Privacy Policy

Privacy Policy

How Sunburnt Palms collects, uses and protects your personal information — across the website, reservations and the resort itself.

Last updated: 1 July 2026

Sunburnt Palms Resort Pty Ltd ('Sunburnt Palms', 'we', 'us') respects the privacy of every guest and website visitor. This policy explains what information we collect, why we collect it, how long we keep it and the choices you have. It applies to sunburntpalms.com, our reservations systems and interactions with the concierge, spa, dining and gaming desks.

Information we collect

We collect information you give us directly — contact details, identification, booking preferences, dietary and accessibility needs, payment details processed by our payment partners, and correspondence with our team.

When you browse the website we collect technical data such as IP address, device type, pages visited and referral source. On resort premises, CCTV operates in public areas for safety and regulatory compliance, and casino play may be recorded as required by our licence.

How we use it

Your information is used to process reservations and payments, personalise your stay, comply with legal obligations (including gaming and liquor licensing), keep the resort safe, and — with your consent — send offers and news we believe are relevant.

We never sell personal information. Marketing emails always include a one-click unsubscribe.

Sharing and processors

We share data only where necessary: payment processors, booking-channel partners, IT and hosting providers, chauffeur and charter operators fulfilling your requests, and regulators or law enforcement where the law requires it.

All processors are bound by contractual confidentiality and data-protection terms equivalent to this policy.

Security and retention

Personal data is stored on encrypted systems with access restricted to staff who need it for their role. Payment card data is handled by PCI-DSS-compliant processors and never stored on our systems.

We retain records only as long as needed for the purposes above or as required by law — gaming and financial records follow statutory retention periods.

Your rights

You may request access to your personal information, ask us to correct or delete it, withdraw marketing consent at any time, or lodge a complaint with our privacy officer. Australian Privacy Act rights apply, and we honour GDPR-standard rights for EU residents as described on our Legal & GDPR page.

To exercise any right, email [email protected] or write to the privacy officer at our Burswood address.

Changes to this policy

We may update this policy to reflect operational or legal changes. The current version is always on this page with its effective date; material changes are flagged to guests with upcoming reservations.

Common questions

Quick answers

For anything not covered here, our team responds within one business day.

No. We never sell personal information — data is shared only with the processors and partners needed to deliver your stay, under strict contractual terms.

Email [email protected] with 'Privacy request' in the subject. We verify identity and respond within 30 days, usually sooner.

No — card details are processed by PCI-DSS-compliant payment partners and are never stored on resort systems.

Contact

Speak to our team

Questions about this policy or your personal information? Our privacy officer responds within one business day and can also be reached through the resort's main contact channels.