Privacy Policy
How Sunburnt Palms collects, uses and protects your personal information — across the website, reservations and the resort itself.
Last updated: 1 July 2026
Sunburnt Palms Resort Pty Ltd ('Sunburnt Palms', 'we', 'us') respects the privacy of every guest and website visitor. This policy explains what information we collect, why we collect it, how long we keep it and the choices you have. It applies to sunburntpalms.com, our reservations systems and interactions with the concierge, spa, dining and gaming desks.
Related documents
Information we collect
We collect information you give us directly — contact details, identification, booking preferences, dietary and accessibility needs, payment details processed by our payment partners, and correspondence with our team.
When you browse the website we collect technical data such as IP address, device type, pages visited and referral source. On resort premises, CCTV operates in public areas for safety and regulatory compliance, and casino play may be recorded as required by our licence.
How we use it
Your information is used to process reservations and payments, personalise your stay, comply with legal obligations (including gaming and liquor licensing), keep the resort safe, and — with your consent — send offers and news we believe are relevant.
We never sell personal information. Marketing emails always include a one-click unsubscribe.
Sharing and processors
We share data only where necessary: payment processors, booking-channel partners, IT and hosting providers, chauffeur and charter operators fulfilling your requests, and regulators or law enforcement where the law requires it.
All processors are bound by contractual confidentiality and data-protection terms equivalent to this policy.
Security and retention
Personal data is stored on encrypted systems with access restricted to staff who need it for their role. Payment card data is handled by PCI-DSS-compliant processors and never stored on our systems.
We retain records only as long as needed for the purposes above or as required by law — gaming and financial records follow statutory retention periods.
Your rights
You may request access to your personal information, ask us to correct or delete it, withdraw marketing consent at any time, or lodge a complaint with our privacy officer. Australian Privacy Act rights apply, and we honour GDPR-standard rights for EU residents as described on our Legal & GDPR page.
To exercise any right, email [email protected] or write to the privacy officer at our Burswood address.
Changes to this policy
We may update this policy to reflect operational or legal changes. The current version is always on this page with its effective date; material changes are flagged to guests with upcoming reservations.
Quick answers
For anything not covered here, our team responds within one business day.
No. We never sell personal information — data is shared only with the processors and partners needed to deliver your stay, under strict contractual terms.
Email [email protected] with 'Privacy request' in the subject. We verify identity and respond within 30 days, usually sooner.
No — card details are processed by PCI-DSS-compliant payment partners and are never stored on resort systems.
Speak to our team
Questions about this policy or your personal information? Our privacy officer responds within one business day and can also be reached through the resort's main contact channels.