Last updated: 07/09/2026
The company GRAPE HOSPITALITY FRANCE — (hereinafter "we," "our," or "the Company") places great importance on the protection of your personal data.
This privacy policy aims to inform you, with full transparency, about how we collect, use, store, and protect your personal data when you:
This policy complies with the General Data Protection Regulation (GDPR – EU 2016/679) and the amended French Data Protection Act.
The data controller is:
Grape Hospitality France, with its registered office at 17 quai du président Paul Doumer, 92400 Courbevoie, registered under number 815 278 288 with the Nanterre Trade and Companies Register (RCS).
The Data Protection Officer (DPO): dpo@grape-hospitality.com
Depending on how you interact with us, we may collect the following categories of data:
3.1 Identification and contact data
Last name, first name, title, date of birth, postal address, email address, phone number.
3.2 Booking and stay-related data
Stay dates, room type, preferences (floor, bedding, reported food allergies), booking history, loyalty card number, license plate number (if parking), check-in/check-out information.
3.3 Payment data
Credit card number (processed securely, generally via a PCI-DSS certified payment provider), billing history. We do not store full credit card details on our own servers.
3.4 Identity data
Copy of ID card or passport, as required by regulations applicable to traveler registration (police forms, hotel registers) in certain countries.
3.5 Video surveillance data
Images captured by video surveillance systems installed in the common areas of our establishments (lobbies, parking lots, hallways) for security reasons.
3.6 Browsing data
IP address, browser type, pages visited, cookies and similar trackers (see section 8).
3.7 Loyalty program and marketing data
Communication preferences, newsletter open history, declared interests.
Your data may be shared, strictly on a need-to-know basis, with the following categories of recipients:
We never sell your personal data to third parties.
If any of our service providers (cloud hosting, marketing tools, booking platforms) are located outside the European Union, we ensure these transfers are governed by appropriate safeguards: European Commission standard contractual clauses, adequacy decisions, or other mechanisms recognized by the GDPR.
Our website and application use cookies to:
You can manage your preferences at any time via the cookie banner displayed during your first visit, or through your browser settings.
In accordance with the GDPR, you have the following rights regarding your personal data:
To exercise these rights, you may contact our Data Protection Officer (DPO) at the following address: dpo@grape-hospitality.com
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, alteration, or disclosure, including: encryption of sensitive data, restricted and secure access to systems, staff training, and regular security audits.
Our services are intended for adults. We do not knowingly collect data from minors without parental supervision, except in the normal course of a family stay and with the authorization of the holder of parental authority.
We may update this policy to reflect changes in legal or regulatory requirements or our own practices. Any significant changes will be communicated to you through an appropriate channel (email or website notification). The date of the last update is indicated at the top of this document.