Privacy Policy
How we collect, use, and protect your personal data, in accordance with the Thailand Personal Data Protection Act (PDPA).
Last updated: 26 July 2026
1. Data Controller
The data controller responsible for your personal data is Ambroise Care Thailand Ltd., a company registered in Thailand, company registration number 0775569000783 (also its Thai tax identification number), operating ThaiCare4u. You can contact us about privacy matters at privacy@thaicare4u.com.
This policy is written to meet the disclosure requirements of the Thailand Personal Data Protection Act B.E. 2562 (2019) ("PDPA"). It applies to all users of the Platform, whether located in Thailand or elsewhere.
2. Personal data we collect
| Category | Examples |
|---|---|
| Account data | Username, full name, email address, hashed password, account role (Seeker/Provider) |
| Provider profile data | Bio, specialty, experience, certifications claimed, languages, rates, location, availability, photos |
| Seeker profile data | Display name, phone number, location, notes about the care you're looking for |
| Care needs data (sensitive) | Free-text description of the elderly person's care needs, which may reveal health-related information about a Seeker's family member |
| Messages and booking data | Contents of messages between Seekers and Providers, hire requests, booking status, ratings and reviews |
| Payment data | Handled directly by Stripe — we receive confirmation of payment and a subscription status, not your full card number |
| Technical data | IP address, browser/device information, log data, cookies necessary for login sessions |
Sensitive personal data: Under PDPA Section 26, health-related information is a special category requiring your explicit consent to process. Where you enter care-needs information that reveals health conditions of the person needing care, you are providing that information voluntarily and consenting to our processing of it for the purpose of matching you with a suitable Provider. Please avoid including more detail than necessary for that purpose.
3. Why we collect it, and our legal basis
| Purpose | Legal basis (PDPA) |
|---|---|
| Creating and managing your account | Performance of a contract with you |
| Displaying provider profiles and enabling search | Performance of a contract; legitimate interest in operating the directory |
| Enabling messaging and hire requests between users | Performance of a contract |
| Processing subscription payments and refunds | Performance of a contract |
| Care-needs / health-related details you submit | Your explicit consent |
| Trust & safety review, moderation, fraud prevention | Legitimate interest; legal obligation where applicable |
| Marketing communications (if any) | Your consent, which you may withdraw at any time |
4. Who we share data with
We do not sell your personal data. We share it only as needed to operate the Platform:
- Supabase (our database provider) — stores profile, message, and booking data. Supabase's infrastructure may process data outside Thailand.
- Stripe (our payment processor) — processes subscription payments and refunds. Stripe may process data outside Thailand.
- Other users of the Platform — your profile (if a Provider) and messages you send are visible to the users you interact with, as necessary for the Platform to function.
- Law enforcement or regulators — where required by Thai law or a valid legal process.
5. Cross-border data transfers
Because Supabase and Stripe operate infrastructure outside Thailand, your personal data may be transferred to and processed in other countries. Where required by PDPA Section 28, we rely on the fact that these providers maintain internationally recognized data protection standards (including Standard Contractual Clauses or equivalent safeguards) and/or your consent to this policy as the basis for such transfers.
6. Data retention
We retain your account and profile data for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within a reasonable period, except where we are required to retain it (for example, transaction records for tax/accounting purposes, or records needed to resolve an active dispute or report).
7. Your rights under PDPA
Subject to the exceptions and conditions under Thai law, you have the right to:
- Access a copy of the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase or anonymize your data, in certain circumstances
- Restrict or object to certain processing
- Data portability — receive your data in a portable format
- Withdraw consent at any time, where processing is based on consent (this will not affect processing carried out before withdrawal)
- Lodge a complaint with the Personal Data Protection Committee (PDPC) of Thailand if you believe we have mishandled your data
To exercise any of these rights, contact us at privacy@thaicare4u.com. We will respond within the timeframe required by PDPA.
8. Security
We use reasonable technical and organizational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, and access controls restricting who can view sensitive data. No system is perfectly secure, and we cannot guarantee absolute security.
9. Cookies
We use essential cookies required to keep you logged in and to protect against cross-site request forgery. We do not currently use third-party advertising or tracking cookies.
10. Children's data
The Platform is not directed at children and is not intended for use by anyone under 18. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new "Last updated" date, and where changes are material we will make reasonable efforts to notify users directly.
12. Contact us
For any question about this policy or how we handle your data, contact privacy@thaicare4u.com or use our Contact page.
Note: This is a general-purpose template, not legal advice, and has not been reviewed by a Thai-qualified lawyer or PDPA specialist. Please fill in the bracketed legal-entity details and have counsel confirm this meets your actual data flows and PDPA obligations — including whether you need to appoint a Data Protection Officer, which depends on the scale and nature of data you process.