Draft: the operator's legal details are not filled in yet, so this document cannot serve as a contract. Set PLATFORM_LEGAL_NAME, PLATFORM_LEGAL_ADDRESS and PLATFORM_CONTACT_EMAIL, and have a Thai lawyer review the text before publishing.

Privacy Policy

Last updated: 21 September 2026

1. Who processes your data

———, ———, contact hello@guesti.app. This policy follows Thailand's Personal Data Protection Act (PDPA). For the data of your own staff and guests, your venue is the controller — it decides what is collected and why. We are the processor: we act on your instructions and only to provide the service.

2. What we hold

Account data: name, email, phone, venue details, role, sign-in times. Staff data: name, role, PIN (stored as a hash, never in readable form), what each person did at the till — the audit log. Guest data your venue enters: name, phone, email, bookings, orders, wristband balance, visit history, notes your staff write. Payment data: the amount, method and status of a payment. We do not store card numbers; card payments are handled by the payment provider. Technical data: IP address, device, browser, error logs.

3. Why

To provide the service you subscribed to — this is the performance of our contract with you. To keep the service secure and diagnose failures — our legitimate interest, and yours. To issue invoices and keep accounting records — a legal obligation. We do not sell data, do not pass it to advertisers, and do not use your guests' data for our own marketing.

4. Your guests

Guest data belongs to your venue, not to us. You are responsible for telling your guests what you collect and why, and for having a lawful basis under the PDPA — for example the consent you take on your booking page. When a guest asks you to show, correct or delete their data, the panel lets you do it. If a guest writes to us directly, we will point them to you.

5. Who else sees it

Only the suppliers the service runs on, each for its own part: hosting and the database, email delivery, SMS delivery, LINE messaging, the payment provider, error monitoring. Each of them processes data on our instructions and only as needed for that task. Hosting and backups are in the region stated in your contract. If data has to leave Thailand, it happens on the terms the PDPA allows.

6. How long

Operational data — while the contract lasts and 30 days after it ends, so you can export it. Accounting documents — for the period required by Thai tax law. The audit log of till actions — at least one year, because it is what settles money disputes. Logs and technical data — up to 90 days.

7. Your rights under the PDPA

You may ask for access to your data, for correction, for deletion, for a copy in a machine-readable form, for processing to be restricted, or object to processing. You may withdraw consent where processing rests on it. Write to hello@guesti.app; we reply within 30 days. If you believe we handled your data wrongly, you may complain to the Personal Data Protection Committee of Thailand.

8. How it is protected

Connections are encrypted. Each organisation's data is isolated in the database at the row level, so one venue cannot read another's. Staff act under their own PIN and every money action is recorded in the audit log. Access to production data is limited to the people who maintain the service. If a breach happens that threatens your rights, we notify you and the regulator as the PDPA requires.

9. Contact

Questions about this policy, or a request about your data: hello@guesti.app, ———, ———.