Market Coverage / PMS Industry Hub
Policy & Regulation

Booking.com stops sending guest phone numbers to PMSes and channel managers on 28 September

PMS News Desk

PMS News Desk

September 25, 2026 · 3 min read

From Monday 28 September, Booking.com stops sending guest phone numbers to connectivity partners. If your property management system or channel manager currently receives a guest's number with the reservation, that field goes empty on every new Booking.com booking from that date.

The change is global and hits every connectivity provider at the same time. There is no phased rollout and no opt-out.

What Booking.com says

The stated reason is phishing. Booking.com has seen a rise in fraudulent SMS and WhatsApp messages sent to travellers that quote real reservation details, usually demanding an immediate payment. Cutting the number of systems that hold a guest's phone number cuts the surface area for that.

Guest numbers stay visible in the Extranet and in the Pulse app. Properties that work directly in the Extranet rather than through a connected system are not affected.

What still works

Reservation sync carries on unchanged. Guest names, rates, availability, booking dates and modifications all continue to flow. Booking.com's own messaging and the masked email address still work, so you can still reach the guest, just not by phone.

Numbers already stored in your system before 28 September stay where they are. This is not a purge of historic data, only a stop on new deliveries.

What breaks

Anything automated that dials or texts. In practice that means SMS door codes, WhatsApp arrival instructions, automated pre-arrival reminders by text, and the front desk calling a guest who has not turned up by 11pm.

Nothing needs changing in your PMS settings. The change happens on Booking.com's side and applies automatically. The work is in your automations, not your configuration, so the useful thing to do before Monday is to list every workflow that reads the phone field and decide what replaces it.

The realistic replacements are Booking.com messaging, the masked email address, or collecting a number yourself at online check-in or in a pre-arrival form. For one-off cases you can still look the number up manually in the Extranet.

Smoobu published a host guide on 25 September. Smily, through its BookingSync changelog, and NextPax have both told their customers the same thing.

The gap nobody has filled

Booking.com already masks guest email addresses, which lets a property send mail without ever holding the real address. There is no equivalent for phone. The number is simply gone rather than replaced with an alias that routes through Booking.com.

NextPax has said as much. Lennart Kok, the company's VP of distribution and marketing, said "traveller safety matters to all of us, and we're glad to see Booking.com tackling phishing head-on", while proposing that Booking.com introduce alias phone numbers in the same way it handles email, and require connectivity partners to hold ISO 27001 or SOC 2 certification. As an interim measure NextPax is attaching Booking.com's customer service number to reservations so front office teams can at least reach someone who can pass a message to the guest.

That is a workaround, not a fix. For an operator, the practical effect is that a channel you could previously reach a guest on has closed, and the remaining route runs through Booking.com's own messaging. The safety argument is sound. It is also worth noticing that the change keeps more of the guest conversation on the platform.

If you run properties on multiple channels, this is a good moment to check which of your arrival workflows depend on a phone number at all, because Booking.com is unlikely to be the last channel to make this move.

Source: Smoobu Blog