U-GO Privacy Policy
1. Who this policy covers
This Privacy Policy explains what personal data U-GO collects from guests using the U-GO service, why, how long it is kept, who it is shared with, and what rights a guest has over their own data. It should be read together with our Terms of Service and Guest Conduct Guidelines.
U-GO is operated by UPPERSETUP Technology LTD, a company incorporated under the laws of the UAE, licensed under DIFC License No. CL7070, registered address: Unit No. 208, 209, Level 1, Gate Avenue – South Zone, DIFC, Dubai, UAE. For any data-protection question, contact support@u-go.ae.
2. What data we collect, and why
| Category | Examples | Why we collect it |
|---|---|---|
| Account/identity | Email address | The sole account identifier; used for one-time-code login (no password) |
| Profile | Display name, avatar, bio | Powers your visible profile within a hotel community you've connected to |
| Business-profile (optional) | Business title, company, skills | Powers the optional business-networking use case; you choose whether to fill these in |
| Hotel membership | Which hotels you've QR-verified or radius-accessed, verification/re-verification timestamps | Enforces the 10-day re-verification rule and per-hotel access/ban logic |
| Event & chat content | Events you create or join, group-chat messages, direct messages | Core product function; retained so a hotel's moderator can review full context if a report is filed |
| Conduct ratings | Ratings you give or receive, tied to a specific event | Powers the guest conduct-rating feature |
| Reports & moderation | Report contents, moderator resolution notes, ban records | Trust & safety enforcement and an audit trail of moderation decisions |
| Payment | Subscription status and billing metadata, handled by Stripe | Billing for paid tiers — U-GO does not receive or store your card number; Stripe holds that directly |
| Referral/points | Referral code used or shared, points balance and history, attribution data | Powers the referral/points growth program |
| Derived/aggregate engagement signals | A hotel-level "this week" activity count and activity-type breakdown; a computed Vibe/Activity Score | Computed from your event/chat/join activity at a hotel, shown on that hotel's public discovery page as an activity/freshness signal — never displayed with your name or any other guest-identifying detail, and never as an individual event's title, time, or location |
| Device/technical | Basic technical and request logs (e.g., IP address, user agent, timestamps) | Service operation, security, and abuse prevention |
3. Lawful basis for processing
- Contract necessity — account/identity data, hotel-membership/QR-verification data, event and chat content, and payment metadata are processed because they are necessary to provide the service you sign up for.
- Legitimate interest — moderation data (reports, autofilter flags, ban records) and conduct-rating data are processed for U-GO's and participating hotels' trust-and-safety purpose: keeping shared communities usable and safe.
- Legitimate interest — aggregate engagement signals. Deriving a hotel-level activity summary and Vibe/Activity Score from your event/chat/join activity, to power a hotel's public discovery page, is based on our and participating hotels' interest in an accurate discovery/freshness signal, balanced against your interest in your own individual activity not being singled out — which is why this data is only ever shown as a hotel-level aggregate, never tied to your name or account.
- Consent — business-profile fields (title, company, skills) are optional and not required to use the core service; filling them in is your consent to that specific processing (making that information visible to Premium-gated viewers, see §6). You can remove these fields at any time in account settings, which withdraws that consent going forward.
4. How long we keep your data
We keep personal data only as long as needed for the purposes in §2.
- Account/profile data: kept for as long as your account is active. You can permanently delete your account at any time — it is a real, irreversible deletion, not a reversible "deactivation." Deleting your account removes your profile and business-profile fields, your hotel-membership/QR-verification history, the chat and direct messages you authored, your event participation, the conduct ratings you gave or received, the guest-to-guest blocks you made, and your referral/points ledger history, along with reports/moderation records tied specifically to your account. Because the aggregate engagement signals described in §2/§5.5 are never stored per-guest, deleting your account simply stops your activity from contributing to that hotel's aggregate going forward.
- Chat and direct-message content: retained for as long as your account exists, because moderation review of a report requires full context; deleted along with everything else when you permanently delete your account.
- Reports and moderation records: retained for as long as the relevant account exists, for audit-trail purposes; deleted on account deletion.
- Conduct-rating data: retained while the relevant accounts remain active.
- Hotel-verification supporting documents (uploaded by hotels, not guests): retained for as long as the hotel's account is active, and handled with restricted access.
- Device/technical logs: retained for a limited operational window for security and abuse-prevention purposes.
5. Who we share your data with
We do not sell your personal data. We share it in the following ways:
5.1 With hotels you're connected to. A hotel you've QR-verified with can see the profile, event, and chat activity relevant to its own community. If you or another guest files a report, the relevant hotel's own staff moderator may see the full chat transcript of the event in question, not only the flagged message.
5.2 With other guests. Your profile (and, only for a viewer with an active Premium/paid tier, your optional business-profile fields) is visible to other guests within a hotel community you share. Your conduct-rating aggregate becomes visible to other guests once you've received a minimum threshold of ratings.
5.3 With our service providers. We use third-party service providers to operate the service, covering: payment processing, transactional email delivery, object storage for uploaded images, application hosting, and web analytics. Each provider only accesses the data necessary to perform its function (for example, our payment processor sees billing metadata but never your raw card number).
5.4 For legal reasons. We may disclose data if required by applicable law, a valid legal process, or to protect the rights, property, or safety of U-GO, our users, or the public.
5.5 With the public, via a hotel's own discovery page. A hotel's public page, and its card on the public directory, both reachable by anyone with no U-GO account, may show:
- content the hotel itself writes and controls (description, photo gallery, amenity tags, outbound booking links) and the hotel's own hotel-official events, individually, with real title/time — none of this is your data, it's the hotel's own content;
- a "this week at [hotel]" aggregate activity count and activity-type breakdown, and a computed Vibe/Activity Score, both derived from real guest event/chat/join activity at that hotel.
Neither of the two aggregate items ever shows your name, account, or any other identifying detail, and neither is ever built from an individual guest-created event's title, time, location, or participant list — only counts and category breakdowns across all guests at that hotel. A hotel independently controls whether this page is published at all and whether the Vibe/Activity Score specifically is shown.
6. Business-profile visibility (Premium gating)
If you choose to fill in optional business-profile fields, they are shown to other guests only if the viewing guest has an active Premium/paid subscription tier — enforced as a fail-closed default, so if that check cannot be completed for any reason, the fields are treated as hidden. Guests without an active Premium tier, and anyone browsing the public hotel directory or a hotel's public page, never see these fields.
7. International data transfers
Because U-GO's guests are hotel guests, some of your data may be processed by service providers located outside your home country. We take steps to ensure any such transfer is subject to an appropriate safeguard consistent with applicable data-protection law.
8. Your rights
Depending on applicable law, you may have rights to:
- access a copy of the personal data we hold about you;
- correct inaccurate data (many profile fields can be edited directly in the app);
- request deletion of your account and associated personal data — a real, self-service, in-app action in account settings. See §4 and our Terms of Service for exactly what that deletion removes (it is permanent, irreversible, and removes everything, including your referral/points ledger);
- object to or restrict certain processing described in §3;
- withdraw consent for consent-based processing (for example, by removing your optional business-profile fields).
To exercise the deletion right, use the in-app account-deletion action directly. For any other right listed above, contact us using the channel in §10.
9. Security
We use the following measures to protect your data:
- Account access is authenticated via short-lived tokens, not a stored password (login itself is by one-time email code).
- All traffic between the app and our servers is encrypted in transit (HTTPS).
- We do not receive or store your payment card number — our payment processor handles that directly, and we only hold processor-issued references.
No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to or stored by the service. We maintain an internal incident-response process for handling a suspected data-security incident.
10. Contact and complaints
U-GO is operated by UPPERSETUP Technology LTD, a company incorporated under the laws of the UAE, licensed under DIFC License No. CL7070, registered address: Unit No. 208, 209, Level 1, Gate Avenue – South Zone, DIFC, Dubai, UAE. For any privacy/data-protection question or complaint, contact support@u-go.ae.
11. Children's data
U-GO's service is intended for adult hotel guests aged 18 and over. We do not knowingly design any part of the product for use by minors.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified in-app. Continued use of the service after an update constitutes acceptance of the revised policy.