Privacy Policy
Last updated: 21 September 2026
1. Who processes your data
———, ———, contact hello@guesti.app. This policy follows Thailand's Personal Data Protection Act (PDPA). For the data of your own staff and guests, your venue is the controller — it decides what is collected and why. We are the processor: we act on your instructions and only to provide the service.
2. What we hold
Account data: name, email, phone, venue details, role, sign-in times. Staff data: name, role, PIN (stored as a hash, never in readable form), what each person did at the till — the audit log. Guest data your venue enters: name, phone, email, bookings, orders, wristband balance, visit history, notes your staff write. Payment data: the amount, method and status of a payment. We do not store card numbers; card payments are handled by the payment provider. Technical data: IP address, device, browser, error logs.
3. Why
To provide the service you subscribed to — this is the performance of our contract with you. To keep the service secure and diagnose failures — our legitimate interest, and yours. To issue invoices and keep accounting records — a legal obligation. We do not sell data, do not pass it to advertisers, and do not use your guests' data for our own marketing.
4. Your guests
Guest data belongs to your venue, not to us. You are responsible for telling your guests what you collect and why, and for having a lawful basis under the PDPA — for example the consent you take on your booking page. When a guest asks you to show, correct or delete their data, the panel lets you do it. If a guest writes to us directly, we will point them to you.
5. Who else sees it
Only the suppliers the service runs on, each for its own part: hosting and the database, email delivery, SMS delivery, LINE messaging, the payment provider, error monitoring. Each of them processes data on our instructions and only as needed for that task. Hosting and backups are in the region stated in your contract. If data has to leave Thailand, it happens on the terms the PDPA allows.
6. How long
Operational data — while the contract lasts and 30 days after it ends, so you can export it. Accounting documents — for the period required by Thai tax law. The audit log of till actions — at least one year, because it is what settles money disputes. Logs and technical data — up to 90 days.
7. Your rights under the PDPA
You may ask for access to your data, for correction, for deletion, for a copy in a machine-readable form, for processing to be restricted, or object to processing. You may withdraw consent where processing rests on it. Write to hello@guesti.app; we reply within 30 days. If you believe we handled your data wrongly, you may complain to the Personal Data Protection Committee of Thailand.
8. How it is protected
Connections are encrypted. Each organisation's data is isolated in the database at the row level, so one venue cannot read another's. Staff act under their own PIN and every money action is recorded in the audit log. Access to production data is limited to the people who maintain the service. If a breach happens that threatens your rights, we notify you and the regulator as the PDPA requires.
9. Contact
Questions about this policy, or a request about your data: hello@guesti.app, ———, ———.