Legal
Privacy policy
Everything we hold about you, why we hold it, and how to make us stop.
Who we are
Frost Wager Harbour Company operates Frost Wager Hotel & Gaming at 1900 Harborside Drive, Galveston, TX 77550, and is the controller of the personal information described here. Reach our privacy team at [email protected] or by writing to the postal address above, marked for the Privacy Office.
This policy covers this website, our reservations line, the property itself, the gaming floor and the rewards programme. Where a third party collects information directly from you under their own policy — a payment processor, for instance — we say so.
What we collect
- Information you give us
- Your name, contact details, the dates and details of your stay, dietary and accessibility requirements, the preferences you tell us about, and anything you write to us.
- Information created by your stay
- Folio and billing records, restaurant and spa bookings, room entries recorded by your key, and correspondence with our teams.
- Gaming information
- If you use a rewards card on the floor we record rated play: the games, the duration and the theoretical value. This determines your tier, and gaming regulation requires us to keep parts of it.
- Technical information
- IP address, device and browser type, pages viewed and the path you took through the booking flow.
- Images and safety records
- CCTV covers public areas and the gaming floor as regulation requires. Cameras are not installed in guest rooms, lavatories or changing areas, and never will be.
We do not ask for, and ask you not to send us, health information beyond what is necessary for an accessibility request, or any other special-category information.
Children
This website and the gaming floor are intended for adults. We do not knowingly collect personal information from anyone under 13 and do not knowingly market to anyone under 21. Guests under 21 may stay as additional occupants on an adult's reservation; the information we hold about them is limited to a name and an age band. If you believe a child has given us information, write to [email protected] and we will delete it.
Why we use it
| Purpose | Basis |
|---|---|
| Taking and honouring your reservation | Performance of a contract with you |
| Running the property safely and preventing fraud | Our legitimate interests |
| Anti-money-laundering, tax and gaming records | Legal obligation |
| Analytics and measuring the site | Your consent, via the cookie banner |
| Marketing email, SMS and personalised offers | Your consent, withdrawable at any time |
| Responding to a complaint or legal claim | Legitimate interests and legal obligation |
We do not use automated decision-making that produces legal or similarly significant effects about you. Tier calculation is automated but is straightforward arithmetic, and you can ask a person to review it.
Who we share it with
We share personal information with payment processors, the reservation and property-management platforms we run on, email and SMS providers where you have consented, professional advisers, and law enforcement or regulators where legally required. Each is bound by contract to use it only on our instructions.
We do not sell personal information for money. Under some state laws, showing you an advertisement elsewhere based on what you looked at here counts as sharing even though no money changes hands. If you consent to personalised offers, that is what happens, and you can withdraw that consent at any time from cookie preferences.
How long we keep it
- Reservation and folio records — seven years from the end of your stay, for tax and accounting.
- Gaming and rated play records — as gaming regulation requires, generally five years.
- CCTV — 30 days, unless retained for a specific incident.
- Marketing consent — until you withdraw it, plus three years so we can prove you were removed when you asked.
- Self-exclusion records — for the full term and afterwards, because that is the only way an exclusion can be enforced.
- Website analytics — 14 months, in aggregate.
Your rights
Depending on where you live you may have the right to know what we hold and get a copy, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable format, to opt out of sale, sharing or targeted advertising, to limit the use of sensitive information, and to withdraw consent at any time without affecting what we did before.
To exercise any of these, write to [email protected]. We will verify who you are, usually by asking about a recent stay, and answer within 45 days or tell you why we need longer. An authorised agent may act for you with written permission.
We will never treat you worse for exercising a right. Your rates, your tier and the service you receive do not change because you asked us to delete something.
How we protect it
Personal information is encrypted in transit and at rest. Access is limited to staff who need it and is logged. We test our systems at least annually, require multi-factor authentication for staff, and run a documented incident-response plan with breach notification timelines built in. No system is perfectly secure, and we will not pretend otherwise: if something happens that puts you at risk, we will tell you promptly and plainly.
Changes
We post any change here and update the date at the top. If a change materially affects your rights we will tell you directly, and where consent is the basis we will ask again rather than assume. The version you agreed to when you booked continues to govern that booking.