Free delivery in Thailand on orders over ฿1,200 · Made local, delivered with care
Ruedee.com
TH

Privacy Policy

Effective 1 November 2018  ·  Last updated 4 August 2026

Your privacy is our responsibility. This policy applies to all personal data collected by Ruedee Retail Co., Ltd., operator of the Ruedee platform, through the website at ruedee.com, our mobile applications, our social media channels, our customer service centre, and any other channel we operate.

Please read this policy together with our Terms & Conditions of Service. If you have any question, you may contact us using the channels set out in Section 13.

 

1. Introduction & Scope

  1. This policy is issued under the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) and its subordinate regulations.
  2. “Personal data” means information relating to a person that enables that person to be identified, whether directly or indirectly, but excludes data of deceased persons and data of juristic entities.
  3. This policy applies to Customers, Providers, partner merchants, website visitors and enquirers alike.
  4. This policy does not apply to processing carried out by Providers or third parties acting as controllers in their own right, which is governed by their own privacy notices.
  5. Separate notices apply to job applicants and business partners, and are published on the Company's website.

 

2. Personal Data We Collect

CategoryExamples of dataNecessity
Identity dataFull name, gender, date of birth, profile photograph, national ID number (Providers only, for verification and tax purposes)Required
Contact dataEmail address, telephone number, delivery address, social media account used to sign inRequired
Account dataUsername, hashed password, login history, language and notification preferencesRequired
Transaction dataBooking history, items ordered, amounts, appointment date and time, branch attended, eVouchers, Cashback CreditsRequired
Payment dataCard type, last four digits, cardholder name, payment token, bank account number (for withdrawals and refunds)Required
Usage dataPages viewed, search queries, favourited listings, session duration, click pathsConsent-based
Device & technical dataIP address, device identifier, browser type, operating system, network carrier, crash logsAutomatic
Location dataApproximate location from IP, or precise device location where permission is granted, to recommend nearby merchantsConsent-based
User-generated contentReviews, ratings, photographs, messages exchanged with Providers and customer supportAs used
Enquiry recordsChat transcripts, call recordings (where notified in advance), complaintsAs used

If you do not provide the data marked Required, we may be unable to create your account, accept your booking, process payment or provide the service.

 

3. Sources of Data

  1. Directly from you — when you register, complete a form, place a booking, write a review, or contact customer support.
  2. Automatically from your use — through cookies, pixels, software development kits (SDKs) and server logs.
  3. From Providers and partner merchants — for example attendance status, eVoucher redemption confirmations, or no-show reports.
  4. From third-party service providers — payment processors, identity verification providers, fraud detection providers and analytics providers.
  5. From social login providers — where you choose to sign in via Google, Facebook, Apple or LINE, we receive the basic profile data you have authorised in that provider's settings.
  6. From public sources — for example the Department of Business Development's company register, to verify the status of corporate Providers.

 

4. Purposes & Lawful Bases for Processing

We process your personal data for the purposes and on the lawful bases set out below.

PurposeData usedLawful basis (PDPA)
Creating and administering your accountIdentity, contact, accountContractual necessity s.24(3)
Processing bookings, confirming slots, issuing eVouchersIdentity, contact, transactionContractual necessity s.24(3)
Processing payments and refunds, preventing fraudPayment, transaction, deviceContractual necessity · Legitimate interest s.24(5)
Providing customer service and handling complaintsContact, transaction, chat recordsContractual necessity s.24(3)
Mediating disputes between UsersTransaction, chat records, submitted evidenceLegitimate interest s.24(5)
Verifying identity and preventing duplicate accountsIdentity, deviceLegitimate interest s.24(5)
Improving the service, analysing behaviour, developing featuresUsage, device, transactionConsent s.19 · Legitimate interest
Personalised recommendations and nearby merchantsUsage, location, transactionConsent s.19
Sending news, promotions and direct marketingContact, usage, transactionConsent s.19
Complying with tax, accounting and anti-money-laundering lawIdentity, transaction, paymentLegal obligation s.24(6)
Establishing legal claims and defending proceedingsAll relevant categoriesLegitimate interest s.24(5)
Preventing danger to life, body or healthIdentity, contact, healthVital interest s.24(1)
Use beyond the original purpose

If we wish to use your data for a purpose other than those notified above, we will inform you and obtain fresh consent before doing so, unless the law permits the processing without consent.

 

5. Sensitive Personal Data

Sensitive personal data under section 26 of the PDPA includes racial or ethnic origin, religion, political opinion, sexual behaviour, criminal records, health data, disability, genetic data and biometric data.

  1. As a general rule, the Company does not seek to collect sensitive personal data, and such data should not be entered into general free-text fields.
  2. However, certain services on the Platform — health services, aesthetic clinics, therapeutic massage or dentistry — may require health information such as allergies, pregnancy, existing medical conditions or physical limitations, for your own safety.
  3. In those cases we collect and disclose the data to the relevant Provider only with your explicit consent, and use it only to the extent necessary for the safe delivery of the service.
  4. You may withdraw consent at any time, but withdrawal may mean a Provider is unable to deliver certain services to you for safety reasons.
  5. We may use biometric data such as face or fingerprint recognition for login authentication only where you enable that feature yourself. Biometric data is processed and stored on your own device; the Company does not receive a copy of it.

 

6. Cookies & Tracking Technologies

Cookies are small text files stored on your device when you visit a website. We use cookies and similar technologies including pixels, tags and in-app SDKs.

Cookie typePurposeTypical lifetimeConsent required
Strictly necessaryMaintaining login state, cart contents, security and CSRF protectionSession – 12 monthsNo
FunctionalRemembering your language, theme, chosen branch and other preferencesUp to 12 monthsYes
AnalyticsMeasuring visitor numbers, navigation paths and page performanceUp to 24 monthsYes
MarketingServing relevant advertising on third-party platforms and measuring campaignsUp to 13 monthsYes
  1. On your first visit a banner lets you accept or reject each category. You can change your choices at any time through the “Cookie settings” link in the footer of every page.
  2. Rejecting strictly necessary cookies will prevent the website from functioning correctly.
  3. You may also delete or block cookies yourself through your browser settings.
  4. We honour Global Privacy Control and Do Not Track signals sent by your browser, treating them as a rejection of marketing cookies.

 

7. Disclosure & Sharing

The Company does not sell your personal data to anyone. We disclose data only as necessary to the following recipients.

RecipientData disclosedReason
Providers and partner merchantsName, contact number, appointment details, and necessary health data (where consented)To deliver the service you booked
Payment providers and banksPayment and transaction dataTo process payments and refunds
Cloud and infrastructure providersData stored on our systemsHosting and backup
Analytics and marketing providersUsage and device data (usually pseudonymised)Measurement and service improvement
Messaging, email and notification providersName, email address, telephone numberSending confirmations and notifications
Legal advisers, auditors and insurersAs necessary for the matterProtecting our rights and complying with law
Government agencies and law enforcementAs required by lawCourt orders, official requests, legal duties
Successors in businessData relating to the transferred businessMerger, sale or corporate restructuring

All recipients are bound by confidentiality undertakings and data processing agreements, and are prohibited from using the data for any purpose beyond that specified by the Company.

 

8. Cross-Border Transfers

  1. Some of our cloud, analytics and communications providers operate servers outside Thailand — for example in Singapore, Japan, the European Union or the United States.
  2. Cross-border transfers are made in accordance with sections 28 and 29 of the PDPA, using one of the following safeguards:
    • transfer to a destination country recognised by the Personal Data Protection Committee as providing adequate protection;
    • standard contractual clauses on data protection concluded with the recipient;
    • audited binding corporate rules within a group of undertakings;
    • your explicit consent, given after being informed of the inadequate protection standard in the destination country.
  3. You may request a copy of, or details about, the safeguards we use by contacting our Data Protection Officer.

 

9. Data Retention

We keep personal data only for as long as necessary for the purposes notified, or as required by law.

Data categoryRetention periodReason
Account dataLife of the account + 1 yearReactivation and audit
Transaction data and tax invoices10 years from the end of the accounting periodRevenue Code and accounting law
Customer service chat records2 yearsComplaint handling and service quality
Call recordings90 daysQuality assurance
System access logs90 days – 1 yearComputer Crime Act requirements
Cookie dataPer the lifetimes in Section 6As consented by you
Reviews and public contentUntil you delete it or close your accountBenefit to other Users
Sensitive health data1 year after the last serviceSafety of any subsequent service
Dispute-related dataUntil the matter is finally determined + 1 yearEstablishing and defending legal claims

Once these periods expire we delete, destroy or anonymise the data. Anonymised data may be retained for continuing statistical analysis.

 

10. Security Measures

We maintain appropriate technical, organisational and physical security measures.

Technical measures

  • Data encrypted in transit with TLS 1.2 or above, and at rest to the AES-256 standard.
  • Passwords stored as salted one-way hashes; plain-text passwords are never stored.
  • Full payment card numbers are not stored; we use tokenisation provided by PCI DSS-certified processors.
  • Access controlled on a least-privilege basis, with multi-factor authentication enforced for critical systems.
  • Access logging and monitoring, periodic vulnerability scanning, and penetration testing at least annually.
  • Regular backups supported by a documented disaster recovery plan.

Organisational & physical measures

  • An information security policy, with data protection training for staff at least annually.
  • Confidentiality undertakings binding employees and contractors.
  • Access to data centres and equipment controlled by key card and CCTV.
No system is completely secure

Although we apply industry-standard measures, transmitting data over the internet always carries some risk. Please use a strong, unique password, avoid reusing passwords across services, and enable two-factor authentication.

 

11. Data Breach Notification

  1. In the event of a personal data breach, we will notify the Office of the Personal Data Protection Committee within 72 hours of becoming aware of it, unless the breach is unlikely to affect the rights and freedoms of individuals.
  2. Where a breach presents a high risk to your rights and freedoms, we will notify you without undue delay, describing the nature of the breach, the data affected, the remedial measures taken, and steps you can take to protect yourself.
  3. We maintain a record of every breach as required by law.
  4. If you discover a security vulnerability or suspect a data leak, please report it to security@ruedee.com. We will not take legal action against anyone who reports a vulnerability in good faith and without causing harm.

 

12. Your Rights as a Data Subject

Under the PDPA you have the following rights.

RightWhat it meansSection
Right to be informedTo be told the purposes, lawful bases and processing details before or at the time of collections.23
Right of accessTo access the data we hold about you and obtain a copy, including information about its sources.30
Right to data portabilityTo receive your data in a machine-readable electronic format, or have it transmitted to another controllers.31
Right to objectTo object to the collection, use or disclosure of your data, particularly for direct marketings.32
Right to erasureTo have your data deleted, destroyed or anonymiseds.33
Right to restrict processingTo have processing suspended while accuracy is verified or an objection is considereds.34
Right to rectificationTo have inaccurate, out-of-date or incomplete data correcteds.35
Right to withdraw consentTo withdraw consent at any time, without affecting the lawfulness of prior processings.19
Right to lodge a complaintTo complain to the Personal Data Protection Committee if you believe we have not complied with the laws.73

Some rights may be restricted by law — for example where we are required to retain data under tax legislation, or where retention is necessary to establish a legal claim. In such cases we will explain our reasons to you in writing.

 

13. How to Exercise Your Rights & Delete Your Data

How to submit a request

  1. In the app or on the website — go to My Account → Privacy settings, where you can download your data, correct it, manage consents, or request account deletion yourself.
  2. By email — write to privacy@ruedee.com stating your name, registered email address, the right you wish to exercise, and details of your request.
  3. By post — address your request to the Data Protection Officer, Ruedee Retail Co., Ltd., at the Company's registered office.

How we handle it

  1. We will verify your identity first, to avoid disclosing data to someone not entitled to it. Additional identification documents may be requested.
  2. We will consider and respond to your request within 30 days of receiving it in complete form.
  3. Where a request is complex or numerous requests are made, we may extend that period by up to a further 30 days, giving you our reasons.
  4. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessively repetitive, in which case we may charge a reasonable fee or refuse it.

Deleting your account and data

When you request deletion of your account, we will:

  • close access to the account immediately, and delete your profile data, search history and personal settings within 30 days;
  • anonymise your reviews, or remove them if you ask us to;
  • retain transaction data and tax invoices for the statutory periods set out in Section 9, with access restricted to authorised staff only;
  • cancel any remaining Cashback Credits, unused eVouchers and other benefits without compensation.

 

14. Marketing & Communications

  1. We send marketing news, promotions and special offers only where you have consented.
  2. You may unsubscribe at any time by:
    • clicking the “Unsubscribe” link at the foot of any marketing email;
    • adjusting your preferences in My Account → Notifications;
    • replying to an SMS with the keyword indicated, or contacting customer support.
  3. Unsubscribing takes effect within 7 days of us receiving your instruction.
  4. Even after unsubscribing from marketing, we must still send transactional messages — booking confirmations, appointment reminders, receipts, notices of changes to service terms, and security alerts. These cannot be switched off while you hold an account.
  5. We may use usage data to build audience segments and display relevant advertising on third-party platforms. You may object to this processing under Section 12.

 

15. Automated Decision-Making & Profiling

We use automated systems in certain processes:

  • Ranking and recommendations — analysing your search history, bookings and location to order search results and suggest merchants likely to match your interests.
  • Fraud detection — scoring transaction risk from usage patterns, device signals and payment history in order to block suspicious transactions.
  • Content screening — detecting messages that may breach the Terms, such as attempts to move a transaction off the Platform.

Automated decisions that significantly affect you — such as suspending an account or declining a transaction — are always subject to review by a human. You have the right to:

  1. be told the reasons for the decision;
  2. request human review of it;
  3. contest the outcome, by contacting privacy@ruedee.com.

 

16. Children's Personal Data

  1. The Platform is not intended for independent use by anyone under 20 years of age.
  2. We do not knowingly collect data from children under 10 years of age. Where such processing is necessary, it requires the consent of the person holding parental power, under section 20 of the PDPA.
  3. Minors aged 10 or over but not yet of legal age may give consent only for acts appropriate to their station in life and reasonably necessary for their livelihood; otherwise parental consent is required.
  4. If we learn that we have collected a minor's data without valid consent, we will delete it without undue delay.
  5. If you are a parent or guardian and believe your child has provided us with data without consent, please contact privacy@ruedee.com so that we can remove it.

 

17. Changes to This Policy

  1. We may update this policy from time to time to reflect changes in law, technology or our business practices.
  2. The updated policy will be published on this page, showing the last-updated date and version number in the document header.
  3. Where a change is material — a new processing purpose, a change of recipients, or an extended retention period — we will give at least 30 days' prior notice by email or in-app notification, and will seek fresh consent where the law requires it.
  4. We retain previous versions of this policy for audit purposes; you may request a copy from our Data Protection Officer.