Privacy Policy
Last updated: April 2025
My Massage is committed to protecting your personal data in accordance with the Personal Data Protection Act (PDPA) of Thailand and applicable international data protection standards. This policy explains what information we collect, how we use it, and the rights you have over your data.
1. Data We Collect
From Clients
- Account registration details (name, email address, date of birth for age verification).
- Booking history and session preferences.
- Platform usage data (search filters used, pages visited) — collected in aggregate form.
- Payment data handled and stored securely by Stripe. We do not store full card numbers or sensitive payment credentials.
From Therapists
- Professional identity and contact information required for verification and booking communications.
- Professional credentials, certifications, and service offerings.
- Profile photos and biographical information for public display on the Platform.
- Payout and banking information processed securely via Stripe Connect.
2. How We Use Your Data
- To operate the booking platform and facilitate appointments between clients and therapists.
- To verify therapist identities and maintain platform safety and trust.
- To process payments and manage payouts via Stripe.
- To send booking confirmations, reminders, and support communications.
- To improve our platform features based on usage analytics.
- To comply with our legal obligations under Thai and applicable international law.
3. Third-Party Sharing
We do not sell your personal data to third parties. Data is shared only with essential service providers required to operate the Platform — principally Stripe for secure payment and payout processing. All third-party providers are contractually bound to handle your data in accordance with applicable privacy law.
4. Data Retention
We retain personal data only as long as necessary to fulfil the purposes for which it was collected, or as required by law. Booking records are retained for a minimum of 24 months for dispute resolution and legal compliance purposes.
5. Your Rights
Under the PDPA and applicable data protection law, you have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your personal data (“right to be forgotten”).
- Object to or restrict certain processing activities.
- Data portability where technically feasible.
To exercise any of these rights, please contact us at contact@my-massage.com.
6. Contact
For any privacy-related enquiries, please contact our data protection team at contact@my-massage.com. We aim to respond to all requests within 30 days.