Legal

Privacy Policy

Last updated: 14 September 2026. This Privacy Policy explains how handles personal information in connection with elvariancrestlodge.com, reservation and guest-service enquiries made through the contact details published on the Website, and the limited browser-storage functions built into the current Website. It is intended to provide clear information consistent with applicable Australian privacy requirements and, where the General Data Protection Regulation (GDPR) applies to a particular processing activity, the transparency requirements and data-subject rights provided by the GDPR.

1. Who we are and who is responsible for your information

is the operator identified on this Website and is responsible for deciding why and how personal information is handled for the Website and the resort contact routes described in this policy. The resort address published on the Website is . The corporate identifiers displayed in the Website's legal materials are ACN 647 293 815 and ABN 53 647 293 815.

You may contact us about privacy by emailing info@elvariancrestlodge.com, calling +61 7 3847 2916, or writing to the address above. The Website does not currently publish a separate Data Protection Officer contact. If we appoint a Data Protection Officer or another dedicated privacy contact and applicable law requires us to identify that person, we will update this policy.

This policy concerns the Website and the contact and reservation-enquiry routes described here. A confirmed accommodation booking, event arrangement or other offline service may be accompanied by additional booking terms, collection notices or operational records that are supplied separately when relevant.

2. What the current Website does

The Website is primarily an informational website for a physical hotel and casino resort. It presents information about rooms, dining, resort facilities, the physical casino, responsible gaming and ways to contact the resort. The current Website does not provide a user account system, an online payment checkout, an online gambling service, a newsletter sign-up form or a general-purpose web contact form.

The home page and rooms page include an availability helper with fields for check-in date, check-out date, number of guests and a promo code. Submitting that helper sends those values to the Website's contact page using a standard HTTP GET request. The Website's current client-side code also stores the availability values in your browser so they can be remembered on the same browser and device.

The Website also shows a cookie/consent notice. In the current implementation, your choice is stored locally in your browser so that the notice does not need to be displayed on every visit. The version of the Website supplied with this policy does not load third-party analytics or advertising trackers through the Website code. If that changes, we will update the relevant notice and seek consent before using non-essential tracking technologies where consent is required.

3. Personal information we may collect

The personal information we receive depends on how you interact with us. We aim to collect only information that is reasonably necessary for the relevant purpose.

  • Reservation and stay information: preferred arrival and departure dates, number of guests, room preferences, booking references, promotional codes and other information needed to discuss or administer a reservation.
  • Contact information you provide directly: for example, your name, email address, telephone number and the content of an enquiry when you contact us by email or telephone.
  • Guest-service information: information you choose to provide about an event, dining request, arrival arrangements, accessibility needs or another service request. Please provide only information that is relevant to the request.
  • Browser-stored Website preferences: the booking-helper values described above and your consent-banner choice. These values are stored in your browser's local storage by the current Website code.
  • Technical request information: when a public website is delivered over the internet, the web-hosting infrastructure may process information such as an IP address, request time, requested page, browser or device information, referrer and security logs as part of delivering, protecting and troubleshooting the Website. The exact technical logs depend on the hosting environment in use.
  • Correspondence and records: copies or notes of communications with you where reasonably needed to answer a request, administer a booking, resolve a complaint or maintain business records.

We do not ask you to enter payment-card details, identity documents, health information or other highly sensitive information into the availability helper. In particular, the promo-code field is intended only for an actual promotional code. Because the availability helper uses a GET request, submitted values may appear in the browser address bar and may be included in ordinary web-server request logs. Do not place confidential, sensitive or unrelated personal information in that field or in any other booking-helper field.

4. How we collect information

We may collect personal information directly from you when you telephone us, email us, make a reservation enquiry, ask for guest assistance or otherwise communicate with the resort. Information may also be generated through your use of the Website, such as the browser-storage values described in this policy and standard technical request information generated when pages are served.

Where another person makes an enquiry or booking on your behalf, we may receive information about you from that person. The person providing the information should have authority to do so and should provide only what is reasonably necessary for the request. If you provide information about another guest, you should make that person aware that their information may be handled in accordance with this policy.

5. Browser local storage, consent choices and the availability helper

The Website's current JavaScript uses browser local storage for two limited purposes. First, it stores whether you selected the optional or essential-only choice on the consent notice. Second, it stores values entered into the availability helper, such as dates, guest count and promo code, so those fields can remain populated on the same browser and device.

Local storage is browser-based storage. It generally remains on the device until it is cleared by the user, overwritten by the Website or removed by browser controls. You can clear local storage through your browser settings. Doing so may cause the consent notice to appear again and may remove previously remembered availability values.

Submitting the availability helper is not the same as sending a completed hotel booking. The current helper redirects to the contact page with the selected values in the URL query string. The public Website code does not itself create a user account, charge a payment card or issue a booking confirmation from those fields.

6. Why we use personal information

We use personal information only for legitimate and specific purposes connected with the Website and resort operations. Depending on the circumstances, those purposes may include:

  • answering reservation, accommodation, dining, event, access, transport or general guest-service enquiries;
  • taking steps at your request before a reservation or other service arrangement is entered into, and administering an arrangement after it is confirmed;
  • communicating current availability, operational information, booking conditions or changes relevant to your request;
  • operating, maintaining, protecting and troubleshooting the Website and preventing misuse or security incidents;
  • remembering your browser-based Website choices and availability-helper state;
  • keeping appropriate business, accounting, complaint and compliance records;
  • establishing, exercising or defending legal claims and responding to lawful requests by courts, regulators or public authorities; and
  • meeting obligations imposed by applicable law, including obligations that may apply to accommodation, casino operations, responsible gaming, tax, accounting, safety or privacy.

7. GDPR legal bases where the GDPR applies

The GDPR does not apply to every interaction with an Australian business. Where the GDPR applies to a particular processing activity, we will rely on an appropriate legal basis under Article 6 of the GDPR. The basis will depend on the purpose and circumstances of the processing.

  • Steps before entering into a contract or performance of a contract: where you ask us to take steps relating to a reservation or another service and the processing is necessary for those steps or for a contract with you.
  • Legitimate interests: where processing is reasonably necessary to operate and secure the Website, answer ordinary enquiries, maintain appropriate business records or protect our rights, provided those interests are not overridden by your interests or fundamental rights and freedoms.
  • Legal obligation: where we must process information to comply with an applicable legal requirement.
  • Consent: where applicable law requires consent for a specific optional activity. If processing is based on consent, you may withdraw that consent at any time for future processing. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

If a different GDPR legal basis is required for a particular activity, we will provide the relevant information at the point where the information is collected or before that processing begins.

8. Australian privacy principles and anonymous enquiries

Where the Australian Privacy Act 1988 and the Australian Privacy Principles apply to us or to a particular handling activity, we aim to manage personal information openly and transparently, collect information that is reasonably necessary for our functions, use and disclose it for appropriate purposes, take reasonable steps to protect it, and provide access and correction rights as required by law.

You may be able to make a general enquiry without identifying yourself or by using a pseudonym where it is lawful and practical for us to deal with the matter that way. Identification will normally be necessary where we need to locate or administer a specific reservation, confirm a guest's authority, meet a legal obligation, process a complaint tied to a specific transaction, or otherwise provide a service that cannot reasonably be delivered anonymously.

9. Sensitive information and information about accessibility

Please do not send sensitive information unless it is genuinely necessary for the service you are requesting. If you voluntarily tell us about an accessibility requirement, dietary need or another matter that could reveal sensitive information, we will seek to use that information only to understand and respond to the relevant request and to meet applicable legal or safety obligations.

Where Australian law or the GDPR requires explicit consent or another special condition for processing sensitive or special-category information, we will rely on an applicable condition before processing that information. We do not use the Website's booking-helper fields to solicit medical information or other special-category data.

10. When information may be shared

We do not describe personal information as being sold through the Website. We may disclose or make information available only where reasonably necessary for a legitimate purpose, where you direct us to do so, or where the law permits or requires it.

Recipients may include personnel who need the information to respond to your enquiry or administer a service; website-hosting, information-technology, email, telecommunications or security providers acting for us; professional advisers such as accountants, auditors, insurers or legal advisers where necessary; payment or reservation providers if you later enter into a booking process that uses those services outside the current public Website; and courts, regulators, law-enforcement bodies or other authorities where disclosure is legally required or reasonably necessary to protect legal rights.

Service providers are expected to handle information only for the relevant service and subject to appropriate confidentiality, security and data-protection requirements. The exact providers used for offline reservations or resort operations may change over time and are not all identifiable from the public Website code.

11. Overseas handling and international transfers

is identified as an Australian company and the resort is located in Queensland, Australia. If you contact us from another country, your communication and related personal information may therefore be received and handled in Australia.

Some technical or business service providers may process information in another country depending on where their infrastructure and support personnel are located. Where the GDPR applies to a transfer of personal data outside the European Economic Area and a transfer mechanism is required, we will use a lawful mechanism appropriate to the circumstances, such as an applicable adequacy decision, appropriate safeguards or another transfer basis permitted by the GDPR. Where Australian privacy law requires steps in relation to an overseas disclosure, we will address those requirements as applicable.

12. How long we keep information

We do not keep personal information merely because it might become useful. Retention depends on the type of information, why it was collected, whether a booking or transaction resulted, legal record-keeping requirements, the need to resolve disputes or complaints, security requirements and applicable limitation periods.

General enquiries that do not lead to a continuing relationship should be deleted or anonymised when they are no longer reasonably needed. Records connected with a confirmed booking, payment, tax or accounting obligation may need to be retained for the period required by applicable law and legitimate record-keeping needs. Complaint, incident or legal records may be kept for as long as reasonably necessary to resolve the matter and protect legal rights.

Browser local-storage values remain on the relevant browser and device until they are cleared, overwritten or otherwise removed. Because those values are stored on your device by the Website's client-side code, you can remove them using your browser controls.

13. Security

We seek to use reasonable technical and organisational measures appropriate to the nature of the information and the risks involved. Measures may include access controls, appropriate staff access restrictions, secure configuration, software maintenance, backup or recovery practices and procedures for responding to suspected data-security incidents where relevant to the systems being used.

No internet transmission, browser storage, email system or information system can be guaranteed to be completely secure. You should avoid sending highly sensitive information through ordinary email or placing it in URL-based Website fields. If we become aware of a data breach that triggers notification duties under applicable law, we will take the steps required by that law.

14. Your GDPR rights where applicable

If the GDPR applies to the processing of your personal data, you may have rights including the right to receive information about the processing, obtain access to your personal data, correct inaccurate or incomplete data, request erasure in circumstances provided by law, request restriction of processing, receive qualifying data in a portable format, and object to certain processing based on legitimate interests.

Where processing is based on consent, you may withdraw consent at any time for future processing. You also have the right not to be subject, where the GDPR conditions are met, to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. The current Website does not use its booking helper or consent banner to make such automated decisions about visitors.

These rights are not absolute. For example, we may need to retain information where a legal obligation requires it or where it is necessary to establish, exercise or defend legal claims. We may request enough information to verify your identity before giving access to personal information or acting on a rights request. We will respond within the period required by applicable law.

If you are in the European Economic Area and believe your GDPR rights have been infringed, you may also lodge a complaint with the data-protection supervisory authority in the EEA country where you live, work or where the alleged infringement occurred.

15. Access, correction and privacy complaints in Australia

If Australian privacy law gives you a right to access personal information we hold about you or to seek correction of inaccurate, out-of-date, incomplete, irrelevant or misleading information, you may contact us using the details in this policy. We may need to verify your identity and may refuse or limit a request where the law permits us to do so. If access or correction is refused, we will provide any notice or reasons required by applicable law.

If you have a privacy concern or complaint, please first contact us and describe the issue with enough detail for us to investigate it. We will assess the complaint, make reasonable enquiries and respond within a reasonable period having regard to the nature and complexity of the issue. Where the Australian Privacy Act applies and you are not satisfied with the outcome, you may be able to complain to the Office of the Australian Information Commissioner (OAIC).

16. Children, minors and the physical casino

The Website contains information about a physical casino. Casino entry and gambling-related participation are restricted to eligible adults aged 18 or over under the rules stated on the Website and applicable local requirements. The Website does not provide online gambling.

The general accommodation and resort information may be viewed by families, but we do not use the Website to knowingly solicit unnecessary personal information from children. If a parent, guardian or organiser provides information relating to a minor because it is genuinely necessary for an accommodation or guest-service arrangement, that information should be limited to what is necessary for the request.

17. Automated decision-making and profiling

The current public Website does not use the availability helper, consent choice or local browser storage to score visitors, profile gambling behaviour, determine eligibility, set personalised prices or make decisions that produce legal or similarly significant effects. The client-side code simply remembers specified browser values and supports ordinary Website interactions.

If we later introduce automated decision-making that materially affects individuals and applicable law requires additional transparency or rights, we will update this policy before or when that processing begins.

18. Third-party websites and services

The Website may from time to time refer or link to services that are operated independently. A third party's handling of personal information is governed by that third party's own privacy information, not by this policy. You should review the relevant terms and privacy notice before providing personal information to an independent third party.

19. Changes to this Privacy Policy

We may update this policy when the Website's functionality, our operational practices or applicable legal requirements change. Material changes should be reflected by updating the date at the top of the policy and, where appropriate, by providing an additional notice. We will not rely on a policy update to retrospectively make materially different use of personal information where applicable law requires a new legal basis or consent.

20. Contact us

Privacy enquiries, requests and complaints may be directed to at info@elvariancrestlodge.com or +61 7 3847 2916. Postal correspondence may be sent to . Please do not send identity documents or other sensitive information with an initial privacy enquiry unless we specifically ask for information that is necessary to verify a request.

Check availability