Hatch resource banner image for How to create and publish a privacy policy

How to create and publish a privacy policy

A clear Privacy Policy is a legal requirement that builds trust with your customers by showing them you handle their data responsibly.

You must create and publish a Privacy Policy if you collect, store, or use any personal information from your customers, such as names, email addresses, or phone numbers. This document is a legal requirement under UK GDPR and its main purpose is to transparently explain to your customers what data you are collecting, why you need it, how you use it, and how you keep it safe. Getting this right is not just about ticking a legal box; it’s about building trust and showing customers you respect their privacy.

Why is a Privacy Policy so important?

In the UK, the processing of personal data is governed by the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018. The Information Commissioner's Office (ICO) is the independent body that upholds these information rights. Failing to comply can lead to significant fines, but more importantly, it can damage your reputation.

A good Privacy Policy demonstrates professionalism and reassures your guests that you are a trustworthy business that handles their personal information with care.

What to include in your Privacy Policy

Your policy needs to be easy to understand and specific to your business. Avoid copying one from another website, as your data practices will be unique. Here are the essential sections you must include:

  1. Your Business Details: Clearly state your business name and provide contact details (like an email address or physical address) so people can get in touch with you about their data.

  2. The Types of Data You Collect: Be specific. List the exact types of personal information you gather. For a hospitality business, this could include:

    • Contact details (name, email address, phone number, postal address)
    • Booking information (dates of stay, special requests)
    • Payment information (credit card details, billing address)
    • Identification data (passport or ID details for foreign nationals, if required)
    • Sensitive information (e.g., dietary requirements or accessibility needs)
    • Technical data (IP addresses or cookie data from your website)
  3. How and Why You Use The Data: For each type of data you collect, you must explain your purpose and your 'lawful basis' for processing it. The most common reasons are:

    • To fulfil a contract: "We use your name and payment details to process your booking."
    • With consent: "We will only send you marketing emails if you have explicitly ticked a box to say you want them."
    • For a legal obligation: "We are required to keep financial records for at least six years for tax purposes."
  4. Data Sharing: You must disclose if you share customer data with any third-party companies. This commonly includes booking system providers, payment processors (like Stripe or PayPal), email marketing services (like Mailchimp), or your accountant.

  5. Data Security: Briefly explain the measures you take to protect the data you hold. You don’t need to give away technical secrets, but you can mention things like using secure servers, password protection, staff training, and only collecting the data you truly need.

  6. Data Retention: State how long you will keep personal data. This should be for as long as is necessary for the purpose you collected it for. For example, you might keep booking records for several years to comply with tax law, but you should delete a casual enquiry after a few months.

  7. Users' Rights: You must inform users of their legal rights regarding their data. Under UK GDPR, these include:

    • The right to be informed
    • The right of access
    • The right to rectification
    • The right to erasure
    • The right to restrict processing
    • The right to data portability
    • The right to object

    You should explain how a customer can exercise these rights, for example, by emailing you at a specific address.

How to create your policy

You don’t necessarily need a solicitor to write your policy, especially if your business is straightforward. You can use a reputable online policy generator or find templates on the ICO's website. However, you must customise any template to accurately reflect how your specific business operates.

Publishing your policy

Your Privacy Policy must be easy for people to find. Don't hide it. The best places to put a link to it are:

  • In the footer of every page on your website.
  • Next to any web form where you ask for personal data (e.g., a booking form or newsletter sign-up).
  • Within your booking confirmation emails.
  • In your terms and conditions.
Top Tip: Write your Privacy Policy for your customers, not for lawyers. Use clear, simple language and avoid confusing legal jargon. A policy that people can actually understand is far more effective at building trust than a document filled with complicated clauses.

Created by hatch. • Updated on April 9, 2026