TH ThaiHotelMinder
Home / Privacy Policy

Privacy Policy

Effective 15 January 2026 · Aligned with the Personal Data Protection Act B.E. 2562 (PDPA)

This Privacy Policy describes how ThaiHotelMinder Co., Ltd. ("ThaiHotelMinder", "we", "us") collects, uses, discloses and safeguards personal data in connection with our advisory workspace and modules for hotels operating on the HotelMinder ecosystem in Thailand. This policy applies to hoteliers, workspace users, visitors to thaihotelminder.org, and — indirectly — to hotel guests whose personal data is processed by us on behalf of a Thai hotel Subscriber.

1. Who we are

ThaiHotelMinder Co., Ltd. (บริษัท ไท โฮเทลมายเดอร์ จำกัด) is a Thai limited company incorporated in Bangkok under DBD registration number 0105566178432, Tax ID 0105566178432, registered office at 88/24 Sukhumvit Soi 21 (Asoke), Klongtoey Nuea, Watthana, Bangkok 10110, Thailand. Managing Director: Somchai Rattanaporn. Registered Data-Protection Officer: dpo@thaihotelminder.org. Regulatory authority: Personal Data Protection Committee (PDPC) of Thailand.

2. When we act as Controller and when we act as Processor

We act as Data Controller in respect of (a) hotelier and workspace user account information (name, work email, phone, hotel property, role); (b) marketing subscribers; (c) website analytics and cookies. We act as Data Processor on behalf of our Subscriber (the Thai hotel) in respect of guest personal data ingested from the Subscriber's HotelMinder workspace through the official API — including guest name, contact details, arrival and departure, room type, F&B preferences and review content. The rules governing our Processor role are set out in the Data-Processing Agreement and the PDPA notice.

3. Categories of personal data we process (as Controller)

  • Account data: full name, work email address, work phone number, job title, name and address of the hotel property, Thai Tax ID (if provided), passwordless-login timestamps and audit logs.
  • Billing data: legal billing name, address, Thai Tax ID, invoice history, payment method identifier (last 4 digits of card, PromptPay reference, bank account identifier), invoice PDFs.
  • Support correspondence: emails, tickets, phone-call notes, chat transcripts exchanged with our Bangkok office.
  • Website analytics: IP address (anonymised to /24), user-agent, referrer, page views, session duration; only if you accept analytics cookies.
  • Marketing preferences: newsletter subscription status, unsubscribe timestamps.

4. Purposes and lawful bases of processing

We process personal data for the following purposes, on the following PDPA lawful bases:

  • Provide and administer the Services — performance of contract (PDPA s.24(3)).
  • Issue invoices and comply with Thai tax law — legal obligation (PDPA s.24(6)).
  • Respond to your support requests — performance of contract (PDPA s.24(3)).
  • Send you operational notifications (billing, security, incident alerts) — legitimate interest (PDPA s.24(5)); this cannot be opted-out because it is essential to the service.
  • Send you commercial newsletters — consent (PDPA s.19); withdrawable at any time via the unsubscribe link in every email.
  • Detect fraud and safeguard security — legitimate interest (PDPA s.24(5)).
  • Website analytics — consent (PDPA s.19) collected via the cookie banner.

5. Retention periods

  • Account data: 5 years after the last day of the last active subscription.
  • Billing and tax records: 10 years, in line with Thai Revenue Code retention obligations.
  • Support tickets: 3 years from ticket closure.
  • Website analytics: 14 months (Google Analytics 4 default).
  • Newsletter subscription: until you unsubscribe, plus 12 months to preserve the audit trail of the unsubscribe request itself.
  • Data-subject request logs: 3 years from closure of the request.

6. Recipients and cross-border transfers

We share personal data only with those Sub-Processors strictly necessary to deliver the Services: our Bangkok data-centre operator (AIS Cloud), our Chiang Mai off-site backup provider (True IDC), our transactional email provider (Postmark Thailand endpoint), our billing gateway (Stripe Thailand), our accounting software (FlowAccount, Thai vendor). The current list is maintained at /security-whitepaper. All personal data of Thai origin is stored in Thailand-resident infrastructure. Cross-border transfers, when strictly necessary (e.g. for legal counsel located outside Thailand), are authorised only under the mechanisms set out in the PDPA — Standard Contractual Clauses or your explicit consent.

7. Your rights under PDPA

Under the PDPA you enjoy the following rights, which you may exercise by writing to dpo@thaihotelminder.org: right of access (s.30), right of rectification (s.35), right of erasure (s.33), right to restrict processing (s.34), right to data portability (s.31), right to object (s.32), right to withdraw consent (s.19). We respond to every valid request within 30 days. If you are dissatisfied with our response, you may lodge a complaint with the Personal Data Protection Committee (PDPC) of Thailand.

8. Security measures

We apply a defence-in-depth approach: encryption at rest (AES-256) and in transit (TLS 1.3); ISO 27001-aligned access controls; role-based access with the principle of least privilege; centralised audit logging retained for 5 years; annual penetration testing by an independent Bangkok cybersecurity firm; PDPA-mandated 72-hour breach notification. Details are published in the Security Whitepaper.

9. Cookies and tracking

We use strictly-necessary cookies to run the workspace (session, CSRF protection). Analytics and marketing cookies are set only if you accept them via the banner. See the Cookie Policy.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes are announced in the workspace and by email at least 30 days before they take effect. The version and effective date at the top of this page always reflect the currently applicable text.

11. Automated decision-making

Some of our modules — notably Channel Tuning and the Monsoon Revenue Model — produce recommendations by processing your booking history through statistical models. These recommendations are advisory. No decision producing legal effects or similarly significant effects on any individual guest is taken automatically without human review inside your workspace. Under PDPA s.32, you retain the right to object to any purely automated decision that materially affects you.

12. Marketing to hoteliers

We market our advisory services to Thai hoteliers via (a) newsletter emails to subscribers who opted in; (b) LinkedIn Sales Navigator outreach by our Bangkok sales team; (c) invited attendance at Thai hospitality industry events. All outbound marketing is calibrated to fall within PDPA "legitimate interest" for business-to-business commercial communications, subject to a documented balancing test that is reviewed annually. You may opt out at any time by writing to optout@thaihotelminder.org.

13. Complaints to the PDPC

If you are not satisfied with the way we handle a data-subject request or any other privacy matter, you may lodge a complaint with the Personal Data Protection Committee (PDPC), Ministry of Digital Economy and Society, 120 Moo 3 The Government Complex Commemorating His Majesty the King's 80th Birthday Anniversary, Chaeng Wattana Road, Thung Song Hong, Lak Si, Bangkok 10210. Website: pdpc.or.th.

14. Children

Our Services are provided on a business-to-business basis and are not intended for use by natural persons under 20 years of age (the age of majority in Thailand). We do not knowingly collect Personal Data of minors. If you believe a minor's Personal Data has reached us, please contact our DPO for prompt deletion.

15. Contact

ThaiHotelMinder Co., Ltd. — Attn. Data-Protection Officer — 88/24 Sukhumvit Soi 21 (Asoke), Klongtoey Nuea, Watthana, Bangkok 10110, Thailand — dpo@thaihotelminder.org — +66 2 664 7500.