LEGAL & PRIVACY
Privacy Policy
How Thailand Navigator collects, uses, shares and protects personal information.
Proposed effective date: To be confirmed after legal review.
1. Overview
This Privacy Policy explains how Thailand Navigator handles personal information when you browse the service, create an account, save content, plan trips, participate in community features, suggest a correction or contact us. It should be read with the Terms of Service.
2. Information we collect
We collect information you provide, information created when you use account features, and limited technical information needed to operate and protect the service.
| Category | Examples in the current service | Why it is collected |
|---|---|---|
| Account information | Display name, email address, account identifiers, account status and creation/update dates. | Create and manage an account and provide requested account features. |
| Authentication data | Password hash, secure authentication and refresh-token records, session identifiers, sign-in dates and related IP addresses. | Authenticate users, maintain sessions and protect accounts. |
| Saved content and trip plans | Saved places or guides; trip names, dates, traveller counts, destinations, custom items and notes. | Remember choices and provide planning features. |
| Community activity | Posts, replies, likes, accepted answers, reports, moderation status and timestamps. | Publish and operate community features, respond to reports and maintain safety. |
| Suggestions and enquiries | Name, email, contact reason, subject, message, page URL, proposed correction, source URL and optional attachment. | Respond to enquiries, assess suggestions and investigate corrections. |
| Newsletter subscription | Email address, signup source, consent-text version, confirmation and unsubscribe timestamps, subscription status, Brevo contact identifier and suppression events. | Operate the requested double-opt-in newsletter, keep consent evidence and honour unsubscribes, bounces and complaints. |
| Service emails | Email address and delivery content for verification, account, password-reset and contact-confirmation messages sent through Brevo. | Send requested or necessary service communications. |
| Anti-spam and security | Cloudflare Turnstile token, verification response and, where sent for verification, IP address; report and moderation signals. | Reduce spam, automated abuse, fraud and security threats. |
| Search and operational data | Search query and result count; request, error, security and diagnostic logs that may include timestamps, IP address or browser/request details. | Operate, secure, troubleshoot and improve service reliability. |
3. Why we use information
Current product flows use personal information to:
Register users, sign them in, maintain sessions and respond to account-security events.
Keep saved items and trip plans connected to the correct account.
Publish contributions, record reactions, review reports and moderate content.
Route, answer and keep a record of contact requests, corrections and suggestions.
Deliver account, password-reset, confirmation and other requested operational emails.
Confirm subscriptions, send requested newsletter content and maintain unsubscribe and suppression records.
Detect automated submissions, investigate misuse and protect users and systems.
Diagnose faults, measure search usefulness and improve application performance.
Preserve or disclose records when a valid legal obligation applies.
4. Lawful bases
The applicable data-protection regime and activity-by-activity lawful-basis assessment have not yet been confirmed. The following is a drafting map for counsel, not a final legal conclusion.
| Possible basis | Processing that may rely on it | Review required |
|---|---|---|
| Contract or steps at your request | Account access, saved content, trip planning and requested service communications. | Confirm which features form the user contract. |
| Legitimate interests | Service security, proportionate moderation, diagnostics, preventing abuse and ordinary enquiries. | Document each interest, necessity and balancing assessment. |
| Consent | The optional newsletter and any non-essential technology introduced later. | Confirm consent wording, records, withdrawal route and the law applicable to each subscriber before use. |
| Legal obligation | Compliance with binding legal, regulatory or court requirements. | Confirm the operator and laws that actually apply. |
5. Cookies and authentication
The current application uses first-party, HTTP-only cookies to authenticate signed-in users and refresh sessions. These cookies are set with SameSite protections and are marked secure in production.
| Cookie type | Purpose | Current configured duration |
|---|---|---|
| Application sign-in cookie | Maintain the signed-in application session. | Up to 14 days, with sliding expiry. |
| Access-token cookie | Authorise requests to signed-in service features. | Up to 14 days. |
| Refresh-token cookie | Obtain a new access token without requiring a fresh sign-in. | Up to 30 days. |
No advertising or behavioural-marketing cookie flow was identified in the reviewed application code. Cloudflare Turnstile is loaded on protected forms and may process technical signals under Cloudflare’s own documentation. Production cookie and tag scans remain required before publication.
6. How information is shared
We do not sell personal information. We disclose it only as needed to run the service, protect users, comply with law or complete a transaction you request.
Email address, message content, newsletter-list status and delivery data for account, password, contact and newsletter emails.
Tokens and technical signals used to verify protected forms and prevent automated abuse.
Hosting, database, storage, monitoring, network and security providers. The production vendor list is to be confirmed.
Requests to map tiles or embeds may be made to OpenStreetMap or the configured map provider when a map is viewed.
Information may be disclosed where legally required or reasonably necessary to protect rights, safety and service integrity.
A future merger, financing or asset transfer may require a controlled disclosure, subject to applicable law and safeguards.
7. International processing
Service providers may process information outside the country where you live. Before this policy becomes effective, the operator must map every processing location, identify the transfer rules that apply and document any required adequacy decision, contractual safeguards or other lawful transfer mechanism.
8. Retention and deletion
Personal information should be retained only for as long as it is needed for the stated purpose, including legitimate security, dispute and legal requirements. The current code does not define a complete deletion schedule.
| Type of information | Draft retention approach |
|---|---|
| Account and authentication records | Keep while the account is active and for a justified period afterwards; token-specific expiry is described above. Full schedule pending production and legal review. |
| Saved content and trip plans | Keep while connected to an active account or until the user removes it; backup deletion timing to be confirmed. |
| Community activity and moderation | Keep while published and as needed for moderation history, safety, disputes and legal duties; deletion/anonymisation rules to be confirmed. |
| Enquiries, suggestions and attachments | Keep only as long as needed to respond, investigate, document the outcome and meet legal requirements; schedule to be confirmed. |
| Newsletter consent and suppression records | Keep while subscribed and afterwards only as needed to demonstrate consent, honour an unsubscribe or suppression and meet legal requirements; schedule to be confirmed. |
| Email delivery records | Keep according to the operational need and the verified Brevo account settings; schedule to be confirmed. |
| Search, operational and security logs | Keep for the shortest period compatible with diagnostics, security and legal duties; production log rotation and downstream retention to be confirmed. |
9. Your rights
Depending on where you live and the lawful basis used, you may have rights over your personal information. These can include access, correction, deletion, restriction, objection, portability, withdrawal of consent and a complaint to the relevant regulator.
Ask whether we process your information and request a copy where the law provides.
Ask us to correct inaccurate or incomplete personal information.
Ask for deletion where there is no overriding reason to keep the information.
Ask us to pause certain use or object where the applicable law gives that right.
Request eligible information in a portable format where the right applies.
Withdraw consent for optional processing without affecting earlier lawful use.
10. Children
The current product does not define a minimum age, parental-consent process or age-assurance mechanism. Those are product and legal decisions—not wording that can safely be invented in a policy.
11. Security
The application uses safeguards intended to reduce unauthorised access and abuse, including password hashing through the identity framework, HTTP-only authentication cookies, production secure-cookie settings, server-side Turnstile verification, role-based administration and moderated community reports. Production transport encryption, access controls, backups, monitoring, incident response and vendor safeguards must also be verified.
No method of transmission or storage is completely secure. If a security incident creates notification duties, the operator will follow the applicable law once the responsible entity and jurisdiction are confirmed.
12. Changes to this policy
Once effective, this policy may be updated when the service, providers or legal requirements change. Material changes should receive a new effective date and an appropriate notice. Previous versions should be retained where required for accountability.
13. Contact
For a privacy question or request, use the contact page and choose “Privacy request”. The final policy must also state the controller’s legal name, postal address, privacy email or other durable contact method, any representative or data-protection officer, and the competent supervisory authority where required.