Cinnamon Hotels & Resorts understands and recognises that privacy is important to you. This privacy statement (“Privacy Statement”) explains the way we collect, store, use and disclose your personal data (“Personal Data”).

Table of Contents
  1. Data covered by this Privacy Statement
  2. What we collect as personal identification information
  3. Web browser cookies
  4. Instances where we collect your data
  5. Requirement to provide data
  6. How we protect your information
  7. Recipients of data
  8. Sharing your personal information
  9. Your rights and your preferences
  10. Changes to this Privacy Statement
  11. Period for which the Personal Data will be stored
  12. Your acceptance of these terms
  13. Contacting us
  14. Disclaimer
  15. Submitted materials
  16. Intellectual property rights
  17. Third party consent
  18. Security
  19. Other Important Provisions
  20. Cinnamon Data Protection Policy
1. Data covered by this privacy statement

This Privacy Statement governs the way Cinnamon Hotel Management Limited (“Company”) [company registration number PB 7] of No. 117, Sir Chittampalam A. Gardiner Mawatha, Colombo 02, Sri Lanka and the hotels it operates under the Cinnamon Brand (jointly “Cinnamon Hotels & Resorts) collects, uses, maintains and discloses information collected whilst providing services and from users (each, a “User”) of this website (“Site”). This Privacy Statement applies to the Site and all products and services offered by Cinnamon Hotels & Resorts. This Privacy Statement describes the privacy practices of Cinnamon Hotels & Resorts for data that we collect through websites,(,,,,, social media pages, emails and other over-the-counter data collection points.

2. What We Collect as Personal Identification Information

We may collect personal identification information from Users in a variety of ways, including, but not limited to, when Users visit our Site, make a reservation, fill out a form, and in connection with other activities, services, features or resources we make available on our Site. Users may be asked for, as appropriate, name, email address, mailing address, phone number. Users may, however, visit our Site anonymously. We will collect personal identification information from Users only if they voluntarily submit such information to us. Users may always refuse to supply personal identification information if they do not wish to supply such information, but that may prevent them from engaging in certain Site related activities.

We will be collecting Personal Data including but not limited to the following:

  • Name
  • Gender
  • Postal address
  • Telephone number
  • Email address
  • Financial information (such as credit and debit card number or other payment data)
  • Language preference
  • Date and place of birth
  • Nationality, passport, visa, or other government-issued identification data
  • Dates: birthdays, anniversaries, and special occasions
  • Employer details (for business-related bookings)
  • Travel itinerary, tour group, or activity data
  • Prior guest stays or interactions, goods and services purchased, special service and amenity requests
  • Social media account ID, profile photo and other data publicly available, or data made available by linking your social media and loyalty accounts
  • Data about family members and companions, names, and ages of children
  • Images, video and audio data: security cameras located in public areas, such as hallways and lobbies and in our properties


We may also collect information about your preferences that we use to make your current and future stays and experience with us more enjoyable, including information about your interests and other relevant information that we learn about you during your stay. This may also include any likes and dislikes about our services that you tell us about so that we can improve our services, and specific dietary, health restrictions or personal needs to ensure your wellbeing. We may also collect your “Personal Preferences,” that you wish to share with us and may include details of your special anniversaries (such as your birthday or wedding anniversary), what type of activities you prefer to take part in when staying with us, and your hobbies. Personal Preferences may also include details about who you usually travel with and their relationship to you. If you submit any Personal Data about other people to us or our Service Providers (e.g., if you make a reservation for another individual), you represent that you have the authority to do so and you permit us to use the data in accordance with this Privacy Statement.

Non-personal Identification Information
We may collect non-personal identification information about Users whenever they interact with our Site. Non-personal identification information may include the browser name, the type of computer and technical information about the Users’ means of connection to our Site, such as the operating system and the internet service providers utilised and other similar information.

3. Web Browser Cookies

Our Site may use “cookies” to enhance User experience. A User’s web browser places cookies on local storage for record-keeping purposes and sometimes to track information about them. Users may choose to set their web browser to refuse cookies, or to alert you when cookies are being sent. If they do so, note that some features of the Site may not function properly.

How we use collected information:
The Company may collect and use Users’ Personal Data for the following purposes:

  • To improve customer service, information you provide which will help us respond to your customer service requests and support needs more efficiently.
  • To personalise user experience, we may use aggregated information to understand how our Users as a group use the services and resources provided on our Site.
  • To improve our Site, we may use feedback you provide to improve our products and services.
  • To run a promotion, contest, survey or other Site feature.
  • To send Users information they agreed to receive about topics we think will be of interest to them.
  • To send periodic emails we may use the email address to send User information and updates pertaining to their order. It may also be used to respond to their enquiries, questions, and / or other requests. If the User decides to opt-in to our mailing list, they will receive emails that may include company news, updates, related product or service information, etc. If at any time the User would like to unsubscribe from receiving future emails, we include detailed unsubscribe instructions at the bottom of each email or the User may contact us via our Site.
  • For the purposes of facilitating the booking made by you and to promote the products and services of the company and its brand.


We may also collect “Other Data” that generally do not reveal your specific identity or do not directly relate to an identified individual. To the extent Other Data reveals your specific identity or relates to an individual, we will treat Other Data as Personal Data. Other Data includes:

  • Your browser or device. We collect certain data through your browser or automatically through your device, such as your computer type (Windows or Apple), operating system name and version, device manufacturer and model, language, internet browser type and version and the name and version of the Online Services you are using. We use this data to ensure that the Online Services function properly.
  • Cookies. We collect certain data from cookies, which are pieces of data stored directly on the computer or mobile device that you are using. Cookies allow us to collect browser type, time spent on the Online Services, pages visited, language preferences, and other aggregated traffic data. We use functional cookies to obtain the data for security purposes, to facilitate navigation, to display content more effectively, to collect statistical data, to personalise your experience while using the Online Services, and to recognise your computer to assist your use of the Online Services. We also gather statistical cookie data about use of the Online Services to continually improve design and functionality, understand how they are used and assist us with resolving questions. Advertising cookies further allows us to select which advertisements or offers are most likely to appeal to you and display them while you are using the Online Services. We also use them to send marketing emails and to track responses to online advertisements and marketing emails.
Manage Cookie Preferences:
  • To Manage your cookie preferences click the black and white paperclip icon on the top, right hand corner of your screen Alternatively you can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.
Third Party Advertising:
  • We may use third-party advertising companies to serve advertisements regarding goods and services that may interest you when you access and use the Online Services, other websites, or online services. To serve such advertisements, these companies place or recognise a unique cookie on your browser (including through use of pixel tags).
  • Pixel Tags and other similar technologies. We collect data from pixel tags (also known as web beacons and clear GIFs), which are used with some Online Services to, among other things, track the actions of users of the Online Services (including email recipients), measure the success of our marketing campaigns, and compile statistics about usage of the Online Services.
  • Analytics. We collect data through Google Analytics and Adobe Analytics, which use cookies and technologies to collect and analyse data about use of the Services. These services collect data regarding the use of other websites, apps, and online resources. You can learn about Google’s practices by going to partners/ and opt out by downloading the Google Analytics opt out browser add-on, available at You can learn more about Adobe and opt out by visiting
  • Your IP Address. We collect your IP address, a number that is automatically assigned to the device that you are using by your Internet Service Provider (ISP). An IP address is identified and logged automatically in our server log files when a user accesses the Online Services, along with the time of the visit and the pages that were visited. We use IP addresses to calculate usage levels, diagnose server problems and administer the Online Services. We also may derive your approximate location from your IP address.
  • Aggregated and Segmented Data. We may aggregate data that we collect, and this aggregated data will not personally identify you or any other user. We may also use both Personal Data and Other Data to divide customers into segments, or groups, to provide more relevant advertising.
  • Precise Location-based Services. With your consent, we may collect the precise physical location of your device by using satellite, cell phone tower, Wi-Fi signals, or other technologies. We will collect this data if you opt-in through the App or other programme (either during your initial login or later) to improve special offers and to enable location-driven capabilities on your device. If you have opted-in to share your location, the App or other programme will continue to collect location data based on how you chose to share the data.
4. Instances where we collect your data

Our intended purpose is to enhance and enrich Cinnamon products and services without compromising guests’ personal identification information.

  • Booking & Guest Registration
    • Facilitate reservations and bookings of hotel accommodations and related services.
    • Engage in pre-arrival communications (logistics, changes, preferences, etc.)
    • Process payments and security deposits.
  • On-site Reception & Stay Services
    • Facilitate check-in and check-out.
    • Processing payments and security deposits.
    • Provide consistent and personalised service and advice about the on-site services (based on past usage or expressed preferences).
    • Provide concierge, luggage storage and parking services.
    • Make arrangements with third-party providers on behalf of guests (such as coordinating tours and other sightseeing excursions).
    • Arrange taxi, shuttle and chauffeur services; and facilitating reservations and bookings at restaurants and events.
    • Administering and facilitating access to Wi-Fi, TV and other connectivity services (including access to business center amenities, such as fax and photocopying services) and entertainment systems (such as music players).
    • Facilitate in-room dining (including taking into account any dietary, health restrictions or other personal needs expressed by the guest).
    • Housekeeping services (including preferences for special pillows, duvets and other amenities expressed by the guest) and dry-cleaning services.
    • Handling customer requests, inquiries and complaints.
    • Determining eligibility for age restricted goods and services (such as alcohol).
  • Conferences & Events
    • Communicate with customers about conferences and other event planning (“Events”).
    • Facilitate reservation and bookings of Events.
    • Engage in pre-event communications (logistics, accommodations, changes, etc.)
    • Preparing for and coordinating Events in accordance with customer instructions, expectations and preferences; facilitating catering.
    • Communicate about billing and recovering amounts owed.
    • Processing of payments and security deposits.
    • Performing credit checks.
    • Handling customer requests, enquiries and complaints.
    • Communicating with participants during Events.
  • Operations & General Business
    • Administering customer care services to facilitate and address inquiries, comments, and complaints about any of our services (such as in person, through phone lines, email, or on social media).
    • Handling security and fraud prevention.
    • Administering online services (including troubleshooting, data analysis, testing, system maintenance, support, reporting and the hosting of data).
    • Monitoring and analysing usage of services and using data analytics to improve services, marketing, programs, overall customer experience, gathering feedback, conducting pilot programs for potential new services and developing new and improving existing services.
    • Facilitating mergers, acquisitions and other reorganisations and restructurings of our business (including prospective transactions).
  • Emergency & Incident Response
    • Ensuring the security of on-site services.
    • Responding to, handling, and documenting on-site accidents and medical and other emergencies (including facilitating in-house doctor services).
    • Actively monitoring properties to ensure adequate incident prevention, response and documentation (including CCTV).
    • Requesting assistance from emergency services.
  • Legal & Compliance
    • Complying with applicable laws.
    • Complying with legal processes.
    • Responding to requests from public and government authorities.
    • Meeting national security or law enforcement requirements.
    • Enforcing our terms and conditions.
    • Protecting our operations.
    • Protecting the rights, privacy, safety, or property of Cinnamon Hotels and Resorts, guests, visitors and other relevant individuals.
    • Allowing us to pursue available legal remedies and limiting the damages that Cinnamon Hotels and Resorts may sustain.
  • Spa & Fitness Services
    • Facilitating reservations and bookings.
    • Determining eligibility for services.
    • Honoring disability or other health-related restrictions and providing appropriate and safe activities, services, and treatments.
    • Providing consistent and personalised service based on past usage and preferences expressed by the individual.
    • Processing payments.
    • Arranging requested professionals for specific treatments and services.
    • Handling customer requests, enquiries, and complaints.
  • Food & Beverage Services
    • Facilitating reservations.
    • Honoring dietary preferences.
    • Providing consistent and personalised service based on past usage and preferences expressed by the individual.
    • Processing payments.
    • Arranging reservations.
    • Handling customer requests, enquiries, and complaints.
  • Child-related Services (for Parents & Legal Guardians)
    • Facilitating babysitting / hotel nanny and kids club.
    • Facilitating reservations and bookings.
    • Preparing for and coordinating hotel accommodations and services in accordance with guest preferences, instructions, and expectations.
    • Payment and billing services.
    • Dining services (for example, special menus for children or special discounts for breakfast for children under a certain age).
  • Marketing, Promotions, Contests & Third-Party Products
    • Communicate about products and services that may be of interest to guests.
    • Providing personalised advertisements for products and services on selected websites.
    • Facilitating participation in sweepstakes, contests, and other promotions (such as best vacation photo contests on social media).
    • Handling customer requests, enquiries, and complaints.
5. Requirement to provide data

You are required to provide full and accurate details in the form required by us for us to process the booking / request made by you. We are unable to confirm or process any bookings / requests made by you if you do not provide such Personal Data as required.

5.1.1 More information about your Personal Preferences

Our goal is to serve you better and meet your expectations and preferred level of hospitality at each stage, from the moment that you book with us through to when you check out. See below to learn more.

  • Anniversaries –
    • When you stay with us, we want to help you celebrate any special occasion, such as an anniversary or birthday. For example, we may make a note of these dates to allow us to provide you with a birthday or anniversary gift.
  • Activity type and hobbies (such as trips to the beach, babysitting, fitness, travel and transportation details, kids club theater, restaurant etc.) –
    • We want to ensure that we provide you with services that enhance your experience. To do this, we may retain your preferences about the types of activities that you like to take part in, so that we can ensure we are able to offer you similar experiences when you stay with us in the future.
  • Relationships (husband, wife, son, daughter, etc.) -
    • We understand that your Preferences may change depending on who you are traveling with (such as your preferred room type). We may keep a record of your relationships to assist us with making your stay as comfortable as possible. For example, if we know you are traveling with small children, we can proactively plan for additional accommodations such as a crib or roll-away bed.
  • Preferences for properties, clubs, and facilities –
    • When you are staying with us, we want to make sure that we can provide you with services to enhance your experience. To do this, we may retain your preferences for our properties, clubs, and facilities, based on your past stay preferences, of our kids’ clubs, nanny services, spa and beauty services, golf, restaurant, and fitness facilities.
  • Dietary preferences –
    • When you stay with us, we want to ensure that you are safe, that we are looking after your wellbeing, and to provide you with services to enhance your experience. For example, we may make a note of your dining or beverage preferences so that we are prepared if you request room service or dine at one of our cafes or restaurants.
6. How we protect your information

We adopt appropriate data collection, storage and processing practices and security measures as reasonably possible to protect against unauthorised access, alteration, disclosure or destruction of your personal information, username, password, transaction information and data stored on our Site.

7. Recipients of data
  • Our service providers, agents and other parties as required for the purpose of facilitating the booking made by you.
  • Promote the products and services of Cinnamon Hotels and Resorts.
  • Our trusted associate companies and other companies of John Keells Group for business, data analytics and promotional activities.
  • Government, law enforcement, regulatory, judicial, or related authorities on request including in relation to obligations arising under law, regulation, national or public security or related inquiry.
8. Sharing your personal information

We do not sell, trade, or rent Personal Data to others. We may share generic aggregated demographic information not linked to any personal identification information regarding visitors and users with our business partners, trusted affiliates and advertisers for the purposes outlined above. We may use third party service providers to help us operate our business and the Site or administer activities on our behalf, such as sending out newsletters or surveys. You acknowledge that we may share your information with these third parties for such limited purposes.

9. Your rights and your preferences

Rights of the Data Subject - You have the right to request from the Company, access to and rectification or erasure of Your Personal Data or restriction of processing concerning Your Data or to object to processing as well as the right to data portability. You also have the right to withdraw your consent for any use of Your Personal Data at any time, provided that any processing of Your Personal Data prior to the withdrawal of your consent shall not be rendered unlawful. Further, where applicable, you shall have the right to lodge a complaint with a supervisory authority in the event that there is a breach of the relevant data protection regulations with regard to Your Data.

10. Changes to this Privacy Statement

The Company has the discretion to update this Privacy Statement at any time. When we do, we will revise the updated date at the bottom of this page. We encourage Users to frequently check this page for any changes to stay informed about how we are helping to protect the Personal Data we collect. You acknowledge and agree that it is your responsibility to review this Privacy Statement periodically and become aware of modifications.

11. Period for which the Personal Data will be stored

Your Personal Data will be stored by the Company for a minimum of seven (7) years and for a maximum period as may be required under accepted business practices.

12. Your acceptance of these terms

By submitting any Personal Data, you signify your acceptance of this Statement. If you do not agree to this Statement, please do not submit any Personal Data. Any submission of your Personal Data will be deemed your acceptance of this Privacy Statement.

13. Contacting us

If you have any questions, feedback, or complaints, please contact us at:

14. Disclaimer

Although we attempt to keep all information in the WWW servers accurate and up to date, the accuracy and timelines of the information provided cannot be guaranteed. We hope that you will find the information helpful and easy to use, but we provide all content for informational purposes only and make no representations or warranties of any kind regarding the same. The Company and its management and its owning company disclaims all liability of any kind whatsoever arising out of the use of, or inability to use, its WWW servers and the information contained on them unless there is negligence or fault on part of the Company. The Company’s WWW servers were designed to provide information about the Company, its products, and links to specific external Sites. Use of this system for any purpose other than that for which it was designed is unauthorised and prohibited.

15. Submitted materials

All parties submitting materials to the WWW servers represent and warrant that the submission, installation, copying, distribution, and use of such materials in connection with the WWW servers will not violate any other party’s proprietary or legal rights.

16. Intellectual property rights

The material and content provided on the Site is strictly for your personal and non-commercial use only. However, you could save where expressly provided, and you agree not to by yourself or through or by way of assistance from any third party to distribute, copy, extract or commercially exploit such material or contents. Except as otherwise indicated, all materials on this Site, including, but not limited to text, information such as; customer or partner references, data, images and pictures, illustrations and written and other materials contained in this Site are protected by copyrights, database rights, trademarks and / or other Intellectual Property rights owned, or used with permission of their owners by us or our partners, affiliates or associates. This Site is protected by copyright and other intellectual property rights. All rights reserved.

17. Third party consent

You confirm that any personal information or data you share on behalf of another person for the purposes of a booking or enquiry with the Company has been obtained with the prior consent of such person who has apprised himself / herself of the booking / enquiry terms and conditions and privacy policy of the Company and such person is aware of their rights in respect of such data provided to us.

18. Security

We seek to use reasonable, organisational, technical, and administrative measures to protect Personal Data. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of your account has been compromised), please immediately notify us.

19. Other Important Provisions


Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security number, taxpayer identification number, passport number, driver’s license number, or other government-issued identification number; credit or debit card details or financial account number, with or without any code or password that would permit access to the account, credit history; or information on race, religion, ethnicity, sex life or practices or sexual orientation, medical or health information, genetic or biometric information, biometric templates, political or philosophical beliefs, political party or trade union membership, background check information, judicial data such as criminal records, or information on other judicial or administrative proceedings).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

International Data Transfers

Cinnamon Hotels and Resorts provides a global service. Transferring data internationally is essential to the Services so that you receive the same high-quality service wherever you are in the world. As a result, we will, subject to law, transfer Personal Data and Other Data collected in connection with the Services, to entities in countries where data protection standards may differ from those in the country where you reside, including outside the EEA, UK, or Switzerland. By making a reservation, visiting, or staying at a Cinnamon branded property or using any Cinnamon Hotels and Resorts branded service, you understand that we transfer your Personal Data globally.

In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries may be entitled to access your Personal Data.

20. Cinnamon Data Protection Policy

I confirm that I will be providing you with my data and hereby expressly consent to the use of my personal data to process and cater to my request or inquiry. This includes express permission to share data, inclusive of personal data, with your service providers and agents, only as required for responding to my request or inquiry. I acknowledge that, in full compliance with applicable regulations, you may share data with your business partners and associates with the view of enriching and enhancing your products and services without compromising my personally identifiable information.