Effective date: 20 September 2026
1. Who is responsible and how to contact us
Ewa Alarab For Travel is responsible for personal data processed by Kease. This policy covers our website, mobile applications, booking and support services, and our ChatGPT integration. The ChatGPT app is listed through the GAIT publisher account; privacy requests concerning Kease services should be addressed to Ewa Alarab For Travel.
Email info@kease.io for privacy requests, access, correction, deletion or withdrawal of authorization. You can also contact us at +966920033775 or Anas Ibn Malik Rd, Al Malqa, Riyadh 13522, Kingdom of Saudi Arabia.
2. Information we collect and why
- Account and contact information: name, phone number, email, account identifiers, authentication records and notification device identifiers, to provide account access, associate guests with bookings and send service notifications.
- Accommodation and booking information: selected city or district, property, stay dates and duration, guest count, preferences, payment plan, discounts, quoted and confirmed prices, booking status and cancellation reasons. We use this information to search, quote, fulfil, change and cancel stays. A destination selected for accommodation is not a request for your device's precise location.
- Payment and accounting information: transaction references, payment status, amounts, installments, invoices and payment links, to collect payments, reconcile accounts, handle refunds and meet accounting obligations. Payment entry takes place in the applicable payment flow. ChatGPT tools do not request card numbers, passwords or government identity documents as tool inputs.
- Communications: enquiries and messages sent to our support, email or WhatsApp channels, and service messages, to answer requests and manage bookings. These are separate from the ChatGPT tool exchange described below.
- Technical and usage information: IP addresses in server logs, browser/device information, cookies and analytics events, pages visited and interaction/session information, to run and protect the service, troubleshoot and understand website use. Booking operations also record available client platform and version information. Retry records help prevent duplicate bookings.
Information comes from you, your connected Kease account, your browser or device, and the booking, payment and communications services involved in fulfilling your request. Required booking fields are needed to provide that service; omitting optional fields may limit the corresponding feature.
We process data for the requested service and contractual relationship, applicable legal obligations, and other lawful grounds permitted by applicable data protection law. Where processing depends on consent, you may withdraw that consent. Withdrawal does not undo processing already carried out or remove a separate legal obligation to retain records.
3. ChatGPT: tool inputs, outputs and related processing
When you use Kease tools in ChatGPT, ChatGPT sends the tool arguments needed for your request to Kease, and Kease returns the result to ChatGPT. This interface does not request your entire conversation history as a tool argument. The table describes the 11 tools on this endpoint, rather than the separate website, mobile or WhatsApp interfaces. Search and quote tools use your selections to find accommodation, check availability and calculate prices. Account tools use your connected Kease account to find, create or cancel your own bookings.
| Tool | Information sent to Kease | Information returned to ChatGPT |
|---|---|---|
get_areas |
No tool arguments. | Area and city IDs, area names and rental counts. |
get_amenities |
No tool arguments. | Amenity IDs and names. |
list_rentals |
Stay type; optional stay dates or monthly duration, city/district selection, guest count, amenities, price range and pagination. | Matching rental IDs/codes, names, districts, guest capacity, stay type, indicative SAR prices and pagination. |
get_rental_details |
Rental ID or code. | Public description, district, capacity, amenities, indicative daily/monthly/yearly prices, monthly availability and stay limits. |
check_availability |
Rental ID/code, stay type and start date; checkout date for daily stays, duration for monthly stays, payment plan for yearly stays, and optional guest count. | Rental and stay identifiers/dates, availability, explanatory message, applicable minimum stay and possible alternative dates. |
get_booking_summary |
The availability inputs, plus optional promo code and pet preference. | Stay dates/type, rental ID, duration/payment plan, price breakdown, fees, VAT, discounts, voucher details, total in SAR, and applicable monthly breakdown and confirmation terms. |
validate_promo_code |
Quote inputs with the promo code required. | Whether the code applies, voucher details, discount and quoted total. |
create_booking |
Quote inputs; guest name and phone, optional email, guest count as required for daily stays, confirmed SAR total and a request retry key. Requires a connected Kease account. | The booking information described below; or a refreshed quote requiring confirmation if the price has changed. |
get_my_bookings |
Optional booking status and pagination. Requires a connected Kease account. | Your booking information, described below, and pagination. |
get_booking_details |
Your booking ID or number. Requires a connected Kease account. | Your booking information, described below. |
cancel_booking |
Your booking ID or number and a cancellation reason ID. Requires a connected Kease account. | Updated booking information, described below. |
Booking information returned to ChatGPT includes booking ID/number, rental ID/code/name, booking status, stay dates and type, guest count, monthly duration, total/currency, payment plan and payment URL, cancellation eligibility, cancellation policy label/refund preview and payment caveat, payment status, and installment numbers, due dates, amounts and paid status. These curated tool responses do not include guest contact fields, door access codes or Wi-Fi credentials. A cancellation preview is not a guarantee of a refund; processing depends on payment status and provider, and some partial refunds require manual processing.
Kease uses guest contact information to associate the guest with the account, create the booking and deliver booking services. Existing account name, mobile and email take precedence over submitted guest fields when those account fields are present. Kease records the cancellation reason to process a cancellation. It stores account/client identifiers, a hashed retry key, a request fingerprint and the complete successful booking response, including its payment URL, to recognize retries and avoid duplicate bookings.
Connecting an account uses OAuth authorization. Authorization credentials are handled by the authentication protocol, not requested as tool arguments or included in booking tool results. Booking actions also record available platform and version metadata linked to the account and booking. Operational web-server logs may separately record IP addresses for troubleshooting and service operation. An IP received through this integration may describe an intermediary rather than the guest's own device.
Recipients for ChatGPT booking tools
- OpenAI / ChatGPT: receives the tool results listed above, including booking and payment-link information for account tools, so it can present and act on your request. OpenAI's handling of information within ChatGPT is governed by its own applicable terms and privacy information.
- Tokeet: receives rental identifiers and stay dates when a supplier availability check uses Tokeet, and guest contact and booking information when the corresponding synchronization runs. Guest creation or update can synchronize contact information before the booking transaction completes; this can occur even if the subsequent booking fails.
- Property operators: receive information needed to fulfil and manage the stay.
- Payment providers: Clickpay, Tabby or Tamara may process payment-related information according to the payment method used. Following a payment link can lead to a separate payment flow. These tools do not ask for payment-card details as tool arguments.
- Communication providers: mail delivery services, Firebase and Respond.io may process recipient/contact details, device notification identifiers where relevant, and message content when their configured booking notification channels are used. Their involvement depends on the event, recipient and enabled channel; every tool call does not trigger every service.
4. Website technologies and other recipients
Our website uses essential session and security cookies and loads Google Analytics, Google Tag Manager, Firebase Analytics, Microsoft Clarity and Hotjar. These services can receive browser/device identifiers, IP and usage information, pages visited and interaction events; Clarity and Hotjar can provide session replay and interaction analysis. They are website technologies, distinct from the booking tool results sent to ChatGPT. You can block or clear cookies and restrict tracking through your browser settings; blocking essential storage may affect sign-in and booking. Removing cookies does not itself delete information already held by a provider.
In addition to the recipients described for ChatGPT, hosting, database and backup providers process stored service data; authorized support and property operations personnel process information needed for their work; and accounting providers such as Xero may receive transaction and invoice information when the accounting integration is used. Relevant records may be disclosed to authorities or professional advisers where required by law or necessary to handle legal claims. Each provider's involvement depends on the service used; not every provider receives every request.
The production application server is hosted in Bangalore, India. Information can therefore be processed outside Saudi Arabia, and connected providers may process information in other countries. This policy does not represent that all processing takes place in Saudi Arabia. Contact info@kease.io for information about destinations and arrangements relevant to your data. Transfers remain subject to applicable data protection requirements.
5. How long we retain data
The following schedule applies from this policy's effective date. Where cleanup is manual, the period is our retention rule, not a claim that an automatic deletion job exists. We review eligible records for deletion or irreversible anonymization; a documented legal retention requirement or unresolved claim can require longer retention. We retain only the information needed for that exception and explain it when responding to a deletion request.
| Category | Retention period or criterion |
|---|---|
| Account profile and guest contact information | While the account is used or needed to provide an active service. On a verified closure/deletion request, unnecessary profile data is reviewed for deletion within the request-handling period below; information needed for bookings, accounting or claims follows the corresponding rule. Closing an account is not immediate erasure of every linked record. |
| Bookings, invoices, payments and related guest information necessary to document the transaction | 6 years after the end of the calendar year in which the booking is completed or cancelled and the related transaction is settled, whichever is later. A longer applicable statutory period or unresolved dispute takes precedence. |
| Booking retry records and booking-linked request metadata | Kept with the related booking under the 6-year rule above, to identify duplicate requests and evidence booking operations. Retry records include a hashed key, request fingerprint, account/client linkage and the successful response, including its payment URL. These records currently require manual cleanup; they do not have a separate automatic expiry. |
| Operational database logs | Configured cleanup thresholds are 14 days for activity logs; 30 days for specified API, integration and webhook logs; 60 days for email/SMS logs; and 90 days for payment-webhook, booking, lock and outbound-call logs. These rules apply to those log categories, not to the underlying business records. |
| Server and application log files | Web-server logs rotate daily with 14 retained archives. Application logs rotate weekly with 2 retained archives and a size threshold. These are rotation settings, not an exact maximum age for each entry; active files and retained incident evidence can last longer. |
| WhatsApp support conversations | Closed or resolved conversations become eligible for the monthly cleanup after 12 months. Information needed for an ongoing request, transaction or claim follows the relevant retention rule. |
| Other support and privacy requests | For the duration of the request and up to 12 months after resolution for follow-up and evidence of handling; necessary transaction or dispute evidence follows the applicable longer rule. Cleanup is manual. |
| OAuth authorization and authentication records | While needed to maintain or secure the connection. Access tokens have a 1-hour lifetime; expiry is not deletion of all authorization records. On a verified withdrawal request we revoke the relevant access and review unneeded authorization records for deletion, subject to security or legal evidence requirements. |
| Production database backups | Daily backups are configured with a 5-day retention period. Backup expiry follows the backup process; this does not mean that a deletion request instantly removes every backup copy. Deleted data must not be returned to active use if a backup is restored. |
| Cookies and third-party website analytics | Browser cookies remain until their configured expiry or your removal. Analytics/session data retained by the named providers follows their applicable service settings and notices. You can request review and deletion of identifiable information through our privacy contact; technical controls in your browser do not erase provider-held copies. |
Payment, booking, communications and analytics providers can have separate retention obligations for their own services. A request to Kease does not itself erase OpenAI's ChatGPT conversation history or every independent provider record. We review relevant onward recipients when handling your request.
6. Your controls and privacy requests
You may request information about processing, access and a copy of your data, correction, deletion where applicable, or withdrawal of consent or integration authorization by emailing info@kease.io. Please identify the account or booking concerned without sending passwords or payment-card details. We may request proportionate identity verification to protect your information.
We act on privacy requests within 30 days, subject to applicable law. Where a permitted extension is needed, we explain the reason before the initial period ends; an extension is no more than an additional 30 days. Where information must be retained, we explain the relevant reason and applicable limits on deletion.
You can disconnect Kease in ChatGPT to stop using the connection, and you can ask us to revoke its authorization. Disconnecting, requesting account closure and requesting erasure are distinct actions. Existing bookings, financial obligations and records are not automatically cancelled or erased by disconnection. The current account closure process does not itself erase all linked records or guarantee that every authorization has been revoked; use the privacy contact for a coordinated erasure or access-revocation request.
You can object to marketing or withdraw any marketing consent through info@kease.io and any unsubscribe control provided in the message. Essential booking and account service messages may still be necessary. For an unresolved privacy complaint, you may contact the competent Saudi data protection authority, SDAIA, through its official channels.
7. Protection, external services and updates
We use access controls and technical measures to protect service data. No system can guarantee absolute security. Authorized staff and service providers should access information only for their relevant responsibilities.
Kease's booking services are intended for adults. If you believe a child's personal data has been provided improperly, contact us so we can review it. Links to payment providers, ChatGPT and other services are subject to those services' own privacy notices for their processing.
We publish changes to this policy on this page with an updated effective date. Contact info@kease.io if you need clarification about a change or about how this policy applies to your booking.