Owning the pre-stay: what Booking.com's phone-number change really exposed
Since 28 September 2026, Booking.com no longer passes guest phone numbers to PMSs and channel managers. The missing field isn't the problem. The dependency is.

It's 1am. Your guest is standing outside the building with a suitcase. The door code was supposed to arrive by text message. It didn't, because there was no number to send it to. Reception closed at eleven. The review is half-written before they've found somewhere else to sleep.
Since 28 September 2026, that scenario is no longer hypothetical for properties selling on Booking.com through a PMS or channel manager. But the missing phone number isn't really the story. The story is how much of the guest journey was quietly resting on it.
What changed, and why
Booking.com no longer sends guest phone numbers to connectivity providers: the channel managers and property management systems most hotels and rentals use to receive reservations. The number still exists. You can see it in the Booking.com Extranet and the Pulse app. It just no longer flows into your other systems.
Two details matter in practice:
- It applies to new reservations from 28 September, and also to older reservations that get modified after that date. The update arrives without the number.
- Booking.com messaging and the guest's masked email address keep working as before.
The stated reason is fraud. Booking.com has seen a rise in fake WhatsApp and SMS messages aimed at travellers, often impersonating the property and asking for payment details. Fewer systems holding the number means fewer places it can leak from. After Booking.com warned some customers earlier this year about possible unauthorised access to reservation data, it's hard to argue the motivation isn't real.
So this isn't a post about OTAs behaving badly. It's about what the change revealed.
Why one field broke so much
When the industry debated this on LinkedIn (Danica Smith's round-up is worth reading), the striking thing wasn't how many people were annoyed. It was how many different things turned out to depend on a single field:
- Pre-arrival WhatsApp and SMS messages
- Door codes and digital keys sent by text
- Upsell sequences timed before arrival
- Recognising a returning guest and matching them to their profile
None of these were designed around "the OTA's data". They were designed around "the guest's phone number", and nobody noticed those were the same thing until one of them went away.
That's the real exposure. If a partner can switch off one field and your arrival process stops working, you didn't own that process. You were renting it.
The 1am door-code test
Here's a simple benchmark. Take a guest who books on Booking.com today, with no phone number in your systems. Without anyone opening the Extranet to look something up, can that guest:
- receive their arrival information,
- complete check-in before arrival, and
- get into the building at 1am?
If the honest answer to any of these is "someone would have to step in", your pre-stay journey isn't resilient. And when it fails, the bad review lands on your property, not on the platform that changed the rules.
What a resilient pre-stay looks like
The fix isn't a cleverer way to recover the phone number. It's a journey that never needed it.
Start with a channel that always works. Every Booking.com reservation comes with a way to reach the guest: Booking.com messaging and the masked email address. Make that the first touchpoint for every booking, carrying a link to online check-in. WhatsApp can come later. It shouldn't be the foundation.
Make check-in the moment you collect your own data. Online check-in is where the guest gives you their details directly: phone number, email, arrival time, and consent to be contacted on the channel they prefer. That data is yours, collected with a lawful basis, in your own system. It doesn't depend on what an OTA chooses to pass along, and it's the same flow for direct, Airbnb and Booking.com guests.
Deliver keys inside the journey, not by text. Door codes and mobile keys should be released once check-in is complete, in the guest's confirmation or guest portal, not fired off by SMS to whatever number came in with the reservation. It's better security too: the key goes to a guest who has actually checked in.
Treat WhatsApp as opt-in, not an assumption. Many guests still prefer WhatsApp. The difference is that the guest gives you the number and opts in, on your own business number, instead of you messaging a number an OTA happened to hand over.
Recognise guests by more than a phone number. Email, name plus stay history and the details collected at check-in are more reliable identifiers than a field you no longer receive.
Put arrival info where guests can find it. A lot of pre-arrival messages answer questions about parking, late arrival or how the door works that belong on your website or in a guidebook link. The fewer things depend on a message reaching the guest, the fewer things can break.
How this works in HolidayHero
This is the flow HolidayHero is built around. Every reservation, from any channel, gets an online check-in invitation through a channel that's guaranteed to reach the guest; for Booking.com, that's the platform's own messaging. The guest checks in online and leaves their own contact details and preferences. Once check-in is complete, the guest portal holds everything they need to arrive, including access to the building or room where a smart lock is connected. From there, the conversation runs on the property's own channels, in one inbox.
For our customers, 28 September changed one thing: a field that used to be filled is now empty. The arrival journey didn't notice.

Audit your pre-stay this week
- Which of your automations still trigger on a phone number? Think pre-arrival messages, upsells and key delivery.
- Do door codes go out by SMS? What happens when there's no number?
- Is Booking.com messaging connected to the tool you use for guest communication, or does someone check the Extranet by hand?
- Does your online check-in ask for a phone number and contact consent?
- Is your arrival information on your own website, in your own words?
- What happens to an existing booking that gets modified after 28 September? Test one.
The next field
Booking.com won't be the last platform to change what it shares, and the phone number won't be the last field to go. Privacy rules tighten, fraud evolves, partners change their APIs. Properties that own the pre-stay, from the first contact through check-in and the key to the conversation, will barely notice. The ones that don't will keep finding out at 1am.
Running the stay starts before the guest arrives.
*Source for the Booking.com change: Smoobu's summary of the update.
Frequently asked questions
Does Booking.com still share guest phone numbers with hotels?+
How can I contact a Booking.com guest without their phone number?+
Can I still send door codes to Booking.com guests?+
Does the change affect reservations made before 28 September 2026?+

Hjalte is CEO and co-founder of HolidayHero, an Amsterdam-based platform that runs the whole guest stay for hotels, holiday parks, hostels, aparthotels and short-term rentals. He also runs a rental property himself, which is a decent cure for building features nobody asked for. Most of his writing here is product: new integrations, guest registration and compliance work, and the reasoning behind decisions that show up in your account a few weeks later.
Keep reading


