Legal
Privacy policy
This page explains how we handle your data when you browse the website or complete a booking.
Last updated: May 18, 2026
1) Who we are
Trampo Kuwait ("we", "us") is a licensed indoor trampoline park in Kuwait operating three venues: Murouj, The Promenade, and Messilah Beach. We are the controller of the data collected through this website.
2) Data we collect
- Account data: name, email, phone number, and an encrypted password (managed by Google Firebase Authentication).
- Booking data: venue, date, time, ticket selections, booking references, and order history.
- Payment data: processed by Ottu and our payment gateway (Gulf Bank / KNET). We do not store full card details on our servers.
- Contact data: messages sent through our contact forms, WhatsApp, or email.
- Technical data: IP address, device/browser type, pages visited, and advertising identifiers (fbclid, gclid, ttclid, etc.) when you reach us through an ad.
3) How we use data
- To process bookings, confirm orders, and send booking confirmations and receipts.
- To provide support, reschedule bookings, and respond to customer requests.
- To send abandoned-checkout reminders: if you start a booking and enter your email on the checkout page but don't complete payment, we may send up to two follow-up emails (the first about 45 minutes later, a second after 24 hours) with a link to resume your order. Every reminder includes an unsubscribe link. This data is auto-deleted after 30 days.
- To send marketing and promotional emails about offers, events, and news from Trampo Kuwait to account holders who accepted our Terms. Every marketing email includes an unsubscribe link in the footer and a one-click unsubscribe button in Gmail. You can also turn off marketing emails at any time from your account settings. Opting out of marketing does not affect booking confirmations or receipts.
- To measure website performance and understand visitor behavior so we can improve the experience.
- To measure ad performance on social platforms and optimize our campaign targeting (Meta, TikTok, and Google Ads).
- For safety, fraud detection, and compliance with legal and accounting obligations.
4) Service providers we use
We share specific data with trusted service providers, only as needed to run the service:
- Ottu — payment processing (KNET, Visa, Mastercard) and checkout technology.
- BMI Leisure — booking and ticketing back-end at our venues.
- Google Firebase (Google Ireland Ltd. / Google LLC) — website hosting, authentication, database (Firestore), and order storage.
- Resend — sending booking confirmation, transactional, recovery, and marketing emails. We maintain an internal suppression list for anyone who has unsubscribed, and email addresses of opted-in subscribers are synced to a Resend Audience for marketing campaigns. Recipients who mark our emails as spam or whose addresses bounce are automatically added to the suppression list.
- Sanity — hosting blog and offers content. No customer data is shared with Sanity.
- Meta Platforms (Facebook, Instagram) — ad measurement and conversions tracking via Meta Pixel and the Conversions API. Certain identifiers (e.g., email, phone) are hashed using SHA-256 (one-way, irreversible) before they leave our servers.
- TikTok — ad measurement and conversions tracking via TikTok Pixel and the Events API. Personal identifiers are hashed with SHA-256 the same way.
- Google Analytics 4 & Google Tag Manager — measuring site usage and improving performance.
Some of your data may be processed outside Kuwait (United States, European Union, Singapore) by the providers listed above. We work with providers that follow applicable data-protection standards.
5) Advertising and marketing
We use Meta, TikTok, and Google to measure ad performance and reach relevant audiences. When you complete a key action on the website (such as Add to Cart or Purchase), we send a measurement signal to those platforms containing securely hashed (SHA-256) identifiers. This helps with:
- Attributing bookings to ads you may have seen or clicked.
- Optimizing ad delivery to similar audiences.
- Evaluating return on ad spend (ROAS).
If you subscribe to our newsletter, you can unsubscribe at any time using the unsubscribe link or by contacting us.
6) Cookies and similar technologies
We use essential cookies to run the website (sign-in, cart, payment session) plus analytics and advertising cookies. Specific types and examples are listed in our Cookie Policy.
Cookie policy7) Data retention
- Account data: retained while your account is active, and for no more than 24 months after your last sign-in.
- Booking and payment records: kept for at least 7 years to comply with Kuwait accounting and tax requirements.
- Analytics and advertising records: retained by the platforms (Meta, TikTok, Google) according to their own policies. On our servers, event logs are kept for a maximum of 90 days.
8) Your rights and contact
You may request access to your data, correction, deletion, or withdrawal of consent at any time. To exercise any of these rights, reach us via our contact page.
To delete your account and associated records, please contact us directly.
We may update this policy from time to time. The latest revision date appears at the top of the page.