Privacy & Cookie Policy
This policy outlines how Bankitt LTD collects, safeguards, and processes personal data across HotelsMint services in compliance with UK/EU GDPR and PECR.
Who We Are & This Policy
1.1 Data Controller Identification
Bankitt LTD (company number 12780965), trading as "HotelsMint", operates as the primary Data Controller for personal data processed through www.hotelsmint.com and its connected services. Our registered office is situated at 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF. For regulated financial services (such as digital wallets, virtual cards, and payment transfers), we operate in conjunction with our FCA-authorised Financial Services Partner, who acts as an independent Data Controller for data processed in connection with regulated e-money and payment transactions.
1.2 Scope of This Policy
This combined Privacy & Cookie Policy details the processing of personal data across: (a) hotel accommodation booking services; (b) the HotelsMint digital wallet and transaction platform; (c) the guest rewards programme; (d) the B2B supplier marketplace; and (e) our website and mobile applications. It satisfies compliance obligations under UK GDPR, EU GDPR (2016/679), Data Protection Act 2018, UK PECR, and the EU ePrivacy Directive.
1.3 Hotel Partner Data Limitation
Hotel Partner Independent Controller Notice: When you complete an accommodation booking with a hotel partner, that property independently processes your personal data as a separate Data Controller for the duration of your stay. HotelsMint is not responsible for how hotel partners manage guest data at their physical properties or in their internal systems. We strongly encourage reviewing the individual privacy policy of any hotel prior to booking.
Personal Data We Collect
2.1 Hotel Booking Services
To facilitate accommodation reservations, we collect:
- Full name, title, email address, and telephone contact details.
- Billing address and tokenised payment card details (raw payment card numbers are never stored by HotelsMint).
- Booking parameters: hotel name, stay dates, room type, guest count, and special accommodation requests.
- Booking history, cancellation records, and customer support correspondence.
- Loyalty programme status, points balance, and redemption history.
2.2 HotelsMint Wallet & Payment Services
Under the Electronic Money Regulations 2011 and Money Laundering Regulations 2017, we collect additional identity data:
- Identity documentation: Full legal name, date of birth, and nationality (for Know Your Customer validation).
- Government verification: Photo identity documents (passport, national ID card, or driving licence).
- Proof of residence: A recent utility bill or bank statement issued within the preceding 3 months.
- Biometric verification: Selfie uploads or liveness video checks for identity validation (processed strictly with your explicit consent).
- Financial background: Source of funds declarations and supporting financial documents for enhanced due diligence accounts.
- Transaction records: Complete payment history including amounts, dates, merchants, counterparties, reference numbers, and currencies.
- Virtual Card attributes: Card details (masked in account view; CVV displayed temporarily and never stored).
- Connected bank accounts: Linked bank account numbers and routing details for top-ups and withdrawals.
- Anti-fraud telemetry: Device fingerprints, IP addresses, and geolocation data for fraud prevention and Strong Customer Authentication (SCA).
2.3 Rewards Programme Data
To administer loyalty rewards, we maintain records of:
- Points balance, points earning transaction log, and redemption history.
- Tier qualification status, tier activity data, and anniversary renewal dates.
- Programme preference choices and linked merchant transaction summaries.
2.4 Supplier Marketplace (Business Users)
For commercial marketplace users, we gather operational attributes:
- Business entity name, company registration number, and VAT registration number.
- Authorised corporate representative name, business title, email, and contact number.
- Business settlement bank details for automated payout processing.
- Platform trading history, invoices, purchase orders, and contract records.
- Know Your Business (KYB) verification data including beneficial ownership structures.
2.5 Automatically Collected Technical Data
When interacting with our website or app, we automatically record:
- IP address and approximate geographic location derived from network data.
- Browser type, software version, operating system, and hardware device model.
- Session analytics: Pages visited, clickstream sequences, session duration, and referral URLs.
- Authentication logs: Login timestamps, security audit events, and MFA state.
- Cookie identifiers and tracking pixel telemetry (detailed in Part 5).
2.6 Special Category Data
We do not intentionally process special category data (health, religion, biometric identification) except: (a) biometric data for KYC identity verification under explicit consent (Art. 9(2)(a) UK/EU GDPR); and (b) accessibility or dietary preferences voluntarily disclosed in special booking requests (passed to hotel partners solely for fulfillment with consent).
Lawful Bases & Purposes of Processing
3.1 Performance of Contract — Art. 6(1)(b) UK/EU GDPR
We process personal data to fulfill our contractual commitments to you:
- Processing hotel reservations, confirmations, modifications, and cancellation requests.
- Opening, operating, and managing your HotelsMint Wallet and payment services.
- Executing payment transfers, P2P transactions, and virtual card operations.
- Administering loyalty points accrual, tier status, and reward redemptions.
- Managing supplier marketplace accounts, orders, and settlement processing.
3.2 Compliance with Legal Obligations — Art. 6(1)(c) UK/EU GDPR
We process data to satisfy statutory requirements under English and European law:
- KYC identity verification under Money Laundering Regulations 2017 (MLR 2017, Reg. 28).
- Transaction monitoring and suspicious activity reporting under Proceeds of Crime Act 2002 (POCA 2002) and Terrorism Act 2000.
- Financial sanctions screening enforced by OFSI (HM Treasury).
- Safeguarding of e-money customer funds under EMR 2011 and FCA Safeguarding Rules (PS25/12).
- Statutory tax and corporate record retention for HMRC and Companies Act 2006.
- Data breach notifications to the Information Commissioner's Office (ICO) under Art. 33-34 UK GDPR.
3.3 Legitimate Interests — Art. 6(1)(f) UK/EU GDPR
We process data for legitimate business interests where balanced against your privacy rights:
- Detecting and preventing fraud, financial crime, and platform security threats.
- Conducting platform performance analytics and service quality optimization.
- Handling legal disputes, enforcement of terms, and legal claims defense.
- Sharing reservation details with hotel partners to ensure seamless stay fulfillment.
- Direct marketing of similar products to existing customers (soft opt-in under UK PECR).
3.4 Consent — Art. 6(1)(a) UK/EU GDPR
We rely on explicit opt-in consent for: promotional email marketing; non-essential cookies; biometric identity verification (Art. 9(2)(a)); and personalized behavioral advertising. Consent can be withdrawn at any time via account settings or our Cookie Preference Centre.
Sharing Your Personal Data
4.1 Third-Party Recipient Categories
WE DO NOT SELL YOUR PERSONAL DATA TO THIRD PARTIES FOR COMMERCIAL PURPOSES. Personal data is shared only under appropriate legal safeguards with:
- Hotel Partners: Name, contact details, and booking parameters to fulfill your confirmed reservation.
- Financial Services Partner: FCA-authorised partner for e-money issuance, card processing, and safeguarding under DPA agreements.
- Payment Processors & Card Schemes: Secure PCI-DSS compliant payment processing partners.
- KYC Identity Verification Providers: Automated AML identity verification specialists (e.g. Onfido, Sumsub, Jumio).
- Sanctions Screening Providers: AML database providers (e.g. ComplyAdvantage) for ongoing sanctions monitoring.
- Law Enforcement & Regulators: National Crime Agency (NCA) for SAR filings, HMRC for tax compliance, FCA, and court orders.
4.2 Statutory Tipping-Off Prohibition Notice
TIPPING OFF PROHIBITION — LEGAL NOTICE: If a Suspicious Activity Report (SAR) is submitted to the National Crime Agency (NCA) under Proceeds of Crime Act 2002 (POCA), Section 333A of that Act makes it a criminal offence (carrying up to 5 years' imprisonment) to disclose this fact to the account holder or any third party. If we suspend your account or decline a payment transaction without specifying internal details, this statutory legal duty may be the cause. This compliance step does not constitute a breach of your data protection rights.
Cookie Policy
5.1 Understanding Tracking Technologies
Cookies are small data files placed on your device during website access. We also utilize web beacons, tracking pixels, local storage objects, and device fingerprinting under UK PECR and the EU ePrivacy Directive.
5.2 Cookie Consent Framework
Non-essential cookies are placed strictly after receiving freely given, specific, and unambiguous consent. Preferences can be updated at any time via the 'Cookie Settings' link in our website footer.
5.3 Category 1 — Strictly Necessary Cookies (No Consent Required)
Essential for baseline platform operation and security. Exemption under UK PECR Reg. 6(4).
| Cookie Name | Purpose | Duration | Type |
|---|---|---|---|
| auth_token | User session authentication state | 30 Days | First Party |
| csrf_token | Cross-site request forgery protection | Session | First Party |
| booking_session | Active reservation payload preservation | Session | First Party |
| wallet_session | Secure wallet session authentication | Session | First Party |
| fraud_id | Device risk telemetry for fraud prevention | 90 Days | First Party |
| mfa_trusted | Trusted device flag for multi-factor auth | 30 Days | First Party |
5.4 Category 2 & 3 — Analytics & Functional Cookies (Consent Required)
Functional cookies remember user preferences (language: `user_lang`, currency: `user_currency`, wallet display: `wallet_prefs`). Analytics cookies help evaluate platform traffic and user journeys.
5.5 Category 4 — Marketing & Targeting Cookies (Consent Required)
Includes third-party pixel technologies (`_fbp` Meta Pixel, `_gcl_au` Google Ads, `MUID` Microsoft Advertising) used to serve relevant marketing campaigns on external platforms.
5.6 Global Privacy Control (GPC)
We recognize and process Global Privacy Control (GPC) opt-out signals automatically where technically supported by your browser.
International Data Transfers
6.1 Cross-Border Transfer Mechanisms
Where personal data is transferred outside the UK or EEA (e.g. US cloud infrastructure or identity verification partners), we enforce approved safeguards: (a) UK Adequacy Regulations; (b) Standard Contractual Clauses (SCCs) / UK International Data Transfer Agreements (IDTAs); and (c) Binding Corporate Rules (BCRs).
Data Retention Schedule
7.1 Retention Requirements Table
We retain personal data strictly as necessary for purpose fulfillment or statutory retention rules:
| Data Category | Statutory Basis | Retention Period |
|---|---|---|
| Wallet & E-Money Records | MLR 2017 Reg. 40 | 5 Years post-relationship end |
| KYC / AML Identity Documents | MLR 2017 Reg. 40 | 5 Years post-relationship end |
| Hotel Booking Records | HMRC & Companies Act 2006 | 7 Years from booking date |
| Financial & Tax Records | HMRC Requirements | 7 Years |
| Marketing Consent Records | PECR Evidential Period | Consent period + 2 Years |
| Customer Support Records | Limitation Act 1980 | 3 Years from matter closure |
| Suspicious Activity Reports (SARs) | POCA 2002 Statutory Rule | Permanent Retention |
| Data Breach Notifications | ICO Regulatory Requirement | Permanent Retention |
Upon expiration of statutory retention windows, data is securely erased or irreversibly anonymised for long-term analytical usage.
Your Rights Under UK & EU GDPR
8.1 Statutory Data Subject Rights
Under UK and EU GDPR, you hold the following rights:
- Right of Access (Subject Access Request — SAR): Obtain copies of your personal data.
- Right to Rectification: Correct inaccurate or incomplete personal records.
- Right to Erasure ('Right to be Forgotten'): Request data deletion where retention is no longer legally justified.
- Right to Restriction: Restrict processing activities during legal disputes.
- Right to Data Portability: Receive data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Human Intervention: Request human review of automated decisions with significant legal effect.
Important Limitation Notice: Statutory retention rules (such as MLR 2017 mandatory 5-year retention for AML data) override erasure or portability requests. We will explain any legal restrictions applied upon request.
Automated Decision-Making & Profiling
9.1 Automated Risk Scoring
We utilize automated processing for fraud scoring, transaction monitoring flags, and KYC risk categorisation. Decisions carrying significant legal effects (such as wallet suspension) are subject to mandatory human compliance review.
Security Standards
10.1 Technical & Organisational Measures
HotelsMint enforces robust security controls: AES-256 encryption at rest; TLS 1.3 encryption in transit; PCI-DSS payment compliance; Multi-Factor Authentication (MFA) for Wallet accounts; role-based access restrictions; 24/7 automated threat monitoring; and ICO data breach notification within 72 hours under Art. 33-34.
Children's Privacy Protection
11.1 Age Restrictions
Financial services (Wallet, virtual cards) are strictly restricted to individuals aged 18 and over. Accommodation booking requires minimum age of 16 (with parental consent under 18). We do not knowingly process data of children under 13.
Supervisory Authorities & Complaints
12.1 Lodging a Complaint
If you are dissatisfied with our data handling, contact info@hotelsmint.com first. You maintain the legal right to lodge a complaint with the Information Commissioner's Office (ICO: ico.org.uk | 0303 123 1113) or your local EU supervisory authority.
Changes to This Privacy Policy
13.1 Update Notifications
Material modifications will be notified via prominent website notice at least 30 days prior to taking effect. Continued platform usage after the effective date constitutes acceptance of the revised policy.
For data protection enquiries, Subject Access Requests (SAR), or GDPR concerns, contact info@hotelsmint.com or write to Bankitt LTD, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.