ข้ามไปยังเนื้อหา

Privacy Policy

Last updated: 27 July 2026

1. Introduction and data controller

This Privacy Policy describes how Toosabai (“Company,” “we,” “us,” or “our”) collects, uses, stores, discloses, and protects personal data when you use our booking and scheduling platform (“Platform”), accessible at toosabai.com and its subdomains.

Toosabai is the data controller for personal data collected through the Platform. We process personal data in compliance with Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) and applicable data protection laws of other jurisdictions where our Users are located.

Each business Owner who accesses Guest personal data through the Platform also acts as an independent data controller with respect to that Guest data and is independently responsible for their own compliance with the PDPA and any other applicable data protection law.

2. Personal data we collect

We collect personal data in the following categories, depending on how you interact with the Platform:

2.1 From business Owners (at registration and during use)

  • Account information: full name, email address, password (stored only as a cryptographic hash — we never store or have access to your plaintext password).
  • Business information: business name, booking site address (slug), business type, about/description text, Google Maps URL, LINE URL, WhatsApp URL.
  • Service and staff information: service names, descriptions, durations, prices; staff member names.
  • Operational information: business hours, break schedules, weekly closure days, one-off closure dates, booking horizon preferences.
  • Photographs: hero images and gallery images uploaded through the Platform.
  • Payment information: collected and processed exclusively by Stripe. We store only your Stripe customer ID, a reference to your saved payment method, and a record of which months have been billed — we never access, see, or store full credit card numbers, bank account details, or other payment credentials.
  • Referral information: referral slug, referral attribution data (whether you were referred by another business and whether you have referred others).
  • Login email history: each email address previously used to sign in to your account, recorded whenever the address is changed. We keep this so that we can identify your account if you contact us unable to sign in and no longer remember which address you used. No password material of any kind is recorded — see Section 6.
  • Support requests: if you send us a message through the support form on our website, we store the name, email address and message you provide, together with the IP address the message was sent from. The IP address is used solely to limit how many messages a single sender can submit in an hour, which is what stops the form being used to send mail in our name.

2.2 From Guests (at the time of booking)

  • Contact information: full name and email address, which are required when you book online so that your confirmation, appointment reminder and (where applicable) review-request email can reach you. A phone number is optional. Where a booking is entered by the business on your behalf — a walk-in or a booking taken over the phone — only a name is required, and a booking recorded without an email address receives no email from us at all.
  • Booking details: selected service, selected staff member, appointment date and time, booking status (confirmed, cancelled, rescheduled), and any notes you provide.
  • Technical identifiers: a unique management token (an unguessable link for self-service booking management) and a short confirmation code.

2.3 From Staff members

  • Account information:name, email address, and password (created by the Owner on the Staff member’s behalf; stored only as a cryptographic hash).

2.4 Automatically collected data

  • Log data: our hosting provider (Vercel) automatically collects standard server logs, which may include IP address, browser type, operating system, referring URL, pages visited, and timestamps. This data is collected and retained by Vercel in accordance with their privacy policy.
  • Cookies: see Section 7 below.

2.5 Data we do NOT collect

We do not collect: government-issued identification numbers, biometric data, health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, trade union membership, criminal records, genetic data, or any other categories of sensitive personal data (as defined under Section 26 of the PDPA). Do not submit such information through the Platform. If you inadvertently provide sensitive personal data, contact us immediately for its deletion.

3. Legal basis for processing

Under the PDPA, we process your personal data on one or more of the following lawful bases:

  • Contractual necessity (PDPA Section 24(3)): Processing is necessary to perform our contract with you — for example, creating and managing your account, billing you in the months your usage exceeds the included allowance, facilitating bookings, and sending transactional emails (confirmations, reminders, and management links).
  • Legitimate interest (PDPA Section 24(5)): Processing is necessary for our legitimate interests, provided those interests are not overridden by your fundamental rights. This includes: preventing fraud and abuse (such as the referral fraud gate and booking-code lookup rate limiting), maintaining the security of the Platform, improving Platform performance, and enforcing our Terms of Service. Where we rely on legitimate interest, we conduct a balancing test to ensure our interests do not override your rights.
  • Legal obligation (PDPA Section 24(6)): Processing is necessary to comply with a legal obligation to which we are subject, such as tax record-keeping requirements, responding to lawful requests from public authorities, or complying with court orders.
  • Consent (PDPA Section 19): Where none of the above bases apply, we may seek your explicit consent before processing your personal data. You may withdraw consent at any time (see Section 9). Withdrawal of consent does not affect the lawfulness of processing that occurred before the withdrawal.

4. How we use your personal data

We use personal data for the following purposes:

  • Account management: to create, maintain, secure, and authenticate Owner and Staff accounts.
  • Booking operations: to create, manage, confirm, reschedule, and cancel bookings; to prevent double-booking; and to enforce business hours, closures, and booking horizons.
  • Transactional communications: to send booking confirmations (containing the management link and confirmation code), appointment reminders (approximately two hours before the appointment), and review-request emails (after the appointment, at a timing configured by the business). These are service-related communications necessary for the performance of the booking, not marketing.
  • Owner notification: to notify Owners by email when a new booking is made at their business.
  • Billing: to count bookings against your monthly allowance, charge the monthly fee in the months you exceed it, retry declined payments, administer the one-time grace period, and apply referral discounts.
  • Referral program: to attribute new signups to referral links, manage referral rewards, and prevent referral fraud.
  • Security and fraud prevention: to prevent unauthorized access, detect and prevent fraudulent activity, enforce rate limits on booking-code lookups, and maintain the integrity of the Platform.
  • Legal compliance: to comply with applicable laws, regulations, and legal processes.
  • Platform operation: to host, maintain, and improve the Platform, resolve technical issues, and ensure the Platform functions as intended.

We do not sell, rent, or trade your personal data to any third party, for any reason, under any circumstances.

We do not use your personal data for profiling, automated decision-making, targeted advertising, or any purpose beyond what is described in this Privacy Policy.

5. Data sharing and third-party processors

We share personal data only with the third-party service providers (“processors”) strictly necessary to operate the Platform, and only to the extent required for each provider to perform its function:

  • Supabase, Inc. (United States) — hosts our database (data physically stored in the AWS Singapore region) and provides user authentication services. Supabase receives and stores: Owner account data, Staff account data, Guest booking data, business information, and all other data described in Section 2 above.
  • Stripe, Inc.(United States) — processes payments for Owners. Stripe receives: Owner email address, payment method details (entered directly into Stripe’s PCI-DSS-compliant interface — we never handle these), the amount charged for a given month, and transaction records. Referral discounts are applied by reducing the amount charged, so Stripe receives the discounted amount rather than a separate credit.
  • Resend, Inc.(United States) — delivers transactional emails. Resend receives: the recipient’s email address, name, and the content of booking-related emails (confirmations, reminders, review requests, and new-booking owner notifications).
  • Vercel, Inc. (United States) — hosts the application and serves web pages. Vercel may receive and process standard server log data (see Section 2.4).

Each of these providers acts as a data processor on our behalf and is contractually obligated to process personal data only as instructed and to maintain appropriate security measures. We do not share personal data with any other third party except as required by law (see Section 5.1 below).

5.1 Disclosure required by law

We may disclose personal data if required to do so by law, regulation, legal process, or enforceable governmental request, including but not limited to: court orders, subpoenas, requests from regulatory authorities, or in connection with legal proceedings. We may also disclose personal data where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a law enforcement request.

5.2 Business transfers

In the event of a merger, acquisition, corporate reorganization, bankruptcy, or sale of all or substantially all of our assets, personal data may be transferred to the acquiring entity or successor. We will notify affected Users of any such transfer and any changes to this Privacy Policy resulting from it.

5.3 Data shared with business Owners

When a Guest books an appointment, the contact details they provided (name, and email address and phone number where given) and their booking details are shared with the business where the appointment was made. The Owner of that business can view this information through their dashboard and receives a notification email. As noted in Section 1, each Owner is an independent data controller for the Guest data they access and is responsible for their own compliance with applicable data protection law. We are not responsible for how an Owner uses, stores, or discloses Guest personal data outside of the Platform.

6. Cross-border data transfers

Our primary database is physically hosted in the AWS Singapore region (via Supabase). However, our other service providers — Stripe, Resend, and Vercel — are incorporated in the United States and may process personal data in the United States or other countries outside of Thailand.

In accordance with PDPA Section 28, we ensure that any cross-border transfer of personal data is made to destinations that have adequate data protection standards, or is subject to appropriate safeguards such as contractual clauses requiring the recipient to maintain data protection standards no less protective than those required under the PDPA. Each of our service providers maintains industry-standard security measures and data processing agreements.

By using the Platform, you acknowledge and consent to the transfer and processing of your personal data outside of Thailand as described in this Section. If you do not consent to such transfers, you should not use the Platform.

7. Cookies and tracking technologies

7.1 Cookies we use

The Platform uses the following cookies:

  • Authentication cookies (essential): Used to maintain your login session after you sign in as an Owner or Staff member. These are strictly necessary for the Platform to function and cannot be disabled. They expire when you log out or when the session naturally expires.
  • Theme preference cookie (functional): Stores your preferred color scheme (light, dark, or system default) so the Platform renders consistently across visits. No personal data is stored or transmitted.
  • Referral attribution cookie (functional): If you arrive at the Platform through a business’s referral link, a cookie is stored to remember which referral to credit if you later sign up as a business yourself. This cookie contains only the referring business’s identifier. It uses a first-click model (subsequent referral links do not overwrite the original attribution) and expires after 60 days. This cookie is not used for advertising, behavioral tracking, or cross-site tracking.

7.2 What we do NOT use

We do not use: advertising cookies, analytics cookies, third-party tracking pixels, social media tracking scripts, fingerprinting, or any other cross-site tracking technology. We do not integrate with any advertising network or data broker.

8. Data retention

8.1 Owner and business data

We retain Owner account data, business information, service and staff records, uploaded photographs, and related data for as long as the business account exists — including periods when online booking is restricted because an allowance was exceeded without payment, or a payment failed. We do not delete data merely because an account is not currently being billed.

8.2 Guest booking data

Guest booking records (including name, email, phone number, and booking details) are retained for as long as the associated business account exists. This is necessary because: (a) the business may need to reference past bookings for operational purposes; (b) the Guest may need to look up their booking using their confirmation code or management link; and (c) we may need to retain records for legal compliance.

8.3 Deleted accounts

If an Owner requests account deletion (see Section 9), we will permanently delete all personal data associated with the account within thirty (30) days of verifying the request, except where retention is required by law (for example, tax records, which may be retained for the period required by Thai tax law). We will also delete or anonymize all associated Guest booking records, unless those records are independently required by law.

8.4 Backup retention

Deleted data may persist in encrypted backups for a limited additional period (typically up to 30 days) consistent with our backup retention schedule. Backup data is not actively used or accessed and is overwritten in the normal course of backup rotation.

8.5 Rate-limiting data

Booking-code lookup attempt records (used for rate limiting) are retained for a sliding window of fifteen (15) minutes and automatically expire. No personal data is stored in these records.

9. Your rights under the PDPA

Under the PDPA, you have the following rights with respect to your personal data. These rights apply to Owners, Staff members, and Guests:

  • Right of access (Section 30): You have the right to request access to the personal data we hold about you and to obtain a copy of that data in a commonly used electronic format.
  • Right to rectification (Section 35): You have the right to request correction of any inaccurate or incomplete personal data we hold about you. Owners can update most of their own information directly through the dashboard.
  • Right to deletion (Section 33(5)): You have the right to request deletion of your personal data where: (a) it is no longer necessary for the purpose for which it was collected; (b) you withdraw your consent and no other lawful basis for processing exists; (c) you object to processing and there are no overriding legitimate grounds; or (d) we have processed it unlawfully. We may decline deletion where retention is required by law or necessary for the exercise or defense of legal claims.
  • Right to restriction (Section 34): You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while we verify the accuracy of your data following a rectification request.
  • Right to data portability (Section 31): You have the right to receive your personal data in a structured, commonly used, machine-readable format and, where technically feasible, to have it transmitted directly to another controller.
  • Right to object (Section 32): You have the right to object to the processing of your personal data where we rely on legitimate interest as the legal basis, unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
  • Right to withdraw consent (Section 19): Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before the withdrawal.
  • Right to lodge a complaint: You have the right to lodge a complaint with the Personal Data Protection Committee (PDPC) of Thailand or any other competent supervisory authority if you believe that the processing of your personal data violates applicable data protection law.

9.1 How to exercise your rights

To exercise any of the rights listed above, contact us at support@toosabai.com. We will verify your identity before processing your request and respond within thirty (30) days. If we need additional time, we will notify you of the delay and the reason.

Guests may also exercise certain rights directly without contacting us:

  • View your booking details using your confirmation code on the business’s page or via the unique management link sent to you by email.
  • Cancel your booking using the management link — this removes your appointment from the business’s active calendar.
  • Reschedule your booking using the management link.

We will not charge a fee for processing your request unless the request is manifestly unfounded or excessive. We do not discriminate against you for exercising your rights.

10. Data security

We implement technical and organizational security measures designed to protect your personal data against unauthorized access, alteration, disclosure, destruction, or accidental loss. These measures include:

  • Encryption in transit: all data transmitted between your browser and our servers is encrypted using TLS (HTTPS).
  • Encryption at rest: our database is hosted on Supabase (AWS Singapore) with encryption at rest enabled.
  • Password security: passwords are stored as cryptographic hashes using industry-standard algorithms — we never store or access plaintext passwords.
  • Access controls: Row Level Security (RLS) policies at the database level ensure that each Owner can only access their own business data, and each Staff member can only view their own bookings. Guest bookings are written through a server-side route with the service role key — Guests never interact with the database directly.
  • Key management: API keys and secrets are stored as environment variables on our hosting provider, not in source code. Keys are rotated periodically.
  • Double-booking prevention: a database-level exclusion constraint prevents overlapping bookings even under concurrent requests — this is a data integrity measure, not just an application-level check.
  • Tenant isolation: composite foreign keys ensure that booking records cannot reference staff or services from a different business, even if a valid UUID from another business is submitted.
  • Rate limiting: booking-code lookups are rate-limited to prevent brute-force enumeration of confirmation codes.
  • Constant-time comparison: security-sensitive comparisons (such as cron authentication) use constant-time algorithms to prevent timing attacks.

While we take commercially reasonable steps to protect your personal data, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security and are not responsible for the acts of parties who gain unauthorized access to our systems despite our reasonable security measures.

11. Children’s data

The Platform is not directed at individuals under the age of 20 (or the age of majority in the relevant jurisdiction). We do not knowingly collect personal data from minors. If a Guest booking is made by or on behalf of a minor, the parent or legal guardian who provides the booking information is responsible for ensuring they have the authority to do so.

If we become aware that we have collected personal data from a minor without proper parental or guardian consent, we will take steps to delete that data as soon as practicable. If you believe we have inadvertently collected personal data from a minor, contact us at support@toosabai.com.

12. Data breach notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will:

  • Notify the Personal Data Protection Committee (PDPC) within seventy-two (72) hours of becoming aware of the breach, as required by the PDPA, unless the breach is unlikely to result in a risk to your rights and freedoms.
  • Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms, informing them of: the nature of the breach, the data affected, the measures taken to address it, and steps they can take to protect themselves.
  • Document the breach, including the facts, its effects, and the remedial actions taken, regardless of whether the breach is notifiable.

13. Third-party links

A business’s page on the Platform may contain links to external websites or services, such as Google Maps, LINE, and WhatsApp. These links are provided by the business Owner for the convenience of Guests. We do not control and are not responsible for the content, privacy practices, or security of any external website. We encourage you to review the privacy policies of any external website you visit.

14. International users

The Platform is primarily designed for use in Thailand, but may be accessed from other countries. If you are accessing the Platform from outside Thailand, please be aware that your personal data may be transferred to and processed in Thailand and other countries as described in Section 6. By using the Platform, you consent to such transfers. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with data protection laws that may differ from Thailand’s, please note that we do not specifically target users in those regions, but we endeavor to maintain protections consistent with the PDPA, which provides comparable safeguards.

15. Changes to this privacy policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable law. When we make material changes, we will: (a) update the “Last updated” date at the top of this page; (b) notify Owners via the dashboard or email; and (c) post the revised Privacy Policy on this page. Material changes will not be applied retroactively to personal data collected before the change without your consent where required by law. We encourage you to review this Privacy Policy periodically.

16. Contact and data protection inquiries

For any questions, concerns, or requests related to this Privacy Policy or the processing of your personal data, including exercising your rights under the PDPA, contact us at:

If you are not satisfied with our response to your inquiry or believe that we are processing your personal data in violation of the PDPA, you have the right to lodge a complaint with the Personal Data Protection Committee (PDPC) of Thailand.

Terms of Service →