Everything the channel sends you about your guest expires

Seven days for the address, twelve months for the card. The standard written for AI agents carries contact details with no expiry at all — just not to you.

Aug 22, 2026

by Markus Busch

Open tomorrow's arrivals and pick one. The couple in the junior suite, four nights, booked eleven weeks ago. There is an email address on the reservation, something like booking1234@guest.booking.com, and it works: write to it and she gets the message.

So far, so good. Now look at the clock running on it.

Seven days, and the address stops

Booking.com publishes the rule on its own partner help page: "You can send messages from the time of booking until seven days after checkout or cancellation." If she writes to you first, "there is a 14-day window to reply." And the thread itself is not yours to keep: "after one year after checkout or cancellation period, you cannot read any of the messages."

The address is real, and it is a loan. It belongs to Booking.com, it points at a guest whose own address you will never see, and a week after she drives away it closes. "We don't share private email addresses," the same page says. "You and your guests will only see an anonymous alias."

Booking.com is direct about the intent: "we cannot share any personal information with either party, and the communication should stay on the platforms."

Read that sentence as a commercial lead rather than a privacy officer. The relationship is on loan for the length of the stay plus a week. Everything you would want to do with it afterward happens after the address has closed. The anniversary of her visit. The shoulder-season offer. The note next March, when the same four nights come up again.

Expedia runs the same clock, at a different speed

Expedia gives you an alias too, on its own domain, ending @m.expediapartnercentral.com. The thread behind it stays visible in Partner Central "for 45 days after check-out." The phone number can arrive masked as +1 ********, a step Expedia describes as reducing "off-platform phishing attempts."

Expedia does not publish this where a hotelier can read it. Both numbers come from booking systems wired to it.

Forty-five days instead of seven, and the same shape underneath: a stand-in for a person, on a timer, on someone else's system.

The phishing worry behind the masked number is a real one, and hotels have been used as a way into travelers' inboxes by people who had no business there. Whatever the reason, what it does to your guest list is the same.

The card expires too, and it was never hers

The pattern repeats on the money. Booking.com describes its virtual cards as "temporary, digital Mastercards that we use to facilitate payments from your guests on our platform." She pays Booking.com. Booking.com issues a card. You charge that card, any time within twelve months of check-out.

So the folio settles against a card created for the transaction and dead after a year. The person who slept in the room is nowhere in it. Two temporary stand-ins, one for the guest and one for her money, arriving together on every reservation.

What they will hand over

The reason given is privacy, and the rules that come with it. Booking.com's own wording: "to protect your and your guests' privacy, we don't share private email addresses."

So open a pay-at-property reservation in the extranet and look at what the same company does hand you: the guest's own credit card number, on a help page that is matter-of-fact about it. "To charge a credit card for reservations, you need to have access to your guest's credit card details." You may look at them "up to three times and for a maximum of 10 days after the guest's check-out or cancellation date," and the security code shows once and never again.

Her card number, yes. Her email address, no. Read those two rules next to each other and see which one sounds like a regulator wrote it.

There is a third clock in there, by the way. Three views, ten days, and the card is gone too.

Count it yourself on Monday

Skip tomorrow's arrivals. Those still work. Go back two months instead and pick a guest you would genuinely like to have again. The one who took the suite in June, or the family who booked four nights and extended to six.

Now try to reach her.

Whatever share of last summer you can still write to, that is the size of your guest list. The rest checked out, and the address went with them. It is also the limit on every guest-marketing tool you bought this year. Software can only write to the guests you can still write to.

What the AI standard carries

When an AI agent buys something for the person it works for, it hands the seller her name, her email address and her phone number — fields in a standard Stripe, OpenAI and Meta published in April, version dated April 17, 2026, which calls her the buyer. Her own address rather than a forwarding one. No window, no timer, no year after which the record goes dark. The standard makes room for those details. Whether they travel is the seller's call.

The machinery the industry has spent a year bracing for arrives holding exactly the details the channels have spent a decade withholding. Whether any of it reaches a hotel comes down to one question: who is selling the room.

In every AI-agent hotel booking that has shipped so far, the answer isn't the hotel. Google's booking test hands the sale to a partner — an OTA, a chain selling direct, a GDS. Booking.com has placed itself inside ChatGPT's checkout, at the moment of payment. The seller gets the buyer's details. You get an alias and a countdown, same as always.

No AI agent sold one of your rooms this month. The wiring is being laid now, and the seller's seat is already taken.

The one clock you control

Which leaves the desk. She is standing in front of you, the stay is beginning, and for ninety seconds nothing is masked and nothing expires. Most properties spend that moment confirming a departure date.

It is the only place in the entire chain where your hotel acquires a guest it can still reach in March.

Read also: Google just put agentic hotel booking into testing · In AI search, the hotel's own website barely counts

Enjoying this analysis? Hospitality.today delivers daily insights on hotel distribution, AI trends, and travel commerce — straight to your inbox. Subscribe for free at Hospitality.today →

Related must-reads

JOIN 34,000+ HOTELIERS

Get our Daily Brief in your inbox

Consumers are changing the face of hospitality - from online shopping to personalized guest journeys and digitalized guest experiences ...
we've got you covered.

By submitting this form, you agree to receive email communication from Hospitality.today and its partners.