This policy explains what personal information Wave Passage Hospitality Ltd, trading as Wave Passage, collects about you, why we collect it, where it goes and how to get it back. It is written under the Privacy Act 2020 and the thirteen information privacy principles in it.
Last reviewed: March 2026.
1. Who we are
Wave Passage Hospitality Ltd, NZBN 9429048317762, of 68 Marsden Road, Paihia 0200, Bay of Islands, New Zealand. We are the agency responsible for the information described here. Our privacy officer can be reached at [email protected] or on +64 9 402 7180.
2. What we collect, and why
When you make an enquiry or a booking
Your name, email address, telephone number, the dates you asked about, the number of people, any room preference, and whatever you write in the message box. We collect it to answer you and to hold the booking. Without a name and a working email address we cannot reply, which is why both are required.
The form also records that you ticked the box confirming you are twenty or over and the box confirming you have read this policy. We keep those two facts because we are asked to be able to show them.
When you stay
Arrival and departure dates, the room, payment details processed by our bank rather than held by us, and any dietary, mobility or accessibility requirements you have told us about. Requirements of that kind are health information under the Privacy Act and we treat them accordingly: they go to the people who need them — the kitchen, housekeeping, the front desk — and nowhere else.
When you enter The Motukōkako Room
We sight photo identification to confirm you are twenty or over. In the ordinary case we look at it and hand it back; we do not scan or copy it. We do record identification details where the Gambling Act 2003, the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 or a condition of our venue licence requires it — for example above certain transaction thresholds at the cage, or in connection with an incident on the floor.
If you self-exclude, we hold your name and a photograph so that door staff can recognise you and turn you away. That record is kept for the length of the order and destroyed when it ends.
When you use this website
Our server keeps standard logs — IP address, browser, page requested, time — for security and for counting traffic. Anything beyond that depends on the cookie choices you make; see the cookie policy.
CCTV
Cameras cover the entrances, the lobby, the corridors, the cage and the gaming floor. They are a condition of our gaming licence. There are no cameras in guest rooms, bathrooms, the treatment rooms at The Haruru Bathhouse, or the changing areas. Footage is held for thirty days and then overwritten, unless it has been retained for an incident or requested by Police under a lawful process.
3. Who else sees it
We do not sell personal information and we do not trade mailing lists. Information is shared only with:
- People inside the hotel who need it to do the job in front of them.
- Our payment provider, which processes card transactions. We never hold full card numbers.
- Suppliers who deliver part of a package you booked — a boat operator, a driver, a cellar door — and only the detail they need to carry it out.
- Our email and hosting providers, which store the enquiries you send us.
- The Department of Internal Affairs, Police, or another agency, where the law requires it or permits it under the Privacy Act.
Some of our providers store data on servers outside New Zealand. Where that happens we satisfy ourselves under principle 12 that comparable safeguards apply.
4. How long we keep it
- Enquiries that do not become bookings — twelve months.
- Booking and guest records — seven years, which is what the Inland Revenue rules require of the financial part.
- Gaming records required by licence or by the AML/CFT Act — five years from the transaction or the end of the relationship.
- Self-exclusion records — the length of the order, then destroyed.
- CCTV — thirty days, then overwritten.
- Marketing consent — until you withdraw it, and the fact of the withdrawal after that so we do not write to you again by accident.
5. Marketing
We only send hotel news to people who ticked the box asking for it. It amounts to two or three emails a year, every one carries an unsubscribe link that works immediately, and asking to be taken off never affects a booking. We do not send gambling promotions to anyone who has self-excluded, ever.
6. Your rights
Under principles 6 and 7 of the Privacy Act 2020 you may ask us for the personal information we hold about you, and ask us to correct it if it is wrong. Write to [email protected]. We will confirm receipt straight away and respond within twenty working days, which is the statutory limit. There is no charge for a request of ordinary size.
We may withhold information where the Act allows it — for example where releasing it would identify somebody else, or would prejudice the prevention or detection of an offence. If we withhold anything we will tell you which ground we are relying on.
7. Keeping it safe, and what happens if we fail
Paper records are held in a locked office. Electronic records sit behind individual accounts with two-factor authentication, and access is limited by role. Card data never touches our systems.
If a privacy breach happens that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and the people affected, as the Act requires, and we will tell you what actually happened rather than a version of it.
8. Complaints
Tell us first: [email protected]. If you are not satisfied with our answer you can complain to the Office of the Privacy Commissioner — 0800 803 909, privacy.org.nz. You do not have to come to us first, but it is usually faster.
9. Changes
If this policy changes materially we will date the new version and, where the change affects information we already hold, tell the people it affects.