Privacy Policy
In short: We are a business-to-business hospitality technology platform. We collect only the data needed to run our two products for hotels and their guests, we never sell personal data, our email is strictly transactional and consent-based, and every non-essential message includes a one-click unsubscribe. Details below.
1. Who we are
UltraHospitality.AI is operated by Ultra Hospitality ("we", "us", "the Platform"), registered at 14 Syria St., Mohandessin, Giza, Egypt. We provide two products:
- Ultra SupplyChain — procurement analytics and sourcing for hotels and restaurants, built on their own e-invoice data.
- Ultra Guest — a guest-commerce marketplace and AI concierge that lets hotel guests discover and book ancillary services (dining, spa, experiences, retail) during their stay.
For guest bookings on Ultra Guest, the hotel is the data controller of the guest relationship and the merchant of record; Ultra Hospitality acts as the technology processor on the hotel's documented instructions, and as an independent controller only for platform security, fraud prevention, legal compliance, and de-identified analytics.
2. The personal data we collect
| Category | Examples |
|---|---|
| Account & contact | Name, work email, phone, employer/hotel, role, preferred language. |
| Guest & stay data | Reservation reference, room, check-in/out dates, supplied by the hotel's booking/PMS. |
| Order & booking data | Items viewed/booked, quantities, scheduling, special requests. |
| Procurement data (SupplyChain) | A hotel's own e-invoice data, used to compute its procurement savings. |
| Dietary & allergen preferences | Only what a guest volunteers, handled as sensitive data. |
| Payment metadata | Amount, currency, status, gateway reference, card last-4/scheme. We never store full card numbers, CVV, or bank credentials — these go directly to the payment gateway. |
| Conversation data | AI concierge and support messages. |
| Technical & usage | IP, device/browser, approximate location from IP, pages viewed, diagnostic logs. |
| Consent records | Time, scope, and version of each consent given or withdrawn. |
3. Email & communications how we use email
Email is central to how we serve hotels and guests, so we are explicit about it:
- We send transactional and operational email only. Specifically: booking and order confirmations and receipts; magic-link / one-time-passcode sign-in; pre-arrival guest welcome and itinerary messages; service and status notifications; account and access-request messages; and operational notices to hotel staff and operators.
- Recipients have a direct relationship with us. Guests provide their email when they book or check in; hotel staff are explicitly invited by their hotel. We never buy, rent, or scrape email lists, and we do not send cold or unsolicited email.
- Consent & opt-out. Any marketing/offer email is sent only with consent and always carries a one-click unsubscribe (List-Unsubscribe). Transactional emails essential to a booking always send. Consent and withdrawal are recorded with a timestamp.
- Bounce & complaint handling. We process delivery, bounce, and complaint events automatically (via Amazon SES event notifications) and immediately add affected addresses to a suppression list, so we stop mailing addresses that bounce or complain. We apply per-recipient throttling.
- Authenticated, hotel-branded sending. Outbound mail is sent from our verified domains
(
ultrahospitalityai.com,guest.ultrahospitalityai.com) with DKIM, SPF, and DMARC, and is branded per hotel while we centrally protect deliverability across all tenants.
4. Why we use your data (lawful bases)
- Performance of a contract — to operate accounts, carts, orders, bookings, sign-in, and to route confirmations and process payments.
- Consent — for marketing/offer emails and for dietary/allergen handling; withdrawable at any time.
- Legal obligation — to issue receipts and keep tax, fiscal, and accounting records.
- Legitimate interests — security, fraud prevention, platform integrity, and de-identified analytics.
5. Who we share data with
We share personal data only as needed and under contract: with the hotel that controls the guest relationship; with payment gateways to process payments; with cloud and AI sub-processors that host the platform and power the concierge (see §6); and with authorities where legally required. We do not sell personal data.
6. International transfers
We use Amazon Web Services, including Amazon SES (email) and Amazon Bedrock (AI) in the US East (N. Virginia) region. Some data — for example concierge message content and the data needed to send an email — is processed in the United States under the cross-border safeguards of the PDPL and GDPR Chapter V (contractual data-protection clauses, encryption in transit, access controls, and data minimisation).
7. How long we keep data, and your rights
We retain personal data only as long as necessary, then delete or irreversibly anonymise it; financial and legal records are kept for the period the law requires. Subject to the PDPL and GDPR you may request access, rectification, erasure, restriction, portability, objection, and you may withdraw consent at any time. To exercise a right, contact us at the addresses below; you may also complain to Egypt's Personal Data Protection Center.
8. Security
We apply encryption in transit, strict tenant isolation (each tenant's data is logically separated and access is re-validated on every request), least-privilege access controls, hardened infrastructure, and append-only audit logging. Payment card data is handled by the gateway and is never stored by us.
9. Cookies
We use strictly necessary cookies for sign-in and security, and — only with consent — analytics cookies to improve the service. Guests can manage choices from the cookie banner in the guest app.
10. Children
The platform is intended for adults (18+) and is not directed at children. We do not knowingly collect data from minors without a guardian's consent.
11. Changes
We may update this policy; the version and effective date appear at the top. Material changes will be notified prominently and, where required, we will seek renewed consent.
12. Contact
- General / support: support@ultrateb.com
- Privacy / data protection (DPO): privacy@guest.ultrahospitalityai.com
- Complaints: complaint@ultrahospitalityai.com
- Postal: Ultra Hospitality, 14 Syria St., Mohandessin, Giza, Egypt