Privacy & Cookie Policy
Learn how HotelsMint gathers, saves, processes, and protects your personal details and complies with UK GDPR, EU GDPR, and Electronic Money Regulations.
Who We Are & This Policy
1.1 Data Controller
Bankitt LTD (company registration number 12780965), trading as "HotelsMint", operates as the primary Data Controller for personal data processed through www.hotelsmint.com and its connected platforms. Our registered office is located at 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF. In respect of financial services (such as digital wallets, virtual payment cards, and fund transfers), we operate in conjunction with our FCA-authorised Financial Services Partner, who acts as an independent Data Controller for processing connected with regulated e-money and payment transaction activities.
1.2 Scope of This Policy
This policy details the processing of personal data across: (a) hotel and accommodation booking services; (b) the HotelsMint digital wallet and transaction services; (c) the guest loyalty rewards programme; (d) the B2B supplier marketplace; and (e) our general website and mobile applications. It complies with UK/EU GDPR requirements and governs the use of cookie and tracking technologies under UK PECR and the EU ePrivacy Directive.
1.3 Hotel Partner Data Limitation
Hotel partner responsibility limitation: When you confirm a lodging reservation with a hotel partner, that property acts independently as a separate Data Controller for the duration of your stay. HotelsMint is not responsible for the data processing practices, internal systems, guest ledger handling, or privacy compliance policies of hotel partners at their respective properties. We advise reviewing each hotel’s individual privacy policy during the booking phase.
Personal Data We Collect
2.1 Hotel Booking Services
When using our booking platforms, we collect the following variables:
- Full name, identity title, and contact details (email address and telephone number).
- Billing address and payment card details (note that card details are fully tokenised; raw card numbers are never stored on HotelsMint servers).
- Accommodation selections: Selected hotel property, travel dates, selected room type, names and count of guests, and special requests.
- Interaction files: Booking and cancellation history and correspondence with client support systems.
- Loyalty values: Points balance metadata, rewards tier status, and points redemption transactions.
2.2 HotelsMint Wallet & Payment Services
For compliance under the Electronic Money Regulations (EMR) 2011 and Money Laundering Regulations (MLR) 2017:
- Identity metrics: Full legal name, date of birth, and nationality (KYC validation).
- Verification files: Government-issued photo identification (passport, national ID card, or driving licence).
- Proof of residence: A recent utility bill or bank statement (issued within 3 months).
- Biometrics: Selfie files or video liveness checks to prevent identity fraud (subject to explicit consent).
- Wealth records: Source of funds declarations for enhanced due diligence accounts.
- Financial transaction history: Transaction amounts, merchant names, recipient details, transaction references, currencies, and timestamps.
- Card attributes: Virtual card details (masked in-app; CVV numbers are displayed briefly and never saved).
- Banking connections: Details of connected bank accounts used for deposits or withdrawals.
- Anti-fraud telemetry: Device fingerprints, IP addresses, and geolocation to satisfy Strong Customer Authentication (SCA).
2.3 Rewards Programme
To operate the customer loyalty platform, we record:
- Detailed balance history of earned and redeemed Mint Points.
- Loyalty tiers, qualification status, and anniversary dates.
- User preferences and transaction listings associated with partner merchants.
2.4 Supplier Marketplace (Business Users)
For the B2B marketplace, we gather operational attributes:
- Business name, business registration number, tax identifiers, and VAT registration.
- Name, job title, and verified direct contact details of corporate representatives.
- Corporate bank account details for trade settlement.
- Transaction listings, purchase invoices, purchase orders, and contract parameters.
- Know Your Business (KYB) checks, including details of beneficial owners.
2.5 Data Collected Automatically
When interacting with the platform, we collect operational telemetry:
- Connection IP addresses and approximate geolocation.
- Browser properties (browser version, operating system, and hardware properties).
- Unique device identifiers.
- Activity listings: Visited links, clicked buttons, session duration, and the referring website.
- System logs: Login timestamps and general session history.
- Cookies and tracking pixels.
2.6 Special Category Data
HotelsMint does not intentionally collect special categories of personal data, except in the following limited situations: 1. Biometric verification: Used for KYC identity checks, requiring explicit consent (Art. 9(2)(a)). 2. Health or belief details: Accessibility needs or dietary requirements provided voluntarily as guest requests. This information is processed solely to accommodate the guest and is forwarded to the hotel property with explicit consent.
Lawful Bases & Purposes of Processing
3.1 Contract Performance — Art. 6(1)(b)
We process your personal data where necessary to perform a contract we have entered with you, or at your request prior to entering a contract. This operates for: processing hotel selections, confirmations, modifications, and cancellations; facilitating digital wallet account openings and management; processing payments, card transactions, and bank movements; administering points, tiers, and member rewards; and processing marketplace B2B trade details.
3.2 Legal Obligation — Art. 6(1)(c)
We process personal data to satisfy legal and regulatory rules: fulfilling identity checks (KYC) under MLR 2017; implementing transaction monitoring and Suspicious Activity Report (SAR) reviews under the Proceeds of Crime Act 2002; vetting names against sanctions databases (OFSI); maintaining client funds safeguarding logs (EMR 2011); filing statutory invoices and taxes (HMRC); and complying with regulatory audit trails from the FCA or ICO.
3.3 Legitimate Interests — Art. 6(1)(f)
We process personal data for our legitimate business interests, provided they do not override your fundamental rights: protecting against cyber fraud, financial crimes, and site security threats; performing analytics to enhance service quality; handling legal defences and claims; passing booking records to hotels to complete stay contracts; and sending direct marketing messages to existing customers concerning related offers (using the soft opt-in under PECR rules).
3.4 Consent — Art. 6(1)(a)
In specific situations, we rely on your consent: sending marketing emails and newsletter updates (which can be opted-out from at any time); setting non-essential performance or advertising cookies; and processing biometric checks during identity vetting.
3.5 Special Category Data Vetting
To process biometric KYC data, we establish explicit consent (Art. 9(2)(a)) combined with the substantial public interest in preventing financial crime (Art. 9(2)(g), read with Schedule 1, Paragraph 10 of the UK Data Protection Act 2018). You can withdraw this consent at any time; however, doing so will require us to disable digital wallet features.
Sharing Your Personal Data
4.1 Third-Party Sharing Guidelines
We do not sell, rent, or trade your personal data to any third party for their own commercial or advertising purposes. We share customer data only where necessary and under strict confidentiality agreements with the following entities:
- Hotel partners: We share guest names, contact details, and booking parameters to complete staying contracts (properties act as independent controllers).
- Payment entities: FCA-authorised banking partners and networks to process payments and maintain safeguarding requirements.
- Payment processors: PCI-DSS compliant companies that process card details securely.
- KYC vendors: Vetting services (such as Sumsub, Onfido, or Jumio) to confirm identity files.
- Compliance verifiers: Sanctions screening and Politically Exposed Persons (PEP) checkers.
- Public authorities: Tax authorities (HMRC), regulatory authorities (FCA, ICO), and national law enforcement services.
- Cloud hosts: Storage and hosting infrastructure providers with databases inside the UK and EEA.
- Communication providers: Client Relations Management (CRM) tools to distribute transaction and update messages.
4.2 Tipping-Off Prohibition
Anti-Money Laundering Regulations Warning: If HotelsMint files a Suspicious Activity Report (SAR) with the National Crime Agency (NCA) under the Proceeds of Crime Act 2002, Section 333A makes it a criminal offence (carrying penalties up to 5 years' imprisonment) for us to disclose this report or related investigations to you or any third party. If your digital wallet is restricted or bookings are declined without detailed explanation, this legal tipping-off prohibition may prevent us from providing additional details. This is a statutory legal obligation, not a violation of your privacy rights.
Cookie Policy
5.1 What Are Cookies?
Cookies are small text documents uploaded to your device when visiting websites. We use cookies, web beacons, tracking pixels, browser local storage, and device fingerprint trackers to monitor traffic, save preferences, and facilitate bookings.
5.2 Our Consent Commitment
Non-essential cookies (such as analytics, functional, or marketing cookies) are disabled by default. They are only placed if you provide active, explicit, and informed consent. You can edit or withdraw consent at any time using the Cookie Settings interface in the website footer.
5.3 Category 1 — Strictly Necessary Cookies (No Consent Required)
These cookies are required for core platform functions, such as authentication, security layers, and booking sessions (UK PECR Reg. 6(4)):
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
auth_token | Manages user login sessions | 30 Days | First Party |
csrf_token | Protects against Cross-Site Request Forgery | Session | First Party |
booking_session | Saves active booking path credentials | Session | First Party |
wallet_session | Maintains active digital wallet state | Session | First Party |
fraud_id | Vets device metrics to prevent transaction fraud | 90 Days | First Party |
mfa_trusted | Remembers trusted devices for multi-factor logins | 30 Days | First Party |
5.4 Category 2 — Performance & Analytics Cookies (Consent Required)
We use these tools to monitor web traffic, path usability, and page loading speeds. They are enabled only with your consent (Art. 6(1)(a)) and process data in anonymised or pseudonymised formats.
| Cookie / Tool | Purpose | Duration | Provider |
|---|---|---|---|
_ga | Google Analytics visitor analytics tracker | 2 Years | Google LLC |
_gid | Google Analytics user ID identifier | 24 Hours | Google LLC |
5.5 Category 3 — Functional Cookies (Consent Required)
These cookies remember choices you make to personalize and improve your platform experience:
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
user_lang | Remembers preferred interface language | 1 Year | First Party |
user_currency | Remembers selected checkout currency | 1 Year | First Party |
wallet_prefs | Determines active wallet user preferences | 1 Year | First Party |
rewards_banner | Remembers if the user closed the rewards banner | 30 Days | First Party |
5.6 Category 4 — Marketing & Targeting Cookies (Consent Required)
These cookies record your visits to help us deliver personalized travel deals on social media and search channels:
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
_fbp | Facebook/Meta pixel targeting tracker | 90 Days | Meta Platforms Inc |
_gcl_au | Google Ads transaction mapping tracking | 90 Days | Google LLC |
MUID | Microsoft Bing Ads search performance | 13 Months | Microsoft Corp |
5.7 Managing Preferences
When first visiting the platform, a Cookie Consent Banner is displayed. You can choose to accept all cookies, reject non-essential cookies, or configure granular settings. You can modify these settings at any time via the 'Cookie Settings' link in the footer. Browser-based settings: You can block or delete cookies in your browser settings (Chrome: Settings → Privacy; Firefox: Options → Privacy; Safari: Preferences → Privacy; Edge: Settings → Cookies). Opt-out services: Google Analytics: tools.google.com/dlpage/gaoptout | Google Ads: adssettings.google.com | Meta/Facebook: facebook.com/privacy.
5.8 Global Privacy Control (GPC)
HotelsMint detects and honours Global Privacy Control (GPC) signals sent by browsers. If a GPC signal is detected, we automatically configure your cookie settings to reject non-essential cookies.
International Data Transfers
6.1 Cross-Border Safeguards
When transferring personal data outside the UK or EEA, we ensure it receives a similar level of protection: we transfer data to countries recognized as having adequate protection under UK Adequacy Regulations, or we implement Standard Contractual Clauses (EU SCCs and the UK International Data Transfer Addendum) alongside supplementary security measures. For details, contact our Data Protection Officer at dpo@hotelsmint.com.
Data Retention
7.1 Retention Schedule
We store personal data only as long as necessary to fulfil our operational requirements or comply with statutory retention periods:
| Data Class | Retention Duration | Regulatory Basis |
|---|---|---|
| Wallet & Transaction Logs | 5 Years from relationship termination | Money Laundering Regulations (MLR 2017, Reg. 40) |
| KYC & Identity Documents | 5 Years from relationship termination | Money Laundering Regulations (MLR 2017, Reg. 40) |
| Accommodation Bookings | 7 Years from stay record date | HMRC / UK Companies Act 2006 compliance |
| Tax & Ledger Files | 7 Years from tax year end | HMRC statutory requirements |
| Marketing Consent Records | Active status + 2 Years from opt-out | ICO audit best practice guidelines |
| Client Support History | 3 Years from case resolution date | Legitimate interest to monitor service quality |
| AML Suspicious Activity (SARs) | Indefinitely | National Crime Agency statutory mandate |
| Sanctions Review Logs | 5 Years minimum from check date | Sanctions Act compliance audits |
| System Data Breach Records | Indefinitely | Information Commissioner's Office (ICO) requirement |
| DPIA Documentation | Duration of processing + 3 Years | UK GDPR compliance audit requirements |
Upon the expiry of these retention periods, personal data is securely deleted or anonymised. Anonymous datasets may be retained indefinitely for analytics and forecasting.
Your Rights Under UK & EU GDPR
8.1 Right to Exercise Control
Under UK/EU GDPR, you have the following rights, which we will respond to within 30 calendar days without charge:
- Right of Access: Request a copy of your personal data and information on how it is processed.
- Right to Rectification: Correct inaccurate or incomplete information.
- Right to Erasure: Request the deletion of data where there is no legal basis for its continued processing.
- Right to Restriction: Restrict processing during verification or disputes.
- Right to Data Portability: Request transfer of your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Human Review: Object to automated decisions and request human intervention.
Limits on rights: We cannot delete index records, transaction logs, or basic identity documents where we are legally required to retain them under the Money Laundering Regulations 2017 (for a minimum of 5 years). We will notify you of the legal basis for any restriction of your request.
Automated Decisions & Profiling
9.1 Automated Fraud & Recommendations
We use automated tools to: calculate fraud risk scores at checkout; flag suspicious activities on wallet accounts; calculate KYC risk tiers; and display personalized hotel suggestions. Decisions with significant legal effects (such as wallet suspension or account termination) are always reviewed by our compliance team; you can request a manual review of any automated decision that materially affects you.
Data Security Measures
10.1 Security Standards
HotelsMint implements robust technical and organisational security measures:
- AES-256 database encryption at rest and TLS 1.3 encryption in transit.
- Secure payment processing via PCI-DSS compliant gateways.
- Mandatory Multi-Factor Authentication (MFA) on all digital wallets.
- Role-Based Access Control (RBAC) to limit data access to authorised personnel.
- Regular cybersecurity penetration tests and code reviews.
- 24/7 automated monitoring for fraud and layout anomalies.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours of detection and communicate the breach to affected users without undue delay.
Children's Privacy Protection
11.1 Age Restrictions
Our digital wallet and transaction services are restricted to users aged 18 and older. Booking services require users to be at least 16 years of age (with parental or guardian consent under 18). HotelsMint does not knowingly collect data from children under the age of 13. If you believe a child under 13 has registered, please contact us at privacy@hotelsmint.com to have their data deleted.
Supervisory Authorities & Complaints
12.1 Lodging a Complaint
If you have questions or complaints regarding our data practices, please contact us first at dpo@hotelsmint.com. You have the right to lodge a complaint with your supervisory authority (the Information Commissioner’s Office in the UK: ico.org.uk | 0303 123 1113, or your local EU supervisory authority).
Changes to This Privacy Policy
13.1 Updates Info
HotelsMint may update this Privacy & Cookie Policy. For material modifications, we will display a prominent notice on our website at least 30 days before they take effect. The effective date at the top of this policy indicates when it was last updated.
For issues regarding personal data handling, exercise of GDPR rights, or cookies under PECR, you may contact our Data Protection Officer directly at dpo@hotelsmint.com.