Legal
Privacy Policy
Last updated: 28 May 2026
This Privacy Policy explains how Oxford Retreat collects, uses and protects your personal data when you visit this site or submit a booking enquiry. We comply with the UK GDPR and the Data Protection Act 2018.
1. Who we are (data controller)
The data controller is [Owner trading name], with its principal address at [address]. For any privacy question, contact us at [email protected] or 07458 114872.
2. Data we collect
You give us directly (booking form)
- Full name
- Email address
- Phone number
- Requested check-in and check-out dates
- Number of adults and children
- Any message you choose to write
Collected automatically
- IP address (used for fraud-prevention and rough country-level analytics)
- Browser and device information (user agent)
- If you accept marketing cookies: Meta Pixel identifiers (
_fbp,_fbc) and page interaction events
3. Why we use it & legal basis
- To handle your booking enquiry — contact details, dates, guest count and message. Legal basis: performance of a contract (or taking steps to enter into one) — Art. 6(1)(b) UK GDPR.
- To run and secure the site — IP address, browser info. Legal basis: legitimate interests — Art. 6(1)(f).
- To measure marketing effectiveness — Meta Pixel events sent to Meta via the browser and the Meta Conversions API server-side, with email/phone hashed (SHA-256) before transmission. Legal basis: consent — Art. 6(1)(a). You can withdraw consent at any time below.
4. Who we share it with (processors)
- Resend (resend.com) — delivers the booking-enquiry email to the owner. Hosted in the US/EU; appropriate safeguards (Standard Contractual Clauses) in place.
- Meta Platforms Ireland Ltd. — only if you accept marketing cookies. Personal data is hashed client-side before transmission. Onward transfer to Meta in the US is governed by the EU-US/UK-US Data Privacy Framework where applicable.
- Hosting provider — [hosting provider] serves the site and handles routine request logs.
We do not sell your personal data.
5. International transfers
Some of our processors are based outside the UK. Where data leaves the UK, we rely on UK-approved transfer mechanisms (Standard Contractual Clauses with the UK addendum, or the UK Extension to the EU-US Data Privacy Framework).
6. How long we keep it
- Booking enquiries — up to 24 months from your last contact, then deleted or anonymised. We may keep records longer where required by law (e.g. tax or accounting purposes).
- Web server / security logs — up to 30 days.
- Cookie / marketing data — see our cookie table below; most cookies expire within 90 days.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data deleted (where applicable).
- Restrict or object to certain processing.
- Request a portable copy of your data.
- Withdraw consent for marketing cookies (without affecting prior processing).
- Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).
To exercise any of these rights, email [email protected].
8. Cookies
We use the smallest set of cookies practical. Optional categories load only after you give consent.
- Essential — your consent choice itself, stored in
localStorageasconsent.v1. Required to remember what you picked. No third-party transmission. - Marketing (only with consent) — Meta Pixel cookies
_fbpand_fbc, used to attribute ads. Expire after 90 days.
You can change your preferences at any time:
9. Security
We use HTTPS in transit, scoped access to the inbox that receives bookings, and hashing of PII sent to Meta. No system is perfectly secure; if you suspect a breach, please contact us immediately.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced on the site. The current version always applies from the date shown at the top of the page.