Privacy Policy

Mandala Hotels & Resorts, ABN 69 639 566 895 (“Mandala”, “the Company”, “we”, “us” or “our”) is committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act), including the Australian Privacy Principles (APPs).

This Privacy Policy explains how we collect, hold, use and disclose personal information when you use our website, make a booking, stay at one of our properties, or otherwise interact with us (the “Service”). It also explains how you can access or correct your information, and how to make a privacy complaint.

We only collect, use and disclose your personal information as set out in this Policy, and in accordance with the Privacy Act. Where the law requires your consent — for example, before we collect sensitive information, or before we place non-essential cookies — we will seek it separately, in the relevant section below.

Quick summary

This section gives you the key points. The full detail is set out in the sections below.

  • We collect your contact, booking, payment and, where required for check-in, ID details — and only sensitive information (e.g. health or accessibility needs) with your consent. If you do not provide information necessary for a booking or legal identification requirements, we may be unable to complete your booking or provide accommodation.
  • Some information is collected because we are legally required to do so under applicable State or Territory accommodation laws.
  • We use your information to run your booking and stay, process payments, and (with an opt-out available at any time) send you marketing.
  • We share information only with trusted partners who help us operate — such as hosting, payment and booking providers — our affiliated properties, and, in limited cases, government bodies or advisers. We do not sell personal information.
  • Some service providers may hold or process information overseas; we take reasonable steps to protect it wherever it is held.
  • You can request access to, or correction of, your information at any time, free of charge, and you can ask for this Policy in an alternative format.
  • If you have a complaint, contact our Privacy Officer first, then the OAIC if you’re not satisfied — see Section 12.

1. Definitions

  • Account means a unique account created for you to access the Service.
  • Affiliate means an entity that controls, is controlled by, or is under common control with a party.
  • Cookies are small files placed on your device by a website to store information about your browsing activity.
  • Personal information has the meaning given in the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
  • Sensitive information is a category of personal information defined in the Privacy Act that includes health information, and information about matters such as racial or ethnic origin, religious beliefs, or membership of a professional or trade association — this attracts a higher level of protection under the APPs.
  • Service refers to the Mandala Hotels & Resorts website and related booking and guest services.
  • Service Provider means any third party that processes personal information on our behalf (e.g. IT hosting, payment processing, booking platforms).
  • You / your means the individual using the Service, or an entity on whose behalf an individual is acting.

2. The kinds of personal information we collect and hold

Depending on how you interact with us, we may collect:

  • Identity and contact information — name, email address, phone number, postal address, date of birth.
  • Booking and stay information — reservation details, arrival/departure dates, room preferences, loyalty program details, special requests.
  • Payment information — credit/debit card details and billing address (generally collected and processed by our payment processors on our behalf; we do not store full card numbers longer than necessary).
  • Government-issued identifiers — passport number, driver’s licence or other ID details where required for check-in, in line with legal requirements (e.g. hotel guest registration obligations). Where we use an ID scanner, a scanned image of your identification document, including the photograph contained on it, may be collected. We retain this information only for as long as required for guest registration purposes.
  • Sensitive information — where you volunteer it, such as dietary requirements, accessibility needs, or health information relevant to your stay. We only collect sensitive information with your consent, or where otherwise permitted by law, and only to the extent necessary to provide the Service.
  • Usage data — IP address, browser and device type, pages visited, time and duration of visits, and similar diagnostic data collected automatically.
  • CCTV and security footage — if you visit one of our properties, your image may be captured by security cameras operating in public areas, for safety and security purposes.
  • Communications — records of correspondence, enquiries, and feedback you provide to us.

Where practicable, we collect personal information directly from you. We may also collect information from third parties such as travel agents, booking platforms (e.g. Expedia, Booking.com), or corporate travel arrangers, where you have made a booking through them.

We only collect personal information that is reasonably necessary for our functions and activities.

3. Cookies and tracking technologies

We use cookies and similar technologies (such as web beacons/pixels) to operate the Service and to understand how it is used. These include:

  • Essential/session cookies — required for core website functionality (e.g. completing a booking).
  • Preference/functionality cookies — remember your settings and preferences.
  • Analytics cookies — help us understand usage patterns and improve the Service.

You can control or disable cookies through your browser settings, though some features of the Service may not work properly if you do. Where required by Australian law, we will seek your consent before placing non-essential cookies.

4. How we use your personal information

We use personal information for purposes including:

  • Providing, operating, and improving the Service and managing your bookings and stays
  • Verifying your identity and meeting legal guest-registration requirements
  • Processing payments
  • Communicating with you about your booking, enquiries, or requested services
  • Sending you marketing communications about offers, promotions, and news (see Section 5 — you can opt out at any time)
  • Managing loyalty programs
  • Internal business purposes such as analytics, service improvement, and fraud/security prevention
  • Complying with our legal obligations

We will only use or disclose personal information for the purpose it was collected for, a directly related secondary purpose you would reasonably expect, or another purpose permitted under the Privacy Act (e.g. with your consent or where required by law).

5. Direct marketing

We may send you direct marketing communications (including email, SMS and postal mail) where permitted by applicable law. Electronic marketing communications will comply with the Spam Act 2003 (Cth). You can opt out at any time by:

  • Using the “unsubscribe” link in any marketing email; or
  • Contacting us using the details in Section 12.

We will not charge you for opting out, and we will action your request promptly. Opting out of marketing will not affect our ability to send you service-related communications (e.g. booking confirmations).

6. Disclosure of your personal information

We disclose your personal information to the following:

  • Service providers who help us operate the Service — including IT and hosting providers, payment processors, booking/reservation platforms, and marketing service providers — under contractual obligations to protect your information.
  • Our affiliated hotel properties and related entities, for shared operational and guest-service purposes.
  • Government and regulatory bodies, where required or authorised by law (e.g. guest registration requirements, law enforcement requests).
  • Professional advisers (legal, accounting) as reasonably required.
  • A prospective buyer or related party, in the event of a business sale, merger, or restructure.
  • Other parties with your consent.
  • Third parties acting on your behalf — for example, a corporate travel booker, a family member, or a law enforcement or emergency service — where we reasonably believe disclosure is appropriate to the circumstances or required by law.

Overseas disclosure (APP 8)

Some of our service providers (for example, cloud hosting, payment processing, or global booking platforms) may store or process personal information outside Australia.

Before disclosing personal information overseas, we take reasonable steps to ensure the overseas recipient handles it consistently with the APPs — including through contractual protections — except where an exception under APP 8.2 applies (for example, where you have consented to the disclosure after being told we may not be able to seek redress under Australian law).

Where it is practicable to do so, we will specify the countries in which such overseas recipients are likely to be located. If it is not practicable to specify the countries, we will state this fact and the reasons why in response to any request for that information.

7. Data quality

We take reasonable steps to ensure the personal information we collect, use, and disclose is accurate, up to date, and complete. You can help by keeping your account and booking details current, and by contacting us if any information we hold about you needs correcting.

8. How we hold, secure and retain your information

Storage. We hold personal information in secure electronic systems, including systems hosted by third-party providers (for example, our property management, booking and cloud hosting providers) under contractual confidentiality and security obligations. Where relevant to a guest’s stay, we may link information across our booking, loyalty and stay records to provide a consistent Service — for example, linking a loyalty profile to a current reservation.

Security. We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These steps include technical safeguards (such as encryption and access controls) and organisational measures (such as staff training, audit and monitoring of internal access, and confidentiality obligations).

While we take reasonable steps to protect personal information, no method of electronic storage or transmission over the internet is completely secure.

If we experience a data breach that is likely to result in serious harm to affected individuals (an eligible data breach under the Notifiable Data Breaches scheme), we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals in accordance with our obligations under the Privacy Act.

Retention. We keep personal information only for as long as necessary for the purposes described in this Policy, or as required by law, after which it is securely destroyed or de-identified. As a guide:

  • Booking and stay records are generally retained in line with our tax and financial record-keeping obligations.
  • Guest registration and ID information is retained only for the period required by applicable guest registration laws, and then securely destroyed.
  • CCTV footage is generally retained for 30 days, unless required for longer as part of a security or legal investigation. CCTV is not used inside guest rooms.
  • Marketing contact details are retained until you opt out or, if earlier, in line with our routine data-quality reviews.

9. Access to and correction of your personal information

Under APPs 12 and 13, you have the right to request access to the personal information we hold about you, and to request that we correct it if it is inaccurate, out of date, incomplete, irrelevant, or misleading.

To make a request, contact our Privacy Officer:

  • Email: admin@mandalahotels.com.au
  • Phone: 1800 161 269
  • Post: Privacy Officer, Mandala Management, 72 Queen Street, Berry, NSW 2535

We will respond within a reasonable period (generally within 30 days). We may need to verify your identity before providing access. In limited circumstances permitted under the Privacy Act, we may need to refuse a request — if so, we will explain our reasons.

There is generally no charge to request access to or correction of your information.

10. Anonymity and pseudonymity

Where lawful and practicable, you may interact with us anonymously or using a pseudonym (for example, when making a general enquiry). However, this is often not practicable for bookings and stays, where we need to verify your identity for legal, safety, and operational reasons.

11. Children’s privacy

We do not knowingly collect personal information from children in a way that is inconsistent with the Privacy Act. Where a child does not have the capacity to understand the nature of their consent to provide personal information, we will seek consent from a parent or guardian where appropriate. If you believe we hold personal information about a child that shouldn’t have been collected, please contact us and we will take reasonable steps to address it.

12. How to contact us / make a complaint

If you have a question about this Policy, or wish to access, correct, or make a complaint about how we’ve handled your personal information, please contact:

Privacy Officer, Mandala Hotels & Resorts

  • Email: admin@mandalahotels.com.au
  • Contact page: https://mandalahotels.com.au/contact/
  • Phone: 1800 161 269
  • Post: Privacy Officer, Mandala Management, 72 Queen Street, Berry, NSW 2535

We will acknowledge your complaint and aim to resolve it within a reasonable time (generally 30 days).

If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992

13. Links to other websites

The Service may contain links to third-party websites not operated by us, including booking platforms. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We will post the updated policy on this page and update the “Last updated” date above. Where a change is likely to significantly affect how we handle your personal information, we will take reasonable additional steps to bring it to your attention — for example, by email to registered account holders or a notice on our homepage — before the change takes effect.

We encourage you to review this Policy periodically.

15. Availability of this Policy

This Policy is available free of charge on our website. If you do not have internet access, or would like a copy in another form — for example, a printed copy at reception, or a version in an alternative format such as large print — please contact our Privacy Officer using the details in Section 12 and we will take reasonable steps to provide it in the form you request.