Clarion Suites Gateway
Privacy Policy
Gateway Park Hotels Pty Ltd (ABN 29 079 551 643)
Trading as Clarion Suites Gateway
Our commitment
Clarion Suites Gateway respects your privacy and is committed to handling personal information transparently, securely and in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Scope
This policy explains how the Hotel collects, holds, uses, discloses, secures and disposes of personal information in connection with accommodation, reservations, payments, guest services, website use, enquiries, marketing, security, fraud prevention and related hotel operations. Third-party booking platforms, payment providers and linked websites may have their own privacy policies.
2. Personal information we may collect
Depending on your interaction with the Hotel, we may collect:
- Name, contact details, address, date of birth and company or travel-agent affiliation;
- reservation, stay history, guest preferences, requests and service records; government-issued identification details and, where reasonably necessary, a secure image of the identification presented; payment and transaction information, including tokenised payment references and limited cardholder information permitted under payment security requirements; communications, complaints, incident reports and records of suspected fraud or unauthorised activity; CCTV footage in common and operational areas; website, cookie, device and online interaction information; and any other information you choose to provide or that is lawfully supplied by a booking partner, employer, travel agent or other authorised third party.
We seek to collect only the information reasonably necessary for our functions and activities. Where identification contains sensitive information, we will only collect it where permitted by law and, where required.
3. Why we collect and use personal information
- to arrange and provide accommodation and guest services;
- to verify identity, entitlement to occupy accommodation and authority to use a payment method;
- to prevent, detect and investigate fraud, identity misuse, chargebacks, theft, security incidents and unauthorised transactions;
- to process payments, deposits, refunds, accounts and financial records;
- to communicate with guests, respond to enquiries and resolve complaints;
- to protect guests, employees, the Hotel, Owners Corporation property and legitimate booking partners;
- to comply with legal, regulatory, insurance, audit and law-enforcement requirements;
- to improve our services and operations; and
- to send marketing communications where permitted, with an option to unsubscribe, only upon request.
4. Identity verification and ID image capture
The Hotel will ask a guest to present current government-issued photo identification at check-in or at another appropriate time. The reservation name, person checking in and identification should reasonably correspond. A live government digital identity may be accepted where the Hotel can reasonably verify it. Photographs, screenshots or copied images presented by the guest are not accepted as original identification.
Where reasonably necessary for fraud prevention, payment verification, security, chargeback management or risk management, authorised employees will securely capture an image of the identification presented. The Hotel will apply the following controls: capture will occur only on an approved Hotel device or approved secure system; the guest will be informed of the purpose of collection at or before capture.
Where sighting identification and recording that it was verified is sufficient, the Hotel may choose not to retain an image. The Hotel may decline or delay check-in where it cannot reasonably verify identity or payment authority, subject to applicable law and booking terms.
5. Payment card information
The Hotel handles payment card information in accordance with applicable merchant requirements and the Payment Card Industry Data Security Standard (PCI DSS). The Hotel does not photograph or retain images of payment cards as part of the check-in process. Guests may transact using an accepted physical card or a live digital wallet through the payment terminal.
Card verification values (CVV/CVC/CID), PINs, PIN blocks, full magnetic-stripe data and equivalent chip data must not be retained after authorisation. Any cardholder data that must be retained for a lawful and documented purpose will be minimised, protected and securely deleted when no longer required. Approved virtual cards and third-party payment authorities are subject to the Hotel’s verification and fraud-prevention procedures.
6. How we collect information
We may collect information directly from you in person, by telephone, email, forms, our website, a digital service or during your stay. We may also receive information from Choice Hotels, online travel agents, travel management companies, employers, corporate clients, payment providers, authorised representatives and other booking partners. Where reasonable and practicable, we will make you aware of information received from a third party.
7. Disclosure of personal information
We may disclose personal information only where reasonably necessary for the purposes described in this policy, where you consent, or where required or authorised by law. Recipients may include:
- Choice Hotels and authorised booking, loyalty and distribution partners;
- payment processors, banks, merchant service providers and fraud-prevention providers;
- technology, cloud, security, records-management and professional service providers;
- insurers, auditors, legal advisers and debt-recovery providers;
- the Owners Corporation or Owners Corporation Manager where legitimately connected to building safety, security or an incident; and
- police, regulators, courts and other authorities where required or authorised by law.
Service providers are expected to handle information securely and only for the authorised purpose. Some providers may store or process information outside Australia; where this occurs, the Hotel will take reasonable steps required by the APPs.
8. Retention and secure disposal
The Privacy Act does not prescribe one universal retention period. The Hotel retains personal information only for as long as it is reasonably needed for a lawful business purpose or as required by law, then takes reasonable steps to destroy or de-identify it. The following schedule is the Hotel’s default operational standard:
| Information category | Default retention period | Key controls / exceptions |
|---|---|---|
| Government ID image | 180 days after check-out | Delete earlier where no longer needed. Retain longer only for an active fraud, chargeback, safety, insurance, legal or law-enforcement matter, then delete when the matter and any required review period are complete. |
| ID verification record (without image) | Up to 2 years after check-out | Record only what is necessary, such as ID type, that it was sighted, date/time and staff identifier. Avoid recording full document numbers unless required. |
| Reservation, folio and financial transaction records | Generally, 7 years after the relevant financial year or transaction | Subject to accounting, taxation, audit, contractual and legal requirements. Payment data remains subject to PCI DSS and data minimisation. |
| Payment card data | Only for the documented legal, regulatory or business need | Never retain CVV/CVC/CID, PIN/PIN block, full track data or equivalent chip data after authorisation. Securely delete permitted cardholder data when no longer required. |
| CCTV footage | Normally 30 days | May be retained longer where footage relates to an incident, complaint, investigation, insurance claim or legal requirement. |
| Complaints, incidents, fraud and chargeback files | 7 years after closure, where reasonably necessary | Review at closure and minimise supporting identity documents. Longer retention only where required by law or an unresolved claim. |
| Marketing records | Until consent is withdrawn, the individual unsubscribes, or the record is no longer needed | Maintain suppression records where needed to honour an opt-out. |
| Website and security logs | Up to 12 months | Longer only where needed for cyber-security investigation, fraud prevention or legal requirements. |
Legal holds: destruction will be suspended where the Hotel reasonably anticipates or is involved in a dispute, chargeback, investigation, insurance claim, litigation, regulatory inquiry or law-enforcement request. Retention will be reviewed when the hold ends.
9. Security of personal information
The Hotel takes reasonable technical, physical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, strong passwords, multi-factor authentication, encryption, restricted folders, logging, staff training, secure disposal, vendor controls and incident-response procedures.
No employee may use a personal device, personal email account, consumer messaging service or unauthorised cloud service to capture, store or transmit guest identification or payment information.
10. Data breaches
The Hotel maintains procedures to assess and respond to suspected data breaches. Where the Notifiable Data Breaches scheme applies, the Hotel will notify affected individuals and the Office of the Australian Information Commissioner when required.
11. Cookies, website use and third-party services
Our website may use cookies and related technologies to support functionality, analytics and advertising. You may adjust browser settings and available advertising preferences. Reservations and other services may be delivered through third-party platforms that have their own privacy practices. We encourage you to review those policies before submitting information.
12. Access and correction
You may request access to personal information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading, subject to permitted exceptions. We may require reasonable proof of identity before responding. We will not charge for making a request, although a reasonable administrative fee may apply for providing access where permitted.
13. Complaints and enquiries
Privacy enquiries or complaints should be directed to:
Clarion Suites Gateway Melbourne
1 William Street, Melbourne VIC 3000 Australia
Email: accounts@clarionsuitesgateway.com.au
We will investigate and respond within a reasonable period. You may also contact the Office of the Australian Information Commissioner if you are not satisfied with our response.
14. Changes to this policy
The Hotel may update this policy from time to time to reflect operational, legal, regulatory or technological changes. The current version will be published through the Hotel’s usual channels and will apply prospectively from its effective date.