This Mobile Application Privacy Policy and Terms of Service ("Policy") applies exclusively to the
Triumph Hotels Official Mobile Application ("App"), distributed through the Google Play Store
for Android devices and the Apple App Store for iOS devices, operated by Triumph Hotels Egypt
(encompassing Triumph Plaza Hotel, Triumph Luxury Hotel, and White Sands Resort).
Your privacy is an essential hallmark of our five-star hospitality. We are committed to safeguarding all personal
data collected through our mobile application, in strict compliance with the Egyptian Personal Data Protection Law No. 151 of 2020,
the General Data Protection Regulation (GDPR), Google Play Developer Policies, and Apple App Store Review Guidelines.
By downloading, installing, or accessing the Triumph Hotels Mobile App, you acknowledge and agree to the practices outlined in this Policy.
We only collect personal information that is strictly necessary to provide you with seamless guest hospitality, reservation fulfillment, and mobile concierge services.
A. Information You Voluntarily Provide
- Guest Profile & Account Details: Full name, email address, mobile phone number, nationality, date of birth, and language preference.
- Reservation & Stay History: Check-in and check-out dates, number of guests (adults/children), room type booked, room preferences (e.g. non-smoking, high floor), and special dietary or accessibility requests.
- Customer Inquiries & Feedback: Correspondence submitted via in-app concierge messaging, service requests, or reviews.
B. Information Collected Automatically
- Device & Telemetry Data: Mobile device model, operating system version (iOS/Android), unique device identifier, IP address, and network connection status.
- Push Notification Tokens: Firebase Cloud Messaging (FCM) registration tokens used solely to dispatch real-time alerts regarding your reservation, hotel promotions, and service updates.
- App Performance & Crash Logs: Aggregated, anonymized diagnostics and crash reports to ensure high availability, smooth 60fps performance, and immediate bug resolution.
C. Payment Information & PCI-DSS Compliance
We never store raw credit card numbers, CVVs, or bank account credentials on your mobile device or our direct application databases.
All monetary transactions and room booking guarantees are processed via certified, PCI-DSS Level 1 compliant reservation gateways (including SynXis by Sabre Hospitality Solutions).
To deliver core mobile experiences, the App requests specific device permissions. You have full control over these permissions and may enable or revoke them at any time in your device's operating system settings.
| Permission |
Platform |
Purpose & Usage |
| POST_NOTIFICATIONS |
Android 13+ & iOS |
Delivers timely reservation confirmations, room check-in notifications, concierge updates, and exclusive seasonal promotions. (User controllable) |
| INTERNET / ACCESS_NETWORK_STATE |
Android & iOS |
Required to communicate securely with Triumph Hotels servers to load real-time room availability, dining menus, and photo galleries. |
| ACCESS_COARSE/FINE_LOCATION (Optional) |
Android & iOS |
Used exclusively when requested by the guest to provide driving directions to Triumph Plaza Hotel, Triumph Luxury Hotel, or White Sands. Location data is not saved or tracked continuously. |
| CAMERA / PHOTO LIBRARY (Optional) |
Android & iOS |
Requested only if you choose to scan a physical booking voucher, attach a photo to guest feedback, or set an account profile picture. |
| BIOMETRIC / FACE ID (Optional) |
Android & iOS |
Enables fast, secure biometric sign-in. Biometric authentication is handled strictly on-device by Apple Secure Enclave or Android Keystore; biometric data is never transmitted to or seen by our servers. |
We partner with industry-leading technology providers to guarantee reliable service delivery. All third-party providers are vetted for strict privacy compliance and contractual data protection:
- Google Firebase (Google LLC): Used for Firebase Cloud Messaging (push notifications) and Firebase Crashlytics (app crash diagnostics). Google Privacy Policy.
- SynXis / Sabre Hospitality: Central Reservation System (CRS) providing encrypted booking engines and rate distribution. Sabre Privacy Policy.
- Google Maps Platform: Used for map rendering and route guidance to Triumph properties.
No Data Selling: Triumph Hotels does not sell, rent, monetize, or trade your personal information or mobile device identifiers to third-party data brokers or behavioral advertisers.
In adherence to Google Play User Data Policy and Apple App Store Review Guideline 5.1.1(v),
every registered user of the Triumph Hotels Mobile App has the unequivocal right to delete their account and all associated personal data at any time.
How to Delete Your Account & Data:
You can request account and data deletion through either of the following two straightforward methods:
1
In-App Deletion
Open the Triumph App → Navigate to Profile / Account → Tap Privacy & Security → Tap Delete My Account → Confirm your request.
What Happens When You Delete Your Account:
- Immediate Profile Purge: Your name, email, phone number, login credentials, saved preferences, and push notification tokens are immediately severed and removed from our active databases.
- Processing Timeline: Full permanent purge or irreversibly anonymized hashing is completed within 30 calendar days of receiving your verified request.
- Legal & Financial Retention Exception: Records of past completed transactions, invoices, and stay records will be anonymized and preserved solely as required by Egyptian fiscal, tax, and hospitality legal retention mandates.
We employ robust administrative, technical, and physical safeguards designed to preserve the confidentiality, integrity, and availability of your personal data:
- Encryption in Transit: All data transmitted between the Mobile App and our backend APIs is encrypted using industry-standard Transport Layer Security (TLS 1.3 / HTTPS).
- Encryption at Rest: Sensitive database records, authentication credentials, and access tokens are secured using AES-256 encryption.
- Role-Based Access Control: Strict least-privilege access policies ensure only authorized hospitality personnel with verified duty requirements can access guest profiles.
- Continuous Monitoring: Routine automated vulnerability assessments, rate limiting against brute-force attacks, and firewall monitoring.
Depending on your jurisdiction (including the European Economic Area under GDPR and Egypt under Data Protection Law 151/2020), you are entitled to exercise the following rights free of charge:
- Right to Access: Request a copy of the personal information Triumph Hotels holds concerning you.
- Right to Rectification: Request correction of inaccurate, incomplete, or outdated information in your profile.
- Right to Erasure ("Right to Be Forgotten"): Request full deletion of your account and personal records as detailed in Section 05.
- Right to Restriction & Objection: Object to processing of your personal information for direct marketing or promotional notifications.
- Right to Data Portability: Obtain your personal reservation data in a structured, commonly used, and machine-readable format.
To exercise any of these rights, please contact our Data Governance team at privacy@triumphhotel.com. We respond to all verified requests within 30 days.
A. App License & Intellectual Property
Triumph Hotels grants you a limited, non-exclusive, non-transferable, revocable license to download, install, and use the Mobile App for your personal, non-commercial hospitality planning. All trademarks, photography, broadsheet journal layouts, typography, logos, and software code are the intellectual property of Triumph Hotels and protected under copyright laws.
B. In-App Reservations & Rate Policies
All reservations made through the App are confirmed subject to hotel availability, rate rules, and deposit terms stated at the time of booking. Cancellation and modification policies depend on the specific room rate selected (e.g. flexible vs non-refundable).
C. Acceptable Use
You agree not to misuse the App, attempt unauthorized API access, reverse-engineer the application binaries, inject malicious payloads, or make fraudulent reservations. Any abuse will result in immediate termination of account access and appropriate legal remedies.
If you have questions, inquiries, complaints, or account deletion requests regarding this Policy or our mobile data handling practices, please contact our dedicated Data Protection team: