Privacy Policy

Privacy Policy

Last updated: 10 August 2026

1. About this Privacy Policy

Rose & Crown (Holbeach) Ltd is committed to protecting the privacy and personal information of our guests, customers and visitors.

This Privacy Policy explains how Rose & Crown (Holbeach) Ltd collects, uses, stores and shares personal information when you:

  • visit or stay at the Rose & Crown;
  • make or enquire about an accommodation or campsite booking;
  • make a restaurant or other reservation;
  • purchase goods or services from us;
  • use our website;
  • use our Guest Wi-Fi;
  • contact us by telephone, email, social media or another method; or
  • otherwise interact or do business with us.

We process personal information in accordance with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

Where the EU General Data Protection Regulation (EU GDPR) applies to our processing, we will also process personal information in accordance with its requirements.

Our separate Cookie Policy explains how cookies and similar technologies are used on our website and the choices available to you.


2. Who we are

Rose & Crown (Holbeach) Ltd is the data controller responsible for the personal information described in this Privacy Policy, except where another organisation acts as a separate data controller for its own purposes.

You can contact us about this Privacy Policy or the way we use your personal information at:

Rose & Crown (Holbeach) Ltd
Rose & Crown
1 Low Road
Holbeach Hurn
Lincolnshire
PE12 8JN

Telephone: 01406 426085
Email: [email protected]


3. What is personal information?

Personal information, sometimes referred to as personal data, is information relating to an identified or identifiable living person.

Depending on how you interact with us, this may include information such as your:

  • name;
  • postal address;
  • telephone number;
  • email address;
  • booking details;
  • payment and transaction information;
  • vehicle details;
  • correspondence with us;
  • IP address;
  • device information;
  • CCTV image; and
  • information relating to an accident or incident involving you.

Some information is treated as particularly sensitive under data protection law and is known as special category personal data.

For example, information about an injury or medical condition recorded following an accident may constitute health information.


4. Personal information we collect

The personal information we collect depends on how you interact with us.

Booking and customer information

When you make an enquiry or booking with us, we may collect:

  • your full name;
  • postal address;
  • telephone number;
  • email address;
  • arrival and departure dates;
  • accommodation, pitch or unit type;
  • number of guests;
  • names or details of additional guests where reasonably required;
  • vehicle or vehicle registration details where required;
  • optional extras and services requested;
  • booking preferences or requirements;
  • communications relating to your booking;
  • payment and transaction information; and
  • other information reasonably necessary to administer your booking or provide the service you have requested.

Payments and transactions

When you make a payment to us, information about the transaction may be processed by us and by the payment service provider involved.

This may include:

  • your name;
  • payment amount;
  • transaction date and time;
  • payment method;
  • transaction reference;
  • payment status; and
  • other information required to authorise or administer the transaction.

Card payments are processed using third-party payment services. We do not generally receive or retain your complete payment-card details where these are processed directly and securely by a payment provider.

Information collected when you visit us

When you visit the Rose & Crown or our campsite, we may collect:

  • booking and check-in information;
  • purchase and transaction information;
  • CCTV footage;
  • vehicle information;
  • correspondence, enquiries or complaints;
  • information relating to lost property; and
  • information concerning accidents, incidents or injuries where appropriate.

Information you provide when contacting us

If you contact us by telephone, email, social media or another method, we may collect:

  • your name;
  • contact details;
  • social media username or profile information;
  • the content of your enquiry or communication; and
  • information reasonably required to respond to you.

5. Information about other people

If you make a booking on behalf of other people, you may provide us with personal information relating to those guests.

You should only provide another person’s personal information where you are entitled to do so.

Where appropriate, you should also make the other members of your booking aware of this Privacy Policy.

We generally do not require personal information about every member of a booking unless it is reasonably necessary to provide the service, meet a legal requirement, deal with a particular request or protect the safety of our guests and premises.


6. Information we receive from third parties

We may receive personal information about you from third parties where you make a booking, payment or other arrangement through another organisation.

This may include:

  • accommodation and campsite booking platforms;
  • online travel agents;
  • reservation services;
  • payment providers;
  • businesses or organisations making a booking on your behalf; and
  • other service providers involved in administering your booking.

The information received will generally include information necessary to identify you and administer the booking, such as:

  • your name;
  • contact details;
  • booking dates;
  • accommodation or pitch requirements;
  • number of guests;
  • booking reference; and
  • payment or transaction status.

Where another organisation collects personal information directly from you, that organisation may also act as a separate data controller and its own privacy policy may apply.


7. Our booking system – Q-Book

We use Q-Book, provided by Queensborough Group, as our accommodation and campsite booking-management system.

Queensborough Group acts as a data processor on our behalf and processes personal information through Q-Book in accordance with our instructions.

We use Q-Book to create, receive and manage bookings and associated customer records.

Depending on your booking, information processed through Q-Book may include:

  • your name;
  • postal address;
  • telephone number;
  • email address;
  • arrival and departure dates;
  • accommodation or pitch details;
  • number of guests;
  • vehicle or booking information;
  • booking notes and preferences;
  • optional extras and services;
  • guest communications;
  • payment and transaction information; and
  • other information reasonably necessary to administer your booking.

Rose & Crown (Holbeach) Ltd remains the data controller responsible for determining why and how this information is used.


8. Website information

When you visit our website, certain technical information may be generated or collected automatically.

Depending on the services and cookies in use, this may include:

  • your IP address;
  • browser type and version;
  • device type;
  • operating system;
  • pages visited;
  • dates and times of visits;
  • links selected;
  • referring website;
  • session information;
  • technical and security information; and
  • information about how you use our website.

Our website is operated using the WordPress platform and associated website and hosting services.

Some technical information is necessary for our website to function correctly and securely.

Other information, such as analytics information, may be collected using cookies or similar technologies.

Where consent is legally required before a particular cookie or similar technology can be used, it will not be used until the required consent has been obtained.

Further information is available in our Cookie Policy.


9. Guest Wi-Fi

We provide Guest Wi-Fi using network equipment and systems operated at our premises.

When you connect to our Guest Wi-Fi, technical information may be generated and recorded by our network systems.

Depending on the device and network activity, this may include:

  • device information;
  • MAC address;
  • assigned IP address;
  • connection dates and times;
  • connection duration;
  • network events;
  • traffic and technical information; and
  • security and diagnostic logs.

We use this information where reasonably necessary to:

  • provide the Guest Wi-Fi service;
  • maintain the performance and security of our network;
  • diagnose technical problems;
  • protect our systems and other users;
  • prevent and investigate misuse;
  • identify network or cybersecurity incidents; and
  • enforce our Guest Wi-Fi Terms and Conditions.

Our lawful basis for this processing is our legitimate interests in providing and maintaining a reliable and secure Guest Wi-Fi service and protecting our network and users against misuse.

Network information is retained only for as long as reasonably necessary for these purposes, taking account of our network-system configuration, available storage, security requirements and the purposes for which the information is held.

Information associated with a particular security incident, suspected misuse, complaint or legal matter may be retained for longer where reasonably necessary.

Our Guest Wi-Fi infrastructure is primarily operated using equipment located on our premises.


10. CCTV

We operate an on-premises CCTV system at parts of the Rose & Crown and campsite.

CCTV is used where reasonably necessary for purposes including:

  • protecting customers, guests, employees and visitors;
  • maintaining the safety and security of our premises;
  • preventing and detecting crime;
  • protecting our buildings, equipment and property;
  • investigating accidents and incidents;
  • investigating suspected breaches of our site rules; and
  • establishing, exercising or defending legal claims.

Our lawful basis for operating CCTV is our legitimate interests in maintaining the safety and security of our customers, staff, premises and property.

CCTV footage may be reviewed following an accident, complaint, security incident, suspected criminal activity or other relevant event.

Access to CCTV footage is restricted to authorised persons.

Relevant footage may be disclosed where appropriate and lawful to:

  • the police or other law-enforcement authorities;
  • insurers;
  • legal or professional advisers;
  • courts;
  • regulatory authorities; or
  • another party where disclosure is necessary and permitted by law.

Routine CCTV recordings are automatically overwritten in accordance with our internal retention arrangements and are not retained for longer than reasonably necessary for the purposes for which the system is operated.

Where footage relates to a particular accident, incident, complaint, criminal investigation, insurance matter or legal claim, relevant footage may be extracted and retained for longer where reasonably necessary.

Our primary CCTV recording and storage system is located on our premises.

Appropriate CCTV signage is displayed at our premises.


11. Accidents and incidents

If you are involved in an accident or incident at our premises, we may record information about what happened.

This may include:

  • your name and contact information;
  • the date, time and location of the incident;
  • circumstances surrounding the incident;
  • details of witnesses;
  • information concerning any injury sustained;
  • action taken by us;
  • supporting photographs;
  • relevant CCTV footage; and
  • related correspondence.

Information about an injury or medical condition may constitute special category health data.

We may process accident and incident information where necessary to:

  • comply with applicable legal or regulatory obligations;
  • maintain appropriate health and safety records;
  • investigate accidents and incidents;
  • deal with insurance matters; and
  • establish, exercise or defend legal claims.

Where health information is processed, we will only process it where an additional lawful condition for processing special category information applies.

This may include circumstances where processing is necessary for the establishment, exercise or defence of legal claims or where another condition permitted by applicable data protection law applies.


12. How and why we use your personal information

Data protection law requires us to have an appropriate lawful basis for using personal information.

The lawful basis depends on why we are using the information.

Managing enquiries and bookings

We use personal information to:

  • respond to booking enquiries;
  • create and confirm bookings;
  • administer accommodation and campsite reservations;
  • administer restaurant or other reservations;
  • process amendments and cancellations;
  • communicate with you before, during and after your visit; and
  • provide the goods or services you have requested.

Lawful basis: Performance of a contract with you or taking steps at your request before entering into a contract.

Payments and transactions

We use relevant information to:

  • take and process payments;
  • administer refunds;
  • maintain transaction records;
  • manage accounts; and
  • deal with payment queries.

Lawful basis: Performance of our contract with you and compliance with applicable legal obligations.

Accounting and business records

We retain appropriate records where necessary for:

  • accounting;
  • taxation;
  • financial reporting;
  • audits; and
  • compliance with other legal requirements.

Lawful basis: Compliance with a legal obligation and, where appropriate, our legitimate interests in maintaining appropriate business records.

Customer service

We use personal information to:

  • respond to questions;
  • handle complaints;
  • resolve booking or service issues;
  • deal with lost property; and
  • provide customer support.

Lawful basis: Performance of our contract with you and/or our legitimate interests in operating our business and providing appropriate customer service.

Safety and security

We use information, including CCTV and relevant Guest Wi-Fi information, where necessary to:

  • protect customers, visitors and staff;
  • prevent and investigate crime;
  • protect our property;
  • investigate incidents;
  • maintain network and premises security; and
  • enforce reasonable site rules and conditions.

Lawful basis: Our legitimate interests in protecting our customers, staff, business, systems and property.

Website operation and improvement

We may use website information to:

  • operate and secure our website;
  • diagnose technical problems;
  • understand how our website is used; and
  • improve our website and services.

Lawful basis: Our legitimate interests in operating, securing and improving our website and, where required, your consent to cookies or similar technologies.

Legal and regulatory matters

We may process information where necessary to:

  • comply with applicable law;
  • respond to lawful requests from authorities;
  • comply with court orders;
  • maintain required records;
  • protect our legal rights; or
  • establish, exercise or defend legal claims.

Lawful basis: Compliance with a legal obligation and/or our legitimate interests in protecting and enforcing our legal rights.


13. Legitimate interests

Where we rely on legitimate interests as our lawful basis, we consider whether the processing is necessary and balance our interests against your rights, interests and reasonable expectations.

Our legitimate interests may include:

  • protecting customers, guests, staff and visitors;
  • protecting our premises and property;
  • maintaining the security of our IT and network systems;
  • preventing fraud, crime and misuse;
  • dealing with complaints and disputes;
  • maintaining appropriate business records;
  • providing and improving customer service;
  • improving our website and services; and
  • establishing, exercising or defending legal claims.

You may have the right to object to processing carried out on the basis of legitimate interests. Further information is provided under Your data protection rights below.


14. Marketing communications

We may occasionally use your contact information to send you information about our services, events, offers or other relevant promotions where we are permitted to do so by law.

Where consent is required before we send electronic marketing communications, we will obtain that consent.

In some circumstances, applicable electronic marketing rules may allow us to contact existing customers about our own similar goods or services, provided the applicable requirements are met and you were given an opportunity to opt out.

You can ask us to stop sending direct marketing communications at any time by:

  • using an unsubscribe option provided in the communication, where available; or
  • contacting us at [email protected].

We will not sell your contact information to third parties for their own marketing purposes.

Objecting to marketing will not prevent us from sending communications that are necessary to administer an existing booking or transaction.


15. Social media

If you interact with us through a social media platform, we may receive information such as:

  • your name or username;
  • information visible on your public profile;
  • comments, messages or posts you send to us; and
  • information you choose to share with us.

We may use this information to:

  • communicate with you;
  • respond to enquiries;
  • administer competitions or promotions where applicable; and
  • manage our social media presence.

Social media providers also process personal information for their own purposes and their own privacy policies will apply to that processing.


16. Who we share personal information with

We do not sell your personal information.

We share personal information only where reasonably necessary to operate our business, provide our services, process transactions, comply with legal obligations or protect our legitimate interests.

Booking services

We use Queensborough Group to provide our Q-Book booking-management system.

Queensborough Group acts as a data processor on our behalf and processes booking information in accordance with our instructions.

Payment providers

We use payment and transaction services provided by organisations including:

  • PaymentSense;
  • CyberSource;
  • Stripe; and
  • Dojo.

These organisations may process information including transaction details, payment information, device information, fraud-prevention information and other information necessary to authorise, process and administer payments.

Depending on the particular service and processing activity, a payment provider may act as a data processor on our behalf or as an independent data controller.

Where a payment provider acts as an independent data controller, it is responsible for its own processing and its own privacy policy will apply.

We do not generally receive or store your complete payment-card details where these are processed directly by a payment service provider.

Website services

Our website is operated using the WordPress platform and associated website and hosting services.

Information generated when you access our website may therefore be processed by organisations providing website hosting, security, technical or related services on our behalf.

Further information about cookies and related technologies is provided in our Cookie Policy.

Email and business communications

We use Google Workspace for our business email and related communications.

Personal information contained in emails, enquiries, booking correspondence or other business communications may therefore be processed using Google’s services.

IT, professional and business services

Where necessary, information may also be shared with:

  • our bookkeeper, accountants and other financial advisers;
  • IT and technical-support providers;
  • insurers;
  • legal advisers;
  • other professional advisers;
  • banks and financial institutions;
  • suppliers supporting our business systems;
  • and contractors providing services to us.

Where an organisation acts as a data processor, we require it to process personal information only for authorised purposes, in accordance with our instructions and subject to appropriate contractual and security requirements.

Some organisations, including our bookkeeper or accountants, payment providers, banks, insurers, professional advisers and public authorities, may act as independent data controllers for some or all of the personal information they receive. Where they do so, they are responsible for complying with data protection law in relation to their own processing.


17. Disclosure to the police and other authorities

We may disclose personal information to the police, courts, regulators, government bodies or other competent authorities where:

  • we are legally required to do so;
  • disclosure is required by a court order;
  • disclosure is necessary and lawful for the prevention or detection of crime;
  • disclosure is necessary to protect the safety or vital interests of an individual;
  • disclosure is necessary for the establishment, exercise or defence of legal claims; or
  • another lawful basis for disclosure applies.

Requests for personal information will be considered appropriately.

We will not disclose personal information merely because it has been requested where there is no appropriate lawful basis for doing so.


18. International transfers

Some of the third-party services we use, including certain website, email, booking and payment services, may involve personal information being stored, processed or accessed outside the United Kingdom.

Where this constitutes a restricted international transfer under UK data protection law, we will ensure that an appropriate lawful transfer mechanism is used.

Depending on the circumstances, this may include:

  • transferring information to a country covered by applicable UK adequacy regulations;
  • using approved contractual safeguards;
  • relying on another transfer mechanism permitted by applicable data protection law; or
  • relying on a permitted exception where appropriate.

Where required, we will also consider whether additional safeguards are necessary to ensure that personal information receives an appropriate level of protection.

Where the EU GDPR applies to our processing and personal information is transferred outside the European Economic Area, we will similarly ensure that an appropriate transfer mechanism is used in accordance with EU GDPR.


19. How long we keep personal information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, accounting, taxation, insurance, security and reporting requirements.

Different categories of information may therefore be retained for different periods.

When deciding how long information should be retained, we consider:

  • the purpose for which it was collected;
  • whether the information remains necessary for that purpose;
  • applicable legal and regulatory requirements;
  • accounting and taxation requirements;
  • contractual requirements;
  • insurance requirements;
  • applicable limitation periods for legal claims;
  • the nature and sensitivity of the information;
  • the amount of information held; and
  • the potential consequences of unauthorised use or disclosure.

Booking, transaction and accounting records may be retained after your booking or visit has ended where necessary to meet accounting, taxation, contractual or legal requirements.

Routine CCTV recordings are automatically overwritten in accordance with our internal retention arrangements. Relevant footage may be retained for longer where it relates to an accident, incident, investigation, complaint, insurance matter, legal claim or another legitimate purpose.

Guest Wi-Fi and network information is retained in accordance with our network-system configuration and only for as long as reasonably necessary to operate, maintain and secure the service. Information relating to a particular security incident, suspected misuse or complaint may be retained for longer where necessary.

Accident and incident information may be retained for as long as reasonably necessary to meet health and safety, insurance and legal requirements.

Where information is no longer required, we will delete it, securely dispose of it or anonymise it as appropriate.


20. Security of your personal information

We take appropriate technical and organisational measures to protect personal information against:

  • unauthorised access;
  • accidental or unlawful disclosure;
  • loss;
  • destruction;
  • misuse; and
  • unauthorised alteration.

Access to personal information is restricted to employees, contractors and service providers who have a legitimate reason to access it.

Where third parties process personal information on our behalf, appropriate contractual and security arrangements are used where required by law.

No method of transmitting or storing information can be guaranteed to be completely secure, but we take reasonable and proportionate steps to protect the information entrusted to us.


21. Is providing personal information mandatory?

Certain information is necessary for us to provide services to you.

For example, we require sufficient information to:

  • identify the person making a booking;
  • contact you regarding your booking;
  • reserve the requested accommodation, pitch, table or service;
  • process or verify payment; and
  • meet applicable legal requirements.

Where information is necessary for us to enter into or perform a contract with you and you do not provide it, we may be unable to accept, administer or fulfil your booking.

Other information may be optional. We will make this clear where appropriate.


22. Your data protection rights

Depending on the circumstances and the lawful basis on which we process your information, you may have the following rights.

Right of access

You may ask us to confirm whether we process your personal information and request a copy of the personal information we hold about you.

This is commonly known as a Subject Access Request.

Right to rectification

You may ask us to correct personal information that is inaccurate or complete information that is incomplete.

Right to erasure

In certain circumstances, you may ask us to delete your personal information.

This right does not apply in every situation. For example, we may need to retain information to comply with a legal obligation or establish, exercise or defend a legal claim.

Right to restriction

In certain circumstances, you may ask us to restrict the way in which we use your personal information.

Right to object

You may have the right to object to processing carried out on the basis of our legitimate interests.

You also have the right to object to the use of your personal information for direct marketing at any time.

Where you object to processing based on our legitimate interests, we will consider your objection and stop processing where required by law unless there are compelling legitimate grounds to continue or the information is required for the establishment, exercise or defence of legal claims.

Right to data portability

Where applicable, you may have the right to receive certain personal information you have provided to us in a structured, commonly used and machine-readable format and to request that it is transferred to another organisation.

Right to withdraw consent

Where we rely on your consent to process personal information, you may withdraw that consent at any time.

Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.

Rights relating to automated decision-making

You may have certain rights where a decision producing legal or similarly significant effects is made solely using automated processing.

We do not currently use personal information to make solely automated decisions about customers that produce legal or similarly significant effects.

Your data protection rights are subject to the conditions, limitations and exemptions provided by applicable law.


23. Exercising your rights

If you would like to exercise any of your data protection rights, please contact us:

Email: [email protected]
Telephone: 01406 426085

or write to:

Rose & Crown (Holbeach) Ltd
Rose & Crown
1 Low Road
Holbeach Hurn
Lincolnshire
PE12 8JN

You do not normally have to pay a fee to exercise your data protection rights.

We may ask you to provide information reasonably necessary to confirm your identity before providing personal information or acting upon certain requests.

We may also ask for additional information where reasonably necessary to identify the information covered by your request.

We will respond within the time limits required by applicable data protection law.


24. Data protection complaints

If you have a concern or complaint about the way we have collected or used your personal information, we encourage you to contact us in the first instance.

You can make a data protection complaint by emailing:

[email protected]

or by writing to:

Rose & Crown (Holbeach) Ltd
Rose & Crown
1 Low Road
Holbeach Hurn
Lincolnshire
PE12 8JN

We will:

  • acknowledge receipt of a data protection complaint within 30 days;
  • take appropriate steps to investigate the matter without undue delay;
  • keep you informed as appropriate; and
  • tell you the outcome of the complaint without undue delay.

You also have the right to make a complaint to the Information Commissioner’s Office (ICO), the independent UK regulator responsible for data protection.

Further information about making a complaint is available from the ICO.

Where the EU GDPR applies to our processing, you may also have the right to lodge a complaint with the competent data protection supervisory authority in an EU Member State.


25. EU GDPR

Rose & Crown (Holbeach) Ltd is established in the United Kingdom.

The fact that a customer or guest lives in an EU or EEA country does not necessarily mean that the EU GDPR applies to every interaction with us.

However, where our processing falls within the territorial scope of the EU GDPR, the applicable requirements and protections of the EU GDPR will apply to that processing.

References in this Privacy Policy to individual data protection rights should therefore be interpreted as including corresponding rights available under the EU GDPR where it applies.


26. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in:

  • our services;
  • our business operations;
  • the way we use personal information;
  • the systems and service providers we use;
  • applicable legislation; or
  • regulatory guidance.

The current version of this Privacy Policy will be published on our website.

Where appropriate, we may also notify customers of significant changes using another suitable method.

Last updated: 10 August 2026