Updated July 2018
How we use your information
This privacy notice tells you what to expect when Heathrow Airport Limited (Heathrow) collects personal information about you when you register and use the Heathrow Rewards loyalty programme. Heathrow is committed to protecting your personal information when you use Heathrow services. Whenever you provide such information we will only use your information in line with all applicable data protection laws, including the General Data Protection Regulation (GDPR). Your information will be kept in a secure environment and access to it will be restricted according to the 'need to know' principle.
What information will we collect about you?
When you use Heathrow Rewards, we will collect the following information about you:
- Date of birth (you must be over 18 to participate in the loyalty programme)
- Email address
- Phone number (we will only contact you by phone if we have a query with your account)
- Staff ID number (if you are a staff member)
- Employer (if you are a staff member)
- Transaction data
- Location data (if you download your Heathrow Rewards card to your mobile wallet)
Heathrow collects information about how you use Heathrow Rewards via our website and the device(s) you use to access the service. This includes collecting unique online identifiers such as IP addresses, which are numbers that uniquely identify a specific computer or other network device on the internet. For more information, see our section on ‘Privacy and Cookies' below.
How will Heathrow use the information it collects about me?
Heathrow will use your personal data for a number of purposes including the following:
- To provide the Heathrow Rewards loyalty programme, activities and to provide you with information about them and to deal with your requests and enquiries related to Heathrow Rewards.
- To send you marketing communications about Heathrow Rewards and other Heathrow products and services.
- We may also match the data we collect with other data that we hold about you if you have used Heathrow products and services before. We do this to build up a picture of your personal preferences and understand how you use Heathrow products and services. This enables us to deliver a richer customer experience and ensures we only send relevant communications to you.
- If you download your Heathrow Rewards card to your mobile wallet, we will use your location data to ensure our marketing communications (such as push notifications) are relevant to the terminal you are travelling through.
The lawful justification for collecting and using your personal data is that it is necessary for providing the Heathrow Rewards loyalty programme which you contractually enter into. Failure to provide mandatory data fields denoted by a ‘*' will mean that we will not be able to provide the Heathrow Rewards loyalty programme to you.
The lawful justification for sending marketing communications about Heathrow Rewards and other Heathrow products and services to you is because we have a legitimate business interest for your personal data to be used for this specific purpose. We have conducted an assessment to make sure that the benefits to you are equal to the benefits to us. You are always in control of how we use your personal data. If you don't want to receive marketing communications from us, you can change your marketing preferences at any time by contacting firstname.lastname@example.org or by clicking ‘Unsubscribe' on the footer of a Heathrow Rewards marketing email.
The lawful justification for matching the data we collect with other data that we hold about you if you have used Heathrow products and services before is because we have a legitimate business interest for your personal data to be used for this specific purpose. This enables us to send you relevant and personalised content designed to make your journey smoother and more enjoyable. We have conducted an assessment to make sure that the benefits to you are equal to the benefits to us. You have the right to object to this processing which you can exercise by contacting email@example.com. Please note that if you object, this may affect our ability to send personalised marketing communications to you.
Your information will be handled and used by the following recipients in order to deliver the Heathrow Rewards loyalty programme:
- Heathrow staff delivering the Heathrow Rewards loyalty programme
- Comarch UK Limited who administer the loyalty programme platform
- Acxiom Limited, our trusted data partner
- Customer service agents employed by Sitel Group who work on behalf of Heathrow
- Loyalty partners (i.e. airline frequent flyer programmes)
- Send and Received Limited who print personalised stationary for us (e.g. membership cards and airport shopping vouchers)
We will keep your information within Heathrow and our trusted third parties except where disclosure is required by law, for example to government bodies and law enforcement agencies.
Some of our trusted loyalty partners (i.e. airline frequent flyer programmes) may transfer your information overseas to fulfil your Heathrow Rewards points conversion to the corresponding currency. As we are responsible for your personal data, we always ensure that your information remains protected and secure when being transferred.
How long will Heathrow keep my information?
Your account information will be retained for a period of three years and three months from the date of your last transaction at which point all of your personal details are removed from our systems. Your personal details for marketing communications will be retained for a period of three years from the date of your last interaction with the marketing communication (i.e. opening an email or clicking on a link within the email) at which point all of your personal details is removed from our systems. Where you tell us that you no longer wish to receive marketing messages about Heathrow Rewards and other Heathrow products and services, we will keep this information about you until you tell us otherwise. This is to ensure that we don't send you any further marketing communications in error.
What rights do I have over my personal data?
Under the General Data Protection Regulation, you have the right to:
- Access your personal data by making a subject access request
- Rectification, erasure or restriction of your information where this is justified
- Object to the processing of your information where this is justified
- Data portability
To exercise your rights, please contact the Heathrow Data Protection Officer using the following contact details:
Data Protection Officer Heathrow Airport Limited The Compass Centre Nelson Road Hounslow Middlesex TW6 2GW Email: firstname.lastname@example.org
What if I find your response unsatisfactory?
Should you find our response unsatisfactory, you have the right to lodge a complaint with the supervisory authority – the Independent Commissioner's Office (ICO). You can find more information on the ICO website at https://ico.org.uk/concerns/ regarding the complaints process.
Privacy and cookies
What are cookies?
The different types of cookies we use
Heathrow uses the following categories of cookies on its websites:
Strictly necessary – These cookies are essential for certain features of our websites to work for example when you make payments for car parking. These cookies do not record identifiable personal information and we do not need your consent to place these cookies on your device. Without these cookies some services you have asked for cannot be provided.
Performance – These cookies are used to collect anonymous information about how you use our websites. This information is used to help us improve our websites and understand how effective our adverts are. In some case we use trusted third parties to collect this information for us which may include recording your use of our websites but they only use the information for the purposes explained. By using our websites, you agree that we can place these types of cookies on your device. You have the right to object from being recorded on our websites by clicking here.
Functionality - These cookies are used to provide services or remember settings to enhance your visit for example text size or other preferences. The information these cookies collect is anonymous and does not enable us to track your browsing activity on other websites. By using our websites, you agree that we can place these types of cookies on your device.
Targeting and Advertising – These cookies are used by trusted third parties to deliver adverts more relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaign. Information contained in these cookies is anonymous and doesn't contain your personal information. To find out more about cookies used for targeting and advertising follow youronlinechoices.com and networkadvertising.org or contact us at email@example.com for further information about the trusted third parties we use.
If you'd prefer to restrict, block or delete cookies from us and our third party advertisers, or any other website, you can use your browser to do this. Each browser is different, so check the 'Help' menu of your particular browser to learn how to change your cookie preferences. If you choose to disable all cookies we cannot guarantee the performance of our websites and some features may not work as expected.
Links to other websites
This privacy notice does not cover the links within this site linking to other websites. We encourage you to read the privacy statements on the other websites you visit.
Changes to this Privacy notice
We keep our privacy notice under regular review and we will place any updates on this webpage. At the start of this privacy notice we will tell you when it was last updated.
- July 2018- Account information retention period updated