Privacy Policy
Tasman Crest Hotel & Casino respects your privacy and handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what we collect, why we collect it, and the choices you have.
Information we collect
We collect personal information you provide directly: name, contact details, identification for casino entry and hotel check-in, payment details, stay preferences, dietary and accessibility requirements, and communications with our concierge, reservations and membership offices.
We also collect information automatically when you use our website or visit the property: device and browser data, pages visited, CCTV footage in public and gaming areas, and — with your consent — location and cookie-based analytics data.
How we use your information
Your information is used to provide our services: processing reservations and payments, operating casino membership and rewards programmes, meeting regulatory obligations under Queensland gaming law, personalising your stay, and communicating with you about bookings and services.
With your consent we may use your information for marketing — offers, the Wharf Street Letter and event invitations. Every marketing message includes a functioning unsubscribe, honoured within five business days.
When we share information
We share personal information only where necessary: with payment processors, regulatory and licensing bodies as required by law, excursion and transfer partners fulfilling your bookings, and professional advisers under confidentiality obligations.
We do not sell personal information. We do not share it with third parties for their own marketing. Where partners process data on our behalf, contracts require equivalent privacy protection.
How we protect it
Personal information is stored on encrypted systems with role-based access — staff see only what their function requires. Payment data is handled under PCI-DSS compliant processes, and retention follows legal minimums rather than indefinite storage.
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme.
Your rights and choices
You may request access to, or correction of, the personal information we hold about you. Requests are answered within 30 days; identity verification is required to protect your data from fraudulent requests.
You may opt out of marketing at any time, request deletion where retention is not legally required (gaming records, for example, carry statutory retention periods), and lodge complaints with us or directly with the OAIC.
Casino-specific obligations
Queensland gaming legislation requires collection of identification for casino entry, exclusion registers, and transaction records. These obligations override some deletion requests — where law requires retention, we will tell you the legal basis and the retention period.
Self-exclusion and voluntary-limit records are handled with additional confidentiality controls, accessible only to the responsible-gambling team and regulators as required.
Questions about this policy?
Privacy questions, access requests and complaints go to our Privacy Officer via email or the contact form — answered within 30 days.