
We asked ourselves how much guest data we held, answered the booking system, and were wrong. The real list ran to six places, and the thing that caught us out was not on it at all: a QR code we had put up ourselves. Oracle and Skift found the largest group of travelers will share data with a hotel on one condition, that they get asked first. Here is that list, five habits we keep, and a statement you can adapt.
A guest who gets a marketing email three weeks after checkout is probably not thinking about your channel manager or the wifi vendor whose login page they tapped through on arrival. Some of them will assume the hotel sold their address. The property name is the one they recognize on the receipt, so it tends to collect the suspicion.
One thing before we start: this post is about good practice and guest trust, not law. What is required of you depends on your country, your state and sometimes your city, and we are hosts, not lawyers. Get advice for your own situation.
What does guest data privacy mean for a small hotel or B&B?
Four habits cover a lot of it. Collect only what the stay needs, and say what each field is for at the moment you ask for it. Keep marketing consent as a separate yes the guest gives on purpose, and be able to find and remove somebody from your marketing records when they ask. We think guests judge you on one narrow thing: whether their details did anything they did not expect.
Where a guest's details ended up

Asked how much guest data we held, we would have said the booking system and stopped. So we sat down and wrote out everywhere a guest's details actually end up. We expected three or four entries. We got six, and the last two were a bit uncomfortable at one point.
Where it came from | What you end up holding | Worth a second look |
|---|---|---|
OTA booking data | Name, an alias email, party size, dates, sometimes a phone number | The channel's terms limit what you may do with it |
Your check-in or registration form | Name, email, phone, country, sometimes an ID scan | We delete copies once they are no longer needed operationally or to meet a local requirement |
Wifi captive portal | Email, device identifier, session times, usually held by a third-party vendor | Worth reading what that vendor is allowed to do with it |
Newsletter or loyalty signup | Email, plus whatever else the form asked for | The entry here that most clearly counts as marketing consent |
Cameras at the entrance or car park | Recorded footage of guests coming and going | Footage is guest information too, and how long you keep it is a real decision |
Staff phones and shared inboxes | Screenshots, forwarded confirmations, threads with a cleaner | The copies that are easiest to lose track of |
The entry that caught us out was not on the list at first, because we had put it there ourselves. In our first year hosting we had a QR code up in the property that opened a form asking for the guest's email so we could market to them later. A printed code does not know which channel anybody booked through. Every guest saw it, including the ones who had arrived through booking channels whose guidance we were, for a little while, probably going against without realizing. We took it down.
Your list will look different. Ours starts at the bottom row, because a booking record you can find, correct and delete is manageable, and the same details sitting in four people's message history are the easiest ones to forget.
What travelers say about giving hotels their data
Guests are not inventing this concern, and the more useful finding is that most of them are not refusing either. Oracle Hospitality and Skift's Hospitality in 2025 study surveyed more than 5,000 travelers across nine markets in 2022. Asked how they felt about hotels analyzing their travel information, the largest group chose "somewhat interested, if I willingly provided the data for this purpose": 43.8% on targeted offers, 45.2% on better service during the trip. Outright refusal, "this violates my privacy", sat at about 7%. Asked separately how concerned they were about the privacy and security of the personal data they give hotels and travel providers, 19.5% said very concerned and 55.6% somewhat concerned.
Two caveats. Oracle sells hotel technology, and a study concluding that guests will share data once asked is a comfortable result for a company selling the systems that use it. And the fieldwork is four years old. Cisco's cross-industry 2024 Consumer Privacy Survey points the same way, with 75% saying they will not buy from an organization they do not trust with their data, though that one is not about travel. What we take from both is that consent is the condition, not the objection.
Three things seem to set the suspicion off, and none of them require you to have done anything wrong: marketing that arrives without a remembered opt-in, a sender name the guest does not recognize, and no statement anywhere about what you do with their details. A guest who goes looking and finds nothing tends to fill the gap with the worst version. We would assume the same in their place.
How we would approach it at a small property

Not a compliance program. Five habits, in the order that has worked for us.
Collect what the stay needs and stop. Ask for a phone number only if you will use one. Fields you do not need are things you now have to look after.
Say what the field is for, next to the field. "So we can send your door code" beside the phone box probably does more for trust than a policy link most people skip.
Keep marketing consent separate from the booking. The guest ticks it themselves and never finds it pre-ticked, and you note when and where it happened. Without that note the question is hard to answer later.
Make removal easy, then honor it fast. One address a guest can write to, and the habit of working through every copy you hold.
Keep the guest list somewhere you control. We have come to think this is the underrated one. A list scattered across a spreadsheet, a mailbox and three staff phones is hard to correct, hard to clean up properly, and hard to hand over when someone leaves.
A property that can answer "what do you have on me?" in one sentence reads as a property that is run properly. Guests seem to pick up competence from small signals like that one, and our sense is that this is part of how small hotels out-host the chains.
Where the booking came from changes the picture
This is the part we found easiest to get wrong, and the QR code above is why. It has less to do with privacy law than with the contract you signed when you listed on a booking platform.
Airbnb's Off-Platform and Fee Transparency Policy, as worded in August 2026, lists among prohibited behaviors "selling, sharing, or using guest contact information for marketing communications or signing guests up for contact list". In the narrow exception that lets you ask for extra identity information where a legal or compliance reason requires it, the same page adds that "hosts are responsible for ensuring compliance with applicable data privacy laws".
Booking.com's partner help page on contacting guests takes a structural approach instead. It says the platform does not share private email addresses, and that you and your guests will only see an anonymous alias. So the address in your inbox is often a relay, and a mail merge run against it may be going somewhere you have not thought about.
Direct bookings work differently. The guest gave you a real address on your own form, and if they ticked the marketing box you have a clear, recorded yes to point to. What decides it is which channel the details arrived on, not whether the guest is new or returning. Demand you generated on your own channel is generally the part a platform's rules do not reach, which is the argument in our post on direct bookings without risking your platform account. Platforms revise these policies, so check the current wording yourself before relying on any quote, including ours.
A short statement you can adapt
Six plain lines, short enough that a guest might read them. Adapt it, link it from your registration form and your check-in card, and give it a page on your website.
How we handle your details
What we collect: your name, email, phone number and country, plus the booking details your reservation channel sends us.
Why: to prepare your room, reach you about your stay, and keep the guest records our local authority asks us to keep.
Marketing: we only email you offers if you ticked the box asking us to. Every email we send has an unsubscribe link.
Sharing: we do not sell your details. We share them only with the services we use to run [property name], and with authorities where we are required to.
How long we keep them: booking records for [X years]. Marketing contacts until you ask us to stop.
Removing you: write to [address] and we will remove you from our marketing lists and delete the personal information we are not required to keep.
Fill in the brackets honestly, retention period included. And put the link where the guest is being asked for something, because the footer is probably not where the question occurs to them.
FAQ
Do hotels sell guest information?
The small properties we know do not, and would be startled to be asked. What we see more often is less deliberate: a wifi portal vendor or a review-request tool holds guest details under its own terms, and an email goes out under a sender name the guest does not recognize. It feels the same to the guest either way, so it is worth knowing which third parties touch your guest data and what each may do with it.
What about the wifi login page? Does that count?
It does, and it is the entry we think gets forgotten most. A portal that asks for an email before it lets someone online is collecting guest data, usually into a system run by whoever supplied the hardware. Worth finding out what that vendor keeps, for how long, and whether anything lets them email your guests. If you cannot get a straight answer, a portal that asks only for a room number is a reasonable trade.
A guest says they never signed up for our emails. What went wrong?
Usually one of three things. They opted in at check-in and do not remember, which is exactly why the note of when and where is worth keeping. Or a collection point could not tell one channel from another, which is the mistake we made with the printed QR code. Or a list went out without the channels being separated first. Rule that third one out before you reply, because on Airbnb the off-platform policy quoted above puts marketing use of guest contact information among its prohibited behaviors.
Do I need a privacy policy for my B&B?
We are not going to tell you what your jurisdiction requires. As practice, if you collect names and email addresses you want a published statement covering what you hold, why, how long and how to be removed. There is a practical reason too: ours will not switch on guest data collection until you have added a policy URL, and we doubt we are the only ones.
Can I email past guests who booked through a platform?
Treat it as no unless you can show where the yes came from. Airbnb's policy language is quoted above, and Booking.com does not hand you the guest's real address in the first place. Contacts collected on your own direct channel, with an opt-in the guest chose, are the ones you can build on. Our post on guest registration covers the mechanics.
Doing this without building it yourself
You can run all of this on paper. A published statement, one address for removal requests, and the discipline of asking what each field is for goes a long way.
After doing the exercise by hand, and after taking that QR code down, we ended up building some of the safeguards into our own software. Our guest registration widget asks each guest for their own details at the guidebook, so the consent is theirs and the record carries a source. The OTA compliance settings behind it decide what a guest sees based on which channel their link came from. Reservation links pick that up on their own, and a link you share yourself carries the flag you set on it. It is the thing we wish the printed code had been able to do.
Two honest limits. It helps you stay inside a channel's rules and does not make you compliant with any law. And it will not turn on until you have added your own privacy policy URL, which is your obligation and not our rule. Everything exports to CSV, so the list leaves with you. Written by two people who run properties in Washington DC and the Riviera Maya, and who had to do this exercise on themselves first.
Latest articles

Glamping Amenities: What Guests Expect, and What to Say About Each One
Which glamping amenities guests actually expect, and what to say about each one so nobody discovers the shared bathroom on arrival. Plus two lists to publish.

How to Word Airbnb Fees and Fines for Guests
How to word Airbnb fees and fines for guests so they inform instead of accuse: what Airbnb counts as a fee, where each number goes, and 7 examples to copy.

What Many Guests Do First When They Arrive
What guests do first when they arrive: the sequence we keep seeing, what goes wrong at each step, and why a QR code at the object beats another page.

Airbnb Hotels and Hosts: What the First Numbers Show, and What They Don't
Airbnb says a third of first-time hotel guests come back to book a home. What that data shows for hosts, what it doesn't, and why it is too early to act on it.


