The part that matters
Wedding directories usually make their money by selling the same enquiry to several venues. That is the business model we are built against. When you send an enquiry through this site:
- It goes to exactly one named hotel — the one whose page you sent it from.
- It is never sent to a second venue, a competing hotel, or a “matched” list.
- It is never sold, rented, or passed to a lead broker, an advertiser, or a data broker.
Hotels pay us per enquiry we deliver. That is the whole commercial relationship. Reselling your details would pay us twice for the same work and break the only thing that makes this site worth using, so it is not a promise we are likely to get bored of.
Who we are
Hotel Weddings publishes hotelweddings.com and decides what happens to the personal data described here — which makes us the controller under UK GDPR and the EU GDPR. Write to privacy@hotelweddings.com about anything on this page.
The registered company name and postal address that belong in this section are not settled yet. They go in before this policy is doing real work, and they are the first thing on the solicitor's list.
What we collect, and why
We ask for the least we can and still have a hotel able to reply to you. There is no account to create and no profile to build.
When you send an enquiry to a hotel
Your name, email address, and — only if you fill them in — phone number, wedding date and whether it is flexible, rough guest count, budget range, and whatever you write in the message box. We also record which page you sent it from, so we can tell the hotel where you found them.
If you tick “After our wedding, invite us to share it”, we record that you did and when, and we may email you once after your wedding date to ask whether you would like it featured on the hotel's page. Nobody who leaves the box unticked gets that email, and you can say no, or ask us to forget it, at any time.
When you ask about a room block
Your name, email address, the venue or city, your dates and how many nights, a rough guest count, and a budget band.
When you claim a hotel profile
Your name, work email, phone number if you give one, your role, and which hotel you are claiming for. This is work contact data about you as a member of hotel staff, not personal life data.
If you answer the one question after sending
After an enquiry or a claim we may ask one optional question, like how you found us, with a few fixed answers to pick from. We store the answer you picked, the page and the time, and nothing else: not your name, not your email, not which enquiry it followed. It cannot be traced back to you.
When an enquiry is refused
Some submissions never become an enquiry: a malformed email address, an impossible wedding date, a burst of submissions from one address in an hour, or a bot that filled the hidden field no human can see or reach. When that happens we log the email address, the venue, the page and the reason, so we can tell how often real people are being turned away by mistake. We keep that separate from enquiries, and we never send it to a hotel.
Two related things happen to enquiries that do go through. We count how many arrive from one connection in an hour, purely as an abuse ceiling — and we do that without keeping your IP address: it is turned into a one-way scrambled value that can be matched against itself for an hour and is useless for identifying anyone. And if you write to the same hotel twice within 90 days, we link the second to the first — both reach the hotel, but the hotel is only billed once. Neither is a judgement about you.
When you just read the site
Nothing that identifies you, unless you press Accept on the cookie banner. Our hosting provider records ordinary server logs — IP address, the page requested, the time — for security and debugging. See the cookie policy for what is and is not set in your browser.
What we never ask for
We do not ask for payment card details — no part of this site takes a payment from a couple. We do not ask for anything in the special-category list under Article 9: health, religion, ethnicity, sexuality. Please keep them out of the message box too. A hotel can quote your wedding without knowing your religion, and we would rather not be holding it. If you do write something like that, it travels to the hotel with the rest of your message and we delete it on the schedule below.
Our legal basis for each of those
UK GDPR and the EU GDPR require a stated basis for every use. Ours, plainly:
Swipe the table sideways to see every column.
| What we do | Basis | In plain words |
|---|---|---|
| Send your enquiry to the hotel you chose | Steps taken at your request before a contract — Art. 6(1)(b) | Forwarding it is the thing you asked us to do. Without it there is no enquiry. |
| Reply to you about that enquiry | Art. 6(1)(b) | Same job. For example, telling you the hotel's address bounced. |
| Handle a hotel's claim of its profile | Legitimate interests — Art. 6(1)(f) | We have to check a real person at that hotel asked, or anyone could claim anyone. |
| Analytics cookies | Consent — Art. 6(1)(a), and PECR / the ePrivacy rules for the cookie itself | Only after you press Accept. Reject and nothing is set. |
| Server logs, the refused-submission log, and the hourly abuse ceiling | Legitimate interests — Art. 6(1)(f) | Keeping the site up and keeping fake enquiries off hotels' desks. A hotel billed for a bot is the failure this prevents. |
| Keeping a record of enquiries we billed a hotel for | Legitimate interests, and legal obligation for accounting records | We invoice per delivered enquiry, so we have to be able to show it happened. |
Where we rely on legitimate interests you can object, and we will stop unless we have a reason that overrides it — see your rights. Where we rely on consent you can withdraw it at any time, and withdrawing does not undo what happened before.
Who else sees it
Three groups, and no others:
- The one hotel you sent an enquiry to. They get your name, contact details and what you told them about the wedding. From that point they hold it as their own controller, under their own privacy policy, and what they do with it is theirs to answer for — so if you want them to delete it, ask them as well as us.
- The suppliers that run the site for us, listed below. They process on our instructions and cannot use your data for their own purposes.
- Anyone we are legally required to give it to — a court order, a regulator. We have never had such a request; if that changes and we are allowed to tell you, we will.
If Hotel Weddings is ever sold, enquiry data would move with the business. A buyer would be bound by this policy for data collected under it — including the single-hotel promise.
Suppliers, and where your data goes
Swipe the table sideways to see every column.
| Supplier | What it does here | What it sees |
|---|---|---|
| Vercel | Hosts and serves the site | Every request: IP address, page, time, browser |
| Supabase | The database that stores hotel data, venue enquiries, room-block requests and hotel claims | Your enquiry, room-block request or claim, as submitted |
| Formspree | Delivers hotel claims and room-block requests to our inbox wherever the database route is not switched on yet | Those forms' contents |
| Resend | Sends us an email alert for each enquiry, room-block request and hotel claim, so none sits unseen | What you submitted, as you submitted it |
| Google Analytics 4 | Counts page views, and which filters, calculators and forms are used (never what you type in them) — only if you accept cookies | Nothing at all unless you accept |
All five are US companies, so personal data reaches the United States. Transfers out of the UK and the EEA rely on the safeguards in each supplier's own data-processing terms — standard contractual clauses, the UK addendum to them, or the EU–US and UK–US Data Privacy Framework. We have not yet countersigned and checked each one. That is on the pre-launch list, and it is on the solicitor's list too.
Our database is hosted in India, in Supabase's Mumbai region, so what you send through a form on this site is stored in India.
No advertising network, no tracking pixel, no data broker, no “partner” anything. There is no Meta pixel and no LinkedIn insight tag on this site.
How long we keep it
- Venue enquiries and room-block requests: 24 months from the day you send them, then deleted. Long enough to settle a billing question with a hotel, short enough that we are not sitting on a file about a wedding that happened two years ago.
- Hotel claims: for as long as that hotel has a claimed profile, plus 24 months.
- Emails you send us: 24 months.
- The refused-submission log: 12 months. Shorter than an enquiry, because it exists to show us a rate, not to keep a file on anyone.
- Server logs: our host's default retention — weeks, not years. We do not copy them anywhere or use them for anything except security and debugging.
- Analytics: 14 months. Our Google Analytics property keeps event data for 14 months, which is long enough to compare one wedding season with the last and is the shortest option that does that. Data linked to your browser is kept for 14 months from your latest visit. None of it exists unless you pressed Accept.
- Accounting records of what we invoiced a hotel: as long as tax law requires, which is longer than the above. Those are invoice records about a hotel, not a file about you.
Being straight about this: the site has not launched, so no enquiry, room-block request or hotel claim has been collected yet, and the automatic deletion job described above is written down as a commitment before it is written as code. It has to exist before the first enquiry does.
Your rights
If you are in the UK, Ireland, or anywhere else in the EEA, you have the rights below. We honour them for everyone who asks, wherever you are, because running two standards would be more work than running one.
- See it — ask for a copy of what we hold about you.
- Fix it — correct anything wrong.
- Delete it — ask us to erase it. Remember the hotel has its own copy; ask them too.
- Restrict or object — tell us to stop a particular use, including anything we do on legitimate interests.
- Take it with you — get what you gave us in a machine-readable file.
- Withdraw consent — for cookies, any time. See the cookie policy.
Email privacy@hotelweddings.com. We answer within one month, and we will not charge you or make you explain why.
If we handle it badly you can complain to a regulator. In the UK that is the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113). In Ireland it is the Data Protection Commission (dataprotection.ie). Elsewhere in the EEA it is your national data protection authority. You do not have to come to us first, though it is usually faster.
Automated decisions
We make none about you. There is no scoring of couples, no ranking of who gets a reply, no profiling.
We do test whether an enquiry is qualified — contactable, a date within range, a realistic guest count, not a duplicate, not spam. That test decides whether we invoice the hotel, not anything about you: your enquiry reaches the hotel either way. Nothing in it produces a legal effect for you or anything like one.
Children
This site is for adults planning a wedding. We do not aim it at children and we do not knowingly collect anything from anyone under 16. If you think we have, email us and we will delete it.
What we haven't settled
Listing these is better than implying they are done. Each is fixed before the matching part of the site goes live:
- The registered legal entity, its name, and its postal address.
- Signed data-processing terms with each supplier above, and the transfer mechanism each one relies on.
- The automatic deletion job that enforces the retention periods above.
- A solicitor's review of this entire page against UK GDPR, the EU GDPR and Irish law.
Changes
When we change this page we change the date at the top. If a change actually affects what happens to data we already hold — a new supplier, a new purpose — we will say so on the site rather than quietly reissuing the page. This version is dated 4 October 2026.
Contact
privacy@hotelweddings.com for anything on this page. Related: cookie policy and terms of use.