cookie Settings interface in the website footer.

5.3 Category 1 — Strictly Necessary Cookies (No Consent Required)

These cookies are required for core platform functions, such as authentication, security layers, and booking sessions (UK PECR Reg. 6(4)):

Cookie NamePurposeDurationProvider
auth_tokenManages user login sessions30 DaysFirst Party
csrf_tokenProtects against Cross-Site Request ForgerySessionFirst Party
booking_sessionSaves active booking path credentialsSessionFirst Party
wallet_sessionMaintains active digital wallet stateSessionFirst Party
fraud_idVets device metrics to prevent transaction fraud90 DaysFirst Party
mfa_trustedRemembers trusted devices for multi-factor logins30 DaysFirst Party

5.4 Category 2 — Performance & Analytics Cookies (Consent Required)

We use these tools to monitor web traffic, path usability, and page loading speeds. They are enabled only with your consent (Art. 6(1)(a)) and process data in anonymised or pseudonymised formats.

Cookie / ToolPurposeDurationProvider
_gaGoogle Analytics visitor analytics tracker2 YearsGoogle LLC
_gidGoogle Analytics user ID identifier24 HoursGoogle LLC

5.5 Category 3 — Functional Cookies (Consent Required)

These cookies remember choices you make to personalize and improve your platform experience:

Cookie NamePurposeDurationProvider
user_langRemembers preferred interface language1 YearFirst Party
user_currencyRemembers selected checkout currency1 YearFirst Party
wallet_prefsDetermines active wallet user preferences1 YearFirst Party
rewards_bannerRemembers if the user closed the rewards banner30 DaysFirst Party

5.6 Category 4 — Marketing & Targeting Cookies (Consent Required)

These cookies record your visits to help us deliver personalized travel deals on social media and search channels:

Cookie NamePurposeDurationProvider
_fbpFacebook/Meta pixel targeting tracker90 DaysMeta Platforms Inc
_gcl_auGoogle Ads transaction mapping tracking90 DaysGoogle LLC
MUIDMicrosoft Bing Ads search performance13 MonthsMicrosoft Corp

5.7 Managing Preferences

When first visiting the platform, a Cookie Consent Banner is displayed. You can choose to accept all cookies, reject non-essential cookies, or configure granular settings. You can modify these settings at any time via the 'Cookie Settings' link in the footer. Browser-based settings: You can block or delete cookies in your browser settings (Chrome: Settings → Privacy; Firefox: Options → Privacy; Safari: Preferences → Privacy; Edge: Settings → Cookies). Opt-out services: Google Analytics: tools.google.com/dlpage/gaoptout | Google Ads: adssettings.google.com | Meta/Facebook: facebook.com/privacy.

5.8 Global Privacy Control (GPC)

HotelsMint detects and honours Global Privacy Control (GPC) signals sent by browsers. If a GPC signal is detected, we automatically configure your cookie settings to reject non-essential cookies.

PART 6

International Data Transfers

6.1 Cross-Border Safeguards

When transferring personal data outside the UK or EEA, we ensure it receives a similar level of protection: we transfer data to countries recognized as having adequate protection under UK Adequacy Regulations, or we implement Standard Contractual Clauses (EU SCCs and the UK International Data Transfer Addendum) alongside supplementary security measures. For details, contact our Data Protection Officer at dpo@hotelsmint.com.

PART 7

Data Retention

7.1 Retention Schedule

We store personal data only as long as necessary to fulfil our operational requirements or comply with statutory retention periods:

Data ClassRetention DurationRegulatory Basis
Wallet & Transaction Logs5 Years from relationship terminationMoney Laundering Regulations (MLR 2017, Reg. 40)
KYC & Identity Documents5 Years from relationship terminationMoney Laundering Regulations (MLR 2017, Reg. 40)
Accommodation Bookings7 Years from stay record dateHMRC / UK Companies Act 2006 compliance
Tax & Ledger Files7 Years from tax year endHMRC statutory requirements
Marketing Consent RecordsActive status + 2 Years from opt-outICO audit best practice guidelines
Client Support History3 Years from case resolution dateLegitimate interest to monitor service quality
AML Suspicious Activity (SARs)IndefinitelyNational Crime Agency statutory mandate
Sanctions Review Logs5 Years minimum from check dateSanctions Act compliance audits
System Data Breach RecordsIndefinitelyInformation Commissioner's Office (ICO) requirement
DPIA DocumentationDuration of processing + 3 YearsUK GDPR compliance audit requirements

Upon the expiry of these retention periods, personal data is securely deleted or anonymised. Anonymous datasets may be retained indefinitely for analytics and forecasting.

PART 8

Your Rights Under UK & EU GDPR

8.1 Right to Exercise Control

Under UK/EU GDPR, you have the following rights, which we will respond to within 30 calendar days without charge:

  • Right of Access: Request a copy of your personal data and information on how it is processed.
  • Right to Rectification: Correct inaccurate or incomplete information.
  • Right to Erasure: Request the deletion of data where there is no legal basis for its continued processing.
  • Right to Restriction: Restrict processing during verification or disputes.
  • Right to Data Portability: Request transfer of your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.
  • Right to Human Review: Object to automated decisions and request human intervention.

Limits on rights: We cannot delete index records, transaction logs, or basic identity documents where we are legally required to retain them under the Money Laundering Regulations 2017 (for a minimum of 5 years). We will notify you of the legal basis for any restriction of your request.

PART 9

Automated Decisions & Profiling

9.1 Automated Fraud & Recommendations

We use automated tools to: calculate fraud risk scores at checkout; flag suspicious activities on wallet accounts; calculate KYC risk tiers; and display personalized hotel suggestions. Decisions with significant legal effects (such as wallet suspension or account termination) are always reviewed by our compliance team; you can request a manual review of any automated decision that materially affects you.

PART 10

Data Security Measures

10.1 Security Standards

HotelsMint implements robust technical and organisational security measures:

  • AES-256 database encryption at rest and TLS 1.3 encryption in transit.
  • Secure payment processing via PCI-DSS compliant gateways.
  • Mandatory Multi-Factor Authentication (MFA) on all digital wallets.
  • Role-Based Access Control (RBAC) to limit data access to authorised personnel.
  • Regular cybersecurity penetration tests and code reviews.
  • 24/7 automated monitoring for fraud and layout anomalies.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours of detection and communicate the breach to affected users without undue delay.

PART 11

Children's Privacy Protection

11.1 Age Restrictions

Our digital wallet and transaction services are restricted to users aged 18 and older. Booking services require users to be at least 16 years of age (with parental or guardian consent under 18). HotelsMint does not knowingly collect data from children under the age of 13. If you believe a child under 13 has registered, please contact us at privacy@hotelsmint.com to have their data deleted.

PART 12

Supervisory Authorities & Complaints

12.1 Lodging a Complaint

If you have questions or complaints regarding our data practices, please contact us first at dpo@hotelsmint.com. You have the right to lodge a complaint with your supervisory authority (the Information Commissioner’s Office in the UK: ico.org.uk | 0303 123 1113, or your local EU supervisory authority).

PART 13

Changes to This Privacy Policy

13.1 Updates Info

HotelsMint may update this Privacy & Cookie Policy. For material modifications, we will display a prominent notice on our website at least 30 days before they take effect. The effective date at the top of this policy indicates when it was last updated.

Bankitt LTD Privacy Directorate

For issues regarding personal data handling, exercise of GDPR rights, or cookies under PECR, you may contact our Data Protection Officer directly at dpo@hotelsmint.com.