Sanam — Privacy & Personal Data Notice
Version: v1.1
Last updated: 24 July 2026
Applies to: the Sanam platform, the operator and reseller portals, Sanam-powered operator storefronts, and the bookings made through them.
This notice is between Sanam — a Saudi company, Commercial Registration 7054775262 — and everyone whose personal data reaches our platform: the operators and resellers who use it, the people who work for them, and the travellers whose booking details pass through it so an experience can be delivered. It explains, in plain language, what we collect, why we collect it, how we use AI, who we pass it to, where it goes, how long we hold it, how we protect it, and the rights you have under the Saudi Personal Data Protection Law (PDPL), which is overseen by the Saudi Data & AI Authority (SDAIA).
#1. In plain terms
- Sanam is a business-to-business platform. Tour and activity operators list their experiences with us, and we distribute those experiences through the operator's own Sanam-powered storefront, through a network of B2B resellers (international travel agencies), and through OTAs such as GetYourGuide.
- Most of the data we hold is business data about operators and resellers. We also hold the limited traveller data needed to make and deliver a booking.
- We use AI across the platform to draft, read and summarise. Section 6 explains exactly where, and what we do not let it do.
- We do not sell personal data, we do not run advertising trackers, and we do not use personal data to train AI models.
- When a booking is distributed internationally, the traveller's booking details leave Saudi Arabia — because the reseller or OTA that sold the booking needs them. Section 10 explains how we handle that.
#2. How this notice reaches you, and where traveller data comes from
Most traveller data reaches us indirectly. Sanam is rarely the party that sells a booking to a traveller. In most cases the traveller books with an OTA or a reseller, and that seller passes us the booking details so the operator can deliver the experience. Sometimes an operator gives us the details directly. We also receive booking documents that operators upload.
So, honestly stated: if you are a traveller, you may never have typed anything into a Sanam screen, and we may hold your booking details without having met you.
How you can find this notice. It is published on the Sanam platform and on every Sanam-powered operator storefront, and we link to it from the booking confirmations, vouchers and invoices we send. Where a booking was sold by an OTA or a reseller, that seller gives its own privacy notice at the time of booking; ours explains what happens once the booking reaches us.
If you would like to know how your details came to us, write to us at the address in section 17 and we will tell you.
#3. Who is responsible for what
Different parties are responsible for different parts of the same booking. Saying this clearly helps you know who to go to.
- Sanam decides how the platform works and how booking, account and compliance data is used on it. For that data, Sanam is the responsible party (the "controller") and this notice applies.
- The operator who delivers the experience is responsible in its own right for the traveller details it receives from us, and for how it uses them to run the activity. Its agreement with us requires it to use those details only to deliver and support the booking.
- An OTA or a reseller that sold the booking is responsible in its own right for its own customer relationship and its own privacy practices. We do not control them, and this notice does not cover what they do on their own platforms.
Each of us answers for the data it controls. Sanam does not act as a data processor for operators or resellers, and they do not act as processors for us. When an operator uploads its own business documents to the platform, we hold them to run the platform and use them only for the purpose they were given for.
#4. What personal data we collect
We collect only what a purpose actually needs.
4.1 Business and account data. Business or legal name, Commercial Registration number, VAT registration number and VAT status, address and contact details, the names, emails, phone numbers and roles of the people who use the account, bank or payout details, log-in credentials, and the record of which terms and consents were accepted and when.
4.2 Compliance documents. Commercial registration certificates, Ministry of Tourism licences, insurance certificates and policy details, and the identity documents of the people authorised to act for the business.
An honest limit. Sanam captures and reviews these credentials. We do not verify them against any government registry, and we do not represent that a document on file has been confirmed by an authority. The business that supplies a credential remains responsible for it being true and valid.
4.3 Traveller booking data. The lead traveller's name and contact details, the number of participants and — where the experience requires it, for example an age-limited activity — participant details such as an age band, plus the experience booked, the date and time, pick-up or meeting details, special requests, and the booking reference.
4.4 Payment and invoicing data. For bookings on the storefront and reseller channels we collect the buyer's payment and issue the buyer's invoice, so we hold the amount, currency, payment status, references, and the invoice, voucher and settlement records. Card and other payment-instrument details are handled by our payment provider — Sanam does not store full card numbers. On OTA channels the OTA takes the payment and pays the operator directly; there we mainly hold the booking and commission records.
4.5 Channel and connectivity data. Where an operator asks us to set up or manage its distribution-channel (OTA) accounts and connections on its behalf, we handle the account and contact details needed to do that, and the booking messages that flow over the connection.
4.6 Usage, technical and security data. Log-in and session data, IP address, device and browser information, page and feature usage recorded by our own servers, and the audit and security logs we keep to protect the platform.
4.7 Support and communications data. The messages you send us and we send you — booking confirmations, changes, invoices, notifications and support correspondence.
#5. Why we use it, and our lawful basis
Under PDPL we need a valid reason for each use. Ours are:
| What we use data for | Our lawful basis |
|---|---|
| Creating and running operator and reseller accounts | Performing our agreement with you |
| Completing and delivering a booking, and handling changes | Necessary to deliver the booking you have bought — from us, or from the reseller or OTA that sold it — and our legitimate interest in running the platform behind it |
| Passing traveller details to the operator so the experience can happen | The same: necessary to deliver the booking, and our legitimate interest in operating the platform |
| Distributing an experience to resellers and OTAs, and running the connection | Performing our agreement with the operator; legitimate interests |
| Taking payment and paying operators | Necessary to deliver the booking; performing our agreement with the operator |
| Issuing invoices and keeping records for tax, accounting and audit | Legal obligation |
| Reviewing licences, registrations and insurance before and during onboarding | Legitimate interests — we need to know who is on the platform |
| Keeping the platform secure, preventing fraud and abuse, and investigating incidents | Legitimate interests |
| Using AI to draft, read and summarise, as described in section 6 | Legitimate interests; and performing our agreement with you |
| Understanding how the platform is used so we can improve it | Legitimate interests |
| Sending you optional marketing about Sanam | Your consent, which you can withdraw at any time |
"Legitimate interests" means we have a genuine business need and have satisfied ourselves that it does not override your rights. We do not rely on it for sensitive data, and we do not rely on it to justify anything you would not reasonably expect. We never use traveller data for our own marketing.
#6. How we use AI
Sanam is an AI-native platform, so we say plainly where AI is involved.
Where we use it. AI helps us draft listing content and descriptions from the information an operator gives us; read booking and reservation documents that are uploaded, to pull out the details instead of re-typing them; draft and prioritise replies to support messages; and put figures from our own systems into readable words.
What that means for personal data. Reservation documents and support messages can contain a traveller's name, contact details and free text. So yes — where those features are used, that content is sent to our AI provider to be processed for that task, and only for that task.
Who provides it. Our AI provider is Anthropic, in the United States. That is an international transfer, and it is covered by section 10.
The limits we put on it — these are the important part.
- AI does not invent facts. Prices, availability and other figures are calculated by our own systems. The AI is only allowed to put those exact figures into words; if it produces a value our systems did not supply, the output is rejected rather than shown.
- A person decides, not the AI. AI produces drafts and suggestions. Decisions that affect a booking, a payment or an account are made by a person, and money and inventory changes stay behind a human confirmation step.
- No training. We do not use personal data to train AI models, and our agreement with our AI provider does not permit it to train its models on what we send.
- A human will look again. If an AI-assisted output has affected you and you disagree with it, write to us and a person will review it.
#7. Identity documents and other sensitive data
Identity documents and government identity numbers get extra care. We collect them only where they are genuinely needed to review a business or meet a legal obligation, we ask for consent where the law requires it, we keep them under stricter access control than ordinary data, and we do not use them for marketing. We do not share them except where the law requires it or to defend a legal claim. As section 4.2 says, we review these documents; we do not check them against a government registry.
#8. Children
The platform is built for businesses and is not directed at children. Where a booking includes a minor as a participant, the adult making the booking provides those details and confirms they are entitled to share them. We do not knowingly collect personal data directly from a child. If you believe we hold a child's data that we should not, write to us and we will deal with it.
#9. Who we share it with, and why
We share personal data only where there is a reason to, and never sell it.
- The operator delivering the experience — the details needed to run the activity and support the traveller: name, contact route, party size, date and time, and any relevant notes.
- Resellers and OTAs that distribute the experience — the booking and traveller details their systems need to sell, confirm and support a booking, and to settle it.
- Payment providers — to take the buyer's payment, issue refunds, and pay operators.
- Our AI provider — as described in section 6, to process the content of a specific task.
- Service providers who work for us — hosting, storage, communications (email, SMS, WhatsApp) and similar technical services. They may use the data only to provide the service to us, under a written agreement.
- Government, tax and regulatory authorities — where the law requires it, or to establish, exercise or defend legal claims, or to prevent fraud or harm.
- A successor business — if Sanam is merged, acquired, or reorganised, data may pass to the successor, still governed by this notice.
Operators, resellers and OTAs receive traveller data to do a job — deliver, sell or support the booking. They must not use it for unrelated purposes, and each remains responsible for its own compliance.
#10. Sending data outside Saudi Arabia
Sanam's platform data is held in Saudi Arabia by default. But distribution is international by nature. Data leaves the Kingdom in three situations: when an experience is sold through an international reseller or OTA, the traveller's booking details go to that recipient in the country where it operates; when an AI feature runs, the content of that task goes to our AI provider in the United States; and some of the technical services we use may process data outside the Kingdom.
When personal data leaves the Kingdom:
- we send only what the recipient actually needs for its role, not the whole record;
- we rely on the transfer conditions set out in the PDPL and the Kingdom's rules on transferring personal data abroad, and we check that a condition applies before we rely on it;
- where we hold the direct relationship with the recipient, we put written terms in place covering confidentiality, security, purpose limits and onward sharing;
- if we learn that a recipient is not protecting the data properly, we will change what we send or stop sending it.
Two honest limits. When an operator enables an OTA or reseller channel, it is asking us to send booking data to that channel, and operators hold their own accounts with the OTAs — so that OTA's own agreement and privacy notice govern what it does with the data once it arrives. And we cannot control what an international OTA or reseller does on its own platform. What we control is what we send, to whom, and on what terms.
#11. How long we keep it
We keep personal data for as long as the purpose needs, then delete it or make it anonymous. We set a defined period for each category below and review those periods; we will tell you the current period for any category if you ask.
| Category | How long, and what decides it |
|---|---|
| Account and business data | While the account is open, plus a limited period after it closes — long enough to settle final payments and deal with any dispute |
| Booking, invoice, payout and settlement records | For the period Saudi tax and accounting rules require records to be kept, counted from the end of the financial year the record belongs to |
| Compliance documents (registration, licence, insurance) | While we rely on the credential — reviewed when it expires, is replaced, or the account closes |
| Identity documents | Only while needed for the review they were collected for, then removed |
| Support and correspondence | A limited period after the matter is closed, extended only if a dispute or claim is open |
| Security and audit logs | A short standard period, longer where an investigation, a legal claim or the law requires it |
| Marketing contact data | Until you unsubscribe or withdraw consent |
Where a record must be kept for tax or legal reasons, we keep only that record and restrict access to it.
#12. How we protect it
- Encryption at rest for personal and financial fields, including identity data and bank details.
- Encrypted connections for data moving over the network.
- Access control — access by role, on a need-to-know basis, with each organisation's data separated from every other organisation's data.
- Audit trails for money movements and significant account actions, so activity can be reconstructed.
- Payment details handled by our payment provider, so full card numbers do not sit on our systems.
- Internal discipline — decrypt only at the point of use, never write personal data into ordinary logs.
No system can be perfectly secure. We keep these measures under review and improve them as the platform grows.
#13. Your rights
Under PDPL, and subject to the conditions and exceptions in the law, you have the right to:
- be informed about how your personal data is used — that is what this notice is for;
- access the personal data we hold about you;
- get a copy of it in a readable, commonly used format;
- correct data that is wrong, incomplete or out of date;
- ask us to destroy data we no longer have a reason to keep;
- withdraw consent where our reason for processing was your consent;
- object to processing based on our legitimate interests, where the law allows;
- complain to the supervisory authority.
How to use a right. Write to privacy@sanam.travel. We will check who you are, then respond within 30 days, and tell you if the law allows us more time. There is normally no charge. If we cannot do what you ask — for example because we must keep a tax record — we will explain why.
A note for travellers. If your booking was sold by an OTA or a reseller, or is being delivered by an operator, some requests are best raised with them, because they hold their own copy and make their own decisions about it. Write to us anyway and we will point you to the right party and help where we can.
#14. Cookies, your browser, and analytics
We keep this simple, and this is what is true today:
- We do not use advertising cookies, ad networks or third-party tracking, and we do not build advertising profiles of anyone.
- We do not use third-party analytics services.
- To keep you signed in, the platform stores a sign-in token and a few preferences (such as your chosen currency) in your own browser's storage. These are needed for the platform to work. Clearing your browser storage signs you out and clears them.
- We measure how the platform is used from our own server logs, described in section 4.6, not from trackers in your browser.
If we later add anything that needs your consent, we will ask for it and give you a way to change your choice before we turn it on.
#15. If something goes wrong
If a personal data breach happens, we will contain and assess it, notify SDAIA within the time the law requires — our standard is within 72 hours of becoming aware — and tell the people affected where the breach is likely to cause them serious harm. We keep a record of every breach and what we did about it.
#16. Changes to this notice
The platform, our partners and the law all change. When we update this notice we will change the version and the "Last updated" date at the top, and for significant changes we will tell account holders directly. The current version is the one that applies.
#17. Contact us and complaints
Questions, requests and complaints about personal data go to:
Sanam — Privacy contact
Email: privacy@sanam.travel
General: hello@sanam.travel
We would like the chance to fix a problem first, so please come to us. If you are not satisfied with our answer, you can complain to the Saudi Data & AI Authority (SDAIA), the supervisory authority for the PDPL, through its official channels.
This notice is governed by the laws of the Kingdom of Saudi Arabia, and any dispute about it will be dealt with by the competent courts of Riyadh unless the law requires otherwise.
*Sanam — Commercial Registration 7054775262 · Kingdom of Saudi Arabia*