Privacy Policy
Effective 2026-10-08 · version 2026-10
This policy explains how Booth-Book (boothbook.me) collects, uses, shares and protects personal data, and the rights you have under the Saudi Personal Data Protection Law (PDPL) and its regulations.
1. Who is responsible for your data
Booth-Book is operated by Booth-Book. We are the controller of the personal data described here.
Privacy questions and requests: E-mail: admin@boothbook.me
2. The personal data we collect
- Account: business name, e-mail address, mobile number (optional), role (organizer or vendor) and a password, which only the authentication service stores, in protected (hashed) form.
- Business details you choose to add: commercial registration number, VAT number, national address and logo.
- Organizers’ payment details: bank name, account holder name and IBAN, so vendors with a booking can pay by bank transfer.
- Business documents vendors upload (commercial registration, VAT certificate, food establishment licence, municipal licence and similar). Upload business documents only — never identity cards or personal medical documents.
- Bookings: booths, prices, fees, status, notes you write, payment receipts you upload, waitlist entries, reviews and reports.
- Invitations: e-mail addresses an organizer enters to invite vendors to an invite-only event.
- Technical data: IP address, browser and device details and sign-in records, processed to keep accounts secure and to prevent abuse; a sign-in cookie and a language cookie (section 9).
We do not ask for sensitive personal data (such as health, religious or biometric data) and ask you not to upload it.
3. Why we use it, and on what basis
- To provide the service you signed up for — your account, events, floor plans, bookings, receipts and the e-mails about them (performance of our agreement with you).
- To share what is needed to complete a booking between an organizer and a vendor (performance of the agreement).
- To keep the platform secure: sign-in protection, rate limits, moderation of reviews and events, and investigating misuse (our legitimate interest, and legal obligations).
- To meet legal, tax and accounting obligations and requests from competent authorities (legal obligation).
- To understand how the site is used through cookie-less, aggregated visit statistics (our legitimate interest).
- Where we rely on your consent — for example showing your logo on a booked booth — you can withdraw it at any time in your account.
We do not sell personal data, do not use it for advertising, do not send marketing messages without your consent, and do not make decisions about you by automated means alone.
5. Transfers outside the Kingdom
Our database is hosted in Germany and our service providers may process data in other countries, including the United States. We transfer personal data outside the Kingdom only in accordance with the Regulation on Personal Data Transfer outside the Kingdom, using the safeguards it provides — such as the standard contractual clauses issued by the Saudi Data and Artificial Intelligence Authority (SDAIA) — and only to the extent needed to provide the service.
6. How long we keep it
- Account and business details: while your account exists. When you delete your account, they are erased at once.
- Bookings and payment receipts: kept as the financial records of the organizer and the vendor. After an account is deleted, its bookings remain without its personal details.
- Business documents: until you remove them or delete your account.
- Invitations: deleted 90 days after the event ends.
- Sign-ups never confirmed: deleted after 30 days.
- Sign-in records: up to 12 months. Records of administrator actions are kept for accountability.
- Backups: kept for a limited time and then replaced.
7. How we protect it
Data travels encrypted (HTTPS) and is encrypted at rest by our hosting providers. Database access rules let each person see only what they are allowed to; administrators must use two-factor authentication and their actions are logged; documents and receipts are shared only through short-lived links.
If a personal data breach puts you at risk, we notify the Saudi Data and Artificial Intelligence Authority within 72 hours of becoming aware of it and tell affected people without undue delay, as the PDPL requires.
8. Your rights
- To be informed how your data is used — this policy.
- To access your data and receive a copy in a readable format: Account → Your data → Download my data.
- To correct or complete it: Account settings.
- To have it destroyed: Account → Your data → Delete my account.
- To withdraw consent you gave, at any time.
If you cannot use these tools, write to us (E-mail: admin@boothbook.me). We answer within 30 days and may need to confirm your identity first. You can also complain to the Saudi Data and Artificial Intelligence Authority (SDAIA).
10. Children
Booth-Book is a service for businesses and is not intended for anyone under 18.
11. Changes to this policy
When we change this policy we publish the new version here with its date, and tell account holders by e-mail before a material change takes effect.