Privacy Policy

Effective from: 19 August 2026

Who we are. Backstage ("Backstage," "we," "us," or "our") operates backstage.sh and related mobile/web applications (the "Platform"). We help travelers discover and book hotels, restaurant reservations, experiences, event tickets, and transportation, together with curated travel services, customer support, a personal concierge, and free city guides.

Company information & contact.

Backstage Hospitality FZCO

Premises No. 41902 001, IFZA Business Park, DDP, Dubai Silicon Oasis, Dubai, United Arab Emirates

Primary contact: support@backstage.sh

1) Scope

This Policy explains how we collect, use, disclose, and protect personal data when you use the Platform, communicate with us (including via WhatsApp), access our free city guides, or make bookings of any kind — hotels, restaurants, experiences, event tickets, or transportation. Separate Terms & Conditions govern your use of the Platform; supplier policies (e.g., hotels, event organisers, restaurants, operators) may also apply.

2) The data we collect

  • Account & identity data - name, title, date of birth, nationality, phone number, email, password, profile photo; identity documents when required by a supplier or event organiser (e.g., passport copy for check-in or registered-name tickets).
  • Booking data - itinerary details, travel dates, property or venue selection, rate/room type, guest and attendee names, preferences (e.g., bed, dietary), loyalty numbers, special requests; reservation details for restaurants (party size, date/time, dietary notes); experience requirements you disclose (e.g., accessibility needs you choose to share); transfer details (pickup address, flight number, luggage).
  • Event ticket data - event and seat/category selection, attendee names and details required by the organiser, order confirmation status, and any credit you hold with us following an unavailable ticket order.
  • Payment data - tokenized card details processed by our payment service provider (we do not store raw card numbers), transaction identifiers, billing address, VAT/Tax numbers for invoices.
  • Promotional credit data - credits or vouchers attached to your bookings and their redemption status.
  • Communications data - messages via in-app chat, email, WhatsApp/Telegram, support tickets, call recordings (if support calls are recorded), and survey responses, including with our concierge team.
  • Guide & support usage data - categories viewed, favorites, notes, support chat transcripts, feedback on recommendations.
  • Device & technical data - IP address, device IDs, OS/browser, app version, language, time zone, crash logs, diagnostic data.
  • Location data - approximate location from IP or consented precise location to tailor suggestions.
  • Cookie/tracking data - cookies, pixels, SDKs for core functionality, analytics, A/B testing, fraud prevention, and advertising (see §10).
  • User content - reviews, photos, and other content you upload or share.

Where we get data from.

We primarily collect personal data directly from you. We may receive limited referral and technical information from metasearch or affiliate partners when they redirect you to our checkout so we can resume your session. We do not obtain your personal data from wholesalers unless they are involved in fulfilling a booking that you asked us to manage or you authorize us to liaise with them. Suppliers (such as hotels, restaurants, event organisers, or operators) may share limited information with us only when necessary to service a change, cancellation, or refund you request.

3) Purposes & legal bases (GDPR/UK GDPR)

  • To perform a contract (Art. 6(1)(b)): create accounts; process and manage bookings, reservations, ticket orders and transfers; provide customer support and concierge services; send confirmations, reminders, and service messages; handle changes, cancellations, refunds, and credits held with us.
  • Legitimate interests (Art. 6(1)(f)): improve and secure the Platform; prevent fraud/abuse; personalize content; analyze product usage; provide free city guides and travel content; B2B outreach; defend legal claims (balanced against your rights).
  • Consent (Art. 6(1)(a)): marketing emails/WhatsApp; push notifications; cookies beyond strictly necessary; optional data such as precise location (withdraw any time).
  • Legal obligations (Art. 6(1)(c)): tax and accounting, KYC/AML (if applicable), responding to lawful requests from authorities.
  • Vital interests (Art. 6(1)(d)):rare cases involving emergencies affecting a guest's safety.

4) How we share data

  • Travel and event suppliers - hotels, restaurants, experience operators, transportation providers, and event organisers or their authorised ticketing channels, to the extent needed to fulfil your booking or ticket order. They act as independent controllers for their own purposes (e.g., check-in or entry obligations).
  • Payment & fraud vendors - Stripe, anti-fraud tools, 3-D Secure providers. For customers in certain regions, payments may be processed by our independent affiliated payment company in Switzerland acting as Merchant of Record; it receives only the data necessary to process the relevant payment.
  • Hosting & infrastructure - cloud providers, CRM/helpdesk tools, email/SMS/WhatsApp delivery platforms, analytics and product tooling.
  • Affiliates & group companies - for centralized operations and support.
  • Professional advisers & authorities - auditors, lawyers, insurers; regulators and public authorities as required by law.
  • Business transfers - in connection with mergers, financing, or sale of assets, subject to safeguards.

We do not sell personal data. Advertising/analytics partners set cookies/SDKs only with consent where required by law.

5) International data transfers

Where personal data is transferred outside the EEA/UK/Switzerland (e.g., to the UAE or US), we rely on mechanisms such as Standard Contractual Clauses (SCCs), the UK Addendum, and supplementary measures. Copies are available on request (with necessary redactions).

6) Retention

  • Booking & invoice records: up to 10 years (accounting/tax laws).
  • Account data: for the life of the account and up to 24 months after last activity.
  • Support chat transcripts: up to 24 months for quality and product improvement (shorter where law requires).
  • Marketing data: until you opt out; we keep a suppression record.
  • Logs & diagnostics: typically 12-24 months.

We may retain data longer to establish, exercise, or defend legal claims.

7) Your rights

Depending on your location, you may have rights to access, rectify, erase, restrict, object (including to profiling/marketing), and data portability, and to withdraw consent. EU/UK residents can also complain to their local supervisory authority. To exercise rights, contact support@backstage.sh.

8) Children

The Platform is intended for individuals 18+. Bookings may include minors as accompanying guests or attendees; the booking adult provides that data and is responsible for having authority to do so. If a child has provided data directly, contact us to delete it.

9) Security

We employ technical and organizational measures appropriate to the risk (encryption in transit, access controls, role-based permissions, logging, vendor due diligence). You are responsible for keeping your credentials confidential and using strong passwords.

10) Cookies & similar technologies

We use cookies/SDKs that are Strictly Necessary, Preferences, Analytics, and Marketing (consent where required). Manage preferences any time via the Cookie Settings link in the site footer, the cookie banner, and your browser/device settings. Full details, including the live list of cookies in use, are in our Cookie Policy at backstage.sh/cookie-policy.

11) Communications & WhatsApp

By opting into WhatsApp or similar messaging, you consent to receiving service updates and support messages there. Provider terms and data practices apply. You can opt out any time.

12) Third-party links

Third-party sites or services we link to have independent privacy practices. Review their policies before providing data.

13) Changes to this Policy

We may update this Policy. Material changes will be notified via the Platform or email. Continued use after the effective date constitutes acceptance.

Controller role.

Unless stated otherwise, Backstage Hospitality FZCO is the controller for processing on the Platform. Where we transmit booking or ticket details to a supplier (such as a hotel, restaurant, operator, or event organiser), that supplier becomes an independent controller for its own processing.

Contact: support@backstage.sh

Address: Premises No. 41902 001, IFZA Business Park, DDP, Dubai Silicon Oasis, Dubai, United Arab Emirates