Privacy Policy
Effective 1 November 2018 · Last updated 4 August 2026
Your privacy is our responsibility. This policy applies to all personal data collected by Ruedee Retail Co., Ltd., operator of the Ruedee platform, through the website at ruedee.com, our mobile applications, our social media channels, our customer service centre, and any other channel we operate.
Please read this policy together with our Terms & Conditions of Service. If you have any question, you may contact us using the channels set out in Section 13.
1. Introduction & Scope
- This policy is issued under the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) and its subordinate regulations.
- “Personal data” means information relating to a person that enables that person to be identified, whether directly or indirectly, but excludes data of deceased persons and data of juristic entities.
- This policy applies to Customers, Providers, partner merchants, website visitors and enquirers alike.
- This policy does not apply to processing carried out by Providers or third parties acting as controllers in their own right, which is governed by their own privacy notices.
- Separate notices apply to job applicants and business partners, and are published on the Company's website.
2. Personal Data We Collect
| Category | Examples of data | Necessity |
|---|---|---|
| Identity data | Full name, gender, date of birth, profile photograph, national ID number (Providers only, for verification and tax purposes) | Required |
| Contact data | Email address, telephone number, delivery address, social media account used to sign in | Required |
| Account data | Username, hashed password, login history, language and notification preferences | Required |
| Transaction data | Booking history, items ordered, amounts, appointment date and time, branch attended, eVouchers, Cashback Credits | Required |
| Payment data | Card type, last four digits, cardholder name, payment token, bank account number (for withdrawals and refunds) | Required |
| Usage data | Pages viewed, search queries, favourited listings, session duration, click paths | Consent-based |
| Device & technical data | IP address, device identifier, browser type, operating system, network carrier, crash logs | Automatic |
| Location data | Approximate location from IP, or precise device location where permission is granted, to recommend nearby merchants | Consent-based |
| User-generated content | Reviews, ratings, photographs, messages exchanged with Providers and customer support | As used |
| Enquiry records | Chat transcripts, call recordings (where notified in advance), complaints | As used |
If you do not provide the data marked Required, we may be unable to create your account, accept your booking, process payment or provide the service.
3. Sources of Data
- Directly from you — when you register, complete a form, place a booking, write a review, or contact customer support.
- Automatically from your use — through cookies, pixels, software development kits (SDKs) and server logs.
- From Providers and partner merchants — for example attendance status, eVoucher redemption confirmations, or no-show reports.
- From third-party service providers — payment processors, identity verification providers, fraud detection providers and analytics providers.
- From social login providers — where you choose to sign in via Google, Facebook, Apple or LINE, we receive the basic profile data you have authorised in that provider's settings.
- From public sources — for example the Department of Business Development's company register, to verify the status of corporate Providers.
4. Purposes & Lawful Bases for Processing
We process your personal data for the purposes and on the lawful bases set out below.
| Purpose | Data used | Lawful basis (PDPA) |
|---|---|---|
| Creating and administering your account | Identity, contact, account | Contractual necessity s.24(3) |
| Processing bookings, confirming slots, issuing eVouchers | Identity, contact, transaction | Contractual necessity s.24(3) |
| Processing payments and refunds, preventing fraud | Payment, transaction, device | Contractual necessity · Legitimate interest s.24(5) |
| Providing customer service and handling complaints | Contact, transaction, chat records | Contractual necessity s.24(3) |
| Mediating disputes between Users | Transaction, chat records, submitted evidence | Legitimate interest s.24(5) |
| Verifying identity and preventing duplicate accounts | Identity, device | Legitimate interest s.24(5) |
| Improving the service, analysing behaviour, developing features | Usage, device, transaction | Consent s.19 · Legitimate interest |
| Personalised recommendations and nearby merchants | Usage, location, transaction | Consent s.19 |
| Sending news, promotions and direct marketing | Contact, usage, transaction | Consent s.19 |
| Complying with tax, accounting and anti-money-laundering law | Identity, transaction, payment | Legal obligation s.24(6) |
| Establishing legal claims and defending proceedings | All relevant categories | Legitimate interest s.24(5) |
| Preventing danger to life, body or health | Identity, contact, health | Vital interest s.24(1) |
If we wish to use your data for a purpose other than those notified above, we will inform you and obtain fresh consent before doing so, unless the law permits the processing without consent.
5. Sensitive Personal Data
Sensitive personal data under section 26 of the PDPA includes racial or ethnic origin, religion, political opinion, sexual behaviour, criminal records, health data, disability, genetic data and biometric data.
- As a general rule, the Company does not seek to collect sensitive personal data, and such data should not be entered into general free-text fields.
- However, certain services on the Platform — health services, aesthetic clinics, therapeutic massage or dentistry — may require health information such as allergies, pregnancy, existing medical conditions or physical limitations, for your own safety.
- In those cases we collect and disclose the data to the relevant Provider only with your explicit consent, and use it only to the extent necessary for the safe delivery of the service.
- You may withdraw consent at any time, but withdrawal may mean a Provider is unable to deliver certain services to you for safety reasons.
- We may use biometric data such as face or fingerprint recognition for login authentication only where you enable that feature yourself. Biometric data is processed and stored on your own device; the Company does not receive a copy of it.
6. Cookies & Tracking Technologies
Cookies are small text files stored on your device when you visit a website. We use cookies and similar technologies including pixels, tags and in-app SDKs.
| Cookie type | Purpose | Typical lifetime | Consent required |
|---|---|---|---|
| Strictly necessary | Maintaining login state, cart contents, security and CSRF protection | Session – 12 months | No |
| Functional | Remembering your language, theme, chosen branch and other preferences | Up to 12 months | Yes |
| Analytics | Measuring visitor numbers, navigation paths and page performance | Up to 24 months | Yes |
| Marketing | Serving relevant advertising on third-party platforms and measuring campaigns | Up to 13 months | Yes |
- On your first visit a banner lets you accept or reject each category. You can change your choices at any time through the “Cookie settings” link in the footer of every page.
- Rejecting strictly necessary cookies will prevent the website from functioning correctly.
- You may also delete or block cookies yourself through your browser settings.
- We honour Global Privacy Control and Do Not Track signals sent by your browser, treating them as a rejection of marketing cookies.
7. Disclosure & Sharing
The Company does not sell your personal data to anyone. We disclose data only as necessary to the following recipients.
| Recipient | Data disclosed | Reason |
|---|---|---|
| Providers and partner merchants | Name, contact number, appointment details, and necessary health data (where consented) | To deliver the service you booked |
| Payment providers and banks | Payment and transaction data | To process payments and refunds |
| Cloud and infrastructure providers | Data stored on our systems | Hosting and backup |
| Analytics and marketing providers | Usage and device data (usually pseudonymised) | Measurement and service improvement |
| Messaging, email and notification providers | Name, email address, telephone number | Sending confirmations and notifications |
| Legal advisers, auditors and insurers | As necessary for the matter | Protecting our rights and complying with law |
| Government agencies and law enforcement | As required by law | Court orders, official requests, legal duties |
| Successors in business | Data relating to the transferred business | Merger, sale or corporate restructuring |
All recipients are bound by confidentiality undertakings and data processing agreements, and are prohibited from using the data for any purpose beyond that specified by the Company.
8. Cross-Border Transfers
- Some of our cloud, analytics and communications providers operate servers outside Thailand — for example in Singapore, Japan, the European Union or the United States.
- Cross-border transfers are made in accordance with sections 28 and 29 of the PDPA, using one of the following safeguards:
- transfer to a destination country recognised by the Personal Data Protection Committee as providing adequate protection;
- standard contractual clauses on data protection concluded with the recipient;
- audited binding corporate rules within a group of undertakings;
- your explicit consent, given after being informed of the inadequate protection standard in the destination country.
- You may request a copy of, or details about, the safeguards we use by contacting our Data Protection Officer.
9. Data Retention
We keep personal data only for as long as necessary for the purposes notified, or as required by law.
| Data category | Retention period | Reason |
|---|---|---|
| Account data | Life of the account + 1 year | Reactivation and audit |
| Transaction data and tax invoices | 10 years from the end of the accounting period | Revenue Code and accounting law |
| Customer service chat records | 2 years | Complaint handling and service quality |
| Call recordings | 90 days | Quality assurance |
| System access logs | 90 days – 1 year | Computer Crime Act requirements |
| Cookie data | Per the lifetimes in Section 6 | As consented by you |
| Reviews and public content | Until you delete it or close your account | Benefit to other Users |
| Sensitive health data | 1 year after the last service | Safety of any subsequent service |
| Dispute-related data | Until the matter is finally determined + 1 year | Establishing and defending legal claims |
Once these periods expire we delete, destroy or anonymise the data. Anonymised data may be retained for continuing statistical analysis.
10. Security Measures
We maintain appropriate technical, organisational and physical security measures.
Technical measures
- Data encrypted in transit with TLS 1.2 or above, and at rest to the AES-256 standard.
- Passwords stored as salted one-way hashes; plain-text passwords are never stored.
- Full payment card numbers are not stored; we use tokenisation provided by PCI DSS-certified processors.
- Access controlled on a least-privilege basis, with multi-factor authentication enforced for critical systems.
- Access logging and monitoring, periodic vulnerability scanning, and penetration testing at least annually.
- Regular backups supported by a documented disaster recovery plan.
Organisational & physical measures
- An information security policy, with data protection training for staff at least annually.
- Confidentiality undertakings binding employees and contractors.
- Access to data centres and equipment controlled by key card and CCTV.
Although we apply industry-standard measures, transmitting data over the internet always carries some risk. Please use a strong, unique password, avoid reusing passwords across services, and enable two-factor authentication.
11. Data Breach Notification
- In the event of a personal data breach, we will notify the Office of the Personal Data Protection Committee within 72 hours of becoming aware of it, unless the breach is unlikely to affect the rights and freedoms of individuals.
- Where a breach presents a high risk to your rights and freedoms, we will notify you without undue delay, describing the nature of the breach, the data affected, the remedial measures taken, and steps you can take to protect yourself.
- We maintain a record of every breach as required by law.
- If you discover a security vulnerability or suspect a data leak, please report it to security@ruedee.com. We will not take legal action against anyone who reports a vulnerability in good faith and without causing harm.
12. Your Rights as a Data Subject
Under the PDPA you have the following rights.
| Right | What it means | Section |
|---|---|---|
| Right to be informed | To be told the purposes, lawful bases and processing details before or at the time of collection | s.23 |
| Right of access | To access the data we hold about you and obtain a copy, including information about its source | s.30 |
| Right to data portability | To receive your data in a machine-readable electronic format, or have it transmitted to another controller | s.31 |
| Right to object | To object to the collection, use or disclosure of your data, particularly for direct marketing | s.32 |
| Right to erasure | To have your data deleted, destroyed or anonymised | s.33 |
| Right to restrict processing | To have processing suspended while accuracy is verified or an objection is considered | s.34 |
| Right to rectification | To have inaccurate, out-of-date or incomplete data corrected | s.35 |
| Right to withdraw consent | To withdraw consent at any time, without affecting the lawfulness of prior processing | s.19 |
| Right to lodge a complaint | To complain to the Personal Data Protection Committee if you believe we have not complied with the law | s.73 |
Some rights may be restricted by law — for example where we are required to retain data under tax legislation, or where retention is necessary to establish a legal claim. In such cases we will explain our reasons to you in writing.
13. How to Exercise Your Rights & Delete Your Data
How to submit a request
- In the app or on the website — go to My Account → Privacy settings, where you can download your data, correct it, manage consents, or request account deletion yourself.
- By email — write to privacy@ruedee.com stating your name, registered email address, the right you wish to exercise, and details of your request.
- By post — address your request to the Data Protection Officer, Ruedee Retail Co., Ltd., at the Company's registered office.
How we handle it
- We will verify your identity first, to avoid disclosing data to someone not entitled to it. Additional identification documents may be requested.
- We will consider and respond to your request within 30 days of receiving it in complete form.
- Where a request is complex or numerous requests are made, we may extend that period by up to a further 30 days, giving you our reasons.
- Exercising your rights is free of charge, unless a request is manifestly unfounded or excessively repetitive, in which case we may charge a reasonable fee or refuse it.
Deleting your account and data
When you request deletion of your account, we will:
- close access to the account immediately, and delete your profile data, search history and personal settings within 30 days;
- anonymise your reviews, or remove them if you ask us to;
- retain transaction data and tax invoices for the statutory periods set out in Section 9, with access restricted to authorised staff only;
- cancel any remaining Cashback Credits, unused eVouchers and other benefits without compensation.
14. Marketing & Communications
- We send marketing news, promotions and special offers only where you have consented.
- You may unsubscribe at any time by:
- clicking the “Unsubscribe” link at the foot of any marketing email;
- adjusting your preferences in My Account → Notifications;
- replying to an SMS with the keyword indicated, or contacting customer support.
- Unsubscribing takes effect within 7 days of us receiving your instruction.
- Even after unsubscribing from marketing, we must still send transactional messages — booking confirmations, appointment reminders, receipts, notices of changes to service terms, and security alerts. These cannot be switched off while you hold an account.
- We may use usage data to build audience segments and display relevant advertising on third-party platforms. You may object to this processing under Section 12.
15. Automated Decision-Making & Profiling
We use automated systems in certain processes:
- Ranking and recommendations — analysing your search history, bookings and location to order search results and suggest merchants likely to match your interests.
- Fraud detection — scoring transaction risk from usage patterns, device signals and payment history in order to block suspicious transactions.
- Content screening — detecting messages that may breach the Terms, such as attempts to move a transaction off the Platform.
Automated decisions that significantly affect you — such as suspending an account or declining a transaction — are always subject to review by a human. You have the right to:
- be told the reasons for the decision;
- request human review of it;
- contest the outcome, by contacting privacy@ruedee.com.
16. Children's Personal Data
- The Platform is not intended for independent use by anyone under 20 years of age.
- We do not knowingly collect data from children under 10 years of age. Where such processing is necessary, it requires the consent of the person holding parental power, under section 20 of the PDPA.
- Minors aged 10 or over but not yet of legal age may give consent only for acts appropriate to their station in life and reasonably necessary for their livelihood; otherwise parental consent is required.
- If we learn that we have collected a minor's data without valid consent, we will delete it without undue delay.
- If you are a parent or guardian and believe your child has provided us with data without consent, please contact privacy@ruedee.com so that we can remove it.
17. Changes to This Policy
- We may update this policy from time to time to reflect changes in law, technology or our business practices.
- The updated policy will be published on this page, showing the last-updated date and version number in the document header.
- Where a change is material — a new processing purpose, a change of recipients, or an extended retention period — we will give at least 30 days' prior notice by email or in-app notification, and will seek fresh consent where the law requires it.
- We retain previous versions of this policy for audit purposes; you may request a copy from our Data Protection Officer.