THE INDUSTRY FILES

Hospitality

A stay often puts your passport on the record, sometimes as an image, and in several countries the law keeps a copy for the state to read. Beyond that, the file is kept as long as they judge necessary, with figures the exception.

TRACKING PRIORITY RECOMMENDED

Identity and travel records. Worth listing.

IF IT LEAKS HIGH
EXPECT IT KEPT FOR YEARS

Guest and payment records are kept for years; registers are required by law.

IDENTITY DEMANDED ID DOCUMENTS

Check-in takes ID and payment; some hotels add a face scan.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

IF IT LEAKS

A stay record says who you were with and where, and hotel files keep passport numbers to prove it. One group's breach exposed 5.25 million unencrypted passport numbers and ran undetected for four years.

What repeats in the policies

WHAT YOU HAND OVER

The passport goes on the record

Booking a stay or a flight often means handing over a passport or national ID number, and often an image of the document with it. Some services hold that picture for a set number of days, others fold the number into your booking record with no end date. One service goes further and turns a photo of your face into a scan it can match you against later. This is usually tied to a moment like check-in or a flight booking, not every visit.

WHERE IT GOES

The law keeps a copy for the state

In several countries the law turns a stay into a record the state can read. In the UK, a hotel must keep every guest's name and nationality, and a foreign guest's passport details, for at least twelve months and open them to any police officer. Spain has traveller data pushed to a state security office and held for three years; Germany keeps a foreign guest's signed arrival form for a year after departure, handed to police on request. This runs by law, whatever a privacy policy says.

WHAT STAYS

Leaving does not clear the file

How long the record lasts is their claim, and most give no number: kept as long as they judge necessary for purposes they set. Where a figure does appear it runs long, one operator holding booking and complaint history for seven years, another keeping account details up to five years after you close it. A tax, accounting, or anti-money-laundering rule is the usual reason a record outlives the stay. Several policies keep data not only where the law requires it but wherever the law permits it.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileIdentity DocumentsPurchasesFinancial Browsing & Activity maybeLocation maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Where you go LIKELY

Stay records map your travel.

Who matters to you POSSIBLE

Who you stay with can be inferred.

What lawfully stays after you leave

Two kinds of hold. LAW SETS IT: a statute makes them keep it. THEY SET IT: a ground the company grants itself.

policing / immigration records YEARS, SOMETIMES DECADES LAW SETS IT

Policing and immigration records carry very long statutory retention.

fraud-prevention markers ABOUT 2 TO 6 YEARS THEY SET IT

To flag suspected fraud, often on a shared industry database you cannot reach through the company.

tax and accounting records ABOUT 6 YEARS LAW SETS IT

Tax and company law makes them keep billing and payment records.

records tied to a live or potential dispute THE LIMITATION PERIOD OF THE CLAIM THEY SET IT

They can keep records to defend a live or possible legal claim.

Who wants this data

A single hotel group's breach exposed roughly 339 million guest records and 5.25 million unencrypted passport numbers, and it went undetected for four years. Passport-grade identifiers gather at the booking sites as much as at the front desk. The fix came only when a regulator forced a deletion path the company had not offered on its own.

SOLD OR SHARED POSSIBLE

Guest data is shared with booking platforms and partners.

AI TRAINING LOW

Limited training use beyond internal analytics.

Even anonymised, this can still be you

Anonymised is their word. A guest register names you, your document, and your dates, which is enough to single you out.

Name, date of birth, postcode TYPICAL

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces SOMETIMES

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns TYPICAL

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

Browsing fingerprint SOMETIMES

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

THE STUDIES Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation, and increasingly AI training can all ride under it. When they want to do something new with your data, this sentence usually already covers it.

THE MOVE An objection draws the line: use your data to run the service, not to improve, target, or train on it.

“we do not sell your personal information”

Often technically true, and still misleading. It usually means no cash changes hands. Data can still flow to ad networks, analytics firms, and partners: on their definition, sharing is not selling.

THE MOVE Flip the do-not-sell switch where one exists. The written objection on top of it goes on your record.

“service providers, partners, and affiliates”

How data leaves the building with no name attached. Recipients are listed by what they do, never who they are. You cannot send a request to a company you cannot name, which is the point.

THE MOVE An access request can ask for the recipients by name, not just the categories. UK and EU law put that choice with you. The reply, or the silence, goes on your record.

“aggregated or de-identified information”

Stripping the name does not strip the pattern, and the pattern often still points at you. Policies grant themselves free, indefinite use of this data because in their telling it is no longer about you.

THE MOVE If a deletion comes back as 'anonymised', keep the reply. It is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

They can keep it for: legal duties, tax rules, fraud prevention, possible lawsuits, their own business reasons. None of them carries a firm end date. Deletion becomes a negotiation, not an event.

THE MOVE Which reasons apply to you, and how long each runs, is a request of its own. Their reply goes on your record.

“you grant us a licence to use your content”

A contract term, not a data setting, so a privacy request cannot undo it. The careful version ends with your account. The broad version can be passed on, never expires, and survives deletion.

THE MOVE Whether the licence ends with the account is written in their terms, not yours. Closing the account goes on your record.

“unless a longer period is required or permitted by law”

The word permitted, not just required, is the weight. It lets an operator keep your record even where no law compels it, turning an optional allowance into a standing right to hold on.

THE MOVE How long they read that as, and what it covers, is theirs to state. The reply, or the silence, goes on your record.

“when disclosure is required by law or to protect the safety of guests, employees, the public or our property”

This pairs legal compulsion with a broad ground the operator judges for itself. It lets them hand over guest data without a court order whenever they decide safety or property is at stake.

THE MOVE What counts as a safety or property reason, and who has received data under it, is theirs to answer. Their reply goes on your record.

“to comply with local registration, permit or short-term rental laws where registration is necessary”

This wires the government lodging registers into the policy. It authorises handing guest or host identity data to the authorities wherever local law runs a register, notification or permit scheme.

THE MOVE Which authorities have received your details under a local register is theirs to answer. Their reply goes on your record.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply. Start your record →