This notice explains what personal information we use, why we use it, who we share it with and the choices available to you.
Website · bookings · guest app · The Lobster Pot Marras community · August 2026
1. Who we are
The Lobster Pot is the controller responsible for deciding how and why personal information is used in connection with our holiday accommodation, website, guest app and community.
| Controller / trading name | Charles Bond trading as The Lobster Pot |
|---|---|
| Postal address | 18 Dalden Grove, Seaham, County Durham, SR7 7DH |
| Privacy email | privacythelobsterpotseaham@gmail.com |
| Telephone number | 07539 766751 |
| ICO registration number | ZC227585 |
2. Information we collect
- Identity and contact details, including names, postal addresses, email addresses and telephone numbers.
- Booking information, including stay dates, guest and dog numbers, guest names, special requests and booking history.
- Payment and transaction information. Card details should normally be handled by the payment provider and not stored by us.
- Account and app information, including login identifiers, device information, notification preferences and app activity.
- Communications, complaints, feedback, reviews, damage reports and photographs supplied in support of an issue.
- Community information, including profile details, posts, photographs, comments and reactions shared with The Lobster Pot Marras.
- Technical information, including IP address, browser or device type, security logs, cookie identifiers and website usage information.
- Brand-guideline request information, including your name, company email address, company and intended use of our brand materials.
- Marketing preferences and records showing when and how consent or an objection was recorded.
- Accessibility, health or emergency information that you choose to provide where it is genuinely needed to support your stay.
3. How we obtain information
We receive information directly from you when you book, create an account, use the app, join the community, contact us or choose marketing preferences. We may also receive booking details from an authorised booking platform, payment confirmation from a payment provider, technical information from our website/app systems and necessary information from another member of your booking party.
4. Why we use information and our lawful bases
| Purpose | Typical information | Lawful basis |
|---|---|---|
| Administer bookings, payments, check-in and the stay | Identity, contact, booking and transaction details | Contract; legal obligation where applicable |
| Operate app accounts and deliver guest information | Identity, booking, account, device and usage details | Contract; legitimate interests in providing and securing the service |
| Manage safety, access, incidents, damage and complaints | Booking, communications, photographs and incident details | Contract; legal obligation; legitimate interests; legal claims |
| Maintain financial, tax and booking records | Booking and transaction records | Legal obligation; legitimate interests |
| Provide newsletters, offers and return-stay marketing | Contact details, booking history and preferences | Consent or, where all legal conditions are met, the customer soft opt-in |
| Send app push promotions | Device token and notification preferences | Consent |
| Operate The Lobster Pot Marras community | Profile, posts, images, comments and moderation records | Contract/community terms; legitimate interests; consent where appropriate |
| Secure, maintain and improve our services | Technical logs, diagnostics and limited usage information | Legitimate interests; consent where required for device storage or access |
| Provide and monitor access to brand guidelines | Name, company email address, company and intended use | Legitimate interests in protecting and managing our brand assets |
| Establish, exercise or defend legal claims | Relevant booking, communication, incident and payment information | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we consider whether the use is necessary, whether you would reasonably expect it and whether your rights override our interests. You may ask for information about this assessment.
5. Special category and accessibility information
Please provide health or accessibility information only where it is relevant to safely supporting the stay. Depending on the circumstances, we may use explicit consent, vital interests or another condition permitted by law. Such information will be restricted and deleted when no longer needed.
6. Service messages and marketing
Booking confirmations, payment reminders, access instructions, safety notices and messages needed to provide the stay are service communications. They are not promotional marketing.
Marketing is optional. Consent requests will be separate from the booking terms and will not use pre-ticked boxes. Every marketing email will provide an unsubscribe route, and app notification preferences can be changed through the device or app settings. Withdrawing consent does not affect earlier lawful use of information.
Where we rely on the customer soft opt-in for email or text marketing, it will be limited to our own similar accommodation and guest services. You will be offered a clear opt-out when details are collected and in every subsequent message.
7. Who we share information with
We share only what is reasonably necessary with service providers and other recipients, which may include:
- Booking and property-management providers.
- Payment processors and banks.
- Website hosting, database, authentication, app and IT support providers.
- Email, messaging and notification providers.
- Housekeeping, maintenance and emergency contractors where information is needed to support the stay.
- Professional advisers, insurers, fraud-prevention services, courts, regulators, police or public authorities where lawful and necessary.
- Local businesses only where you ask us to make an introduction, booking or claim an offer requiring your information.
Current providers must be completed following the final technical build:
| Service | Provider | Purpose / location |
|---|---|---|
| Booking management | Bookalet PRO | Bookings, availability and guest communications |
| Payments | Stripe | Secure payment processing |
| Website hosting | Netlify | Website delivery and security |
| App/database/login | To be confirmed | Guest accounts, content and notifications |
| Email/newsletter | Gmail; newsletter provider to be confirmed | Service and marketing emails |
| Analytics | None currently; any future provider will be added here | Optional website analytics |
| Push notifications | To be confirmed | Optional app notifications |
8. International transfers
Some technology providers may process information outside the United Kingdom. Where this occurs, we will use an adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard, and will complete this section once the final providers and hosting locations are known.
9. How long we retain information
| Record | Indicative retention |
|---|---|
| Booking, contractual and financial records | Normally six years after the end of the relevant stay, or longer where tax law requires. |
| Routine guest communications | Normally up to two years after the stay unless required with the booking record or a dispute. |
| Complaints, incidents, damage and legal claims | Normally six years after resolution, depending on the nature of the matter. |
| App account | While active, then normally deleted or anonymised within two years after the last stay or account activity. |
| Community posts and profile | Until removed by the member, account closure, moderation or community closure, subject to backup and legal needs. |
| Marketing records | Until opt-out or consent withdrawal; a minimal suppression record may be retained to respect the choice. |
| Technical and security logs | Normally between 30 days and 12 months depending on purpose and security requirements. |
| Brand-guideline requests | Normally up to three years so that we can record authorised use and respond to brand enquiries. |
| Accessibility or health information | Deleted promptly after the stay unless needed for an incident, legal obligation or future stay at your request. |
These are working retention periods and should be confirmed against the final systems, accounting status, insurance requirements and operational needs.
10. Security
We use appropriate technical and organisational measures intended to protect personal information, including access controls, secure authentication, restricted administrator access, supplier checks, software updates, backups where appropriate and procedures for responding to suspected data incidents. No internet service can be guaranteed completely secure.
11. Your rights
Depending on the circumstances, you may have rights to be informed, obtain a copy of your information, correct it, request deletion or restriction, object to particular uses, receive certain information in a portable format and withdraw consent. You also have an absolute right to object to direct marketing.
To exercise a right, contact the privacy email in section 1. We may need information to verify identity. We will respond within the period required by law and will explain if an exemption applies.
12. Data-protection complaints
Please contact us first so that we can investigate. We will provide an accessible electronic route for complaints, acknowledge a data-protection complaint within 30 days and respond without undue delay. You may also complain to the Information Commissioner’s Office at ico.org.uk or telephone 0303 123 1113.
13. Children
Bookings must be made by a lead guest aged at least 21. The app and community are not intended for independent use by children. Adults should not post children’s personal information or images without appropriate authority and careful consideration of their privacy.
14. Third-party links and community visibility
Our services may link to independent websites and local businesses. Their privacy practices are their responsibility. Information posted in a community may be visible to other members according to its settings. Do not post booking codes, access instructions, financial information or another person’s private information.
15. Changes to this notice
We will review this notice regularly and update it when our systems or uses of information change. Material changes will be brought to the attention of affected users before the new use begins where required.