Book GCC Trip
Legal

Privacy Policy

Effective date: 1 August 2026  ·  Last updated: 6 August 2026
Policy Version 1.0  ·  Policy Owner: Book GCC Trip

This Privacy Policy explains how Book GCC Trip collects, uses, shares, retains, and protects personal data when you visit our website or app, create an account, or make a hotel booking through us. It applies to every visitor and guest using the Book GCC Trip platform, regardless of which hotel or destination you book.

This Policy works alongside three focused companion documents that go into more detail on specific rights frameworks and procedures: our UAE Personal Data Protection Compliance Statement, our GDPR Statement, and our Data Subject Rights procedure. Where this Policy and a companion document both address a topic, the companion document controls for that specific procedural detail; this Policy remains the primary statement of what data we collect and why.

On this page
1. Definitions2. Who We Are and the Data Controller3. Personal Data We Collect4. How We Collect Personal Data5. Purposes of Processing6. Legal Bases for Processing7. Disclosures to Hotels and Suppliers8. Disclosures to Payment Service Providers9. Other Service Providers10. Fraud Prevention and Security Processing11. International Data Transfers12. Data Retention13. Security Measures14. Your Data Protection Rights15. Cookies, Analytics and Marketing16. Children's Privacy17. Automated Support Assistant18. Changes to This Policy

1. Definitions

"Personal Data":
any information relating to an identified or identifiable individual, such as your name, contact details, booking details, or device identifiers.
"Processing":
anything done with personal data — collecting, storing, using, sharing, or deleting it.
"Data Controller":
the party that decides why and how personal data is processed — see Section 2 for who this is for data collected through the Platform.
"Hotel", "Property", "Supplier":
the accommodation provider, or the wholesaler/channel partner supplying that accommodation's availability and rates to us, whose rooms are listed and bookable on the Platform.
"Platform":
the Book GCC Trip website, mobile-optimised site, and any associated apps or interfaces.

2. Who We Are and the Data Controller

Book GCC Trip is operated by TESSMA Destination Services FZ-LLC, a company licensed in Ras Al Khaimah, United Arab Emirates.

For personal data collected through the Platform — your account, your bookings, and your use of our website and app — Book GCC Trip is the data controller: we decide why and how that data is processed, subject to this Policy. Once a booking is confirmed, the hotel separately becomes responsible, as an independent controller in its own right, for the guest data it needs to deliver your stay (for example, ID checks at check-in) — see Section 7.

Throughout the rest of this Policy, "Book GCC Trip", "we", "us" and "our" refer to the operator acting under this brand, without repeating the full legal entity name again.

3. Personal Data We Collect

We collect the following categories of personal data in connection with your use of the Platform:

Account Data

Your name, email address, phone number, password (stored in hashed form), and any profile preferences you choose to add.

Booking and Payment Data

Booking details (hotel, dates, room type, occupancy, price paid), a payment reference and transaction status supplied to us by our payment service provider, billing name and address, and invoice details. We do not store full payment card numbers ourselves — card data is handled directly by our payment service provider(s), described further in Section 8.

Hotel-Guest Data

Where you book for other travellers (for example, a family member or colleague), the guest names, ages of any children, and any special requests you provide for the stay, which we pass to the relevant hotel to fulfil the booking — see Section 7.

Device, Cookie and Analytics Data

Your IP address, browser and device type, pages viewed, referring pages, and similar technical data, collected automatically through cookies and similar technologies as described in our Cookie Policy.

Communications Data

The content of emails, support chats, and phone calls you have with us, including messages exchanged with our automated support assistant described in Section 17.

4. How We Collect Personal Data

  • Directly from you — when you create an account, complete a booking, contact support, or fill in a form on the Platform.
  • Automatically — through cookies, analytics tools, and similar technologies as you use the Platform (see our Cookie Policy).
  • From a travel companion — where someone else books on your behalf and provides your name and guest details for the stay.
  • From our payment service provider — a payment reference and transaction status confirming whether your payment succeeded, not your full card details.

5. Purposes of Processing

We use personal data to:

  • Create and manage your account.
  • Process, confirm, and manage your hotel bookings, including sending confirmations, vouchers, and booking-related updates.
  • Collect payment for your booking through our payment service provider(s), on behalf of the hotel.
  • Share the guest and stay details a hotel needs to honour your booking.
  • Provide customer support before, during, and after your stay, including through our automated support assistant.
  • Detect and prevent fraud and protect the security of the Platform and our guests.
  • Meet our legal, financial-record-keeping, and regulatory obligations.
  • Improve the Platform and, where you have consented, personalise your experience and send marketing communications.

7. Disclosures to Hotels and Suppliers

We share the booking and guest details necessary to fulfil your reservation with the hotel or supplier you have booked — typically guest names, contact details, dates, room type, occupancy, and any special requests you provided. This disclosure is necessary to complete the booking you have asked us to make; without it, the hotel cannot honour your reservation or prepare for your stay.

8. Disclosures to Payment Service Providers

To collect payment for your booking, we share the necessary payment details with an authorised payment service provider selected for the transaction, who processes the charge on our behalf and on behalf of the hotel. We do not name a specific payment service provider in this Policy because the provider used can vary by transaction; whichever provider is used is bound to handle your payment data securely and only for the purpose of processing your transaction.

9. Other Service Providers

We use a limited number of other service providers to operate the Platform, acting on our instructions and only for the purposes described in this Policy — for example, providers that deliver transactional emails (such as booking confirmations), providers that host our infrastructure and databases, analytics tools that help us understand how the Platform is used, and customer-support tooling that helps our team respond to you. We do not sell personal data to advertisers or data brokers.

10. Fraud Prevention and Security Processing

We process account, booking, and payment data using automated and manual checks to detect and prevent fraudulent bookings and payment fraud. This may include reviewing patterns across bookings, verifying identity information, and, where fraud is suspected, declining or cancelling a booking and reporting the matter to relevant authorities. See our Terms and Conditions for how this affects a booking.

11. International Data Transfers

Some of our service providers may process or store personal data outside the United Arab Emirates. Where we transfer personal data internationally, we take reasonable steps appropriate to the circumstances — such as using providers that offer contractual or equivalent safeguards — to keep that data protected consistent with this Policy, regardless of where it is processed.

12. Data Retention

We keep personal data only for as long as it is needed for the purpose it was collected, or for the period required by applicable financial, tax, or legal record-keeping obligations, whichever is longer. Booking and payment records are generally kept for a period after your stay to meet financial-record obligations; account data you have not used is deleted or anonymised in the ordinary course once it is no longer needed, unless you ask us to delete it sooner or the law requires us to keep it. Our Data Subject Rights procedure explains how retention obligations can affect a deletion request.

13. Security Measures

We apply industry-standard safeguards appropriate to the sensitivity of the data involved, such as encryption of data in transit, access controls limiting who within our team can view personal data, and monitoring for suspicious activity. No method of storage or transmission is completely secure, and we cannot guarantee absolute security; we continue to review and improve our safeguards as the Platform grows.

14. Your Data Protection Rights

Depending on your location and the applicable law, you have rights over your personal data — including access, correction, deletion, restriction, objection, data portability, and the right to withdraw consent. The practical steps for exercising these rights are set out in our Data Subject Rights procedure; guests connected to the UAE should also see our UAE Personal Data Protection Compliance Statement, and guests connected to the EU/EEA should see our GDPR Statement.

You can withdraw consent for anything we process on the basis of your consent (such as marketing emails or optional analytics cookies) at any time, using the same methods described in Section 15 or by contacting us — withdrawal does not affect the lawfulness of processing carried out before you withdrew it.

If you are not satisfied with how we have handled your personal data or a rights request, you can raise a complaint with us using our Complaint Handling Procedure, and, where applicable, with a relevant supervisory authority.

15. Cookies, Analytics and Marketing

We use essential cookies needed for the Platform to function, and, with your consent, analytics and marketing cookies. You can manage your cookie preferences at any time — see our Cookie Policy for full detail on the categories of cookies we use and how to control them. Marketing communications are sent only with your consent and always include a way to opt out — see our Marketing Consent Policy for how we obtain and manage that consent.

16. Children's Privacy

Book GCC Trip is not directed at children, and our Platform is not intended for use by minors creating their own account. Bookings, including for any accompanying children, must be made by an adult who accepts responsibility for the accuracy of the information provided. See our Children's Privacy Policy for further detail on how children's data supplied as part of a booking is handled.

17. Automated Support Assistant

The Book GCC Trip Assistant is an automated support tool that helps answer common questions and guide you through booking-related tasks within the Platform. Messages you send to the assistant are stored and processed to generate a response, provide support, and help us maintain and improve the quality, accuracy, and safety of the feature, in line with the purposes described in Section 5. We do not currently use assistant conversations to train or fine-tune the underlying AI model.

A conversation may be reviewed by authorised staff for quality, safety, fraud-prevention, and support purposes, including automatically where a conversation is flagged for escalation to a human agent. We retain assistant conversation data for as long as reasonably necessary for these purposes, to maintain booking-related context, and to meet our legal and record-keeping obligations, after which it is deleted or anonymised.

Where fulfilling a request made through the assistant requires it — for example, completing a booking — relevant details may be shared with the hotel or a service provider in the same way as for any booking made through the Platform (see Section 7), or with the third-party AI service provider we use to generate assistant responses, under the safeguards described in Section 9. The assistant is a support tool, not a substitute for a human agent — you can always ask to be connected to our support team.

You have the same rights over your assistant conversation data as over any other personal data we hold about you, described in Section 13 — including the right to request access to or deletion of it. To exercise these rights for your conversation data specifically, contact us at support@bookgcctrip.com or see our Data Subject Rights page for how to submit a request.

18. Changes to This Policy

We may update this Policy from time to time to reflect changes in our data practices, service, or legal requirements. We will update the "Last updated" date above when we do, and for material changes we will take reasonable steps to bring them to your attention, such as a notice on the Platform or an email. Continued use of the Platform after an update takes effect constitutes acceptance of the update.

Related policies
UAE Personal Data Protection Compliance StatementGDPR StatementData Subject RightsCookie PolicyMarketing Consent PolicyChildren's Privacy PolicyComplaint Handling Procedure
Revision History
Version 1.0Initial publication6 August 2026
Questions or Complaints

Contact our support team at support@bookgcctrip.com or +971 54 339 3555 (09:00–18:00 UAE time, English; Arabic support planned for a future phase). If you are not satisfied with our response, see our Complaint Handling Procedure.