AI and data

What the everyday tells you.

A programme that is opened twice a year tells you what was bought. A programme that sits in an app people open on a Tuesday tells you what they like, where they go, who they go with and what they leave unused.

That is the difference we build on. The signals come from ordinary use, they come back to you as data and dashboards, and they are what the personalisation runs on — for the member, and for the campaigns you run.

A lit alley at night
Stools at a café counter
01 · The dashboards

Your programme, live, inside BLACKBOOK.

A portal for your team: who is using the programme this week, in which cities, on which benefits; what is being booked and what is being ignored; the liability sitting against benefits that have been granted but not taken.

It is the same view we run on, not an export sent monthly.

02 · What comes back to you

The signals, as data.

Where the card is used and where it goes quiet. Which benefits are taken up, by whom, and how often. What is booked, in which city, at which times, with how many people. What a campaign moved, and what it did not.

Delivered into the portal, and into your own systems through the API.

03 · How personalisation is driven

The right thing, at the moment it is useful.

The AI reads live intent rather than a segment set last quarter: the city they are in today, the table they book every second Thursday, the benefit that runs out this month, the trip already in the wallet.

The member sees something worth acting on. You see the take-up move.

04 · Where the line is

Consent, held as a record.

Members are anonymous to us until they say otherwise: we hold an encrypted reference, and identity opens only with the member’s permission. Permissions are recorded as timestamped events, so what a member allowed, and when, can be evidenced. Browsing history is not a feed we take.

How identity, tenancy and permission work is set out in full below.

A member checking the phone in the sun
Interactive
What we see
What it says
What surfaces, and when

Signals are consented and event-based. Nothing here comes from browsing history.

  1. MembersWho joined, who is active this week, who has gone quiet, and what moved them.
  2. BenefitsGranted, surfaced, used and expired — with the liability against each.
  3. BookingsHotels, tables, cars, experiences and retail, by city and by week.
  4. CurrencyPoints and miles earned, spent and exchanged, and where they came from.
  5. CampaignsWhat was sent, what was opened, what was booked, and what it cost per booking.
05 · Privacy

Members are anonymous to us until they say otherwise.

Every member on BLACKBOOK is held as an encrypted reference. We see what happens in the app, so the product can work for them; we do not see who they are unless they give us permission to.

Each partner runs in its own tenancy, and sees what its role needs and nothing more. Every permission is recorded, can be seen by the member and can be taken back.

A member with a phone, at ease

Who sees what

WhoWhat they seeWho the member is
The memberEverything held about them, and every permission they have given.Themselves
BLACKBOOKActivity in the app, held against an encrypted reference, so the product can plan, book and personalise.Only with the member’s permission
A bank or airlineHow its own card or programme is used by its own members, in its own tenancy.Its own customer, as it already knows them
A hotelWhat the guest chose to share for the stay: arrival, preferences, who is travelling.At check-in, if the guest reveals it
A club, publisher or merchantSignals and groups of at least forty members, and what happened with its own offers.Never
01

Anonymous by default

A member is an encrypted reference, not a name. Their name, contact details and documents are held encrypted and apart from what they do in the app, and are opened only for a purpose the member has allowed.

02

Identity, one permission at a time

A member reveals who they are to a partner, or to us, one permission at a time: the hotel desk at check-in, the car-hire counter, our own team when they ask for help. Each reveal is scoped to its purpose and ends with it.

03

A tenancy for every partner

Each partner runs in its own tenancy, with its own data, its own keys and, where it needs one, its own region. One partner’s data is never visible to another, and no model is trained across partners.

04

Encrypted, in transit and at rest

Data is encrypted as it moves and where it is stored, with keys held per tenancy. Access is limited to the people and systems that need it, and every access is logged.

05

Permissioned, logged, asked again

Every permission and every consent is recorded as a timestamped event. A member can see what they have agreed to and change it at any time, and we ask again whenever the purpose changes.

06

What we never do

We do not sell member data and we do not buy it. Browsing history is not a feed we take, and a card number never moves through our systems.

07

Signals, where a name is not needed

Where a partner does not need a member’s details, it gets signals instead: an opportunity to offer something, a benefit going unused, a group of members in town. What a member does elsewhere in the app stays with us.

08

Retention with an end date

Data is kept for as long as its purpose lasts and no longer. A partner that leaves takes its data with it, and a member who leaves can have theirs removed.

09

Consent is enforced

A permission is checked every time something is done under it. If it has been withdrawn or has run out, the action does not happen.

07 · The benchmark

GDPR as the standard, wherever a partner operates.

We hold ourselves, and the partners who run on BLACKBOOK, to the GDPR standard in every market, alongside the law where each partner operates: at home, the DIFC Data Protection Law and the UAE’s Personal Data Protection Law.

  • Lawful and consentedA clear basis for every use of data, and consent that is specific, recorded and as easy to withdraw as it was to give.
  • Purpose and minimumData is collected for a stated purpose and no more of it is taken than that purpose needs.
  • The member’s rightsTo see what is held, correct it, move it, object to a use of it, and have it deleted.
  • Roles, written downWho controls and who processes each piece of data is set out in the agreement with every partner.
  • ResidencyData held in the region the partner chooses, in its own tenancy.
  • If something goes wrongIncidents are reported to the partner and, where the law requires it, to the regulator and to the members affected, within the time the law sets.
08 · Behavioural data

Insight from the everyday, on the member’s terms.

Behavioural insight needs everyday use: an app opened twice a year has very little to learn from. BLACKBOOK is used every day, and members share that use when they can see what it does for them, and when they can switch it off or narrow it at any time.

01

Everyday use is the signal

The coffee, the court, the table on Thursday and the trip in October. The pattern comes from an ordinary week.

02

On, off or limited

Location, spending, calendar and preferences are separate permissions. A member can turn any of them off or limit it, and the app keeps working.

03

Useful, or not used

A signal is used to put something helpful in front of the member. If it does not make the app more useful to them, we do not collect it.

09 · Agentic commerce

Our own rails, end to end.

An agent can only act for a member if it knows who they are, what they have allowed, what they hold and how to pay. In BLACKBOOK those sit on one system we build and run ourselves: identity and consent, the wallet, supply, and payment, with every action logged against the permission it was taken under.

That closed loop is why BLACKBOOK can offer agentic commerce from search to settlement sooner than platforms that have to stitch it together from other people’s systems.

Identity and consent

The member, their permissions and the limits on them, checked on every action.

The wallet

Cards, points, miles and memberships the agent can pay with, inside the member’s limits.

Supply

Stays, flights, tables and experiences the agent can search, hold and book.

Payment and the log

One basket settled once, and every step written to the log.

A car on a Paris street at dusk
10 · Permission to act

Permission to act, in both directions.

  • OncePermission given, then acted on
  • Every actionRecorded as a timestamped event
  • Both waysYour supply, reachable by other agents

The member gives permission once, and the app can act for them: hold the table, move the booking, pay for it, keep the itinerary current when the flight moves. Every permission and every consent is recorded as a timestamped event, so what was agreed to can be evidenced later.

It runs the other way as well. Through our connectors, a partner’s rooms, tables, seats and benefits can be reached by other agents and assistants, with identity, consent and payment attached to the request — so the supply can be found and bought where the customer is already asking, rather than only on the partner’s own site.

This is what we are building, on the identity and permission layer set out above.

Interactive
Standing permission
Given byDylan Smith · member 4712
AllowsHold, move and pay for bookings up to AED 5,000
Recorded12 Sep, 09:41 · ref CN-4712-08
RevocableAny time, in the app

Every line on the right carries the consent it was acted under. Nothing happens without one.

See it running on your programme, with your benefits and your rules.