Privacy notice
Effective 29 September 2026 · Version sbh-privacy-2026-09-29-v5
Who is responsible for your information
The owner and operator of Sunset Beach House is responsible for personal information used to answer enquiries and administer direct bookings. You can contact us at [email protected].
Information we use
When you enquire or book, we use the lead guest’s name, email address and telephone number, stay dates, party breakdown, messages, quote and booking status, payment status and the version of the booking terms accepted. We do not receive or store your full card details.
When someone clicks a public booking, house, contact, guide, map or social link, our first-party CTA log records only the normalized source path, normalized destination path, a coarse CTA type, a coarse source section and a server timestamp. Query strings, link text, names, contact details, booking identifiers and payment information are not included in that log.
A separate first-party booking-funnel log records the event type, validated arrival and departure dates, party size, quoted stay total when available, bounded failure stage, status and closed-format detail, and a server timestamp. Invalid dates are stored only as blank values. Without current advertising-measurement consent, this log does not include campaign parameters or advertising click identifiers. It does not include guest names, email addresses, telephone numbers, messages, booking or provider identifiers, payment URLs, API keys or raw provider responses.
When a valid quote is shown in the booking flow, a separate first-party record stores only a one-way digest of a random, short-lived quote-response receipt and the server acknowledgment time. It does not contain stay dates, price, guest or browser identifiers, contact details, campaign attribution or IP address.
With current advertising-measurement consent, selected entries in that same booking-funnel log may also include bounded UTM source, medium, campaign, content and term values, Google and Meta click IDs, and a referrer value. These fields are stored with the current consent version and can be associated with quote, booking and payment-confirmation events to measure advertising return. We do not add them to the log without that consent.
For OpenAI Ads, current consent may also let us retain the opaque __oppref advertising referral value with a booking attempt in our protected conversion record. We do not decode it or include it in public pages, logs or owner reports. Only if the separate server integration is enabled may a payment-verified booking event carry that value to OpenAI.
For security and reliability, our hosting provider may process limited technical information such as IP address, browser details, request time and low-cardinality error information. Provider booking identifiers are restricted to the protected booking journal and are not put in public responses, analytics or the operator dashboard.
Why we use it
We use booking and enquiry information to take steps at your request before a contract, perform the booking contract, provide the stay, take and reconcile payment, communicate with you, prevent duplicate reservations, protect the property and meet tax, accounting and other legal obligations.
We use the limited first-party CTA log for our legitimate interests in understanding whether public navigation and the direct-booking journey work, prioritising improvements and measuring their effect. It is not used for advertising profiles or cross-site tracking. You may object to this use by contacting us.
We use the essential fields in the first-party booking-funnel log for our legitimate interests in measuring whether quote, booking and hosted-checkout hand-off steps work and in diagnosing bounded failure stages. These essential fields are not used for advertising profiles or cross-site tracking. You may object to this use by contacting us. Any campaign and click attribution added to that log is used only with the advertising-measurement consent described below.
We use the limited client acknowledgment record for our legitimate interests in estimating how often a returned quote reaches the visible booking step. It is not proof that a person viewed the quote, and is not used to identify visitors or for advertising profiles or cross-site tracking. You may object to this use by contacting us.
With your consent, we use Google Analytics, Google Ads measurement, Meta Pixel, Meta Conversions API, OpenAI Ads Measurement Pixel and OpenAI Conversions API to understand which advertising and website journeys lead to delivered booking enquiries and confirmed paid bookings, prevent duplicate conversion reporting and improve advertising effectiveness. You can refuse or withdraw this consent at any time through the Cookie choices control without affecting essential booking functions.
We use limited security and reliability information for our legitimate interests in keeping the service safe, diagnosing failures and preventing fraud, balanced against your rights.
Services that process information
Lodgify provides availability, quotes, reservation management and the hosted checkout. Stripe processes card payments within that checkout. Cloudflare hosts and protects this website. Our email providers process booking and enquiry messages. Each provider processes information under its own contractual and legal responsibilities.
Google provides Analytics and Ads measurement. Meta provides Pixel, Conversions API and advertising measurement. Their scripts and non-essential cookies load only after an affirmative choice. Lodgify remains the authoritative source for availability, confirmed stays and booking value; platform-estimated purchases are not treated as confirmed bookings.
OpenAI provides Ads measurement for consented page and property views, checkout starts, delivered booking enquiries and payment-verified direct bookings. The Pixel may process the website origin, advertising attribution, browser and device information, an event identifier and booking value. If we enable the separate server integration, our server may also send the verified payment time, stay value, event identifier, booking-page URL and original opaque OpenAI referral value through OpenAI Conversions API. Our event code does not include guest names, email addresses, telephone numbers, messages or stay dates. OpenAI’s automatic advanced matching may detect supported contact information entered on the page, normalise it and send a SHA-256 hash to match conversions to adverts; raw contact information is not sent through that matching feature. Events are marked to opt out of future user-level advertising personalisation.
Cookies and browser storage
The booking flow uses essential, tab-scoped session storage. Before submission it may keep the booking-attempt identifier for the selected stay. On submission it keeps the exact request bytes—including contact details, stay dates, party breakdown, accepted terms version and quoted amounts—so every retry, reload or return from Lodgify can resume only that UUID instead of creating another reservation. Those exact bytes remain while the attempt is resumable and through the hosted-checkout hand-off.
When payment is confirmed, the attempt enters manual review, or Lodgify verifies a rollback, the stored contact details and exact request bytes are replaced with a non-contact tombstone containing the attempt identifier, stay dates, party counts and terms version. A verified rollback can be explicitly restarted, which removes the tombstone; otherwise it remains only for the life of that browser tab. If the server proves that checkout stopped before any Lodgify write, the attempt is cleared immediately. Invalid stored records are removed when read.
The first-party CTA log does not set a browser cookie or local-storage identifier. Its same-origin request contains only the bounded fields described above.
The quote-display acknowledgment does not set a cookie or browser identifier. The short-lived receipt is returned with a valid quote and sent back after the quote step is shown by the site. We use a protected network-address key to limit repeated acknowledgments in a ten-minute window; daily maintenance deletes expired keys.
Your current advertising-measurement choice and its notice version are stored in local storage and in a same-site cookie named sbh_tracking_consent for up to 180 days. Choosing Reject removes known Google, Meta and OpenAI measurement cookies that this site can access. You can reopen the choice at any time using the Cookie choices control.
For server-side booking measurement, an affirmative choice also creates random, opaque browser-family and consent-scope identifiers in this browser. They are shared across tabs in first-party local storage and cookies. The cookies expire after 180 days; local storage is cleared when you reject or when you next visit after consent expires. These identifiers are not guest names or contact details. Reject clears their cookies and queues a server withdrawal for every known family; if offline, the browser retries when it reconnects. A later acceptance creates new identifiers and cannot restore measurement for an earlier booking attempt.
After consent, advertising providers may set identifiers including _ga, _fbp, _fbc and OpenAI’s __oppref attribution cookie. OpenAI requests a 30-day lifetime for __oppref; browser restrictions may shorten it. Other consented campaign attribution can be retained for up to 90 days in this browser so a later direct-booking step can be linked to the consenting advertising visit. Withdrawal removes accessible advertising cookies and blocks new advertising measurement.
Retention and international processing
We keep confirmed booking, payment and communication records only for as long as reasonably needed to provide the stay, handle a complaint or legal claim, and meet tax or accounting duties. Short-lived booking coordination records are minimised and provider identifiers are scrubbed from the operational journal under its retention controls when no longer required.
The first-party CTA log is capped at the latest 1,000 accepted events rather than kept for a fixed calendar period; each older event is displaced as a newer one is accepted. Hashed retry-deduplication and rate-limit guard keys expire within two minutes.
The first-party booking-funnel log is capped at the latest 2,000 accepted events rather than kept for a fixed calendar period; each older event is displaced as a newer one is accepted.
Quote-display acknowledgment records are scheduled for deletion after 90 days. A failed scheduled cleanup may delay deletion until the next successful run.
Protected quote-acknowledgment rate-limit keys are eligible for deletion after ten minutes and are pruned by daily maintenance. A failed scheduled cleanup may delay deletion until the next successful run.
Consented campaign attribution attached to the first-party booking-funnel log is subject to the same 2,000-event cap. Protected advertising attribution, acceptance, dispatch and operations records, including any consented opaque OpenAI referral value, are retained for up to 13 months for seasonal comparison, deduplication and audit, then deleted or aggregated. Separate website booking and provider payment reconciliation records are operational records kept under the booking-record purposes and retention described above, whether or not you consent to advertising measurement. A previous notice choice does not authorise the expanded server processing; you must choose again under this notice.
Opaque server consent-scope and withdrawal records, including attempt withdrawal suppression, are retained for up to 15 months, separately from the 13-month advertising records. This longer suppression period prevents a delayed request from reactivating an old withdrawn scope while a booking might still await payment. A missing or expired grant blocks server advertising measurement across ad platforms.
Some service providers may process information outside the United Kingdom. Where this happens, the provider must use an applicable legal safeguard for the transfer.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or objection, and may withdraw consent where consent is the legal basis. Contact [email protected]. You may also complain to the UK Information Commissioner’s Office at ico.org.uk.