Privacy Policy

Effective date: 26 March 2026 | Last updated: 26 March 2026

This policy applies to: The GroupBooker consumer booking platform (B2C), the GroupBooker business platform (B2B), and the GroupBooker public website. GroupBooker is a trading name of Son of Will Ltd.


1. Who We Are

This is the privacy policy for GroupBooker, a trading name of Son of Will Ltd. In this policy, “we”, “us”, and “our” refer to the organisations responsible for your personal data as set out below.

DetailInformation
Platform operatorSon of Will Ltd, trading as GroupBooker
Company number (Son of Will Ltd)10328311
Data controllerMeta Cannect Ltd
Company number (Meta Cannect Ltd)09295106
Privacy contact emailgdpr.groupbooker.com@meta-cannect.com
ICO registration numberZB037106 (Meta Cannect Ltd)

Meta Cannect Ltd acts as the data controller for the personal data described in this policy, on behalf of Son of Will Ltd, the operator of the GroupBooker platform. This means Meta Cannect Ltd decides how and why your personal data is processed in connection with the GroupBooker services.

We are not required to appoint a Data Protection Officer under UK GDPR Article 37, as our core activities do not involve large-scale monitoring of individuals or processing of special category data. For any data protection queries, please contact us at gdpr.groupbooker.com@meta-cannect.com.


2. About This Policy

This policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have. It covers the GroupBooker consumer booking platform, business-to-business services, and public website, all of which are operated by Son of Will Ltd with Meta Cannect Ltd acting as data controller.

We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and the Data (Use and Access) Act 2025.

If you believe we are not handling your data in accordance with this policy, please contact us at the details above. You also have the right to complain to the Information Commissioner’s Office (ICO) — see Section 11.


3. What Personal Data We Collect

3.1 Data We Collect Directly From You

CategoryExamplesWhen Collected
Identity dataFirst name, last name, titleAccount registration, booking
Contact dataEmail address, phone numberAccount registration, enquiries
Account dataUsername, password (encrypted), account preferencesAccount registration
Authentication data (B2B)Email address used as your username for platform authentication via AWS CognitoWhen you register for a B2B account
Booking dataBooking details, dates, group size, special requirementsWhen you make or manage a booking
Financial dataPayment card details (processed by our payment provider — we do not store full card numbers)When you make a payment
Communications dataEmails, messages, feedback, and support requests you send usWhen you contact us
Business data (B2B)Company name, job title, business contact details, contract informationWhen you register as a business client or enter a contract
User-generated contentReviews, comments, forum posts, and profile information you choose to publishWhen you post content on our platform

3.2 Data We Collect Automatically

CategoryExamplesHow Collected
Technical dataIP address, browser type and version, device type, operating systemAutomatically when you visit our site
Usage dataPages visited, time on page, click patterns, referring URLCookies and similar technologies (see Section 8)
Location dataApproximate location derived from IP addressAutomatically when you visit our site

We treat IP addresses and device identifiers as personal data in accordance with UK GDPR.

3.3 Data We Receive From Third Parties

SourceData CategoriesPurpose
Service providers listed on our platformBooking confirmations, availability, service details relating to your bookingTo fulfil your booking
Payment processorsTransaction confirmation, fraud screening resultsTo process payments and prevent fraud
Business partners (B2B)Business contact details provided by your employer or organisationTo manage our B2B relationships
Publicly available sourcesBusiness registration information, publicly listed contact detailsTo verify business clients

Where we receive your data from a third party, we will provide you with this information within one month of obtaining it, or at the point of first communication with you, whichever is sooner.


4. Why We Use Your Data and Our Lawful Basis

Under UK GDPR, we must have a lawful basis for each way we use your personal data. The table below sets out our processing purposes and the corresponding lawful basis.

PurposeLawful BasisApplies To
To create and manage your accountPerformance of a contract with you (Article 6(1)(b))B2C and B2B
To authenticate B2B users via AWS CognitoPerformance of a contract with you (Article 6(1)(b))B2B
To process and fulfil bookingsPerformance of a contract with you (Article 6(1)(b))B2C and B2B
To process paymentsPerformance of a contract with you (Article 6(1)(b))B2C and B2B
To communicate with you about your bookings or accountPerformance of a contract with you (Article 6(1)(b))B2C and B2B
To respond to your enquiries and provide customer supportPerformance of a contract, or our legitimate interest in providing good service (Article 6(1)(f))B2C, B2B, Public
To send you marketing emails about our services (B2C consumers)Your consent (Article 6(1)(a)), obtained via opt-in at registration or bookingB2C
To send marketing communications to business contactsOur legitimate interest in promoting our services to existing and prospective business clients (Article 6(1)(f)). We have conducted a legitimate interest assessment and concluded that this processing does not override your rights. You can opt out at any time.B2B
To send transactional and marketing emails via SendGridPerformance of a contract (Article 6(1)(b)) for transactional emails; your consent (Article 6(1)(a)) for B2C marketing emails; legitimate interest (Article 6(1)(f)) for B2B marketingAll
To improve our website and servicesOur legitimate interest in understanding how our services are used and improving them (Article 6(1)(f))All
To detect and prevent fraudOur legitimate interest in protecting our business and users (Article 6(1)(f))All
To comply with legal obligations (e.g., tax, accounting)Legal obligation (Article 6(1)(c))All
To display user-generated content you have postedOur legitimate interest in operating a platform that includes user contributions (Article 6(1)(f))B2C, Public
To share data with service providers to fulfil your bookingPerformance of a contract with you (Article 6(1)(b))B2C

Where we rely on consent, you can withdraw your consent at any time by contacting us at gdpr.groupbooker.com@meta-cannect.com or by using the unsubscribe link in any marketing email. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

Where we rely on legitimate interest, you have the right to object (see Section 11). We will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests.


5. Who We Share Your Data With

We do not sell your personal data. We share your data only as described below:

Recipient CategoryWhat We ShareWhy
Service providers listed on our platformYour booking details, name, contact information, and any special requirements you provideTo fulfil the booking you have requested (contract performance)
Payment processorsPayment transaction dataTo process your payment securely. They act as independent controllers for fraud prevention.
Amazon Web Services (AWS) — hosting and infrastructureAll platform data is hosted on AWS infrastructure in the UK (eu-west-2, London). Data is encrypted at rest and in transit. AWS does not have access to our unencrypted data and processes it solely on our instructions as a data processor under a data processing agreement.To host and operate our services securely. AWS acts as our data processor.
Amazon Web Services (AWS) — Cognito authenticationEmail address used as B2B account username only. This data is not linked to any other personal data we hold about you within the Cognito service. Hosted in the UK (eu-west-2, London).To provide secure authentication for B2B platform users. AWS Cognito acts as our data processor.
SendGrid (Twilio Inc.) — email deliveryEmail addresses, names, email content. SendGrid processes this data via API solely to deliver emails on our behalf and does not use it for their own purposes.To send transactional emails (e.g., booking confirmations, account notifications) and, where you have consented or we have a legitimate interest, marketing communications. SendGrid acts as our data processor under a data processing agreement.
Analytics providersAnonymised/pseudonymised usage dataTo help us understand how our site is used and improve it. Subject to your cookie consent.
Professional advisersData relevant to the advice soughtLegal, accounting, and insurance purposes (legitimate interest or legal obligation)
Law enforcement or regulatorsData as lawfully requestedTo comply with legal obligations or to protect our legal rights
Credit reference agenciesIdentity and transaction data, only where you have initiated a chargeback without first contacting us to resolve the issueFraud prevention (legitimate interest). See Section 5.1 below.

5.1 Credit Reference Sharing

Where a customer instructs their payment provider to reverse a charge (chargeback) without first contacting us to resolve the matter, we may share limited information with credit reference agencies for the purpose of fraud prevention. We rely on our legitimate interest for this processing and have conducted a balancing test. We recognise your consumer rights, including your right to initiate chargebacks in appropriate circumstances. We will only share data where we have reasonable grounds to believe a transaction was fraudulent or abusive. You have the right to object to this processing (see Section 11).


6. Marketplace and Third-Party Bookings

When you use our platform to book a service provided by a third party, we need to share certain personal data with that service provider so they can fulfil your booking. This sharing is necessary for the performance of your contract with us and with the service provider.

We will share only the data that is necessary for the booking (typically your name, contact details, booking dates, group size, and any requirements you have specified). The service provider becomes an independent data controller for the data we share with them, and their own privacy policy will apply to their use of your data.

We require our listed service providers to handle your data in accordance with applicable data protection law, but we are not responsible for their processing once the data has been shared.


7. How Long We Keep Your Data

We keep your personal data only for as long as necessary for the purposes for which it was collected. The retention periods below apply:

Data CategoryRetention PeriodReason
Account and identity dataDuration of your account plus 2 years after closureTo allow you to reactivate and to handle any post-closure enquiries
B2B authentication data (Cognito)Duration of your B2B account; deleted from Cognito upon account closureRequired for platform authentication
Booking and transaction records6 years from the date of the transactionLegal and regulatory requirements (tax, accounting, potential claims)
Marketing consent recordsDuration of consent plus 1 year after withdrawalTo evidence that consent was given and when it was withdrawn
Customer support communications3 years from resolutionTo handle follow-up queries and improve our service
Website analytics data26 months (anonymised data may be kept longer)To analyse trends. Anonymised data is no longer personal data.
Business client records (B2B)Duration of the contract plus 6 yearsContractual and legal obligations
User-generated contentUntil you delete it, or we remove it in accordance with our terms, or account closureTo operate the platform
Credit reference data shared6 years from the date of sharingFraud prevention records
Email delivery logs (SendGrid)30 days for delivery/bounce logs; marketing suppression lists retained as long as necessary to honour opt-outsEmail delivery and compliance

When we no longer need your personal data, we will securely delete or anonymise it.


8. Cookies and Similar Technologies

Our website uses cookies and similar technologies (such as JavaScript-based analytics and pixel tags). A cookie is a small file placed on your device that helps us provide and improve our services.

8.1 Types of Cookies We Use

Cookie TypePurposeLawful BasisDuration
Strictly necessaryEssential for the website to function (e.g., session management, security)Exempt from consent (PECR Regulation 6(4))Session / up to 1 year
AnalyticsHelp us understand how visitors use our site (e.g., pages visited, time on site)Your consentUp to 26 months
FunctionalityRemember your preferences (e.g., language, region)Your consentUp to 1 year
Marketing / AdvertisingUsed by third-party advertisers to deliver relevant ads and measure ad performanceYour consentVaries by provider

When you first visit our site, we will ask for your consent before placing any non-essential cookies on your device. You can change your cookie preferences at any time using the cookie settings in our website footer.

If you choose not to accept non-essential cookies, the core functionality of our website will still work, but some features (such as personalised recommendations or analytics-driven improvements) may be limited.

8.2 Third-Party Cookies

Third-party advertisers and analytics providers may place cookies on your device when you visit our site. We require consent before enabling these cookies.

We audit the third-party cookies on our site regularly.


9. International Data Transfers

We are based in the United Kingdom. Our primary hosting infrastructure (AWS) and authentication service (AWS Cognito) are both located in the UK (eu-west-2, London region), so the majority of your personal data remains within the UK. However, some of our service providers process your data outside the UK. The following transfers apply:

ProviderData TransferredTransfer DestinationSafeguard
Amazon Web Services (AWS)All platform data (encrypted at rest and in transit)UK — AWS eu-west-2 (London). AWS does not have access to unencrypted data.No international transfer — data remains in the UK. Data processing agreement with AWS in place.
AWS CognitoB2B user email addresses onlyUK — AWS eu-west-2 (London)No international transfer — data remains in the UK. Data processing agreement with AWS in place.
SendGrid (Twilio Inc.)Email addresses, names, email contentUnited StatesUK International Data Transfer Agreement (IDTA) with Twilio Inc.; Twilio also participates in the EU-US Data Privacy Framework

Where we transfer personal data outside the UK, we ensure it is protected by one or more of the following safeguards:

You may request a copy of the safeguards we have in place by contacting us at gdpr.groupbooker.com@meta-cannect.com.


10. Automated Decision-Making and Profiling

We do not currently use your personal data for automated decision-making (including profiling) that produces legal effects or similarly significant effects on you.


11. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

RightWhat This Means
Right of accessYou can request a copy of the personal data we hold about you (a “Subject Access Request”).
Right to rectificationYou can ask us to correct inaccurate or incomplete personal data.
Right to erasureYou can ask us to delete your personal data in certain circumstances (e.g., when it is no longer necessary for the purpose it was collected).
Right to restrict processingYou can ask us to limit how we use your data in certain circumstances (e.g., while we verify accuracy).
Right to data portabilityYou can request your data in a structured, machine-readable format and have it transferred to another controller, where processing is based on consent or contract and carried out by automated means.
Right to objectYou can object to processing based on legitimate interest (including profiling) and to direct marketing at any time.
Right to withdraw consentWhere we process your data based on your consent, you can withdraw that consent at any time. This does not affect the lawfulness of processing before withdrawal.
Rights related to automated decisionsYou have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, unless specific conditions apply.

To exercise any of these rights, please contact us at gdpr.groupbooker.com@meta-cannect.com. We will respond within one month. In complex cases we may extend this by a further two months, but we will let you know within the first month if this is necessary.

We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.

11.1 Right to Complain

If you are not satisfied with how we handle your personal data or respond to your request, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

We would appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first.


12. Data Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:

We do not store full payment card details. Payments are processed securely by our payment provider, who is PCI DSS compliant.


13. Children’s Data

Our services are not directed at children under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without appropriate parental consent, we will take steps to delete that data promptly. If you believe a child has provided us with personal data, please contact us at gdpr.groupbooker.com@meta-cannect.com.


14. User-Generated Content

Our platform may allow you to post reviews, comments, forum posts, and other content. Any personal data you include in content you post will be visible to other users of the platform and may be indexed by search engines.

We moderate content in accordance with our Terms of Use. We use user-generated content for the following specific purposes:

If you would like content you have posted to be removed, you can delete it from your account or contact us at gdpr.groupbooker.com@meta-cannect.com. We will consider removal requests in line with your right to erasure under Article 17 UK GDPR, balancing this against any rights of others (such as freedom of expression) where applicable.


15. Third-Party Advertising

Third parties may advertise on our website. Where those advertisers use cookies or similar tracking technologies to deliver or measure advertisements, we will obtain your consent before those technologies are activated (see Section 8).

We audit the advertising partners who operate on our site. While we take reasonable steps to ensure our advertising partners comply with applicable data protection law, they are independent data controllers for the personal data they collect through their own technologies.


16. Marketing Communications

16.1 Consumer Marketing (B2C)

We will only send you marketing communications by email, SMS, or other electronic means if you have given us your explicit opt-in consent, or in limited circumstances where you are an existing customer and the marketing relates to similar products or services (the “soft opt-in” under PECR Regulation 22). You can opt out of marketing at any time by:

All marketing emails are delivered via SendGrid, which processes your email address and name solely for the purpose of email delivery on our behalf (see Section 5).

16.2 Business Marketing (B2B)

We may send marketing communications to business contacts at their corporate email addresses, relying on our legitimate interest in promoting our services. We have conducted a legitimate interest assessment and provide an opt-out in every communication. Corporate subscribers can unsubscribe at any time using the same methods listed above.


17. Is Providing Your Data a Requirement?

Some personal data is necessary for us to provide our services to you. Where providing data is a contractual requirement (e.g., your name and contact details to process a booking), we will make this clear at the point of collection.

For B2B users, providing an email address is a contractual requirement for account authentication via AWS Cognito. Without this, we cannot provide access to the B2B platform.

If you choose not to provide data that is necessary for a booking or account registration, we may not be able to provide the relevant service. You are never required to consent to marketing as a condition of using our services.


18. Data Protection Complaints Procedure

In accordance with the Data (Use and Access) Act 2025, we maintain a formal complaints procedure for data protection matters.

If you are dissatisfied with how we have handled your personal data, you can submit a data protection complaint to us by emailing gdpr.groupbooker.com@meta-cannect.com.

We will acknowledge your complaint within 5 working days and aim to provide a full response within 28 days. If we cannot resolve your complaint to your satisfaction, you may escalate it to the ICO (see Section 11.1).


19. Changes to This Policy

We may update this policy from time to time. Where changes are significant, we will notify you by email (if we have your email address) or by a prominent notice on our website. The “last updated” date at the top of this policy shows when it was last revised.

We encourage you to review this policy periodically.


20. How to Contact Us

If you have any questions about this policy, your personal data, or wish to exercise your rights, please contact the data controller, Meta Cannect Ltd, by email at gdpr.groupbooker.com@meta-cannect.com.

You can also view our Terms and Conditions.