Privacy Policy
Last updated: June 2025
Welcome to yuluneinnreviewer.com (the "Website"), operated by We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable Canadian and international privacy legislation. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you visit our Website, make a reservation, use our hotel and casino services, or interact with us in any other way.
Please read this Privacy Policy carefully. By accessing or using our Website or services, you acknowledge that you have read, understood, and agree to the practices described herein.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Company Name | |
| Trading Name | Yuluneinnreviewer |
| Registration Country | Canada |
| Legal Address | |
| Website | yuluneinnreviewer.com |
| Privacy Email | info@yuluneinnreviewer.com |
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us using the details provided in the Contact Information section at the end of this document.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO:
| Title | The Data Protection Officer |
| Organisation | |
| Address | |
| info@yuluneinnreviewer.com |
3. Personal Data We Collect
We collect personal data that you provide to us directly, data collected automatically when you use our Website, and data obtained from third parties. The categories of personal data we may collect include, but are not limited to, the following:
3.1 Data You Provide Directly
- Identity Data: Full name, date of birth, gender, nationality, and government-issued identification details (e.g., passport number, driver's licence number) as required by law for hotel check-in and casino regulatory compliance.
- Contact Data: Email address, telephone number, mailing address, and postal code.
- Reservation and Booking Data: Check-in and check-out dates, room type preferences, number of guests, special requests, and booking confirmation numbers.
- Payment Data: Credit or debit card details, billing address, and transaction history. Payment card details are processed securely via our PCI-DSS compliant payment processors; we do not store full card numbers on our systems.
- Casino and Gaming Data: Player account registration details, gaming history, wins and losses, responsible gambling self-exclusion requests, and age verification information as required by applicable gaming regulations.
- Account and Profile Data: Username, password, loyalty programme membership details, preferences, and communications history.
- Communications Data: Messages, enquiries, complaints, and feedback you submit via our contact forms, email, telephone, or live chat.
- Marketing Preferences: Your preferences for receiving marketing communications from us and our third-party partners.
- Health and Accessibility Data (Special Category): Where you voluntarily provide information regarding dietary requirements, disabilities, or accessibility needs to enable us to provide appropriate services, such data is treated as special category data under GDPR Article 9 and processed only with your explicit consent.
3.2 Data Collected Automatically
- Technical Data: IP address, browser type and version, operating system, device identifiers, and time zone settings.
- Usage Data: Pages visited, links clicked, referral URLs, session duration, and interaction data on our Website.
- Cookie and Tracking Data: Information collected through cookies, web beacons, pixels, and similar tracking technologies. Please refer to our Cookie Policy for full details.
- Location Data: Approximate geographic location derived from your IP address, or precise location data if you have granted permission through your device settings.
3.3 Data Received from Third Parties
- Booking Platforms and Travel Agencies: Reservation data received from online travel agencies (OTAs), global distribution systems (GDS), and affiliate booking partners.
- Payment Processors: Transaction confirmation and fraud prevention data.
- Identity Verification Providers: Age and identity verification data for casino regulatory compliance.
- Marketing Partners: Contact and demographic information where you have consented to sharing your data with partners.
- Social Media Platforms: Profile information where you choose to connect your social media account or log in via a social media provider.
- Regulatory and Government Authorities: Data shared with or received from gaming regulatory bodies, law enforcement, or other government agencies as required by law.
4. Legal Basis for Processing Personal Data
We process your personal data only where we have a lawful basis to do so under Article 6 of the GDPR. The legal bases we rely upon are as follows:
4.1 Performance of a Contract (Article 6(1)(b))
We process your personal data where it is necessary to enter into or perform a contract with you, or to take steps at your request prior to entering into a contract. This includes processing data to:
- Process hotel reservations and manage your stay.
- Manage your casino player account and facilitate gaming activities.
- Process payments and issue receipts and invoices.
- Administer loyalty programme memberships and rewards.
- Respond to your enquiries and provide customer support.
4.2 Compliance with a Legal Obligation (Article 6(1)(c))
We process your personal data where it is necessary for compliance with a legal obligation to which we are subject. This includes processing data to:
- Comply with hotel registration and guest identification laws under Canadian provincial regulations.
- Fulfil obligations under applicable gaming and casino licensing legislation, including age verification and responsible gambling requirements.
- Comply with anti-money laundering (AML) and counter-terrorism financing (CTF) regulations.
- Respond to lawful requests from law enforcement or regulatory authorities.
- Maintain accounting and tax records as required by Canadian tax legislation.
- Adhere to data retention obligations imposed by applicable laws.
4.3 Legitimate Interests (Article 6(1)(f))
We process your personal data where it is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests, fundamental rights, or freedoms. Our legitimate interests include:
- Operating, improving, and securing our Website and digital services.
- Preventing and detecting fraud, cheating, and other unlawful activities within our hotel and casino.
- Operating CCTV and physical security systems on our premises for the safety of guests and staff.
- Conducting analytics and business intelligence to improve our products and services.
- Sending direct marketing communications about similar products and services where permitted by applicable law.
- Managing and defending legal claims.
- Sharing data within our corporate group for internal administrative purposes.
4.4 Consent (Article 6(1)(a))
Where we rely on your consent as the legal basis for processing, we will request your consent in a clear and affirmative manner. You have the right to withdraw your consent at any time without detriment. Processing based on consent includes:
- Sending promotional emails, newsletters, and marketing communications about offers, events, and promotions.
- Placing non-essential cookies and similar tracking technologies on your device.
- Processing special category data, such as health or accessibility information.
- Profiling for personalised marketing purposes.
4.5 Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person, for example, in the event of a medical emergency on our premises.
4.6 Public Task (Article 6(1)(e))
We may process personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, as may be required under applicable Canadian gaming or hospitality regulation.
4.7 Special Category Data
Where we process special categories of personal data (as defined under GDPR Article 9), including health data, we rely on your explicit consent (Article 9(2)(a)) or other applicable conditions, such as the establishment, exercise, or defence of legal claims (Article 9(2)(f)).
5. Purposes of Data Processing
We use your personal data for the following purposes:
- Reservation Management: To process, confirm, modify, and manage hotel room and suite bookings.
- Hotel Services Delivery: To facilitate check-in and check-out, manage guest preferences, and deliver personalised in-room and on-property services.
- Casino and Gaming Services: To register and manage player accounts, verify age and identity, facilitate gaming activities, administer responsible gambling programmes, and comply with gaming regulatory requirements.
- Payment Processing: To process transactions, prevent payment fraud, and issue invoices and receipts.
- Customer Support: To respond to enquiries, complaints, and requests, and to resolve disputes.
- Loyalty Programme: To enrol and manage your membership, track and redeem points, and deliver member benefits and rewards.
- Marketing and Communications: To send you information about our services, promotions, events, and special offers, subject to your preferences and consent where required.
- Personalisation: To personalise your experience on our Website and during your stay based on your preferences and past interactions.
- Security and Fraud Prevention: To protect the safety and security of our guests, staff, and premises; to detect, investigate, and prevent fraud, cheating, and other illegal activities.
- Legal and Regulatory Compliance: To fulfil our legal obligations under applicable hotel, gaming, tax, anti-money laundering, and data protection laws.
- Business Analytics and Improvement: To analyse Website traffic and usage patterns, improve our services, and conduct internal research and development.
- CCTV Surveillance: To monitor our premises for safety and security purposes using closed-circuit television systems.
6. Cookies and Tracking Technologies
Our Website uses cookies and similar tracking technologies (such as web beacons, pixels, and local storage) to enhance your browsing experience, analyse Website performance, and deliver targeted advertising.
The types of cookies we use include:
- Strictly Necessary Cookies: Essential for the Website to function correctly. These cannot be disabled.
- Performance and Analytics Cookies: Help us understand how visitors interact with our Website by collecting anonymous statistical data.
- Functional Cookies: Enable enhanced functionality and personalisation, such as remembering your preferences.
- Targeting and Advertising Cookies: Used to deliver relevant advertisements and track the effectiveness of marketing campaigns.
You may control and manage cookies through the cookie consent tool displayed upon your first visit to our Website, or through your browser settings. Please note that disabling certain cookies may affect the functionality of our Website. For full details, please refer to our separate Cookie Policy available on our Website.
7. Data Sharing and Disclosure
We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients, only where necessary and on appropriate legal grounds:
7.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instructions. These include:
- Payment processors and banking institutions for secure transaction processing.
- IT service providers, cloud hosting providers, and cybersecurity firms.
- Booking and reservation management platform providers.
- Email marketing and communications service providers.
- Customer relationship management (CRM) software providers.
- Analytics and market research providers.
- Identity verification and age verification service providers.
- Fraud detection and anti-money laundering screening service providers.
- Printing, mailing, and fulfilment service providers.
All service providers are required to implement appropriate technical and organisational security measures and are bound by contractual data processing agreements in accordance with GDPR Article 28.
7.2 Business Partners
We may share data with trusted business partners, such as online travel agencies, tour operators, and affiliated hospitality brands, where necessary to fulfil your reservation or service request, or where you have consented to receive joint marketing communications.
7.3 Regulatory and Government Authorities
We may disclose your personal data to regulatory authorities, gaming commissions, law enforcement agencies, tax authorities, or courts where we are legally required or permitted to do so, including but not limited to:
- The Alcohol and Gaming Commission of Ontario (AGCO) or other applicable gaming regulators.
- The Canada Revenue Agency (CRA) for tax compliance purposes.
- The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) for anti-money laundering compliance.
- Police services or law enforcement agencies in response to lawful requests.
7.4 Corporate Transactions
In the event of a merger, acquisition, restructuring, sale of assets, or other corporate transaction involving , your personal data may be transferred to the relevant successor entity, subject to equivalent privacy protections.
7.5 Legal Claims
We may share personal data with legal advisors, courts, or other parties where necessary to establish, exercise, or defend legal claims.
7.6 With Your Consent
We may share your personal data with other third parties where you have given your explicit consent for us to do so.
8. International Transfers of Personal Data
is based in Canada. Where we transfer your personal data to recipients located outside of Canada or the European Economic Area (EEA), we ensure that appropriate safeguards are in place to protect your data in accordance with applicable privacy legislation, including:
- Transfers to countries recognised by the European Commission or relevant supervisory authorities as providing an adequate level of data protection.
- Use of Standard Contractual Clauses (SCCs) approved by the European Commission where required.
- Binding Corporate Rules (BCRs) where applicable.
- Other legally recognised transfer mechanisms under GDPR Chapter V and PIPEDA.
You may request further information about the specific safeguards applied to international data transfers by contacting our Data Protection Officer.
9. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. The criteria used to determine our retention periods include:
- Contractual Data: Personal data processed for the performance of a contract is generally retained for a period of seven (7) years following the conclusion of the contractual relationship, in accordance with Canadian commercial and tax law limitation periods.
- Reservation and Guest Records: Hotel guest registration records are retained for a minimum of two (2) years, or longer where required by applicable provincial hotel regulations.
- Casino and Gaming Records: Player account data, gaming transaction records, and identity verification documents are retained for a minimum of five (5) years following the closure of a player account or the last gaming transaction, in compliance with gaming regulatory and anti-money laundering requirements.
- Financial and Tax Records: Accounting, payment, and invoicing records are retained for a minimum of seven (7) years as required by the Canada Revenue Agency.
- Marketing Data: Contact details and marketing preferences are retained until you withdraw your consent or opt out of marketing communications, after which they are deleted or anonymised within thirty (30) days.
- CCTV Footage: Security camera recordings are typically retained for a period of thirty (30) days, unless required for longer retention in connection with an incident, investigation, or legal claim.
- Website Analytics Data: Aggregated and anonymised analytics data may be retained indefinitely; identifiable usage data is retained for no longer than twenty-six (26) months.
Upon expiry of the applicable retention period, personal data is securely deleted, destroyed, or anonymised so that it can no longer be associated with an identified or identifiable individual.
10. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect your information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include, but are not limited to:
- Encryption of data in transit using Transport Layer Security (TLS) protocols.
- Encryption of sensitive data at rest using industry-standard encryption algorithms.
- Access controls, role-based permissions, and multi-factor authentication for systems containing personal data.
- Regular security assessments, penetration testing, and vulnerability management.
- Staff training on data protection and information security.
- Physical security measures for our premises and data storage facilities.
- Incident response procedures and data breach notification protocols.
- PCI-DSS compliance for payment card data processing.
While we take every reasonable precaution to protect your personal data, no method of transmission over the internet or method of electronic storage is 100% secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, in accordance with applicable data protection legislation.
11. Your Rights Under GDPR and Applicable Privacy Law
Subject to applicable law and certain conditions and exceptions, you have the following rights with respect to your personal data:
11.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether we process personal data about you and, if so, to request a copy of the personal data we hold about you, along with information about how and why we process it.
11.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.
11.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw your consent and no other legal basis exists, or where the data has been unlawfully processed. This right is subject to exceptions where retention is required by law or for the establishment, exercise, or defence of legal claims.
11.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while the accuracy of the data is contested or where you have objected to processing based on legitimate interests.
11.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to have that data transmitted directly to another controller where technically feasible.
11.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where processing is based on legitimate interests or the public interest, including profiling. You also have the right to object at any time to the processing of your personal data for direct marketing purposes, including profiling to the extent it relates to direct marketing.
11.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you, unless you have provided your explicit consent, it is necessary for the performance of a contract, or it is authorised by applicable law.
11.8 Right to Withdraw Consent
Where we process your personal data based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to the withdrawal. You may withdraw your consent by contacting us at info@yuluneinnreviewer.com or by using the unsubscribe mechanism in any marketing communication.
11.9 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Canada, this is the Office of the Privacy Commissioner of Canada (OPC), reachable at www.priv.gc.ca. For individuals in the EEA, you may also lodge a complaint with your local data protection authority.
How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to our Data Protection Officer using the contact details provided in this Privacy Policy. We will respond to your request within one (1) month of receipt, subject to any lawful extensions where requests are complex or numerous. We may need to verify your identity before processing your request. We will not charge a fee for handling your request unless the request is manifestly unfounded or excessive.
12. Children's Privacy
Our hotel services may be accessed by guests of all ages; however, our casino and gaming services are strictly for individuals aged 19 years or older in accordance with Ontario provincial law. We do not knowingly collect personal data from children under the age of 13, and we do not permit children to access our casino or gambling-related services. If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us immediately at info@yuluneinnreviewer.com, and we will take prompt steps to delete such information.
13. Third-Party Links and Services
Our Website may contain links to third-party websites, applications, or services that are not operated or controlled by This Privacy Policy does not apply to those third-party platforms. We encourage you to review the privacy policies of any third-party websites you visit. We are not responsible for the privacy practices or content of third-party websites.
14. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our data processing practices, legal obligations, or applicable regulations. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or by posting a prominent notice on our Website. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website or services after the effective date of any changes constitutes your acknowledgement of the updated Privacy Policy.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:
| Data Controller | |
| Data Protection Officer | The Data Protection Officer |
| Address | |
| info@yuluneinnreviewer.com | |
| Website | www.yuluneinnreviewer.com |
We are committed to working with you to resolve any concerns about your privacy. If you are not satisfied with our response, you retain the right to lodge a complaint with the Office of the Privacy Commissioner of Canada or your applicable local supervisory authority as set out in Section 11.9 above.