Privacy Policy
Hotel Melody Tents Ltd · 118 West End, Street, Somerset, BA16 0LR
Last updated: 14 June 2026
1. Introduction
Hotel Melody Tents Ltd (“Hotel Melody”, “we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy.
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and what rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Please read it carefully.
2. Data Controller
Hotel Melody Tents Ltd is the data controller for personal data collected through this website and in connection with Hotel Melody bookings and services.
Hotel Melody Tents Ltd
118 West End, Street, Somerset, BA16 0LR
3. Data Protection Contact
Our nominated data protection contact is Jeremy Saunders.
4. What Personal Data We Collect
4.1 Data You Provide to Us
- Name, email address, and telephone number
- Billing address
- Payment card details (processed securely by our payment providers, Kaboodle and Stripe; we do not store card numbers)
- Dietary requirements, health conditions, and accessibility needs (see section 6 on special category data)
- Content of enquiries, correspondence, and complaints
4.2 Data Collected Automatically
Where you decline cookie consent, all third-party tracking and analytics scripts are blocked. We may collect aggregated, anonymous usage metrics (such as total page views, button interaction counts, or average time on page) using our own internal tooling. This data is collected without cookies, without recording IP addresses, and without any device or user identifiers. It cannot be linked to any individual and therefore falls outside the scope of UK GDPR.
Where you consent to cookies, we and our third-party partners may additionally collect:
- IP address
- Device type, browser, and operating system
- Pages visited, time spent, and actions taken on our website
- Referral source (how you found us)
- Cookies and similar tracking identifiers set by third-party platforms
You can manage your cookie preferences at any time via the cookie settings link in our website footer.
4.3 Data Received from Third Parties
- Booking data from Kaboodle (name, email, telephone, billing address)
- Email engagement data from Klaviyo
- Email delivery and engagement data from Postmark (see section 4.4)
4.4 Transactional Email Data (Postmark)
We use Postmark to send transactional and service emails. We may collect delivery, open, and link-click information to understand whether emails are delivered, opened, and interacted with. This may include the recipient’s email address, message metadata, time of interaction, device and email client information, and IP-derived technical information. We use this data for service reliability, security, analytics, support, and improving our communications.
5. Cookies
We use cookies and similar technologies on our hotelmelody.co.uk. Cookies fall into the following categories:
| Category | Purpose | Consent required? |
|---|---|---|
| Strictly necessary | Required for the website to function (e.g. security, session management) | No |
| Analytics | Help us understand how visitors use the site (e.g. Google Analytics / GA4) | Yes |
| Advertising | Used by third-party platforms (Meta, TikTok) to show relevant adverts and measure campaign performance, including custom audience targeting | Yes |
| Functional | Remember your preferences and settings | Yes |
Our cookie consent banner is managed by CookieYes. You can update your preferences at any time via the cookie settings link in our website footer.
6. Special Category Data
We may request and retain information about dietary requirements, health conditions, and accessibility needs. This information constitutes special category data under UK GDPR and is processed only with your explicit consent, for the sole purpose of ensuring your safety and wellbeing and delivering appropriate services during your stay at Hotel Melody.
This data is handled with additional care, restricted to staff who require it for operational purposes, and is not used for any other purpose without your further consent.
7. Why We Process Your Data (Legal Bases)
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Processing and managing your booking | Performance of a contract |
| Communicating with you about your booking | Performance of a contract |
| Responding to enquiries and complaints | Legitimate interests |
| Sending marketing and promotional communications | Consent |
| Website analytics and service improvement (anonymised) | Legitimate interests (anonymised data outside UK GDPR scope) |
| Website analytics (where cookies consented to) | Consent |
| Advertising and retargeting (Meta, TikTok) | Consent |
| Processing special category data (dietary, health, accessibility) | Explicit consent |
| Internal CRM and business operations | Legitimate interests |
| Fraud prevention, security, and debt recovery | Legitimate interests / Legal obligation |
| Compliance with legal and accounting obligations | Legal obligation |
8. How We Store and Use Your Data
8.1 Internal Data Platform and CRM
Personal data collected through Hotel Melody’s operations — including bookings, website interactions, and marketing communications — is consolidated into a centralised data platform hosted on Supabase (see section 9). This platform forms the foundation of our internal customer relationship management (CRM) system and is used to manage and improve the services we provide to you.
If we expand the use of this data in a way that materially changes the purpose for which it was collected, we will notify you in advance and, where required, seek your consent.
8.2 Use of Artificial Intelligence
We may use artificial intelligence tools for the internal organisation, analysis, and distribution of data. Our intention is to use AI to help us understand our customers better, improve our services, and operate more efficiently — for example, to identify trends in booking behaviour, personalise communications, and support internal decision-making. This is limited to internal operational use; it does not involve automated decision-making with legal or similarly significant effects on you. We will never sell your data to any third party.
9. Third-Party Data Processors
We use the following third-party service providers (data processors) in the course of our operations. Each is engaged under a data processing agreement (or equivalent terms) and is required to process your data only on our instructions and in accordance with UK GDPR.
We will never sell your personal data to any third party.
| Processor | Purpose | Location |
|---|---|---|
| Kaboodle | Booking and ticketing platform | UK |
| Stripe | Payment processing | USA |
| Supabase | Database infrastructure and internal CRM | EU (Frankfurt) |
| Klaviyo | Email marketing and customer communications | USA |
| Postmark | Transactional and service email delivery; email engagement tracking (delivery, opens, link clicks) | USA |
| Google Analytics (GA4) | Website analytics | USA |
| Google Ads | Advertising | USA |
| Google Tag Manager | Tag and script management | USA |
| Google Fonts | Web font delivery | USA |
| Google reCAPTCHA | Bot and fraud prevention | USA |
| Google Maps | Embedded mapping | USA |
| Meta (Facebook / Instagram) | Advertising, retargeting, and custom audience matching | USA |
| TikTok | Advertising, retargeting, and custom audience matching | USA / Singapore |
| CookieYes | Cookie consent management | UK |
| myblocs.io Ltd | Web development agency responsible for website build and hosting infrastructure. Data is accessible to myblocs.io Ltd in the course of development and technical support, but is owned and controlled by Hotel Melody Tents Ltd. | UK |
10. International Data Transfers
Several of our processors operate outside the United Kingdom. Where personal data is transferred to countries that do not provide an equivalent level of data protection to the UK, we ensure appropriate safeguards are in place, including:
- UK adequacy regulations, where the destination country has been recognised as providing adequate protection
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office
- The UK–US Data Bridge, for US-based processors that have self-certified under that framework
All processors receiving your personal data are required to maintain appropriate technical and organisational security measures in line with UK GDPR.
11. Data Retention
We retain your personal data only for as long as is necessary for the purpose for which it was collected and to comply with our legal obligations. General guidelines:
- Booking and financial records are retained for a minimum of six years following the relevant transaction, in compliance with HMRC requirements
- Marketing data is retained until you unsubscribe or request deletion
- Website analytics data is retained in accordance with the relevant platform’s own retention settings
- Special category data (dietary, health, accessibility) is deleted once no longer operationally necessary
If you would like specific information about the retention period for a particular category of data, please contact us.
12. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access — to request a copy of the personal data we hold about you.
- Right to rectification — to request correction of inaccurate or incomplete data.
- Right to erasure — to request deletion of your data in certain circumstances.
- Right to restriction — to request that we limit how we use your data.
- Right to data portability — to receive your data in a structured, machine-readable format.
- Right to object — to object to processing based on legitimate interests, or to direct marketing at any time.
- Rights related to automated decision-making — to not be subject to a decision made solely by automated means that has a legal or similarly significant effect on you.
To exercise any of these rights, please contact us at support@hotelmelody.co.uk. We will respond within one calendar month of receiving your request. No fee is charged for exercising your rights unless a request is manifestly unfounded or excessive.
13. Requesting Deletion of Your Data
To request deletion of your personal data, please email support@hotelmelody.co.uk with the subject line “Data Deletion Request”. Please include your full name and the email address associated with your booking. We will acknowledge your request and process it in accordance with UK GDPR.
Please note that some data may be retained where we have a legal obligation to do so — for example, financial and transaction records required for tax purposes.
14. Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These measures include encryption in transit and at rest, access controls, and regular security reviews. However, no method of transmission over the internet is completely secure and we cannot guarantee absolute security.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, and will inform you directly where required.
15. Complaints
If you are concerned about how we have handled your personal data, please contact us in the first instance at support@hotelmelody.co.uk and we will do our best to resolve your concern promptly.
You also have the right to lodge a complaint directly with the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The current version will always be available on this page, with the “last updated” date shown at the top. Where we make material changes and hold a means of contacting you, we will notify you directly.
17. Contact
Hotel Melody Tents Ltd
118 West End, Street, Somerset, BA16 0LR
