Privacy Notice for Gathern Customers
Last Data Update:
The last update to the Privacy Notice data was made on July 20, 2025.
Table of Contents
- What is the purpose of this Privacy Notice?
- What personal data do we collect about you?
- How do we collect your personal data?
- Why and how do we use your personal data?
- How do we use cookies?
- What are the legal bases for processing your personal data?
- With whom do we share your personal data?
- Where is your data stored and how long do we keep it?
- What are your rights regarding the processing of your personal data?
- How can you exercise your rights?
- What if you have questions or want more information?
- How to file a complaint or objection
- Changes to this Privacy Notice
1. What is the purpose of this Privacy Notice?
- This Notice explains how personal data is collected, used, stored, disclosed, and protected regarding customers and platform users, through our electronic platform, smart device applications, and all other related interactions.
- This includes data related to customers (guests), hosts, employees, suppliers, job applicants, app users, and social media users.
- This Notice aims to fulfill your right to know, pursuant to Article (4)(1) of the Personal Data Protection Law (PDPL) in the Kingdom of Saudi Arabia, and Article 4 of the Executive Regulations.
- This Notice complies with the Personal Data Protection Law in the Kingdom of Saudi Arabia and the Executive Regulations issued thereunder, privacy policy guidelines, and official directives issued by the Saudi Data and Artificial Intelligence Authority (SDAIA).
- We maintain an internal record of personal data processing activities (RoPA) that documents all processing operations conducted on personal data, and this record is made available to the Saudi Data and Artificial Intelligence Authority (SDAIA) upon request.

2. What personal data do we collect about you?
We collect only the personal data necessary for the purposes outlined in this Notice, and we are committed to applying the principles of data minimization and purpose limitation.
A. From Customers (Guests)
- Personal Information: Name, email address, phone number, date of birth, nationality, passport number or residence ID (Iqama), and address.
- Booking and Transaction Data: Booking dates, order details, cancellations, refunds, and compensation claims.
- Payment and Financial Data: Credit card information, bank account details, billing records, and installment payment service details.
- Location Data: Location shared during the booking process or used for app operation purposes.
- Marketing and Retargeting Data: App usage data, browsing history, and customer segmentation data.
- Online Interaction and Device Data: Browsing history, preferences, Internet Protocol (IP) addresses, cookies, activity logs, device type, operating system, and session data.
- Customer Service Interaction Records: Records of communications with customer service, including call recordings, chat logs, and emails.
B. From Hosts
- Personal Information: Name, email address, phone number, date of birth, nationality, passport number or residence ID (Iqama), and address.
- Property Listing Information: Host registration permit license, property address, description, and photos.
- Payment and Financial Data: Bank account details, transaction data, and payment records.
C. App Users (Individuals who use the Gathern app on mobile phones or web)
- Device and Session Data: Device identifiers, Internet Protocol (IP) addresses, browser and operating system details, session timestamps, and crash logs.
- Location Data: Location shared during the booking process or used for app operation purposes.
E. Job Applicants
- Data: Resume, work history, educational qualifications, certificates, and training records.
3. How do we collect your personal data?
We collect your personal data using a variety of methods that ensure accuracy, transparency, and compliance with the Personal Data Protection Law (PDPL).
First: Direct Collection
- Electronic Forms and Account Registration: When creating or updating your account as a guest or host.
- Property Listings: When listing a property as a host, including providing permit or license details.
- Bookings and Transactions: When making bookings or executing transactions.
- Customer Service Interaction: When you contact customer support via phone, email, or chat.
- Feedback and Surveys: When providing reviews or sending feedback.
Second: Automated Collection
- Website and App Tracking Tools: To track user behavior, clicks, page visits, and session data.
- Cookies: To enhance functionality, track preferences, and personalize your experience.
- Device Information and Technical Data: Such as Internet Protocol (IP) addresses, device type, and operating system.
- Location Data: When enabled, to improve search functionality.
Third: External Sources
- Payment Service Providers: To process transactions securely and prevent fraud.
- Government Agencies and Regulatory Bodies: To verify identity documents, such as Iqama or national ID, through official verification systems.
- Marketing and Advertising Partners: To conduct targeted promotional campaigns.
4. Why and how do we use your personal data?
| Purpose of Data Use | How It's Used |
| :--- | :--- |
| To enable platform operations and manage bookings | Facilitate property searches, manage bookings, and verify host listings and property permits. |
| To facilitate payment and disbursement processes | Process financial transactions, manage guest payments, issue refunds, and disburse payments to hosts. |
| For marketing and promotional purposes | Send customized offers, execute targeted advertising campaigns, and communicate via email and text messages. |
| To provide support to customers and hosts | Assist users with inquiries and complaints, refund requests, and dispute resolution. |
| For business development and analytics | Analyze platform usage, booking trends, and customer behaviors to improve features and services. |
| For regulatory compliance and legal obligations | Comply with legal requirements, execute government agency requests, and verify identities through official systems. |
| For security and fraud prevention purposes | Monitor fraudulent activities, prevent unauthorized access, and implement cybersecurity measures. |
| To enhance user experience | Customize user preferences, improve property search results, and recommend listings. |

5. How do we use cookies?
- Our website and mobile application use cookies and similar technologies (such as SDKs) to improve your experience, ensure platform functionality, and develop our services.
- These technologies help analyze website traffic, remember your preferences, and enable targeted advertising.
- For a detailed explanation of the types of cookies, the data they collect, and how to manage your preferences, please refer to our Cookie Notice.
6. What are the legal bases for processing your personal data?
We rely on the following legal bases for processing your personal data:
Consent
- We rely on your consent to process your personal data, especially for direct marketing and promotional campaigns.
- You can withdraw your consent at any time, and consent is obtained through clear positive actions (such as checking a consent box).
- You can contact us at the email address
[email protected] to withdraw your consent.
Contractual Obligation
It is necessary to enter into our contract with you in order to:
- Create and manage host and customer accounts on the Gathern platform.
- Facilitate communication between customers and hosts, and support platform functions such as bookings and payments.
- Collect payments and process refunds and payment disbursements to hosts.
Legal Obligation
Processing is necessary to comply with any applicable law or regulation, including:
- Sharing national ID or residence details with legal authorities upon request and responding to official complaints.
- Ensuring tax compliance by issuing instant invoices through government electronic billing platforms.
- Verifying host property details to meet Ministry of Tourism requirements and other regulations.
Legitimate Interests
We process your personal data based on our legitimate interests, which do not override your rights or interests, and include:
- Managing property listings, bookings, and profiles to provide a seamless platform experience.
- Monitoring service interactions and collecting feedback to improve support quality.
- Preventing fraud and misconduct by monitoring activity and restricting suspicious accounts.
- Developing, testing, and improving system features to ensure reliability and performance.
7. With whom do we share your personal data?
We share personal data only when necessary to provide our services and comply with legal obligations.
| Recipient Category | Purpose of Sharing | Disclosure Frequency |
| :--- | :--- | :--- |
| Hosts | To facilitate bookings by sharing booking details and communication between customers and hosts. | Regular |
| Service Providers and Business Partners | To support operations through external vendors for payment processing, IT infrastructure, and marketing. | Regular |
| Government Agencies and Regulatory Bodies | To comply with legal obligations, conduct identity verification, and support dispute resolution. | As required |
| Payment Processors and Financial Institutions | To process payments, refunds, and payment disbursements to hosts. | Regular |
Cross-Border Data Transfer
- We may transfer personal data outside the Kingdom of Saudi Arabia in some cases, and this complies with the Personal Data Protection Law and its regulations.
- We apply appropriate safeguards to ensure your personal data remains protected, including transfer impact assessments and standard contractual clauses issued by the Saudi Data and Artificial Intelligence Authority.
- In cases where approved safeguards are not available, transfers may be made based on your explicit consent or if the transfer is necessary for entering into or performing a contract with you.
8. Where is your data stored and how long do we keep it?
Where do we store your data?
- We store your personal data securely using cloud service providers such as Amazon Web Services and Google Cloud.
- Some of these cloud servers are located outside the Kingdom of Saudi Arabia, in regions such as Europe and the United States of America.
- We ensure that any external storage provider we work with meets strict confidentiality standards, access controls, and data protection standards.
How long do we keep it?
We retain your personal data only for the period necessary to achieve the purposes for which it was collected, including for purposes of meeting any legal, regulatory, or accounting requirements.
- Operational necessity: We retain your data as long as it is necessary to provide services to you and manage our business operations efficiently.
- After the retention period ends: Personal data is securely deleted or converted to anonymized data, ensuring it cannot be linked back to you.
9. What are your rights regarding the processing of your personal data?
As a data subject, you have the following rights under the Personal Data Protection Law:
- Right to notification: Being informed about how your personal data is collected and the legal basis for its collection.
- Right to access your personal data: Access to your personal data that we hold through the means we provide that allow automatic access.
- Right to request access to your personal data: You can request a copy of your data in a clear and easy-to-read format.
- Right to correct personal data: You have the right to request correction or updating of your personal data if you find it to be inaccurate or outdated.
- Right to request erasure of personal data: You can request the erasure of your personal data when it is no longer needed for the purposes for which it was collected.
- Right to withdraw consent: You can withdraw your consent to the processing of your data at any time, unless there is a legal basis that requires otherwise.
- Right to file a complaint: You have the right to file a complaint with the competent authority (SDAIA) within a period not exceeding (90) days from the date of the incident.
- Right to claim compensation: You have the right to claim compensation from the competent court for any material or moral damage resulting from a violation of the Personal Data Protection Law.

10. How can you exercise your rights?
- To exercise any of these rights, please contact us via email at
[email protected].
- You will not be asked to pay any fees for exercising your rights.
- If you submit a request to exercise your rights, you will receive a response within 30 days from the date of receiving your request.
11. What if you have questions or want more information?
You can contact our Data Protection Officer (DPO):
12. How to file a complaint or objection
If you are not satisfied with how your complaint was handled, or if we are unable to respond within 30 days, you can file a complaint with the competent authority, which is the Saudi Data and Artificial Intelligence Authority (SDAIA).
13. Changes to this Privacy Notice
We reserve the right to update or modify this Privacy Notice at any time to reflect changes in our data processing practices, changes in law, or modifications to our business operations.