Privacy Policy

We're pretty serious about keeping your info safe. Here's the honest rundown on how we handle your data at Frostwyrm Legacy.

Last updated: October 27, 2025

Introduction

Look, we get it - nobody really enjoys reading privacy policies. But here at Frostwyrm Legacy Hotel, we believe you deserve to know exactly what happens with your personal info when you book a room or just browse our site.

This policy covers everything from the moment you land on our website to when you're checking out after an amazing stay in the mountains. We're based in Whistler, BC, Canada, so we follow Canadian privacy laws (PIPEDA, to be specific), but we also respect international standards because guests come to us from all over the world.

Bottom line? We only collect what we actually need, we don't sell your data to random companies, and we take security pretty seriously. If you've got questions after reading this, just give us a call at (604) 555-8372 - we're happy to chat about it.

What Info We Collect

When you're making a reservation or setting up an account with us, we'll ask for things like:

  • Your full name and preferred name (if different)
  • Email address and phone number
  • Mailing address and billing address
  • Date of birth (for age verification and special occasions)
  • Government-issued ID (sometimes required for check-in, especially international guests)
  • Payment card details (we don't actually store full card numbers - more on that later)

We only ask for what's necessary to provide the service you're looking for. If you're just browsing? We collect way less.

To make your stay awesome, we keep track of:

  • Booking dates, room preferences, and special requests
  • Dietary restrictions or allergies (for our restaurant)
  • Accessibility needs
  • Activity bookings (spa appointments, guided expeditions, ski passes)
  • Guest preferences (like pillow types, room temperature, or if you want extra towels)
  • Loyalty program info if you're part of our returning guest program

This helps us remember what you liked for next time so we can make your return visit even better.

Like pretty much every website these days, we automatically collect some technical stuff:

  • IP address and general location data
  • Browser type and device information
  • Pages you visit on our site and how long you hang out
  • Referring website (how you found us)
  • Time and date of your visits
  • Cookie data (see our cookies section below)

This helps us figure out if our website's working properly and what parts people actually use.

When you reach out to us or leave feedback, we keep records of:

  • Emails, phone calls, and chat messages
  • Survey responses and reviews
  • Social media interactions
  • Any complaints or compliments (we learn from both!)

We save these conversations so we can follow up properly and improve our service based on what guests tell us.

How We Actually Use This Stuff

We're not collecting data just for fun - here's what we actually do with it:

Core Hotel Operations

Processing your reservations, managing check-ins and check-outs, handling payments, and basically making sure you've got a room when you show up. This includes coordinating with our restaurant, spa, and activity teams to fulfill any bookings you've made.

Communication

Sending booking confirmations, pre-arrival info, and any updates about your stay. We'll also reach out if there's something important you need to know (like if a massive snowstorm's coming and you should probably get here early).

Personalization

Remembering your preferences so we can make future stays better. If you loved the corner suite last time, we'll try to get you that same room. If you mentioned you're celebrating an anniversary, we might surprise you with something special.

Marketing (But Only If You're Cool With It)

Sending you emails about special offers, seasonal packages, or new experiences we're launching. You can opt out anytime - there's an unsubscribe link in every marketing email, and we won't take it personally.

Improving Our Service

Analyzing trends to figure out what's working and what isn't. Like, if everyone's booking the Nordic spa on Tuesdays, maybe we need more staff then. We use aggregated, anonymized data for this kind of analysis.

Legal & Safety Stuff

Complying with laws and regulations, preventing fraud, and keeping everyone safe. Sometimes we're legally required to keep certain records for a specific period.

Website Optimization

Making sure our site works smoothly, loads quickly, and actually helps you find what you're looking for. We test different layouts and features to see what works best.

Who We Share Your Info With

Real talk: We don't sell your personal information. Period. But we do share it with certain partners who help us run the hotel. Here's the complete list:

Payment Processors

We use secure third-party payment processors to handle credit card transactions. They're PCI-DSS compliant (that's the security standard for handling card data), and we never see or store your full card number on our own servers.

Service Partners

Our guided mountain expeditions are run by licensed local guides, and ski passes are coordinated with Whistler Blackcomb. These partners only get the info they need to provide the service you booked.

Technology Providers

Our booking system, email service, website hosting, and analytics tools are provided by trusted third parties. They're all bound by strict confidentiality agreements and can only use your data to provide services to us.

Legal Requirements

If we're legally required to disclose information (like responding to a valid court order or complying with tax regulations), we will. We'll try to notify you if we can, unless we're prohibited from doing so.

Business Transfers

If Frostwyrm Legacy Hotel is ever sold or merged with another company (unlikely, but we have to mention it), your information would be transferred to the new owners. They'd still have to follow this privacy policy though.

With Your Permission

Sometimes we might want to share your info in ways not covered above - like featuring your review on our website. We'll always ask for your explicit consent first.

Cookies & Tracking Technologies

Yeah, we use cookies - not the delicious kind, unfortunately. These are small files that get stored on your device when you visit our site. Here's what they do:

Essential Cookies

These are necessary for the website to work properly. They handle things like keeping you logged in, remembering what's in your booking cart, and maintaining your session security. You can't really turn these off without breaking the site.

Analytics Cookies

We use tools like Google Analytics to understand how people use our site. This helps us figure out which pages are confusing or if there's a broken link somewhere. The data's anonymized, so we're not tracking you personally.

Preference Cookies

These remember your choices, like language preferences or if you've already dismissed certain pop-ups. Makes your experience smoother on return visits.

Marketing Cookies

Used to show you relevant ads on other websites after you've visited ours. If you've looked at our spa packages, you might see spa-related ads later. You can opt out of these through your browser settings or ad preference tools.

Managing Cookies

Most browsers let you control cookies through their settings. You can block all cookies, delete existing ones, or set up alerts when cookies are being placed. Just keep in mind that blocking essential cookies might prevent parts of our site from working correctly.

How We Keep Your Data Safe

We take security seriously because, honestly, data breaches are a nightmare for everyone involved. Here's what we do to protect your info:

Encryption

All data transmitted between your browser and our servers is encrypted using SSL/TLS technology. That's the lock icon you see in your browser's address bar.

Secure Servers

Our servers are hosted in secure data centers with physical security measures, fire protection, and backup power systems.

Access Controls

Only authorized staff can access guest data, and they're trained on privacy and security best practices. We log all access for audit purposes.