Legal

Privacy Policy

How Keydesk handles personal information when you visit our website, contact us, subscribe to our updates, use a Keydesk account, or interact with a booking journey operated through Keydesk.

Effective date:

About this policy

This policy explains how Keydesk handles personal information when you visit our website, contact us, subscribe to our updates, use a Keydesk account, or interact with a booking journey operated through Keydesk.

Keydesk provides software for accommodation businesses, including holiday parks, campsites and glamping sites. If you are booking with an accommodation provider, that provider’s own privacy notice also applies. It explains why the provider collects and uses your booking information.

In this policy, “Keydesk”, “we” and “us” mean Keydesk, a business based in the United Kingdom. You can contact us about this policy at hello@keydesk.co.uk.

When Keydesk is a controller or a processor

We are a controller when we decide why personal information is used for Keydesk’s own activities. These include handling sales enquiries, sending our newsletter, administering Keydesk accounts and subscriptions, providing support, and protecting and operating our services.

An accommodation provider using Keydesk will normally be the controller of its guests’ and other customer information. The provider decides why it collects booking, stay and customer information and how long it needs that information. Keydesk supplies the software and normally processes that information on the provider’s behalf, under the arrangements between us and the provider. This includes information entered by the provider’s staff, supplied by a guest through Keydesk Direct, or received through an enabled integration.

These roles can differ even where information relates to the same person. For example, we may process a guest’s booking details for the provider while separately using limited technical records to keep the Keydesk service secure.

Information we handle

Depending on how you interact with Keydesk, we may handle:

  • Contact and business information: names, email addresses, telephone numbers, business or site names, websites, business addresses, accommodation type and information included in an enquiry.
  • Account information: authorised users’ names and contact details, invitations, login credentials in protected form, access roles, verification and sign-in records.
  • Booking and customer information held for providers: guest names and contact details, postal addresses, dates and accommodation choices, booking history and status, prices, notes, requests and communications.
  • Party and stay information held for providers: numbers of adults, children, infants and pets; names of party members; children’s ages where entered; and vehicle registration numbers.
  • Payment and billing information: subscription and booking amounts, invoices or payment status, payment-provider references, refund records and, where future collections are authorised, a payment-method identifier and limited card description such as brand, last four digits and expiry date.
  • Technical and security information: IP addresses and request information, browser and device details, session information, audit events, support-access records, errors and performance data.
  • Marketing and research information: newsletter preferences, survey responses, assessment scores, pages visited and campaign or referral information.

We receive information directly from you, from an accommodation provider, from someone making a booking, from an authorised account user, or from an integration or payment provider involved in the service.

Please avoid putting sensitive information into free-text booking notes or enquiries unless it is necessary. An accommodation provider controls the purposes for which information about its guests is collected.

Visiting our website, contacting us and research

Our public website receives the technical information needed to deliver pages and maintain security. We also use Google Analytics 4 and first-touch attribution information to understand visits and interactions. The attribution record can include the first landing page, referrer and campaign parameters. See Cookies and browser storage below.

If you submit a product enquiry, we use the details to review and answer it and to communicate about the enquiry. Submitting an enquiry does not, by itself, subscribe you to The Operator Brief.

If you opt in to The Operator Brief, we use your email address to send that newsletter and the product updates described at sign-up. You can unsubscribe through an email or contact us. Newsletter sign-up uses a confirmation step.

If you take part in our Operations Benchmark, we use the answers to analyse accommodation operations in aggregate. Supplying an email is optional. If you give one and ask to be notified, we use it to send the benchmark when published; it is kept separate from the analysis and does not add you to the Keydesk newsletter list.

Figures entered into the website’s calculators and checklists remain in your browser according to the reviewed implementation; those figures are not submitted to Keydesk. We may receive interaction events, such as when a tool is started or reset.

Creating and using a Keydesk account

We process account owners’ and authorised users’ details to set up accounts, issue invitations, verify contact details, authenticate users, assign access permissions, provide the service and respond to support requests. We record relevant account and security events, including sign-in attempts and actions taken in the application.

An accommodation provider controls which people it authorises to use its account and should keep those permissions current. Where our support staff are given access to help with an account, access can be recorded with a reason and audit information.

We use billing contact and subscription information to manage Keydesk’s own fees, subscriptions and related records. Stripe supports subscription billing and connected payment-account setup. Stripe may need business, representative or payment information for its services.

Guest and booking information

Accommodation providers can use Keydesk to keep customer profiles, make and manage reservations, record stay and party details, communicate with guests, manage payments and maintain booking histories. Provider staff may add internal booking notes, customer tags or restrictions. Information can also come from a guest booking journey or an enabled external integration.

For these provider purposes, Keydesk normally processes the information on the provider’s behalf. The provider is responsible for explaining its own purposes, lawful basis and retention to guests, and for deciding what information its staff should enter. We do not treat provider guest records as Keydesk’s own marketing list.

Keydesk Direct and guest access links

Keydesk Direct lets a guest search accommodation, begin a checkout, provide contact and address details, choose booking options and, where available, pay for a booking. A provider can also use secure links that let a guest provide stay details or let a payer view a payment schedule and manage an authorised payment method. These links do not require a general Keydesk guest account.

If enabled for a provider, an unfinished Direct checkout may be retained for a limited period so the guest can return to it and receive a recovery email. A checkout that becomes a booking, or has associated payment records, is retained with the related records rather than removed by the abandoned-checkout purge. The provider controls the booking purpose and relevant guest communications.

Address search can send the text or postcode entered for a lookup to our address-lookup provider, Loqate, so suggestions can be returned. Manual address entry is available.

Payments

Guest card-entry forms in Keydesk Direct use Stripe’s payment interface. The reviewed application stores payment and transaction records, payment-provider references, and limited saved-card details where a guest has authorised future collections. It does not have fields for storing full card numbers.

Accommodation providers may connect their Stripe accounts to accept guest payments. Depending on the provider’s settings and a payer’s authorisation, Keydesk can support deposits, balance requests, scheduled instalments, later collections, card updates and refunds. Payment status, reminders and related events may be visible to the provider’s authorised users.

Stripe also processes information under its own applicable terms and privacy information. The responsibilities of Keydesk, the accommodation provider and Stripe depend on the particular payment activity.

Emails and SMS

We use email for Keydesk account matters such as invitations, verification, password resets and subscription messages. These are delivered through a third-party transactional email provider on our behalf.

Accommodation providers can use Keydesk to send booking confirmations, stay-details requests, payment notices and other service messages to guests. Where configured, some messages are sent by SMS through a third-party SMS provider. Delivery records can include the recipient, subject or message preview, status and provider response.

A provider’s guest-service messages are separate from Keydesk’s own newsletter. Where a provider chooses to market to its guests, it is responsible for the applicable marketing rules and the preferences it records in Keydesk. Our own electronic marketing is subject to your sign-up choice and the applicable rules.

Integrations

If an accommodation provider enables an integration, booking, availability, pricing or related information may be exchanged with the selected service. The repository supports a Pitchup integration subject to activation settings, as well as calendar import and export connections. A calendar feed shared with another service can disclose availability dates. An external calendar feed may include text supplied by that service.

The accommodation provider decides which integrations to connect and is responsible for considering the other service’s privacy information. We use the information exchanged through an integration to provide the requested connection and to diagnose its operation.

Cookies and browser storage

The public website can use Google Analytics 4, which sets analytics identifiers and collects information about visits and interactions. It can also store first-touch attribution information in browser localStorage, recording the first page you landed on, the site that referred you and any campaign parameters in the address. These are used for measurement and attribution, rather than to deliver a page or complete a booking.

None of this runs unless you accept it. When you first visit, we ask whether to use analytics and offer accepting and declining as equally available choices. Until you accept, Google Analytics is not loaded at all, no analytics cookie is set and no attribution record is written. Declining, or simply not choosing, leaves the site fully working.

We remember your choice in your browser so we do not ask again. Storing that preference is necessary to honour it, so it applies whichever option you pick. You can change your decision at any time using the Cookie settings link in the footer of every page. If you decline after previously accepting, we also remove the analytics cookies and the attribution record already stored in your browser.

Our account and Direct applications use session technology to maintain logins, checkouts and secure-link journeys. Browser storage can also remember interface preferences or temporary choices, such as selected extras. Stripe may use browser technologies in its payment interface for payment and security functions.

How we use information as a controller, and our lawful bases

When Keydesk is the controller, we use personal information for these purposes and bases under UK data-protection law:

Purposes for which Keydesk acts as controller and the lawful basis relied on for each
PurposeLikely lawful basis
Responding to a requested product enquiry or taking steps towards a customer agreementSteps before a contract, where applicable; otherwise legitimate interests in answering business enquiries
Providing and administering a Keydesk customer account and subscriptionContract where the individual is party to it; otherwise legitimate interests in delivering and administering the business service
Billing, accounting and required recordsContract or legitimate interests as appropriate; legal obligation where a law requires the record
Sending The Operator Brief to people who sign upConsent
Sending a requested benchmark notificationConsent, given when you ask to be notified and supply an address
Measuring website use and attributionConsent, given through the cookie banner and withdrawable at any time from Cookie settings in the footer
Protecting the service, investigating misuse, maintaining logs and providing supportLegitimate interests in a reliable and secure service; legal obligation where applicable
Establishing, exercising or defending legal claimsLegitimate interests, where applicable

Where we rely on legitimate interests, we consider the purpose, necessity and your interests and rights. Where we rely on consent, you may withdraw it for future use at any time. We do not assign the accommodation provider’s lawful basis for its guest and booking processing in this policy.

The legal framework includes the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations, as amended.

Who receives information

We share information with service providers that help us host, operate, secure, measure, bill and communicate through Keydesk. Depending on the activity and enabled features, these include providers of website and application hosting, databases and backups, file storage, newsletter and email delivery, SMS delivery, website analytics, payments, address lookup, error monitoring and survey collection. We can provide the current list of these suppliers on request.

For provider-controlled guest information, relevant recipients can also include the accommodation provider’s authorised staff, Stripe for payments, messaging providers for guest notices, and external booking or calendar services that the provider enables. Some recipients, including payment and marketplace providers, may have their own responsibilities under privacy law.

We may disclose information where required by law, to protect legal rights, or as part of a business transaction subject to appropriate safeguards. We do not sell provider guest records as a Keydesk marketing product.

International transfers

A supplier or enabled integration may process information outside the UK. The location depends on the particular service, account settings and contractual arrangements; a supplier’s country of incorporation does not by itself establish where information is processed.

Where Keydesk is responsible for a restricted international transfer, we will use an applicable UK adequacy arrangement or another lawful transfer safeguard and make relevant information available on request.

The Keydesk application and its main database are hosted in the European Union. Some of our suppliers, including providers of analytics, email delivery, payments and website hosting, are based in or may process information in the United States. For those transfers we rely on the UK Extension to the EU–US Data Privacy Framework where the supplier is certified under it, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses included in the supplier’s data processing terms.

Retention

We keep personal information for as long as needed for the relevant purpose, taking account of customer instructions, account status, legal and accounting duties, security needs and disputes. Provider-controlled booking and customer records are handled under our arrangements with the accommodation provider. The provider decides its own retention requirements for those records.

The application has targeted expiry and deletion processes for some temporary records, including certain abandoned checkout intents and calendar diagnostic records. Those processes do not establish a single retention period for all Keydesk or provider data. Where Keydesk is the controller, we normally keep:

  • Enquiries and contact messages for up to 24 months after our last contact, unless you become a customer.
  • Newsletter subscriptions until you unsubscribe. After that we keep only what we need to make sure you are not emailed again.
  • Benchmark survey email addresses until the benchmark report has been sent, and no longer than 12 months after submission. Survey answers are kept without the email address for comparing results over time.
  • Account information for as long as the account is active. When an account ends, provider-controlled booking and customer records are deleted or returned within 90 days, unless the provider asks us otherwise or the law requires us to keep them.
  • Billing and accounting records for six years after the end of the financial year they relate to, to meet UK tax requirements.
  • Server logs for a short period, normally no more than 30 days.
  • Database backups on a rolling cycle, so deleted information leaves our backups within 30 days.

Security and support access

We use access controls, protected authentication, encrypted connections, audit records and operational monitoring to help protect the service. Authorised support access to an account can be recorded and limited. No online service can guarantee absolute security; we review and respond to issues under our operational processes.

Accommodation providers should keep their users’ permissions appropriate, protect credentials, and avoid entering unnecessary personal information into free-text fields.

Children’s information

Keydesk is a business service, and our website and customer accounts are aimed at adults acting for accommodation businesses. We do not offer Keydesk accounts directly to children.

A provider’s booking or stay-details process may include children in a travelling party. The service can record whether a party member is a child or infant, a name and an age where entered. This is used to administer the provider’s booking and stay requirements. Keydesk does not use those children’s details for its own marketing.

Your rights and how to make a request

Where Keydesk is the controller, you may have rights to access, correct or erase information, restrict or object to its use, receive portable information where applicable, and withdraw consent. These rights have legal conditions and exceptions. You can also object to direct marketing at any time.

Contact hello@keydesk.co.uk to make a request about information Keydesk controls.

If your request concerns a booking, stay, customer profile or other information held by an accommodation provider through Keydesk, contact that provider first. It normally decides how that information is used and is responsible for responding to the request. We will assist the provider as required by our arrangements and applicable law. If you contact us instead, we can help direct the request to the appropriate provider where possible.

You can raise a concern with us. You also have the right to complain to the Information Commissioner’s Office in the UK.

Changes and contact

We may update this policy when our services or legal obligations change. We will publish the revised version with a new effective date and provide additional notice where appropriate.

For privacy questions, contact hello@keydesk.co.uk.

We use cookies

We use cookies to analyse site traffic and personalise content. You can accept all cookies or reject non-essential ones. Read our Cookie Policy for details.