Privacy notice
Effective 1 September 2026 · Version sbh-privacy-2026-09-01-v2
Who is responsible for your information
The owner and operator of Sunset Beach House is responsible for personal information used to answer enquiries and administer direct bookings. You can contact us at [email protected].
Information we use
When you enquire or book, we use the lead guest’s name, email address and telephone number, stay dates, party breakdown, messages, quote and booking status, payment status and the version of the booking terms accepted. We do not receive or store your full card details.
When someone clicks a public booking, house, contact, guide, map or social link, our first-party CTA log records only the normalized source path, normalized destination path, a coarse CTA type, a coarse source section and a server timestamp. Query strings, link text, names, contact details, booking identifiers and payment information are not included in that log.
A separate first-party booking-funnel log records only the event type, validated arrival and departure dates, party size, quoted stay total when available, bounded failure stage, status and closed-format detail, and a server timestamp. Invalid dates are stored only as blank values. It excludes names, email addresses, telephone numbers, messages, booking and source identifiers, campaign attribution, payment URLs, API keys and raw provider responses.
If you consent to advertising measurement, we also process campaign parameters and advertising click identifiers such as UTM values, Google click IDs and Meta click IDs. These may be associated with quote, booking and payment-confirmation events so we can measure advertising return. They are not used unless the current consent choice is affirmative.
For security and reliability, our hosting provider may process limited technical information such as IP address, browser details, request time and low-cardinality error information. Provider booking identifiers are restricted to the protected booking journal and are not put in public responses, analytics or the operator dashboard.
Why we use it
We use booking and enquiry information to take steps at your request before a contract, perform the booking contract, provide the stay, take and reconcile payment, communicate with you, prevent duplicate reservations, protect the property and meet tax, accounting and other legal obligations.
We use the limited first-party CTA log for our legitimate interests in understanding whether public navigation and the direct-booking journey work, prioritising improvements and measuring their effect. It is not used for advertising profiles or cross-site tracking. You may object to this use by contacting us.
We use the limited first-party booking-funnel log for our legitimate interests in measuring whether quote, booking and hosted-checkout hand-off steps work and in diagnosing bounded failure stages. It is not used for advertising profiles or cross-site tracking. You may object to this use by contacting us.
With your consent, we use Google Analytics, Google Ads measurement, Meta Pixel and Meta Conversions API to understand which advertising and website journeys lead to confirmed bookings, prevent duplicate conversion reporting and improve advertising effectiveness. You can refuse or withdraw this consent at any time through the Cookie choices control without affecting essential booking functions.
We use limited security and reliability information for our legitimate interests in keeping the service safe, diagnosing failures and preventing fraud, balanced against your rights.
Services that process information
Lodgify provides availability, quotes, reservation management and the hosted checkout. Stripe processes card payments within that checkout. Cloudflare hosts and protects this website. Our email providers process booking and enquiry messages. Each provider processes information under its own contractual and legal responsibilities.
Google provides Analytics and Ads measurement. Meta provides Pixel, Conversions API and advertising measurement. Their scripts and non-essential cookies load only after an affirmative choice. Lodgify remains the authoritative source for availability, confirmed stays and booking value; platform-estimated purchases are not treated as confirmed bookings.
Cookies and browser storage
The booking flow uses essential, tab-scoped session storage. Before submission it may keep the booking-attempt identifier for the selected stay. On submission it keeps the exact request bytes—including contact details, stay dates, party breakdown, accepted terms version and quoted amounts—so every retry, reload or return from Lodgify can resume only that UUID instead of creating another reservation. Those exact bytes remain while the attempt is resumable and through the hosted-checkout hand-off.
When payment is confirmed, the attempt enters manual review, or Lodgify verifies a rollback, the stored contact details and exact request bytes are replaced with a non-contact tombstone containing the attempt identifier, stay dates, party counts and terms version. A verified rollback can be explicitly restarted, which removes the tombstone; otherwise it remains only for the life of that browser tab. If the server proves that checkout stopped before any Lodgify write, the attempt is cleared immediately. Invalid stored records are removed when read.
The first-party CTA log does not set a browser cookie or local-storage identifier. Its same-origin request contains only the bounded fields described above.
Your current advertising-measurement choice and its notice version are stored in local storage and in a same-site cookie named sbh_tracking_consent for up to 180 days. Choosing Reject removes known Google and Meta cookies that this site can access. You can reopen the choice at any time using the Cookie choices control.
After consent, Google and Meta may set identifiers including _ga, _fbp and _fbc. Campaign attribution is retained for up to 90 days in this browser so a later direct-booking step can be linked to the consenting advertising visit.
Retention and international processing
We keep confirmed booking, payment and communication records only for as long as reasonably needed to provide the stay, handle a complaint or legal claim, and meet tax or accounting duties. Short-lived booking coordination records are minimised and provider identifiers are scrubbed from the operational journal under its retention controls when no longer required.
The first-party CTA log is capped at the latest 1,000 accepted events rather than kept for a fixed calendar period; each older event is displaced as a newer one is accepted. Hashed retry-deduplication and rate-limit guard keys expire within two minutes.
The first-party booking-funnel log is capped at the latest 2,000 accepted events rather than kept for a fixed calendar period; each older event is displaced as a newer one is accepted.
Consented campaign attribution attached to the first-party booking-funnel log is subject to the same 2,000-event cap. Advertising conversion and operations records are retained for up to 13 months for seasonal comparison, deduplication, audit and cancellation/refund reconciliation, then deleted or aggregated.
Some service providers may process information outside the United Kingdom. Where this happens, the provider must use an applicable legal safeguard for the transfer.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or objection, and may withdraw consent where consent is the legal basis. Contact [email protected]. You may also complain to the UK Information Commissioner’s Office at ico.org.uk.