Privacy Policy
Effective date: 24 September 2026
This policy explains how Beacon Info Tech Limited handles personal data when you visit getbeacon.cloud or use the Beacon platform (app.getbeacon.cloud) or Beacon Pro (pro.getbeacon.cloud). Our Terms of Service explain how the Services work.
1. Who we are
Beacon Info Tech Limited (“Beacon”, “we”, “us”) is the controller of the personal data described in this policy. We are registered in England and Wales, company number 16682371, and our registered office is 696 Yardley Wood Road, Birmingham, B13 0HY. We are registered with the Information Commissioner’s Office under registration number ZC080736. Contact us about privacy at [email protected].
When a hotel connects its property management system to the Beacon platform, the hotel is the controller of any guest personal data that passes through our systems, and we act as the hotel’s processor (see section 5). The hotel’s own privacy notice covers that data.
2. What we collect
- Account details: your name, business name, email address, password (stored in a form we cannot read) and role. If you invite colleagues, the names and email addresses you give us.
- Billing details: for Rate Radar and Beacon Pro, Paddle, our Merchant of Record, takes payment. We receive your name, email address, country and transaction history from Paddle, and never receive full card details. For plans we invoice directly, we hold your billing contact and company details, and the payment details you give us.
- Account content: the properties, reports, settings and messages in your account. This is mostly business information, but it can include names or contact details.
- Connected system data (Beacon platform only): booking and inventory figures from a hotel’s connected systems. We exclude guest personal data from the integration wherever the connected system allows. Where it cannot be excluded, we do not save it (see section 5).
- Usage and device data: IP address, browser and device type, the pages and features you use, and technical logs.
- Cookies and analytics: see section 9.
- Support, feedback and forms: what you tell us when you email us, send feedback, or fill in a form on our site, such as a demo request.
- Email activity: whether our emails were delivered, opened or clicked, and your email preferences.
3. How we use it, and our legal basis
- To create and run your account, provide the Services and give support. Basis: performing our contract with your business, and our legitimate interest in serving the people who use its account.
- To take payment and keep financial records. Basis: contract, and our legal obligations.
- To keep the Services secure and prevent fraud and misuse, including the one-free-allowance rule for Beacon Pro credits. Basis: legitimate interests.
- To understand how the Services are used and improve them. Basis: legitimate interests, and your consent where cookies or similar technologies need it.
- To send service emails, such as account, billing and security messages. Basis: contract and legitimate interests.
- To send occasional marketing emails (section 4). Basis: legitimate interests, as allowed for business contacts under the Privacy and Electronic Communications Regulations (PECR).
- To meet legal obligations and to establish or defend legal claims. Basis: legal obligation and legitimate interests.
Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time (section 8). We need your account details to provide the Services, so we cannot open an account without them. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
4. Marketing emails
Every marketing email has an unsubscribe link, and you can also unsubscribe by emailing [email protected]. Unsubscribing does not stop service emails about your account.
5. Guest data and AI Insights
- Guest data. Where a hotel’s connected system includes guest personal data that cannot be excluded from the integration, we process it only to run the connection, on the hotel’s instructions. It is processed in memory and never saved to our databases or backups. If a technical error captures fragments of it in our error logs, they are deleted automatically within 30 days. Our processor commitments are in our Data Processing Agreement.
- AI Insights. To generate AI Insights, we send anonymised booking figures, such as rooms sold and revenue, with the currency, to third-party AI model providers. We never send guest personal data, the hotel’s name or location, or anything else that identifies the hotel. We only use AI providers that do not use what we send to train their models. A provider may keep it for a short period to check for misuse before deleting it.
6. Who we share it with
We do not sell or rent personal data. We share it only with the suppliers who help us run the Services. They act on our instructions, under contracts that require them to protect it, except where noted:
- OVH: hosting, on servers in the UK and the EU.
- Cloudflare: website delivery, security and network protection.
- Paddle: payment, invoicing and sales tax. As Merchant of Record, Paddle is the seller of Rate Radar subscriptions and Beacon Pro credits, and it is a controller of your payment data in its own right, under its own privacy notice.
- Brevo: service and marketing emails.
- Google (Tag Manager and Analytics): website analytics.
- PostHog: product analytics.
- CookieYes: cookie consent.
- Featurebase: support and product feedback.
- Tally: forms on our website.
We may also share personal data with professional advisers, with authorities where the law requires it, or with a buyer if our business is sold, in which case this policy continues to apply.
7. International transfers
We host the Services in the UK and the EU. Some suppliers process data in other countries, including the United States. Where personal data leaves the UK or EEA, we rely on UK adequacy regulations (such as the UK–US data bridge) or EU adequacy decisions, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses. Contact us for details.
8. Your rights
Under UK GDPR, and EU GDPR where it applies, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we use it, including an absolute right to object to direct marketing;
- receive your data in a portable format; and
- withdraw consent at any time, where we rely on consent.
Email [email protected] to use any of these rights. We will reply within one month.
Complaints. You have the right to complain to us about how we handle your personal data. Email [email protected], or contact us any other way. We will acknowledge your complaint within 30 days, look into it without undue delay, and tell you the outcome. You can also complain to the Information Commissioner’s Office at ico.org.uk, or to your local data protection authority.
9. Cookies
Our website and apps use cookies and similar technologies. Essential cookies make the site and the Services work. Analytics cookies, from Google Analytics and PostHog, are used only with your consent, which we collect through CookieYes. You can change your choice at any time from the cookie banner or your browser settings.
10. How long we keep it
- Open accounts: for as long as the account is open, including Beacon Pro reports.
- Closed accounts: access ends immediately, and account data is deleted within 7 days. We keep a minimal record (business name, contact name, email address and subscription or credit history) for 6 years to meet legal and accounting duties.
- Paused free trials: 12 months after the trial ends, then deleted.
- Guest data from connected systems: never saved to our databases or backups. Fragments captured in error logs are deleted within 30 days.
- Marketing preferences: if you unsubscribe, we keep your email address on a suppression list so we do not email you again.
- Enquiries and forms from people without an account: up to 24 months after our last contact.
11. Security
We protect personal data with encryption, access controls limited to the people who need it, and regular security monitoring. If a breach puts your data at risk, we will tell you and the regulator as the law requires.
12. Age
The Services are for businesses and professionals. They are not for anyone under 18, and we do not knowingly collect data about children.
13. Changes to this policy
We may update this policy. The current version is always on this page, with its effective date. If a change materially affects you, we will tell you by email or in the Services.
14. Contact us
Email [email protected], or write to Beacon Info Tech Limited, 696 Yardley Wood Road, Birmingham, B13 0HY, United Kingdom.