Terms and Conditions

1. Introduction

Welcome to annwn stay, a mobile and web application (the "App") provided by annwn inc. ("we", "us", "our", "Company"). By using the App, you agree to comply with and be bound by the following terms and conditions (the "Terms"). These Terms govern your access to and use of the App, which facilitates the registration, check-in, and check-out processes for hotel guests. If you do not agree to these Terms, you must not use the App.

2. Company Information

Name: annwn inc.
Registered Address: 2234 Nida Court, Mississauga, ON L4X1J8, Canada
Data Protection Contact: Email: privacy@annwn.app
General Contact: Email: legal@annwn.app

3. Age Restrictions and Availability

The App is intended for use by individuals who are at least 18 years old. The App is available globally, except in countries where Canadian companies are prohibited from doing business.

4. User Registration and Identity Verification

4.1. Information Collected: During the registration process, we collect your name and email address. For the main guest staying at the hotel, we also collect identity verification data through our contracted service provider, Veriff. This includes identity documents and a photo of your face.

4.2. Identity Verification: You will verify your identity through Veriff by taking photos of your identification documents and a photo of your face. Veriff processes this data using automated decision-making technology. See Section 10 of our Privacy Policy for details on your rights regarding automated processing.

5. User Conduct

Users must not attempt to hack or interfere with the App unless expressly given permission by us. Unauthorized access or interference may result in account suspension or termination.

6. Data Privacy and Security

6.1. Data Collection and Retention: We collect and retain user data in accordance with the retention periods specified in Section 6 of our Privacy Policy below. Users can request the deletion of their data by sending an email to privacy@annwn.app.

6.2. Data Sharing: We share user data with the partnered hotel property solely for the purposes of fulfilling your booking and managing your stay. Hotels may not onward-share your personal data except as required by law or with your explicit consent. See Section 5 of our Privacy Policy for full details.

6.3. Cookies and Tracking: Our App uses analytics cookies and tracking technologies to improve the user experience and analyse usage patterns. These are only activated after you provide consent via the cookie notice presented on your first visit. You may withdraw consent at any time through your browser settings. See Section 9 of our Privacy Policy for details.

7. Liability and Disclaimers

7.1. Limited Liability: To the maximum extent permitted by law, our liability in connection with the App is limited to the extent appropriate for an application facilitating check-in and check-out processes. The hotel operator assumes liability for all other matters related to the stay.

7.2. Disclaimers: We do not warrant the accuracy or completeness of any information provided by the App.

8. Changes to Terms and Conditions

We may update these Terms from time to time. For material changes—including any changes that affect how your personal data is processed—we will notify you by email or through a prominent notice in the App at least 30 days before the changes take effect. Non-material changes (e.g., formatting or clarifications) may take effect immediately upon posting. The Terms applicable to your stay will remain in effect until you check out, after which any updated Terms will apply. Continued use of the App after the notice period constitutes acceptance of the updated Terms.

9. Governing Law

These Terms are governed by and construed in accordance with the laws of Canada. Any disputes arising out of or relating to these Terms shall be subject to the exclusive jurisdiction of the courts of Canada. Nothing in these Terms limits the rights of users in the European Union or European Economic Area under the General Data Protection Regulation (GDPR) or other applicable local laws. Where GDPR applies, its provisions take precedence over any conflicting terms herein.

10. Contact Information

If you have any questions or need support regarding these Terms, please contact us at legal@annwn.app.

11. App Versions

These Terms apply to all versions of the App, including the web app, iOS app, and Android app.

12. Payment Terms

12.1. Credit Card Storage and Consent: Users have the option to add a credit card to their account for future transactions related to their stay. By adding a credit card, you expressly consent to us storing your payment information with our third-party payment processor, Stripe. We do not store your credit card data directly on our servers.

12.2. Holds for Incidentals: At the time of check-in, we will place a temporary hold on your credit card for anticipated incidentals. This hold will be released in accordance with your card issuer's policies if there are no additional charges beyond your room rate or other agreed-upon expenses.

12.3. Authorization for Charges: You will not be charged without explicit user action, except for the hold placed at check-in. However, you acknowledge and agree that we will complete the final charge on your credit card upon checkout to cover the room rate, taxes, fees, incidentals, or any other charges accrued during your stay. In cases of damages or extra charges related to your stay, we reserve the right to charge the stored credit card accordingly.

12.4. Dispute Resolution: If you have any disputes regarding charges, please contact us at legal@annwn.app. We will make reasonable efforts to address any billing disputes in good faith and in accordance with applicable laws.

13. Refund Policy

13.1. No Refunds: All bookings are non-refundable unless the rate name explicitly states otherwise (e.g., “Refundable Rate” or “Free Cancellation”). The refund terms, if any, are determined by the specific rate selected at the time of booking and are displayed during checkout.

13.2. Refundable Rates: Where a rate explicitly includes refund or free cancellation terms, refunds will be processed in accordance with the cancellation policy displayed at the time of booking. Cancellation requests must be submitted before the deadline specified in the rate’s cancellation policy.

13.3. Exceptions: In exceptional circumstances (e.g., force majeure events, property closures, or errors in booking processing), we may issue a refund at our discretion. To request an exception, contact us at legal@annwn.app.

Privacy Policy

Last updated: March 29, 2026

1. Introduction

This Privacy Policy explains how annwn inc. ("we", "us", "our") collects, uses, discloses, and protects your information when you use our app, annwn stay (the "App"). This policy applies to all users, including hotel guests, booking engine visitors, and users of the guest app, store, and experiences features.

If you are located in the European Union or European Economic Area, the General Data Protection Regulation (GDPR) applies to our processing of your personal data, regardless of the governing law clause in our Terms. Where GDPR applies, we act as the data controller for the personal data described in this policy.

2. Information We Collect

We collect the following categories of personal data:

2.1. Account & Identity Information

  • Name and email address (provided during registration or booking)
  • Phone number (if provided)
  • Language preference

2.2. Biometric & Identity Verification Data (Special Category Data)

  • Photographs of government-issued identity documents
  • Facial photographs used for identity matching
  • Verification results and session metadata from Veriff

Important: Identity documents and facial photographs constitute special category / biometric data under GDPR Article 9. We process this data only with your explicit, separate consent, which you provide during the check-in process before the identity verification step begins. You may decline identity verification where the hotel property does not require it. Veriff processes this data using automated decision-making (see Section 10 below).

2.3. Booking & Stay Information

  • Check-in and check-out dates, room selections, and guest count
  • Special requests, arrival time preferences, and early check-in requests
  • Promotional codes applied to bookings

2.4. Payment Information

  • Credit card details are collected and stored exclusively by our payment processor, Stripe. We do not store card numbers on our servers.
  • Transaction records, payment amounts, and refund history

2.5. Store & Experiences Data

  • Products browsed, added to cart, and purchased
  • Vendor services viewed, appointment bookings, and time requests
  • Order history and service questionnaire responses

2.6. Communications

  • Messages sent and received through the in-app concierge chat (powered by Stream Chat)
  • Feedback survey responses and sentiment ratings

2.7. Usage & Analytics Data

  • Pages visited, features used, and interaction patterns within the App
  • Device type, browser, operating system
  • Approximate geographic location derived from IP address (city and country level only; IP addresses are masked)
  • Referral source, UTM campaign parameters, and landing pages
  • Booking funnel progression (search, room selection, checkout steps)

3. Lawful Basis for Processing

We process your data under the following lawful bases (GDPR Article 6, and Article 9 for special categories):

Data Category Purpose Lawful Basis
Account information (name, email) Registration, booking fulfilment, communications Contract performance (Art. 6(1)(b))
Booking & stay data Check-in/check-out, room assignment, service delivery Contract performance (Art. 6(1)(b))
Payment information Processing payments, deposits, refunds Contract performance (Art. 6(1)(b))
Identity documents & facial photographs Identity verification for hotel security Explicit consent (Art. 9(2)(a))
Usage & analytics data Improving the App, understanding usage patterns Legitimate interest (Art. 6(1)(f))
Cookies & tracking technologies Analytics, session tracking, promotion personalisation Consent (Art. 6(1)(a))
Store & experiences data Order fulfilment, appointment booking Contract performance (Art. 6(1)(b))
Chat messages Guest-property communication Contract performance (Art. 6(1)(b))
Feedback & surveys Service quality improvement Legitimate interest (Art. 6(1)(f))
Marketing communications Promotional emails and special offers Consent (Art. 6(1)(a))

4. How We Use Your Information

Operational Purposes: To facilitate user registration, identity verification, the check-in/check-out process, bookings, store purchases, experience bookings, and payment processing.

Communication: To send booking confirmations, check-in instructions, order notifications, and respond to inquiries via the concierge chat and email.

Marketing Communications: With your explicit consent, we may send you promotional emails about special offers, events, and news from the property where you stayed. You can withdraw your marketing consent at any time by using the unsubscribe link in any marketing email, or by updating your preferences in your account settings. Withdrawing consent does not affect transactional emails (booking confirmations, check-in instructions, etc.).

Analytics & Improvement: To understand how guests use the App, identify booking funnel drop-off points, measure feature engagement, and improve the guest experience. Analytics data is aggregated for reporting in our property management dashboard.

Promotion Personalisation: With your consent (via cookie acceptance), we may use session-level analytics data—such as search dates, length of stay, device type, and booking funnel stage—to select which optional promotional offers are displayed to you during your booking session. This does not affect room pricing or availability; it only determines which optional discounts or promotional offers are shown. You can opt out at any time by declining or withdrawing analytics cookie consent, in which case you will see default (non-personalised) promotions.

Compliance: To comply with legal obligations, prevent fraud, and enforce our terms and conditions.

5. How We Share Your Information

With Hotel Properties: We share your booking, stay, and check-in information with the specific hotel property where you are staying, solely for the purpose of managing your reservation and stay. Hotels are contractually prohibited from using your data for unrelated purposes or sharing it with third parties except as required by law.

With Service Providers: We use the following third-party processors who access your data solely to provide their services to us:

  • Veriff (Estonia) — Identity verification processing
  • Stripe (USA) — Payment processing and card storage
  • Stream (USA) — In-app chat messaging infrastructure
  • PostHog (EU) — Product analytics (only with your consent)
  • Vendor partners — Third-party vendors at the property receive your name and booking details only when you purchase products or book experiences from them

Legal Requirements: We may disclose information if required by law, court order, or in response to valid requests by public authorities.

We do not sell your personal data to any third party.

6. Data Retention

We retain personal data for the minimum period necessary for each purpose:

Data Category Retention Period
Account information (name, email) Until account deletion is requested, or 3 years after last activity
Booking & stay records 7 years from check-out (legal/tax compliance)
Payment transaction records 7 years from transaction date (legal/tax compliance)
Identity verification data Processed and stored by Veriff per their retention policy (typically 90 days). We store only the verification result (pass/fail), not the documents or photographs.
Chat messages 1 year from the end of the stay
Analytics & usage data 26 months from collection (anonymised thereafter)
Store & experience orders 7 years from order date (legal/tax compliance)
Cookies (ahoy_visitor) 2 years (only set with your consent)
Marketing consent preference Until consent is withdrawn, or 3 years after last activity

You can request early deletion of your data at any time by contacting privacy@annwn.app. We will process deletion requests within 30 days, except where retention is required by law.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information from unauthorized access, use, or disclosure. These include encryption in transit (TLS), encryption at rest for sensitive data, access controls, and regular security reviews.

8. Your Rights

Under applicable data protection law (including GDPR for EU/EEA residents), you have the following rights:

  • Right of Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request correction of inaccurate or incomplete personal data.
  • Right to Erasure: You can request deletion of your personal data where there is no compelling reason for continued processing.
  • Right to Data Portability: You can request your personal data in a structured, commonly used, machine-readable format and have it transferred to another controller.
  • Right to Restrict Processing: You can request that we limit the processing of your personal data in certain circumstances (e.g., while we verify accuracy of data you have contested).
  • Right to Object: You can object to processing based on legitimate interests. We will cease processing unless we have compelling legitimate grounds that override your interests.
  • Right to Withdraw Consent: Where processing is based on your consent (e.g., cookies, biometric data), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority. If you are in the EU/EEA, you may contact the supervisory authority in your member state. A list of authorities is available at edpb.europa.eu.

To exercise any of these rights, contact us at privacy@annwn.app. We will respond within 30 days.

9. Cookies and Tracking Technologies

We use the following cookies and tracking technologies:

Cookie / Technology Purpose Duration Requires Consent
privacy_cookie Stores your cookie consent preference 90 days – 1 year No (strictly necessary)
ahoy_visitor Identifies returning visitors for analytics 2 years Yes
ahoy_visit Tracks the current browsing session 4 hours of inactivity Yes
PostHog Product analytics and usage patterns 1 year Yes
Session cookies Authentication and CSRF protection Browser session No (strictly necessary)

Analytics cookies (Ahoy and PostHog) are only activated after you accept the cookie consent notice. If you reject or do not interact with the notice, no analytics cookies are set. You can change your preference at any time by clearing your browser cookies and revisiting the site, which will re-display the consent notice. IP addresses are masked before storage for analytics purposes.

Server-side analytics (page views and events) are collected without cookies for operational monitoring, but this data is not linked to a persistent visitor identity unless you have consented to cookies.

10. Automated Decision-Making and Profiling

Identity Verification: Our identity verification provider, Veriff, uses automated processing to compare your facial photograph against your identity document. This automated decision determines whether your identity is verified (pass/fail) and directly affects your ability to complete the check-in process at properties that require identity verification.

Under GDPR Article 22, you have the right to:

  • Obtain human intervention in the verification decision
  • Express your point of view regarding the outcome
  • Contest the decision

If you wish to exercise these rights or if your verification fails and you believe it was in error, contact us at privacy@annwn.app and we will arrange a manual review.

Promotion Personalisation: If you have consented to analytics cookies, we may use session-level data (such as search dates, length of stay, device type, and booking stage) to select which optional promotional offers are displayed during your booking. This is lightweight profiling under GDPR Article 22(1) that does not produce legal effects or significantly affect you—it only determines which voluntary discount offers appear. Room pricing and availability are never affected. You can opt out at any time by withdrawing cookie consent, after which only default (non-personalised) promotions will be shown.

11. International Data Transfers

Your personal data may be transferred to and processed in countries outside your country of residence:

  • Veriff processes identity verification data in Estonia (EU/EEA — adequate protection under GDPR).
  • Stripe processes payment data in the United States. Stripe is certified under the EU-U.S. Data Privacy Framework.
  • Stream processes chat data in the United States. Transfer is governed by Standard Contractual Clauses (SCCs).
  • PostHog analytics data is processed in the European Union (eu.i.posthog.com).
  • annwn inc. is based in Canada, which has an adequacy decision from the European Commission for transfers from the EU.

Where data is transferred outside the EU/EEA to countries without an adequacy decision, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.

If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, describing the nature of the breach, its likely consequences, and the measures taken to address it.

13. Payment Information

We allow you to add a credit card to your account for the purpose of facilitating transactions, deposits, and charges related to your stay, store purchases, and experience bookings. We do not store your credit card details on our servers; they are securely stored by our payment processor, Stripe.

By providing your credit card information, you consent to its storage by Stripe and acknowledge that certain holds may be placed for incidentals. At checkout, any remaining charges will be processed automatically. If you wish to dispute any charges, contact us at privacy@annwn.app.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. For material changes—particularly those affecting how we collect, use, or share your personal data—we will notify you by email or through a prominent notice in the App at least 30 days before the changes take effect. The "last updated" date at the top of this policy will always reflect the most recent revision.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Data Protection Contact: privacy@annwn.app
General Legal: legal@annwn.app
Mailing Address: annwn inc., 2234 Nida Court, Mississauga, ON L4X1J8, Canada

We use cookies to improve your browsing experience, measure site performance, and show you relevant ads. You can accept all, reject all non-essential cookies, or choose which categories to allow.
See privacy policy.