Ready for your dream vacation? BOOK NOW!

Grotto Bay Beach Resort and Spa and its affiliates (collectively, “Grotto Bay”, “we”, “our” or “us”) are committed to safeguarding your privacy and want you to be familiar with how we collect, disclose and otherwise use information about you. References in this Privacy Policy to “Grotto Bay,” “we,” “our” or “us” are references to the entity responsible for the processing of your personal data, which generally is the entity that obtains your personal data in the respective case, or the data controller.

This Privacy Policy describes:

    our practices in connection with the information we collect from you when you visit our websites that link to this Privacy Policy (the “Site”),
    when we communicate with you through e-mail messages that link to this Privacy Policy (collectively, referred to as the “Services”);
    our privacy practices when we communicate with you by offline channels, such as when you provide your information to our staff, or in person (“Offline Services”); and
    the basis on which we will process personal data we collect from you or that you provide to us, and your choices with respect to that data.

Please read this Privacy Policy carefully. By providing your personal data and other information through our Services, you acknowledge that your personal data will be processed pursuant to the terms of this Privacy Policy. If any term in this Privacy Policy is unacceptable to you, please do not use the Services or provide any personal data.

This Privacy Policy is written in English and may be translated into other languages. In the event of any inconsistency, the English version shall prevail.

1. What Information Does Grotto Bay Collect?
2. When is Your Personal Data Collected?
3. Why is Personal Data Used?
4. When and to Whom Do We Disclose Your Personal Data?
5. What Cookies and Other Technologies Do We Collect?
6. How Do We Protect Your Personal Data?
7. Third-Party Websites and Services
8. Cross-Border Data Transfers
9. How Long Do We Retain Your Personal Data?
10. How Can You Manage Your Preferences and Information?
11. What Are Your Rights and How To Exercise Your Rights?
12. What Information is Collected From Children?
13. What About Privacy Policy Modifications?
14. How to Contact Us?



1.1 Personal Data from or about You

The term “Personal Data” as used in this Privacy Policy refers to any information relating to an identified or identifiable individual, or as defined under applicable law. When you contact us, book as a guest, visit our property, or use our Site, we collect certain Personal Data from you. In the preceding twelve (12) months, we have collected categories of Personal Data such as:

    Contact Details: Your name, e-mail address, phone number, physical address (billing and shipping), company affiliation, title;
    Demographic Data: Demographic information and location data, and government-issued identifiers (e.g., drivers’ license (including dates of birth), passport numbers or other national identifiers);
    Financial Details: Your credit card and/or debit card details;
    Guest Stay Information: Guest stay information, special requests and preferences (including preferred room type or floor, spend, vacation preferences, amenities requested, language preferences, interests, hobbies, ages of children or companions and any other aspects of the Services used), telephone numbers dialed, faxes and telephone messages received;
    Frequent Flyer Details: Frequent flyer and travel partner program affiliations and member number; hotel, airline and rental car packages booked;
    Social Media Details: Social media account information, profile pictures or posts;
    Your Feedback: Information, feedback or content you provide regarding your marketing preferences, in surveys, comment cards, sweepstakes, or promotional offers on our Services and those of third parties;
    CCTV/Surveillance: For your safety and security, images and visual recordings through the use of closed circuit television systems collected while visiting a Grotto Bay hotel or property, where permitted by applicable law;
    Call Recordings: Conversations, including records or monitoring of guest service calls for quality assurance and training purposes, and other communications such as in-app messages or SMS text messages, where permitted by applicable law or based upon consent;
    Corporate Account Data: Contact details concerning the employees of corporate accounts and vendors and other individuals with whom we do business (e.g., travel agents, bookers, event planners); and
    Other Data: Other types of information that you voluntarily choose to provide to us.

1.2 Sensitive Personal Data

From time to time, you may provide or we may collect what is considered sensitive personal information or “special categories of personal data” under applicable privacy laws (herein referred to as “Sensitive Personal Data”). For example, you may disclose your religious affiliation to us when you host or attend an event at one of our hotels or provide your health information or dietary restrictions so that we can accommodate you during your stay.

We only process Sensitive Personal Data if and to the extent permitted and required by applicable law or with your express consent. Unless otherwise required by applicable law, you are not required to provide us with any of your Sensitive Personal Data. Should you choose not to, your decision would not prevent you from using our Services.



We collect Personal Data about you in a number of ways, including when you provide such data to us. This includes:

    When you make reservations, stay at a property or plan or attend an event. Visitors who elect to make reservations using our Services or Offline Services will be asked to supply specific Personal Data, including your Contact Details and Demographic Details such as your name, e-mail address and contact information, as well as Financial Information to secure the reservation, such as a credit card number. We collect your Personal Data, and with your consent, Sensitive Personal Data to provide you with services, including when you purchase goods and services, inform us of any requests, or take advantage of services such as concierge services, health clubs and spa treatments, activities, equipment rentals, and child care services. If you plan or host an event with us, we collect meeting and event specifications, such as your name, contact details, date of event, occasion, number of guest rooms required, and length of stay. We also collect information about guests that are a part of your group or event.
    When you sign up for promotional offers and sweepstakes. We collect your e-mail address when you sign up for promotional offers, newsletters or sweepstakes.
    When you provide your comments and feedback or communicate with us. We may collect Personal Data that you voluntarily share with us in surveys, guest feedback or comment cards, as well as on third-party websites. We also collect your Personal Data when you communicate with us via text or e-mail or otherwise, like social media apps.
    When you share photos. We collect and publish photos and images you voluntarily share with us about your experience with us, which you may post on our Services. For more information, please visit Grotto Bay’s User Generated Content Terms of Use at

When you purchase a gift card. If you decide to purchase a gift card, we collect Personal Data including the recipient’s name, e-mail address, shipping information, and any other information you voluntarily provide.
From social media. We may collect Social Media Details such as when you ‘like’ the Website, share content or follow us on social media sites like Facebook, Twitter, Pinterest Instagram, etc. If you choose to log-in, connect with or link to Services using your social media account certain Personal Data is shared with us consistent with your settings within the social media service, such as location, check-ins, activities, interests, photos, status updates, as well as Personal Data that may be a part of your profile or friend’s profile.


We use your Personal Data, both for business and commercial purposes as set forth below.

3.1 Performance of a Contract. We process your Personal Data in order to perform a contract with you, including to complete your reservation, provide you goods and services that you requested, or to inform Owners of your stay in order to render services to you while visiting our hotel or other property that we manage.

3.2 Legitimate Business Reasons. We use your Personal Data where we have a legitimate business reason to do so, pursued by a third party or us. This includes providing you with superior customer service and a personalized experience when staying with us, keeping our Services safe and secure and to protect our operations or those of any of our affiliates or other third parties, and distributing and responding to surveys regarding your experience, allowing you to participate in sweepstakes, contests, and other promotions and to administer these activities. Please bear in mind that some of these promotions have additional rules, which could contain additional information regarding what Personal Data we collect and how it is used. We encourage you to read these rules carefully. Such legitimate business reasons also include providing you with information that you have requested and responding to your inquiries, anonymizing Personal Data provided under this Privacy Policy to improve the Services and guiding the development of new features and services, detecting security incidents, protecting against malicious, deceptive, fraudulent or illegal activity; debugging and repairing errors; verifying customer information; and subject to applicable law and regulations, in the event of a corporate event such as a sale, merger or change in control.

3.3 To Comply with Legal Obligations. We process your Personal Data where it is necessary to comply with legal obligations to which it may be bound. This includes complying with legal processes, responding to requests from public and government authorities around the world, and pursuing available remedies or limit damage we or other third parties may sustain.

3.4 With Your Consent. We process your Personal Data when we have your valid consent to do you, including to communicate (including by e-mail, social media and SMS) with you during your stay, to send you promotional offers, newsletters, information on us, our Services, and other marketing communications in accordance with your preferences; and to process Sensitive Personal Data you may have provided us in connection with your stay; for example, any dietary restrictions or special accommodations for physical and medical conditions.

3.5 Vital Interest. In certain circumstances when it is not possible to obtain your consent, it may be necessary for us to process your Personal Data, including Sensitive Personal Data you provided through our Services, where it is in your vital interest or in the interest of others, for example in the event of a medical emergency.



In the preceding twelve (12) months, we have disclosed or shared your Personal Data described as follows:

4.1 The Personal Data you provide to us in connection with making a reservation, including your Contact Details, Demographic Data, Financial Details, and Guest Stay Information, is shared with the respective Owner and hotel or property for purposes of meeting your reservation request. After your stay, we retain your Personal Data, including the details of your stay and your preferences (e.g., room, type, interest, hobbies, amenities used) to provide you personalized service during your next stay, subject to your preferences.

You can object to the retention of your Personal Data for this purpose by contacting us as described in Section 14 of this Privacy Policy.

4.2 To Affiliates. We are a global enterprise and may disclose your Personal Data described in this Privacy Policy to other companies, including booking engines based in the European Economic Area (EEA) and the United States in order to help render services to you associated with your stay at our hotel and with your Contact Details to provide you marketing communications, consistent with your choices. For a complete listing of our affiliates, please contact us as indicated in Section 14 or see

4.3 Commercial Service Providers and Suppliers. We outsource certain functions and/or information to third parties that provide services to Grotto Bay such as Services hosting, booking, data analysis, payment and credit card processing, order fulfillment, customer service, e-mail delivery, financial services companies, delivery services, advertising networks, and information technology. We may also share your Personal Data described above with third-party providers that provide services such as spa treatment, bars and restaurants within our hotel property, or event planners or organizers of any event you plan or host with us.

4.4 External Partners. We may share your Personal Data to other partners, consultants and advisors who render services to us, including financial institutions, external auditors, lawyers, and credit card issuers.

4.5 Travel-Related Service Partners. We may share your Personal Data with select third parties, including your Contact Details, Demographic Data, Financial Details, Frequent Flyer Details, and Guest Stay Information. For example, we may help arrange rental cars and share Personal Data with them in order to provide those services. We also may work with third parties, such as travel agencies and airlines to help provide you with a single source for purchasing travel-related services. This Privacy Policy does not apply to information that you provide directly to third parties.

4.6 Co-Sponsors of Promotions and Sweepstakes. Your Personal Data, including your Contact Details or Feedback, may be shared with our affiliates or other unaffiliated business partners that serve as co-sponsors or third-party sponsors of promotions, sweepstakes, or other contests if you enter into one of these activities on our Services.

4.7 Social Media and Message Boards. If you connect to one of our social media pages, we may disclose your Personal Data including your Social Media Details to your friends associated with your social medial account, to other website users, and to your social media account provider, in connection with your social sharing activities. We may make reviews, message boards, blogs and other user-generated content available to users on our Services. Any information disclosed in these areas is public information and you should accordingly exercise caution when deciding to disclose your Personal Data in this context. We are not responsible for the privacy practices of other users including web operators to whom you provide information.

4.8 Business Transfers. From time to time, we may sell our business, hotel and other assets or may cease managing a property owned by an Owner. In those circumstances, we may include Personal Data collected about you, or control of that Personal Data, as a business asset in any such transfer. For example, if we cease to operate a hotel property we do not own, the Owner may continue to have and use your Personal Data for continued business purposes consistent with the hotel’s operations, including direct marketing. Additionally, we may disclose your Personal Data to a buyer or other successor in the event of a merger, sale or other transfer event, in which Personal Data held by us about our users is among the assets transferred.

4.9 Anonymized Data. We may share aggregated data with third parties collectively in an anonymous way, which does not reveal Personal Data.

4.10 Legal Obligation. If we are under a duty to disclose or share your Personal Data in order to comply with any legal obligation, pursuant to a legal request, subpoena or other legal processes, or in order to enforce or apply our Terms of Use and other agreements, including for billing and collection purposes; or to protect the rights, property, or our safety, our guests, or others. This may include exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.



5.1 Automatic Data Collection.. We may use automatic data collection technologies to collect certain statistical (non-personal) information about your equipment, browsing actions, and patterns, including (a) details of your visits to our Services, including traffic data and location data, date and time of access, frequency and other communication data; (b) information about your computer and internet connection, including your IP address, operating system, host domain, and browser type; and (c) details of referring websites actions, and patterns.

5.2 Cookies. We use cookies and other similar technologies (e.g., web beacons, pixels, ad tags and device identifiers) to recognize you and/or your device(s) on or across different Services and devices. We also allow other third parties to use cookies. You can control cookies through your browser settings or the ’cookie settings’ link at the bottom of this site.

5.3 Social Media Plug-ins. One of the features of our Site is that it uses what are called social plugins (“plugins”) from the social networks Twitter, Facebook, YouTube, Pinterest, and Instagram. These plugins are indicated by the respective logo of the social network. When you access our Site, your browser establishes a direct connection with the servers of these social networks. The content of the plugin is transferred by the social network directly to your browser, which then integrates it into the Site.

5.3.1 Integration of the plugin causes Facebook, for example, to receive the information that you have loaded the corresponding page of our Site. If you are logged in with Facebook, it will be able to assign your visit to your Facebook account. Please note that an exchange of this information already takes place when you visit our Site, regardless of whether you interact with the plugin or not. If you interact with the plugins, such as by pressing the ‘Like’ button, the corresponding information is sent directly to Facebook by your browser and saved there. You can find information on the purpose and extent of data acquisition as well as how the data is processed further and used by the social networks, together with your rights and optional settings to protect your private sphere, in the data protection notes of the social networks.

5.3.2 If you do not want incorporated social networks to gather data about you via our Site, you must log out on the respective domain of the social network before visiting our Site. If you wish to prevent information being exchanged with the above-mentioned social networks during your visit to our Site, you can opt out of cookies through your browser settings or the ’cookie settings’ link at the bottom of this site.

5.4 Wi-Fi and Location-Based Services. In the course and for the purpose of providing Wi-Fi services at our hotel and properties, we may collect device identifiers (such as your IP address, or other unique identifier). Based upon your consent, we also may collect information about the physical location on your device through use of the Wi-Fi services or other technologies to provide you with personalized location-based services, such as to customized offers and promotions or to find a hotel near you.



We maintain commercially reasonable security safeguards that are designed to protect the Personal Data we collect against unauthorized use, disclosure, alteration or destruction. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure and we cannot guarantee or warrant that your Personal Data is under absolute security with the existing security technology. Additionally, when requesting information or sending information or forms to us by e-mail, please be advised that e-mail communication to and from our Services are not secure unless clearly noted otherwise. This is a risk inherent in the use of e-mail.



7.1 Our Services may contain links to, or have features that are hosted by, other third-party websites or services that are not owned or controlled by us. For example, we give you the opportunity to connect, link, or share our Services (and the content you access) via certain social media websites.

7.2 This Privacy Policy only addresses the collection, use, and disclosure of information by us through your interaction with our Services. This Privacy Policy does not address the policies or practices of any third parties or any third-party websites or features that are linked to or available from our Services. If you provide any information to any other third parties, different rules regarding the collection and use of your Personal Data by such third parties may apply. Please contact these entities directly if you have any questions about their privacy practices.

7.3 We also may partner with a limited number of Internet providers to offer Internet access to our guests. Your use of on-property Internet service is subject to the third-party Internet provider’s terms of use and privacy policy, which you can access using the links on the service sign-in page, or by visiting the Internet provider’s website.



8.1 The Personal Data and other information that we collect from you will be transferred to, and stored at, a destination outside the EEA. It also may be processed by staff operating outside the EEA who work for us or other entities acting as data processors processing data on our behalf. This includes staff and providers engaged in, among other things, the fulfillment of your request or order and the provision of support services. More information on to whom your data is disclosed can be found in Section 4.

8.2 To comply with applicable data protection law, we have implemented international data transfer agreements on the basis of EU Standard Contractual Clauses in order to provide appropriate and suitable safeguards for Personal Data transferred to countries outside the EEA where an adequate level of protection is not already guaranteed. A redacted copy (removing commercial terms) can be obtained by contacting us at the contact details provided in Section 14 below.



We retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by applicable law. Note that we may need to retain certain information for recordkeeping purposes and/or to complete transactions (e.g., when you make a purchase or reservation), and you may not be able to change or delete the Personal Data you provided until after completion of such purchase or reservation.



10.1 Commercial E-mails. You may opt-out of receiving commercial e-mails from us by following the instructions contained in any of the commercial e-mails. Unsubscribing from one type of communication may not unsubscribe you from another type. Please note that even if you unsubscribe from commercial e-mail messages, we may still e-mail you non-commercial (transactional) e-mails related to your account and your transactions via the Services.

10.2 Owners (following termination or expiration of our management agreements) and third-party providers may use your Personal Data for marketing purposes. If you wish to opt-out of receiving offers directly Owners and third-party providers, you can follow the instructions in the e-mails that they send you.

10.3 EU Users and Commercial E-mails. If you are a user based in the EU, we only send you commercial e-mails when we have obtained your explicit prior consent, except where we have obtained your e-mail address in the course of a sale or negotiations for a sale of a product or service and where the commercial e-mails are only marketing similar products or services.

10.4 Text Messages and SMS. To opt out of text messages, reply STOP to the message you received or contact the hotel front desk to inform them you no longer wish to receive text messages.

10.5 Mobile Apps. You can control whether our Apps send you push notifications by change your notification settings on your mobile device.

10.6 Access and Connections to Social Media. If you registered with the Services through your social media account, or connected, linked, or shared your use of our Services via your social media profile, you can manage the permissions granted to such third-party social media services by accessing your user settings under your account. You also can remove our access to your social media account or otherwise control what information these third-party social media services share with us at any time by accessing the privacy settings in your social media account.



Under applicable law and regulations, you may, at any time, exercise certain rights, as described below:

11.1 For Residents in the European Union/European Economic Area

    Access: The right to request access to your Personal Data, which includes the right to obtain confirmation from us as to whether Personal Data concerning you is being processed, and where that is the case, access to the Personal Data and information related to how it is processed. We will usually share this information with you within one (1) month of you asking us for it.
    Rectify or Erase: The right to rectification or erasure of your Personal Data, which includes the right to have incomplete Personal Data completed.
    Restrict: The right to obtain a restriction of processing concerning your Personal Data, which includes restricting us from continuing to process your Personal Data under certain circumstances (e.g., where you contest the accuracy of your Personal Data, for a period enabling us to verify the accuracy of the personal data).
    Object: The right to object to the processing of your Personal Data under certain circumstances, including objecting to processing your Personal Data for direct marketing purposes, or objecting to processing your Personal Data when it is done based upon legitimate interests.
    Data Portability: The right to data portability, which includes certain rights to have your Personal Data transmitted from us to you or another controller.
    Consent: Where we process your Personal Data based on your consent, the right to withdraw consent at any time with effect for the future. Any requests related to the above rights may be made by contacting us as set forth in Section 14.
    Complaint: If you think we have not complied with a data protection law, you may also have the right to lodge a complaint with a supervisory authority.

11.2 For residents in other jurisdictions

Where permitted by applicable law, you may request access, correction and deletion of the Personal Data Grotto Bay has about you.

How to Exercise Your Rights

To exercise the rights described above, contact us as provided for in Section 14 below. Grotto Bay will respond to your request(s) as soon as reasonably practicable, but in any case, within the legally required period of time.

Verification Process

Your privacy and information security are important to us. For this reason, we verify your identity or authority to make the request and confirm the Personal Data relates to you, or others, if you are an authorized agent. Accordingly, Grotto Bay will collect your name, e-mail address and phone number to verify your identity. Upon receiving your request, we also contact you via email and/or other secured communication channel to verify your identity by asking you additional security questions in order to match to your identity with the data we maintain about you.

Please note that, if we cannot verify your identity, we are not obligated to provide you or your Authorized Agent information regarding your Personal Data.

For Your Security

Grotto Bay does not collect sensitive information, such as your full credit card details, social security or national identification number, to verify your identity. Please do not send Grotto Bay sensitive information and be aware of any phishing scams or fraudulent calls requesting such information from you.

While we maintain commercially reasonable safeguards to protect your Personal Data, no method of transmission is 100% secure and we do not guarantee or warrant that your Personal Data is under absolute security with the existing security technology.

Submitting Request via an Authorized Agent

You may also exercise your rights via an authorized agent (“Authorized Agent”).

An Authorized Agent can be a third party that you authorize to act on your behalf, such as a third party with power of attorney.

If you are a resident of California, an Authorized Agent can only be a person or a business entity that you authorize to act on your behalf to submit a verifiable consumer request related to your personal data.

When an Authorized Agent is submitting a request on your behalf, we will require such Authorized Agent to provide evidence of their entitlement, e.g., a written permission, declaration or affidavit demonstrating that they have authority to make the request on your behalf, and the Authorized Agent would have to verify their own identity directly with us.

Disclosure of Personal Data

Once we have verified you or your authorized agent’s identity, we will disclose the specific pieces of Personal Data we collected about you, which will be made in writing and delivered through your account with us, if you maintain such an account. If you do not maintain an account with Grotto Bay, we will provide such information by mail or electronically, at your option, in a readily useable format that allows you to more readily transmit the information from one entity to another entity.



12.1 We have not designed the Services for, and do not intend for them to be used by, anyone under age 16. We do present information regarding our Rose Buds® program on our Services for the reference of adults that are interested in activities at our locations for children. Accordingly, the Services should not be used by anyone under age 16 without adult supervision. If you are under 16, please do not provide Personal Data of any kind whatsoever.

12.2 Should we inadvertently acquire Personal Data or other information from users under the age of 16, we will not knowingly provide this data to any third party for any purpose. If a child does provide us with Personal Data over Services, a parent or guardian of that child may contact us and upon notification, we will delete from our records any information collected from children under the age of 16.



We reserve the right to change this Privacy Policy at any time. Any changes we make will be posted on this page. If we make material changes to how we treat your Personal Data, we will notify you through a notice on the Services home page. The date this Privacy Policy was last revised is identified at the top of the page. It is your responsibility to ensure that we have a deliverable e-mail address for you, and for you to periodically monitor and review any updates to this Privacy Policy. Your continued use of our Services after such amendments will be deemed your acknowledgement of these changes to this Privacy Policy.



If you have any questions or comments about our privacy practices or this Privacy Policy or to exercise your rights with respect to your Personal Data (as applicable), you may:

Email us at

Call us toll free in the U.S. at 1 (855) 4GROTTO or 1 (855) 447 - 6886

Write to us at 
Grotto Bay Beach Resort & Spa
11 Blue Hole Hill
Hamilton Parish, CR04

Local: 1 (441) 293-8333

To Top