Privacy Policy
Last updated: June 2025
Welcome to Luminoragrandstay. We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Personal Information Protection and Electronic Documents Act (PIPEDA), and all other applicable privacy legislation. This Privacy Policy explains who we are, what personal data we collect, why we collect it, how we use it, with whom we share it, how long we retain it, and what rights you have regarding your personal information.
This Policy applies to all personal data processed through our website luminoragrandstay.com, our reservation and loyalty systems, our on-site hotel and casino operations, and any other service we provide to you as a guest, visitor, or customer.
Please read this Policy carefully before using our website or services. By accessing our website or making a reservation with us, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The entity responsible for the collection and processing of your personal data is:
| Legal Entity Name | Luminoragrandstay Inc. |
|---|---|
| Trading Name | Luminoragrandstay |
| Registration Country | Canada |
| Corporation Number | 7842169 |
| GST/HST Registration | GST/HST No. 847 216 935 RT0001 |
| Registered Address | 135 Queen Street, Niagara-on-the-Lake, ON L0S 1J0, Canada |
| Website | luminoragrandstay.com |
| Privacy Contact Email | privacy@luminoragrandstay.com |
When this Policy uses the terms "we", "us", "our", or "the Hotel", these refer exclusively to Luminoragrandstay Inc., the registered data controller for all personal data processing activities described herein.
1.1 Data Protection Officer
In accordance with Article 37 of the GDPR and equivalent provisions under Canadian privacy law, we have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring compliance with applicable privacy legislation.
You may contact our Data Protection Officer at any time regarding any matter relating to your personal data or this Privacy Policy:
| Title | The Data Protection Officer |
|---|---|
| Organisation | Luminoragrandstay Inc. |
| Postal Address | 135 Queen Street, Niagara-on-the-Lake, ON L0S 1J0, Canada |
| privacy@luminoragrandstay.com |
2. Personal Data We Collect
We collect personal data in a variety of ways depending on how you interact with us — through our website, in person at the hotel or casino, over the telephone, or via third-party booking platforms. Below we outline the categories of personal data we may collect.
2.1 Identity and Contact Data
- Full name and title
- Date of birth and age verification information
- Home address, billing address
- Email address
- Telephone number(s)
- Nationality and country of residence
- Passport, national identity card, or government-issued photo ID details (required by gaming regulations)
2.2 Reservation and Stay Data
- Booking reference numbers and reservation history
- Check-in and check-out dates
- Room type, preferences, and special requests
- Number and names of accompanying guests
- Purpose of visit (leisure, business, event)
- Vehicle registration number (if parking on-site)
2.3 Financial and Payment Data
- Credit or debit card details (processed securely via PCI-DSS compliant payment processors)
- Bank account details (for refund processing where applicable)
- Invoicing and billing records
- Records of expenditure on hotel and casino services
2.4 Casino and Gaming Data
- Gaming history, wagers, wins, and losses
- Responsible gambling self-exclusion requests and declarations
- Player account information and loyalty tier status
- Anti-money laundering (AML) and Know Your Customer (KYC) documentation
- Source of funds declarations where required by law
2.5 Loyalty Programme Data
- Loyalty membership number and tier level
- Points earned, redeemed, and current balance
- Preferences, interests, and activity history linked to your membership
2.6 Technical and Website Data
- IP address and geolocation data
- Browser type and version
- Device type, operating system, and identifiers
- Pages visited, time spent on pages, and click behaviour
- Referring URLs and search terms used to reach our site
- Cookie identifiers and tracking pixel data (see our Cookie Policy)
2.7 Communications Data
- Content of emails, enquiry forms, and messages sent to us
- Records of telephone calls (which may be recorded for training and quality purposes, with appropriate notice)
- Feedback, reviews, and survey responses
- Social media interactions where you engage with our official accounts
2.8 Security and Safety Data
- CCTV footage captured within and around our premises
- Access control and key-card entry records
- Incident reports and security logs
2.9 Special Categories of Personal Data
In limited circumstances, we may collect special categories of personal data as defined under Article 9 of the GDPR. This includes:
- Health and dietary information: such as food allergies, dietary requirements, or mobility needs that you voluntarily share to allow us to accommodate your stay safely and comfortably.
- Health data relating to responsible gambling: where you have voluntarily enrolled in a self-exclusion or responsible gambling programme.
We only process special category data with your explicit consent or where processing is necessary to protect your vital interests or to comply with legal obligations, in accordance with Article 9(2) GDPR.
2.10 Data Collected from Third Parties
We may also receive personal data about you from the following sources:
- Online travel agencies and booking platforms (e.g., Expedia, Booking.com)
- Corporate travel management companies acting on your behalf
- Fraud prevention agencies and credit reference agencies
- Government and regulatory authorities (e.g., gaming regulators, law enforcement)
- Social media platforms, where permitted by your privacy settings on those platforms
3. Legal Basis for Processing
We are required by the GDPR to identify and document the legal basis upon which we process your personal data. All processing activities carried out by Luminoragrandstay Inc. are founded on one or more of the following legal bases as set out in Article 6 of the GDPR:
3.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process personal data where processing is necessary to fulfil a contract with you or to take steps at your request prior to entering into a contract. This includes:
- Processing your hotel reservation and managing your stay
- Administering your casino player account and loyalty programme membership
- Processing payments and issuing invoices and receipts
- Communicating with you regarding your booking, stay, or account
3.2 Legal Obligation (Article 6(1)(c) GDPR)
We process personal data where processing is necessary to comply with a legal obligation to which we are subject. This includes:
- Identity verification and Know Your Customer (KYC) checks required under Canadian anti-money laundering legislation (Proceeds of Crime (Money Laundering) and Terrorist Financing Act)
- Age verification to prevent minors from accessing casino services
- Retention of financial and accounting records as required by Canadian tax authorities
- Compliance with gaming licence conditions imposed by the Ontario gaming regulator (AGCO)
- Responding to lawful requests from law enforcement or regulatory authorities
- Health and safety obligations in relation to guests and employees
3.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process personal data where it is necessary for the purposes of our legitimate interests or the legitimate interests of a third party, provided that these interests are not overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Protecting our premises, guests, staff, and assets through CCTV and security systems
- Preventing and detecting fraud, money laundering, and other criminal activity
- Improving and optimising our website, services, and guest experience
- Conducting analytics and business intelligence to understand how our services are used
- Sending service-related communications and updates to existing guests
- Managing and defending legal claims or disputes
- Network and information security to protect our IT infrastructure
Where we rely on legitimate interests, you have the right to object to this processing. Please refer to Section 8 (Your Rights) for further information.
3.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will always obtain your consent through a clear and affirmative act before commencing processing. Consent-based processing includes:
- Sending you direct marketing emails, newsletters, and promotional offers
- Placing non-essential cookies and similar tracking technologies on your device
- Processing special category data such as health or dietary information
- Profiling for personalised marketing and targeted advertising purposes
You have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to your withdrawal. To withdraw consent, please contact us at privacy@luminoragrandstay.com or use the unsubscribe link in any marketing communication.
3.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another person. This may arise in emergency medical situations during your stay where we need to share information with emergency services or healthcare providers to protect life.
3.6 Public Task (Article 6(1)(e) GDPR)
This legal basis is not routinely relied upon by us. However, it may apply in limited circumstances where we are required to assist public authorities in the performance of a task carried out in the public interest or in the exercise of official authority.
4. How We Use Your Personal Data
We use the personal data we collect for a range of purposes, all of which are described below along with the legal basis upon which each activity is founded. We will never use your personal data for purposes that are incompatible with the purpose for which it was originally collected without first obtaining your consent or establishing another lawful basis.
4.1 Providing Hotel and Accommodation Services
Legal basis: Performance of a contract (Article 6(1)(b))
- Processing and confirming hotel reservations
- Managing check-in and check-out procedures
- Allocating rooms and fulfilling special requests and preferences
- Managing room service, concierge, and ancillary hotel services
- Communicating with you before, during, and after your stay
4.2 Operating Casino and Gaming Services
Legal bases: Performance of a contract (Article 6(1)(b)); Legal obligation (Article 6(1)(c))
- Creating and managing your casino player account
- Administering gaming activities, wagers, and winnings
- Conducting mandatory age and identity verification
- Implementing responsible gambling tools, limits, and self-exclusion programmes
- Fulfilling anti-money laundering and KYC regulatory requirements
4.3 Processing Payments and Financial Administration
Legal bases: Performance of a contract (Article 6(1)(b)); Legal obligation (Article 6(1)(c))
- Processing payments for hotel stays, casino activities, dining, and other services
- Issuing invoices, receipts, and accounting records
- Managing refunds and disputed charges
- Detecting and preventing fraudulent transactions
4.4 Loyalty Programme Administration
Legal basis: Performance of a contract (Article 6(1)(b))
- Enrolling you in and managing your loyalty membership
- Crediting and tracking loyalty points
- Communicating your membership status, benefits, and rewards
- Processing reward redemptions
4.5 Marketing and Promotional Communications
Legal basis: Consent (Article 6(1)(a)) or Legitimate interests (Article 6(1)(f)) for existing guests
- Sending you promotional offers, special packages, and event information by email or post
- Personalising marketing content based on your stay history and stated preferences
- Conducting targeted advertising on social media and third-party platforms
- Inviting you to participate in surveys, competitions, and guest programmes
You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any email or by contacting us at privacy@luminoragrandstay.com.
4.6 Security, Safety, and Fraud Prevention
Legal bases: Legitimate interests (Article 6(1)(f)); Legal obligation (Article 6(1)(c))
- Operating CCTV surveillance across our premises for the safety of guests and staff
- Monitoring access to restricted areas of the hotel and casino
- Investigating and preventing theft, fraud, and other criminal conduct
- Supporting law enforcement investigations where lawfully required
4.7 Website Operations and Analytics
Legal bases: Legitimate interests (Article 6(1)(f)); Consent (Article 6(1)(a)) for non-essential cookies
- Ensuring the technical functionality and security of our website
- Analysing website traffic, user behaviour, and booking funnel performance
- Improving the usability and content of our website
- Personalising your online experience and displaying relevant content
4.8 Legal and Regulatory Compliance
Legal basis: Legal obligation (Article 6(1)(c)); Legitimate interests (Article 6(1)(f))
- Complying with requirements imposed by gaming regulators, tax authorities, and other bodies
- Establishing, exercising, or defending legal claims
- Responding to subject access requests and other data subject rights requests
- Maintaining appropriate records as required by applicable law
4.9 Guest Experience Improvement
Legal basis: Legitimate interests (Article 6(1)(f))
- Processing feedback and guest satisfaction surveys
- Training staff to improve service quality
- Reviewing operational performance and identifying areas for improvement
5. Sharing Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the categories of recipients described below, always subject to appropriate safeguards and only where a lawful basis for sharing exists.
5.1 Service Providers and Data Processors
We engage trusted third-party service providers to help us operate our business and deliver our services. These processors act on our instructions and are bound by data processing agreements that require them to protect your data in accordance with applicable law. They include:
- Cloud hosting and IT infrastructure providers
- Payment processing and fraud prevention service providers
- Reservation management system providers
- Email delivery and marketing automation platforms
- Customer relationship management (CRM) software providers
- Analytics and website performance tools
- Printing, mailing, and direct marketing fulfilment services
- CCTV monitoring and physical security service providers
- Legal, accounting, and professional advisory firms
5.2 Regulatory and Law Enforcement Authorities
We may be required to disclose personal data to regulatory bodies, government agencies, or law enforcement authorities where we are under a legal obligation to do so. This includes:
- The Ontario gaming regulator (AGCO)
- The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
- The Canada Revenue Agency (CRA)
- Ontario Provincial Police or other law enforcement agencies
- Courts and tribunals in connection with legal proceedings
5.3 Business Partners
Where you participate in joint promotions, packages, or events operated in partnership with other businesses (such as local attractions, dining partners, or spa providers), we may share relevant data with those partners to the extent necessary to fulfil the service you have requested. We will inform you of any such sharing at the time of collection.
5.4 Online Travel Agencies and Booking Platforms
If your reservation was made through an online travel agency (OTA) or third-party booking platform, we may receive your data from and share confirmation data back to that platform for the purposes of fulfilling your booking. Those platforms operate their own privacy policies.
5.5 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of our business, your personal data may be transferred to the acquiring entity as part of that transaction. We will notify you of any such transfer where required by applicable law, and your data will remain subject to the protections set out in this Policy.
5.6 International Transfers of Personal Data
Some of our service providers are located outside Canada and the European Economic Area (EEA). When we transfer personal data to countries that have not been deemed to provide an adequate level of data protection by the European Commission or relevant Canadian authorities, we ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where the recipient country has been deemed adequate
- Binding Corporate Rules where applicable within corporate groups
- Certification frameworks such as the Global Privacy Framework where relevant
You may request details of the specific safeguards applicable to any international transfer by contacting us at privacy@luminoragrandstay.com.
6. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, regulatory, or reporting obligations. The criteria we use to determine retention periods include:
- The nature of the personal data and the sensitivity of the information
- The purpose for which it was collected and whether that purpose has been fulfilled
- Applicable statutory limitation periods for legal claims
- Regulatory requirements imposed by gaming, financial, or tax authorities
- Whether retention is required to resolve a dispute or enforce a contract
6.1 Retention Periods by Category
| Category of Data | Retention Period | Rationale |
|---|---|---|
| Hotel reservation and stay records | 7 years from date of stay | Canadian tax and accounting requirements |
| Financial and payment records | 7 years from transaction date | CRA requirements under the Income Tax Act |
| Casino gaming and player account records | 7 years from account closure or last activity | AGCO regulatory obligations and AML legislation |
| KYC and identity verification documents | 5–7 years from completion of KYC | FINTRAC and PCMLTFA requirements |
| Marketing preferences and consent records | Until consent is withdrawn, plus 3 years | Evidence of lawful marketing basis |
| CCTV footage | 30 days, unless required for investigation | Proportionality and operational need |
| Website analytics and log data | Up to 26 months | Analytical and security purposes |
| Customer service and complaint records | 3 years from resolution | Limitation periods for legal claims |
| Self-exclusion and responsible gambling records | Duration of exclusion plus 10 years | Regulatory obligation and duty of care |
When personal data is no longer required, it is securely deleted or anonymised so that it can no longer be associated with you. Where anonymisation is not possible, data is restricted from further active processing until it can be securely destroyed.
7. Your Rights Under Data Protection Law
Subject to applicable exceptions and conditions, you have the following rights with respect to your personal data under the GDPR and Canadian privacy law. We will respond to any valid request within one calendar month of receipt, although complex requests may require up to a further two months, in which case we will notify you.
7.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, along with information about how it is used, the legal basis for processing, who it has been shared with, and how long it will be retained. This is commonly known as a Subject Access Request (SAR).
7.2 Right to Rectification (Article 16 GDPR)
If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it without undue delay. Please ensure that the information you provide to us is always current and accurate.
7.3 Right to Erasure (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, where you withdraw consent on which processing was based, or where you object to processing based on legitimate interests and we have no overriding grounds to continue. This right does not apply where we are required to retain data to comply with a legal obligation.
7.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while we verify the accuracy of data that you have contested, or where you have objected to processing and we are assessing whether our legitimate interests override your rights.
7.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
7.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where that processing is based on legitimate interests (Article 6(1)(f)), including profiling based on those grounds. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for the establishment, exercise, or defence of legal claims.
You also have an unconditional right to object to the processing of your personal data for direct marketing purposes at any time, after which we will stop such processing immediately.
7.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for entering into or performing a contract, is authorised by law, or is based on your explicit consent. We do not currently make solely automated decisions that produce legal effects without human oversight. If this changes, we will inform you and implement appropriate safeguards.
7.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. To withdraw consent, please contact us at privacy@luminoragrandstay.com or use the opt-out mechanism in any relevant communication.
7.9 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority:
- Canada (Federal): Office of the Privacy Commissioner of Canada (OPC) — www.priv.gc.ca
- Ontario (Provincial): Information and Privacy Commissioner of Ontario (IPC) — www.ipc.on.ca
- EU/EEA residents: Your local data protection authority in the EU member state of your habitual residence, place of work, or alleged infringement.
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority, and we encourage you to contact us in the first instance.
7.10 Exercising Your Rights
To exercise any of the rights described in this section, please submit a written request to us using the contact details below. We may need to verify your identity before processing your request to ensure that personal data is not disclosed to an unauthorised person. We will not charge a fee for handling requests unless they are manifestly unfounded, excessive, or repetitive.
9. Third-Party Links and Services
Our website may contain links to third-party websites, social media platforms, or embedded content from third-party providers (such as maps or video players). We are not responsible for the privacy practices or content of those third-party sites. We encourage you to review the privacy policies of any third-party websites you visit. The inclusion of a link does not constitute our endorsement of that site or its privacy practices.
10. Children's Privacy
Our hotel accommodates families, and children are welcome in non-gaming areas of our property. However, access to our casino and gaming facilities is strictly restricted to individuals aged 19 years or older in accordance with Ontario law. We do not knowingly collect personal data directly from children under the age of 16 without verifiable parental consent. If you believe that we have inadvertently collected data from a child without appropriate consent, please contact us immediately at privacy@luminoragrandstay.com and we will take prompt steps to delete such data.
11. Data Security
We implement and maintain appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. Our security measures include, but are not limited to:
- Transport Layer Security (TLS/SSL) encryption for all data transmitted via our website
- Encrypted storage of sensitive personal and financial data
- PCI-DSS compliant payment processing systems
- Role-based access controls limiting staff access to personal data on a need-to-know basis
- Regular staff training on data protection and information security
- Periodic security assessments, penetration testing, and vulnerability scanning
- Data breach response procedures in accordance with GDPR Article 33 and PIPEDA requirements
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with our obligations under Article 34 of the GDPR and applicable Canadian law.
12. Changes to This Privacy Policy
We review and update this Privacy Policy periodically to reflect changes in our services, legal obligations, or data protection practices. When we make material changes, we will:
- Update the "Last updated" date at the top of this Policy
- Post the revised Policy on our website at luminoragrandstay.com
- Where appropriate, notify you by email or through a prominent notice on our website
We encourage you to check this page periodically to stay informed about how we are protecting your data. Your continued use of our website or services after the publication of a revised Policy constitutes your acknowledgement of the updated terms.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way in which we handle your personal data, please do not hesitate to contact us. We are committed to addressing your enquiries promptly and transparently.
| Data Controller | Luminoragrandstay Inc. |
|---|---|
| Contact Person | The Data Protection Officer |
| Postal Address | 135 Queen Street, Niagara-on-the-Lake, ON L0S 1J0, Canada |
| Email Address | privacy@luminoragrandstay.com |
| Website | luminoragrandstay.com |
When contacting us regarding a data subject rights request, please include sufficient information to allow us to identify you and locate your records, along with a clear description of your request. We may contact you to verify your identity before processing your request.
We aim to respond to all enquiries within 30 calendar days. For complex requests, we may extend this period by a further two months, and we will notify you accordingly within the initial 30-day period.