Your Information

Privacy Policy

How Palm Grove Hideaway Resort handles the personal information entrusted to us before, during and after your stay.

Last updated 17 July 2026
Purposeful collection

We ask for information needed to manage your enquiry, booking and stay.

Responsible use

We use personal information for clear operational, legal and service purposes.

Appropriate protection

We use reasonable organisational, technical and physical safeguards.

Palm Grove Hideaway Resort respects your privacy and aims to handle personal information fairly, transparently and securely.

This Policy applies when you visit our website, contact us, make or join a reservation, stay at the resort, participate in an experience, use our services or interact with our official digital channels.

01

About this Policy and who is responsible

Palm Grove Hideaway Resort, Tharawilluwa, West Wilpotha, Chilaw, Sri Lanka, is responsible for deciding how personal information covered by this Policy is handled. In data-protection terminology, Palm Grove acts as the controller for that processing.

We aim to process personal information consistently with applicable Sri Lankan law, including the Personal Data Protection Act, No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025, as and when the relevant provisions apply.

What is personal information?

Information that identifies you or can reasonably be linked to you, whether by itself or together with other information.

02

Information we may collect

The information collected depends on how you interact with us. We may collect the following categories where reasonably necessary.

Identity

Guest and identification details

Name, title, date of birth or age, nationality, signature, and passport, NIC or other identification details where required.

Contact

Ways to reach you

Email address, telephone or WhatsApp number, postal address, country of residence and emergency-contact details.

Reservation

Booking and stay information

Dates, selected stay, party members, children’s ages, arrival information, booking reference, preferences and stay history.

Payment

Transaction and billing data

Charges, payment status, invoices, billing details and limited payment references supplied by banks or secure payment providers.

Experience

Meals, activities and requests

Meal choices, celebrations, activities, accessibility requests, feedback and service preferences.

Digital

Website and device data

IP address, browser and device information, approximate location, referring page, cookie identifiers and website interaction data.

Communications

Messages and feedback

Email, form, telephone, WhatsApp and social-media messages, enquiries, reviews, survey responses and complaint records.

Security

Safety and incident records

Access, loss, damage, accident and security records, and CCTV footage if cameras are operated and appropriately signposted.

Dietary, allergy, accessibility or health-related information can be sensitive. Please provide only what we reasonably need to assist you. We will handle such information with additional care and use it for the relevant request, safety need or another lawful purpose.

03

How we obtain information

We may receive personal information:

  • directly from you through forms, reservations, messages, calls, payments and your stay;
  • from the person organising a booking, event or visit on your behalf;
  • from travel agents and booking platforms such as Booking.com;
  • from payment processors, banks and fraud-prevention providers;
  • from transport, tour or activity providers involved in a requested service;
  • from Google, Meta or other platforms when you use their services to contact or interact with us; and
  • automatically from your browser or device through necessary cookies, logs and any enabled analytics tools.

If you give us information about another person, you should have authority to do so and make this Policy available to them.

04

How we use personal information

We may use information to:

  • answer enquiries and provide quotations;
  • check availability, confirm and administer reservations;
  • process deposits, payments, refunds, invoices and accounting records;
  • prepare accommodation, meals, activities, transfers, celebrations and special requests;
  • communicate before, during and after a stay;
  • personalise and improve guest service where appropriate;
  • support safety, security, incident response, fraud prevention and property protection;
  • maintain, secure, troubleshoot and improve our website and operational systems;
  • analyse demand and business performance using aggregated or appropriately protected information;
  • manage reviews, feedback, disputes and legal claims;
  • send marketing where you have consented or where otherwise permitted, with a way to opt out; and
  • comply with tax, accounting, tourism, immigration, public-health, court, law-enforcement and other legal requirements.
06

Who we may share information with

We do not sell personal information. We may disclose only the information reasonably required to:

  • payment processors, banks and financial-service providers;
  • website hosting, email, communications, booking, analytics, security and IT providers;
  • travel agents and booking platforms connected with your reservation;
  • approved transport, tour, guide, activity, catering or other providers needed for a requested service;
  • professional advisers such as accountants, auditors, insurers and lawyers;
  • competent government, tourism, immigration, tax, law-enforcement, court or regulatory authorities where lawfully required; and
  • a successor or adviser involved in a genuine sale, financing or reorganisation of the resort, subject to appropriate confidentiality.

Service providers are expected to use information only for authorised purposes and apply appropriate protection. Independent booking, payment and tour providers may also act under their own privacy policies.

07

International data transfers

Some technology, booking, communications, cloud or payment providers may process information outside Sri Lanka. Where cross-border processing occurs, we will take measures required by applicable law, which may include contractual protection, a recognised safeguard, consent where appropriate, or another lawful transfer mechanism.

Protection and legal rights can differ between countries. You may contact us for more information about the safeguards relevant to your information.

08

How long we keep information

We retain personal information only for as long as reasonably needed for the purpose collected, including providing a stay or service, maintaining business and tax records, resolving complaints, protecting legal rights and meeting regulatory obligations.

Retention periods vary according to the type of record, legal requirement, sensitivity and risk. When information is no longer required, we will take reasonable steps to delete, destroy or anonymise it. Backup copies may remain for a limited period until securely overwritten through normal cycles.

09

Your choices and privacy rights

Subject to the relevant provisions of applicable law, exceptions and the status of those provisions, you may be entitled to ask us to:

  • confirm whether we process your personal information and provide access;
  • correct or complete inaccurate or incomplete information;
  • erase information in circumstances where it is no longer lawfully required;
  • stop or restrict certain processing, including objecting where applicable;
  • withdraw consent where consent is the basis of processing; and
  • review certain decisions or pursue a complaint through an available legal or regulatory process.
Step 1 Send your request

Use our contact page or email and clearly describe the information or action requested.

Step 2 Confirm your identity

We may ask for reasonable verification so information is not disclosed to the wrong person.

Step 3 Receive our response

We will respond within the period required by applicable law and explain any lawful limitation.

A request may be limited where we must protect another person, preserve legal privilege, prevent fraud, comply with law or retain information for a lawful purpose. We may ask an authorised representative to demonstrate their authority.

10

Marketing communications

We may send promotional news or offers where you have consented or where otherwise permitted. You can opt out using the unsubscribe method in the message or by contacting us. Opting out of marketing does not prevent essential communications about an enquiry, booking, payment or active stay.

If you interact with Palm Grove through Facebook, Instagram, WhatsApp or another social platform, that platform also processes information under its own terms and privacy policy.

11

Cookies and website technologies

Our website may use small files or similar technologies to operate forms and security features, remember choices, understand site performance and, where enabled and permitted, measure visits or marketing effectiveness.

You can manage cookies through your browser and any cookie controls made available on the website. Blocking necessary cookies may prevent parts of the site from working correctly. Browser “do not track” signals do not operate consistently across services and may not be recognised by every provider.

12

How we protect information

We use reasonable measures appropriate to the nature of the information and risk. These may include access controls, staff confidentiality, authentication, secure transmission and storage, backups, provider review, physical safeguards, monitoring and procedures for incidents.

Payment-card transactions may be handled directly by secure payment providers. We do not intend to store complete card details when the payment process is hosted or tokenised by such a provider.

No internet transmission or storage system can be guaranteed completely secure. Please avoid sending unnecessary sensitive information through ordinary email or public social-media messages and tell us promptly if you suspect misuse of your information.

13

Personal-data incidents

If a security incident affects personal information, we will assess it, take reasonable containment and remedial steps, preserve appropriate records, and notify the relevant authority or affected individuals where notification is required by applicable law.

14

Information about children

Our website and direct booking process are intended for adults. A parent, guardian or authorised adult may provide limited information about a child where needed for occupancy, meals, safety or services. Please do not provide more information than necessary. We do not knowingly use children’s information for direct marketing.

16

Updates to this Policy

We may update this Policy to reflect changes in law, technology, providers or resort operations. The latest version will be published here with its revision date. If a change materially affects how we use information already collected, we will take any additional steps required by applicable law.

If this Policy is translated, the English version will prevail to the extent permitted by law if there is an inconsistency.

17

Contact us about your privacy

To ask a question, exercise a privacy right or raise a concern, contact Palm Grove and mark your message “Privacy Request”. Please do not send a full passport, NIC or payment-card number in your first message.

Palm Grove Hideaway Resort
Tharawilluwa, West Wilpotha, Chilaw, Sri Lanka
connect@pghtw.com
Questions are welcome

Speak with us if you need clarity

Contact Palm Grove
WhatsApp