Bookio

Privacy Policy

Effective [EFFECTIVE DATE]

Draft: under review. This text is being reviewed and may change before it takes effect.

This policy explains how Bookio handles personal data. Bookio is operated by [COMPANY LEGAL NAME], [REGISTERED ADDRESS] ("Bookio", "we"). You can reach us at [CONTACT EMAIL].

Bookio is a booking and messaging service that businesses in Thailand use to take bookings, answer customers on LINE and follow up on leads. We handle personal data in two different roles, explained below.

1. Our two roles

  • For the businesses that sign up for Bookio and their staff, we are the data controller for account and billing data.
  • For the people who book with those businesses or message them on LINE (their customers), each business is the data controller under Thailand's Personal Data Protection Act B.E. 2562 (PDPA). Bookio is the business's data processor: we process customer data only to provide the service to that business and on its instructions.

If you are a customer of a business that uses Bookio, please contact that business first about your data. We will help the business answer your request.

2. The data we process

Business accounts:

  • the owner and staff names, email addresses and a scrambled (hashed) password; we never store passwords in readable form;
  • the business name, logo, brand colour, services, opening hours, branches and team setup;
  • the credentials of the business’s LINE Official Account and LINE Login channel, stored encrypted;
  • sign-in records, including IP address and browser details, used for security.

Billing: when a business subscribes, card payments are handled by Stripe. We store the Stripe customer and subscription references, the plan, its status and its renewal date. We never see or store full card numbers.

Customer data, processed for the business:

  • name, phone number and email address, as entered on the booking form;
  • the LINE user ID and display name, when a customer connects LINE (through LINE Login) or adds the business’s LINE Official Account;
  • the address and province, for services at the customer’s home or site;
  • the service booked, dates and times, preferred dates and time windows, answers to the business’s questions and photos the customer uploads;
  • messages exchanged on LINE with the business’s Official Account (text, images and stickers), replies from staff and replies from Mali, the AI assistant;
  • records of consent to be contacted by LINE, SMS or email, with the time it was given or withdrawn;
  • leads a business sends to Bookio from its own website forms or tools, and what staff did with them (claimed, called).

Website enquiries: when someone asks us to set up a booking form ("claim this form"), we store their name, phone number, LINE ID, business name and business type.

Technical data: server logs, IP addresses (for security and rate limiting) and the cookies described in section 9.

3. Why we process it, and the legal basis

  • To provide the service a business signed up for: booking pages, confirmations and reminders, the dashboard, speed-to-lead alerts and Mali (performance of a contract).
  • To bill subscriptions (performance of a contract, and legal obligations such as accounting and tax records).
  • To keep the service secure, prevent abuse and fix problems (our legitimate interests).
  • To send customers booking messages by LINE, SMS or email, based on the consent the customer gives on the booking form or on the business’s own legal basis as controller.
  • To reply to website enquiries (steps taken at your request before a contract, and your consent).

We do not sell personal data and we do not use customer data for our own advertising.

4. Mali, the AI assistant

A business may switch on Mali to answer its LINE messages. When it does, the customer’s messages, the recent conversation history and the business’s own information (its services, prices and answers it has written) are sent to a large language model to produce a reply. Mali can also look up free times and create bookings or requests for the business.

These requests go through the Vercel AI Gateway to the model the business uses: models from Anthropic, or from Google, as set in the business’s settings. The providers process the data to return the reply. We do not use customer messages to train models of our own. [LEGAL REVIEW: confirm each provider’s data retention and training terms through the AI Gateway.]

Mali can make mistakes. She hands the conversation to the business’s staff when a person is needed, and staff can take over any chat.

5. Who we share data with

We use these service providers to run Bookio. Each receives only what it needs to do its part:

  • Vercel (hosting, application functions and file storage for booking photos), in Singapore, with parts of its platform in the United States;
  • Neon (the database), in Singapore;
  • LY Corporation (LINE Messaging API and LINE Login), to send and receive LINE messages;
  • Resend (email delivery) and ThaiBulkSMS (SMS delivery), to send booking messages and account emails;
  • Stripe (subscription payments for businesses);
  • Vercel AI Gateway with Anthropic or Google (Mali’s replies, see section 4);
  • Google (the Places API, to look up a business on our website; and Google Business Profile links a business adds).

We may also disclose data where the law requires it, or to protect the rights and safety of Bookio, the businesses using it or their customers.

6. International transfers

Bookio’s database and files are stored in Singapore. Some providers above process data in the United States or elsewhere (for example AI models, email delivery and payments). Where data leaves Thailand we rely on the safeguards the PDPA allows, such as the providers’ contractual commitments. [LEGAL REVIEW: confirm the PDPA section 28/29 basis for each transfer.]

7. How long we keep data

  • Account data: while the business’s account is open, then for up to [RETENTION PERIOD] after it closes, unless the law requires longer.
  • Customer data: for as long as the business keeps it in Bookio, or as the business instructs us. When a business closes its account we delete or return its customer data within [RETENTION PERIOD].
  • Photos uploaded on a booking form that never became a booking are deleted automatically, usually within a day.
  • Billing records: as long as accounting and tax law requires.

8. Your rights

Under the PDPA you may ask to access your data or get a copy, to have it corrected, deleted, restricted or transferred, and to object to processing. Where processing is based on consent you may withdraw it at any time; a customer can also stop LINE messages by blocking the business’s LINE Official Account.

Customers of a business should send requests to that business. Business owners and staff can contact us at [CONTACT EMAIL]. You may also complain to the Office of the Personal Data Protection Committee (PDPC).

9. Cookies

We use only cookies the service needs: the dashboard sign-in session, your language choice, and a short-lived cookie that remembers a LINE connection while you finish a booking. We do not use advertising cookies.

10. Security

Data travels over encrypted connections (HTTPS). Passwords are hashed, LINE credentials are encrypted, staff see only their own business’s data, and access to the dashboard requires a verified email address. No system is perfectly secure; if a breach affects your data we will act as the PDPA requires.

11. Changes and contact

We will post any change to this policy on this page and tell businesses of significant changes by email. Questions: [CONTACT EMAIL], [COMPANY LEGAL NAME], [REGISTERED ADDRESS].

Book onlinePowered byBookio