Privacy Policy
Last updated: 10/08/2026
This Privacy Policy ("Policy") explains how Tabu Co., Ltd. ("Tabu", "we", "us" or "our"), a company registered in Thailand under company registration number 0105569086462, collects, uses, discloses, transfers, retains and protects personal data when you access or use the Tabu mobile applications, website, operator dashboard and related services (together, the "Platform").
This Policy is issued in accordance with Thailand’s Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and other applicable data-protection laws. Thailand’s PDPA requires data controllers to provide information about matters including the purposes of processing, data collected, retention, recipients, contact information and data-subject rights.
This Policy should be read together with our Terms of Service, Cookie and Similar Technologies Policy, Refund & Cancellation Policy, Community Guidelines and any other privacy notice presented to you in connection with a particular feature.
By creating an account or using the Platform, you acknowledge that you have been provided with this Policy. Your use of Tabu does not constitute consent to every processing activity described in this Policy. Where the PDPA or another applicable law requires your consent for a particular activity, Tabu will seek that consent separately.
1. Summary
This section provides a short overview. The remainder of this Policy contains further detail.
Who we are: Tabu Co., Ltd. is generally the data controller responsible for the personal data described in this Policy.
What we collect: Depending on how you use Tabu, we may process account and profile data, Booking and Event information, payment and transaction information, Social Feature content, messages and communications, location information, device and usage data, and information supplied by Venues and service providers.
Why we use it: We use personal data to operate Tabu, create and secure accounts, process Bookings and payments, operate The Scene and other Social Features, provide location-based features, personalise discovery, prevent fraud and abuse, communicate with users, comply with law and, where applicable consent has been obtained, send marketing.
Who receives it: Information may be disclosed to Venues and Hosts you interact with, other users according to your Social Feature choices, service providers, professional advisers and authorities where appropriate.
We do not sell your personal data.
International processing: Tabu is based in Thailand. Certain providers process personal data outside Thailand, including in Singapore. Other processing locations will depend on the providers used by Tabu and are subject to the international-transfer provisions in Section 10.
Your rights: Subject to applicable law, you may have rights to access, correct, delete, restrict, object to or obtain certain personal data, withdraw consent and complain to Thailand’s Personal Data Protection Committee.
2. Who We Are
2.1 Data controller
The data controller responsible for this Policy is:
- Tabu Co., Ltd.
- Company registration number: 0105569086462
- Registered/contact address: 27/2 Sukhumvit 33 (Daeng Udom), Khlong Tan Nuea, Watthana, Krung Thep Maha Nakhon 10110
- Website: tabu.social
2.2 Privacy contact
For questions about this Policy or requests relating to your personal data:
Privacy contact: support@tabubookings.com
Tabu has not appointed a Data Protection Officer at the date of this draft. Tabu will keep its obligations under the PDPA under review and will appoint and publish the contact details of a Data Protection Officer if and when required by applicable law.
2.3 Regulator
You may have the right to submit a complaint to the Office of the Personal Data Protection Committee of Thailand ("PDPC") in accordance with applicable law.
3. Scope of This Policy
3.1 People covered
This Policy applies to personal data Tabu processes about:
- customers and other users of the Platform;
- users of The Scene and other Social Features;
- visitors to the Tabu website;
- people who contact Tabu;
- Venue and Host representatives who use Tabu’s operator dashboard or otherwise interact with Tabu in a business capacity; and
- other individuals whose personal data is provided to Tabu in connection with the Platform.
3.2 Third-party services
Tabu integrates with third-party services, including payment, mapping, authentication, cloud-hosting and communications providers.
The way a third party processes information depends on its role.
Where a provider processes personal data on Tabu’s behalf and under Tabu’s instructions, it may act as Tabu’s data processor.
Where a provider determines its own purposes or means of processing, including for its own regulatory, fraud-prevention or compliance obligations, it may act as an independent data controller for that processing and its own privacy notice may apply.
Tabu will not describe every third-party provider as a processor where that does not accurately reflect the relationship.
3.3 International users
Tabu is established in Thailand and the Platform initially focuses on Venues and Events in Thailand.
If you access Tabu from another country, applicable mandatory laws of that jurisdiction may also apply in certain circumstances.
Tabu does not rely merely on your use of the Platform as blanket consent to international processing or transfers.
4. Personal Data We Collect
The personal data we collect depends on which Tabu features you use.
4.1 Account and profile information
When you create and use a Tabu account, we may collect information including:
- name;
- username;
- email address;
- mobile number;
- date of birth;
- authentication credentials;
- profile photograph;
- profile biography;
- city or location information that you choose to provide; and
- account and profile settings.
Certain information is required to create or operate a Tabu account, while other profile information may be optional depending on the feature you use and the current Platform functionality.
Where you use Sign in with Apple or Google Sign-In, we receive the account information made available to Tabu by the relevant provider in accordance with your settings and that provider's rules.
4.2 Booking and Event information
When you browse, make or manage a Booking, we may process:
- the Venue or Event;
- Booking date and time;
- party size;
- table, space, seating or ticket type;
- Deposit and prepayment information;
- Booking status;
- cancellation status;
- Late Cancellation or No-Show status;
- check-in or attendance status;
- special requests;
- transfer information where Booking transfers are supported; and
- other information reasonably required to process or administer the Booking.
4.3 Payment and transaction information
Tabu processes information relating to payments, Deposits, Event purchases, Tabu Service Fees, Late Cancellation Charges, No-Show Charges, refunds and payment disputes.
Payment-card processing is provided through Omise / Opn Payments. Card details used to create a payment token are transmitted to Omise / Opn Payments through the payment flow. Tabu does not receive or store complete payment-card numbers or card security codes in Tabu-controlled systems.
To process, reconcile, secure and administer payments, Tabu stores payment and transaction information returned by Omise / Opn Payments. Depending on the payment method and information returned by Omise, this may include:
- payment or charge identifiers;
- payment status and amount;
- payment-method type;
- card brand;
- masked card information, including the last digits of a card number;
- card expiry information;
- cardholder name where returned;
- card or payment fingerprints or identifiers;
- issuing bank or country information where returned;
- authentication or 3-D Secure information;
- payment-risk or fraud-related information where returned; and
- related webhook and payment-processing information.
Tabu retains the payment-provider response associated with a transaction where reasonably necessary to administer the payment, maintain transaction records, handle refunds or disputes, prevent fraud and comply with applicable legal, accounting and regulatory requirements.
4.4 Social Feature information
When you use The Scene or other Social Features, Tabu may process:
- profile photographs and cover images;
- bios and public profile information;
- posts;
- stories;
- photographs and other uploaded content;
- captions;
- comments;
- emoji Reactions;
- tags and mentions;
- followers, following and friend relationships;
- Venue follows;
- content sharing;
- shared Booking or Event activity;
- blocks;
- user and content reports;
- moderation and enforcement information; and
- interactions with other users and accounts.
Tabu does not currently operate a public Venue-review system. Emoji Reactions to posts or stories are social interactions, not Venue ratings or reviews.
4.5 Direct messages
Where you use Tabu's messaging functionality, Tabu processes information necessary to deliver and operate those communications, including:
- participants;
- message content;
- attachments where supported;
- sending and delivery information; and
- related safety, reporting or moderation information.
Direct messages are stored within Tabu's Supabase-hosted Platform infrastructure.
Messages are protected using encrypted network connections during transmission and provider-managed protections for stored data. Direct messages are not end-to-end encrypted, which means authorised Platform systems may technically process message content where necessary to provide, secure or administer the messaging service.
Messages do not currently expire automatically merely because a particular period of time has passed.
Where an account is erased, Tabu is designed to anonymise the erased user's retained messaging records and remove message content, captions and associated media references from the relevant retained message records. Limited structural conversation information may remain so that the conversation history of other participants can continue to function.
Blocking another user does not necessarily delete previously stored messages. Blocking instead controls the relevant user's ability to interact with or view information through the Platform according to the applicable feature.
4.6 Communications with Tabu
We may collect information contained in:
- customer-support requests;
- complaints;
- payment or refund enquiries;
- enforcement appeals;
- reports submitted under the Community Guidelines;
- privacy requests;
- surveys;
- feedback; and
- other communications with Tabu.
5. Location Information
5.1 Device location
At launch, Tabu does not request, collect or continuously track the geographic location of your device through GPS or comparable device-location permissions.
Tabu does not currently request foreground or background device-location permission.
If Tabu introduces a feature in the future that requires access to precise or approximate device location, Tabu will update the relevant privacy disclosures and request any device permission or consent required before that functionality is used.
5.2 Why location is used
Tabu may process location-related information that does not come from your device's GPS location.
This may include:
- the address, neighbourhood or geographic information associated with a Venue or Event;
- a Venue or Booking that you choose to view, follow, book or share;
- a Venue that you voluntarily indicate you are attending or associated with; and
- other location-related information that you deliberately provide through a Social Feature.
Tabu may also display maps or map images associated with Venue locations.
5.3 Information visible to others
Tabu does not display your device's precise GPS coordinates to other users.
Depending on the relevant Social Feature and your actions or settings, other users may instead see information such as:
- a Booking you choose to share;
- a Venue you choose to indicate that you are attending;
- a Venue, Event or neighbourhood associated with content you share; or
- another social or location-related status that you choose to make visible through the Platform.
5.4 Location history
At launch, Tabu does not collect device GPS location and therefore does not maintain a history of your precise device location.
Venue-, Event- or neighbourhood-related information that you deliberately provide or share may be retained as part of the relevant Booking, Social Feature or Platform activity in accordance with the applicable retention provisions in this Policy.
6. Device, Usage and Derived Data
6.1 Device and technical information
Tabu and its providers may process device and technical information necessary to operate, secure and support the Platform.
Depending on the service used, this may include:
- device type and model;
- operating system;
- app version;
- browser or application information;
- language or regional settings;
- network and connection information;
- IP address or privacy-preserving identifiers derived from IP address;
- app installation or session identifiers used for diagnostics;
- Expo or device push-notification tokens; and
- technical and diagnostic information.
At launch, Tabu does not access Apple IDFA, Android Advertising ID or comparable advertising identifiers for cross-app tracking or behavioural advertising.
Tabu does not currently require Apple's AppTrackingTransparency permission.
If advertising or tracking technologies requiring additional disclosures, permissions or consent are introduced in the future, this Policy and the relevant Platform permissions will be updated before that processing begins.
6.2 Usage information
We may process information about how you use Tabu, including:
- pages and screens viewed;
- Venues and Events viewed;
- searches;
- Bookings;
- clicks and interactions;
- session activity;
- Social Feature use;
- content interactions;
- performance information; and
- errors or crashes.
6.3 Analytics and diagnostics
Analytics
At launch, Tabu does not use a dedicated third-party product analytics platform or analytics SDK to track user behaviour across the Platform.
Tabu may use operational information generated through its own Platform systems where reasonably necessary to operate, secure, debug and improve the service.
Tabu does not currently use session-replay or heatmap technology.
Crash and error monitoring
Tabu uses Sentry in the mobile application for crash, error and performance diagnostics.
Diagnostic information sent to Sentry may include:
- application version;
- device model and operating system;
- application installation or session identifiers;
- technical error and crash information;
- application-performance information; and
- technical events associated with the circumstances in which an error occurred.
Tabu configures its mobile diagnostic implementation to reduce the amount of personal information included in diagnostic events and to redact categories of sensitive or identifying information before transmission where technically supported.
Sentry is not configured by Tabu as an advertising or behavioural-marketing analytics service.
Diagnostic information is retained in accordance with Tabu's applicable Sentry account configuration and for as long as reasonably necessary for troubleshooting, service reliability, security and related technical purposes.
6.4 Personalisation and inferred information
Tabu may use information including:
- general location;
- Venues or Events viewed;
- search activity;
- previous Bookings;
- followed Venues;
- friends’ or connections’ activity where relevant;
- popularity or engagement; and
- other Platform activity
to personalise discovery and recommend Venues, Events or content.
Tabu may derive preference information or behavioural groupings from this activity.
Such information will not be used for unrelated purposes merely because it may be commercially useful to Tabu. Processing remains subject to the specific purposes and legal bases described in this Policy.
7. Sensitive Personal Data and Special Requests
7.1 Limited sensitive information
Certain Booking requests may involve information that could constitute sensitive personal data under the PDPA.
For example, a customer may voluntarily disclose:
- allergy or health-related information;
- accessibility requirements;
- disability-related requirements; or
- religious or dietary information
where relevant to a Booking.
7.2 Special-request information
Where you voluntarily include such information in a Booking special request, Tabu will use it only as reasonably necessary to:
- process the Booking;
- communicate the request to the relevant Venue or Host; and
- handle associated support or disputes.
Where the PDPA requires explicit consent for this processing, Tabu will obtain it separately or through an appropriately designed special-request flow.
Thai electronic-consent guidance recommends clear electronic privacy notices and consent records rather than treating unrelated acceptance as blanket consent.
7.3 Social content
Do not post sensitive personal data about another person through Social Features unless you are legally entitled to do so.
The fact that a user voluntarily posts sensitive information publicly does not give Tabu unrestricted rights to use that information for unrelated purposes.
8. How and Why We Use Personal Data
Tabu processes personal data only where there is an appropriate purpose and legal basis under applicable law.
| Purpose | Main basis |
|---|---|
| Create and manage your Tabu account | Performance of contract |
| Provide the Platform and core functionality | Performance of contract |
| Process Bookings, tickets, payments, Deposits and refunds | Performance of contract; legal obligations where applicable |
| Administer Late Cancellation and No-Show processes | Performance of contract; legitimate interests in administering and protecting the Booking system |
| Send Booking confirmations, reminders, security notices and essential service communications | Performance of contract; legitimate interests |
| Operate posts, stories, profiles, follows, comments, Reactions and messaging | Performance of the service requested by you; legitimate interests in operating the social service |
| Display social information you choose to share | Performance of the requested Social Feature and, where required, consent |
| Use precise device location | Consent/device permission where required |
| Provide local discovery and recommendations | Contract and/or legitimate interests; consent where required for underlying data |
| Personalise Venue, Event and content recommendations | Legitimate interests, subject to appropriate balancing; consent where required |
| Crash, error and performance diagnostics | Legitimate interests in maintaining the reliability, security and performance of the Platform; consent where specifically required by applicable law |
| Optional analytics or tracking technologies introduced in the future | Consent or another lawful basis where permitted and appropriate under applicable law |
| Security, Community Guidelines moderation and abuse prevention | Legitimate interests; legal obligations where applicable |
| Fraud detection and payment-risk management | Legitimate interests; legal obligations and payment requirements where applicable |
| Send marketing email, SMS, push or in-app promotions | Consent where required |
| Comply with tax, accounting, regulatory and legal requirements | Legal obligation |
| Respond to complaints and establish, exercise or defend legal claims | Legitimate interests; legal obligations where applicable |
| Corporate transactions and due diligence | Legitimate interests subject to confidentiality and applicable law |
Where Tabu relies on legitimate interests, it will consider the relevant business or safety interest, necessity of the processing and potential impact on individuals.
9. Marketing and Communications
9.1 Service communications
Tabu may send communications reasonably necessary to operate the Platform, including:
- account notices;
- Booking confirmations;
- Booking reminders;
- cancellation or Event updates;
- ticket information;
- payment and refund notices;
- security alerts;
- Community Guidelines enforcement notices;
- important Platform notices; and
- changes to legal terms where appropriate.
These are service communications rather than marketing.
9.2 Marketing
Tabu may send promotional communications about:
- Tabu;
- Venues;
- Events;
- offers;
- promotions; and
- recommendations
where Tabu has an appropriate lawful basis and any required consent.
Current intended channels include: email, SMS, push notifications and in-app communications.
9.3 Withdrawal
Where marketing is based on consent, you may withdraw your consent through the relevant settings, unsubscribe mechanism or privacy contact.
Withdrawal does not affect processing that lawfully occurred before withdrawal.
Device permission to receive push notifications and consent to receive promotional marketing are not necessarily the same thing, and Tabu will maintain appropriate marketing preferences separately where required.
10. Who We Disclose Personal Data To
10.1 Venues and Hosts
Where you make a Booking, Tabu shares information reasonably necessary for the relevant Venue or Host to administer and provide the booked service.
This may include:
- your name;
- phone number;
- email address;
- Booking date and time;
- party size;
- table, space or ticket details;
- special requests;
- payment or Deposit status where relevant;
- cancellation or No-Show information where relevant; and
- information reasonably necessary to address the Booking.
Venues and Hosts may become separate data controllers for information they lawfully receive and process for their own provision of the booked service, legal obligations and associated legitimate purposes.
Tabu’s Venue arrangements restrict use of guest information for unrelated purposes. A Venue must not treat a customer’s Tabu Booking as automatic permission to add that customer to its own marketing list.
10.2 Other Tabu users
Information is disclosed to other users according to the relevant Social Feature and your settings or actions.
This may include:
- profile information;
- posts and stories;
- follows and connections;
- comments and Reactions;
- tags and mentions;
- Bookings or Venues you choose to share; and
- general neighbourhood or location-related information where you choose or permit the relevant Social Feature.
Users may be able to save, screenshot or further share information they can legitimately see. Tabu cannot technically control all activity occurring outside the Platform after another person has viewed information.
10.3 Service providers
Tabu uses service providers and technology partners for functions including:
- cloud hosting, databases, authentication and storage, including Supabase;
- payment processing, including Omise / Opn Payments;
- mobile crash, error and performance monitoring, including Sentry;
- map and Venue-location image services, including Mapbox;
- third-party authentication, including Google and Apple;
- application build, update and push-notification infrastructure, including Expo / EAS;
- push-notification delivery, including Firebase Cloud Messaging and Apple Push Notification Service;
- email and SMS authentication or one-time-password delivery through Supabase Auth and the delivery providers configured for that service;
- image and media storage or delivery, including Supabase Storage and, where configured for the relevant feature, Cloudinary; and
- other infrastructure providers reasonably necessary to operate, secure and support the Platform.
Tabu does not currently use a dedicated third-party product-analytics provider.
Tabu does not currently use a separate third-party customer-support or live-chat platform. Customer-support and privacy enquiries are handled through Tabu's designated communication channels.
The exact role, processing location and technical configuration of a provider may depend on the relevant service and configuration used by Tabu.
10.4 Advisers and corporate transactions
We may disclose information where reasonably necessary to lawyers, accountants, auditors, insurers, investors, prospective buyers or professional advisers, subject to appropriate confidentiality and applicable law.
10.5 Authorities and legal disclosures
We may disclose information where required or permitted by law, including to courts, regulators, law-enforcement authorities or other competent bodies.
We may also make proportionate disclosures where reasonably necessary to protect users, investigate serious fraud or security incidents, or establish, exercise or defend legal claims.
10.6 No sale of personal data
Tabu does not sell personal data.
Tabu also does not currently provide identifiable customer information to advertising partners in exchange for payment or other consideration.
If Tabu’s business model materially changes, the relevant privacy disclosures and any required choices or consent must be updated before the new processing begins.
11. Cookies, SDKs and Similar Technologies
Tabu uses cookies and similar technologies as described in the separate Cookie and Similar Technologies Policy.
On Tabu's website, these technologies may include:
- strictly necessary authentication and session cookies used by Supabase to keep users securely signed in; and
- functional cookies used to remember preferences such as the user's selected language.
Tabu does not currently use advertising, behavioural-targeting, retargeting or third-party analytics cookies on the Platform.
The Tabu mobile application does not rely on browser cookies for ordinary application sessions. Application information may instead be stored locally on the device using mobile storage technologies necessary for functionality such as authentication and preferences.
The mobile application includes technologies used for functionality and diagnostics, including Supabase services, Expo technologies, push-notification functionality and Sentry crash/error monitoring.
Mapbox may receive technical connection information such as an IP address when map imagery is requested from its services.
Tabu does not currently access mobile advertising identifiers or use advertising or retargeting SDKs such as the Meta advertising SDK.
If Tabu introduces additional analytics, advertising or tracking technologies in the future, the relevant privacy disclosures, Cookie Policy, Apple App Privacy disclosures, Google Play Data Safety declarations and consent or permission mechanisms will be updated where required.
12. International Transfers
12.1 Processing locations
Tabu is based in Thailand.
Certain service providers process personal data outside Thailand, including in Singapore and other countries in which the relevant providers maintain infrastructure or personnel.
Where personal data is transferred outside Thailand, Tabu will apply the international-transfer safeguards described in Section 12.2 and any other measures required by applicable law.
12.2 Transfer safeguards
Where personal data is transferred outside Thailand, Tabu will use a transfer mechanism permitted by applicable law, which may include:
- transfer to a jurisdiction providing appropriate protection;
- appropriate contractual or organisational safeguards;
- transfers necessary for an applicable contractual purpose;
- another statutory exception; or
- consent where consent is genuinely the applicable lawful mechanism.
Tabu does not treat ordinary use of the Platform as blanket consent to every international transfer.
13. How Long We Keep Personal Data
Tabu retains personal data only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, tax, accounting, security, fraud-prevention, dispute and regulatory requirements.
The launch retention framework is as follows:
Account/profile data
Retained while the account is active and thereafter for as long as reasonably necessary to process an account-erasure request and satisfy applicable legal, security, fraud-prevention, dispute or other permitted retention requirements.
Where information is no longer required, Tabu will delete or anonymise it in accordance with the applicable account-erasure and technical deletion processes.
Booking and payment records relevant to accounting/tax
Generally at least 5 years and potentially longer where applicable legal, tax or accounting requirements require or permit longer retention.
Refund, dispute and chargeback records
For the duration of the relevant matter and thereafter for a reasonable period necessary for accounting, evidentiary, fraud-prevention and legal purposes.
No-Show and Booking-enforcement records
For as long as reasonably relevant to Booking administration, enforcement, disputes, safety or legal claims.
Posts, stories, comments and profile content
Until deleted, expired by feature design or the relevant account is erased, subject to moderation, safety, dispute and legal-retention requirements.
Direct messages
Direct messages do not currently have an automatic time-based expiry.
They are retained while required to provide the messaging service.
Where the relevant account is erased, Tabu is designed to anonymise the erased user's retained message records and remove message content, captions and associated media references from the retained records while preserving limited structural information where necessary for other participants' conversation history.
User reports and moderation records
For the period reasonably necessary for safety, enforcement, appeals, dispute handling and legal compliance. Serious matters may be retained for longer where reasonably necessary.
Device location records
Not applicable at launch because Tabu does not currently collect device GPS location.
Venue-, Event- or neighbourhood-related information voluntarily provided or shared by a user is retained according to the retention period applying to the relevant Booking or Social Feature.
Security, access, error and audit logs
Retained for security, service-integrity, fraud-prevention, debugging, auditing, incident-investigation and legal purposes.
The applicable retention period is determined according to the continuing necessity of the relevant record and applicable technical and legal requirements rather than a single fixed retention period for every type of log.
Product analytics data
Tabu does not currently operate a dedicated third-party product-analytics system.
Mobile crash and diagnostic information
Retained according to Tabu's configured diagnostic-provider settings and for as long as reasonably necessary for troubleshooting, Platform reliability, security and related technical purposes.
Marketing preferences
Retained while relevant to the account and marketing relationship and for as long as reasonably necessary to record and respect an opt-out.
Evidence of consent or withdrawal
Retained for the period reasonably necessary to demonstrate compliance and establish, exercise or defend legal claims.
Customer-support records
Retained for as long as reasonably necessary to respond to and manage the relevant request, complaint or dispute and to satisfy applicable legal obligations.
Venue/operator account records
Retained during the business relationship and for relevant legal, accounting, audit, security and dispute periods thereafter.
Irreversibly anonymised statistics
May be retained without a fixed personal-data retention period where the information no longer identifies or can reasonably be linked to an individual.
13.1 Account deletion
You may request deletion of your Tabu account and associated personal data through the privacy-contact channel described in this Policy.
At launch, account-deletion requests are handled through Tabu's internal support and privacy process rather than through a self-service deletion function within the Platform.
When Tabu processes an account-erasure request, the account may first be disabled or marked for deletion while the required technical and compliance steps are completed.
Tabu will delete or anonymise personal data that it no longer requires, subject to lawful retention requirements.
For Social Features, Tabu's systems are designed to delete or anonymise the erased user's relevant account information and content.
Where necessary to preserve another user's conversation history, limited structural message records may remain, but the erased user's identity and retained message content are designed to be removed or anonymised.
Tabu may retain limited information where reasonably necessary to:
- comply with tax or accounting requirements;
- complete or evidence an existing Booking, payment, refund or dispute;
- prevent fraud, abuse or security incidents;
- preserve necessary safety or moderation evidence;
- establish, exercise or defend legal claims; or
- comply with another legal obligation.
13.2 Backups
Personal data removed from active systems may remain temporarily in backups maintained by Tabu's infrastructure providers.
Backup copies are retained and overwritten or deleted according to the applicable provider and Platform backup cycle.
Information retained only in backup systems is not ordinarily accessed or used for normal Platform operations and may be restored only where reasonably necessary for disaster recovery, security, service continuity or similar operational purposes.
Where a backup is restored, Tabu will take reasonable steps to ensure that previously processed deletion or erasure requirements continue to be respected.
14. Your Rights
Subject to the PDPA and applicable conditions or exceptions, you may have rights relating to your personal data, including rights to:
- access certain personal data and obtain a copy;
- correct inaccurate or incomplete information;
- request deletion in applicable circumstances;
- request restriction of processing in applicable circumstances;
- object to certain processing;
- withdraw consent where processing relies on consent;
- receive or transfer certain personal data where the portability right applies; and
- lodge a complaint with the PDPC.
14.1 How to make a request
At launch, Tabu does not provide a self-service tool for formal PDPA access, portability, deletion or similar privacy requests.
Some ordinary account or profile information may be editable through the functionality made available within the Platform.
For privacy requests, including requests relating to access, correction, deletion, restriction, objection, portability or withdrawal of consent, contact: support@tabubookings.com
Tabu may take reasonable steps to verify your identity before responding.
14.2 Requests and exceptions
Tabu will respond within the period required by applicable law.
A request may be limited or refused where permitted by law, including where Tabu must retain information to comply with a legal obligation, protect another person’s rights, address fraud or security, or establish, exercise or defend legal claims.
Where Tabu cannot fulfil a request, it will explain the basis for that decision where required and permitted.
14.3 No general imported "excessive request fee"
Tabu does not intend to charge users simply for exercising PDPA rights.
The previous Privacy Policy wording allowing a general fee for "manifestly unfounded, excessive or repetitive" requests has been removed pending any specific Thai-law basis identified by counsel.
15. Automated Processing, Moderation and Fraud Detection
15.1 Current automated processing
At launch, Tabu does not use automated profiling, behavioural scoring or automated moderation systems to make decisions about users that produce legal or similarly significant effects.
Tabu also does not currently operate an automated consumer-account suspension or banning system based on profiling or automated evaluation of a user's personal characteristics.
15.2 Automated Platform mechanics
Certain Platform functions may operate automatically according to predetermined technical or contractual rules.
For example, booking, checkout, ticket or payment holds may expire or be released when the applicable time period expires or a payment fails.
Tabu's authentication infrastructure may also temporarily rate-limit repeated authentication or verification requests for security and service-protection purposes.
These processes are deterministic Platform mechanics and are not intended to evaluate a user's personality, behaviour or personal characteristics for profiling purposes.
15.3 Payment-provider systems
Payment processors, banks, card networks and other financial-service providers may independently use automated systems to authenticate, approve, reject or assess payment transactions, including for fraud and risk-management purposes.
Where such processing is undertaken by Omise / Opn Payments or another independent provider for its own payment, regulatory or fraud-prevention purposes, that provider's own privacy information may also apply.
If Tabu later introduces automated profiling or decision-making that produces legal or similarly significant effects, Tabu will review the relevant legal basis, safeguards and disclosure requirements before that functionality is introduced.
16. Security
Tabu maintains technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, misuse or disclosure.
Depending on the relevant system and information, these measures include:
- encrypted network connections for information transmitted between Platform components and service providers;
- provider-managed encryption and other protections for information stored within cloud infrastructure;
- authentication, authorisation and role-based access controls;
- row-level and other data-access controls in relevant parts of the Platform, including Social Feature systems;
- private storage controls and access-restricted delivery of user media where applicable;
- restricted access to production systems and server-side service credentials;
- audit and security-event logging for relevant administrative and system activity;
- verification controls for payment-related webhook events and server-side payment processing;
- server-side determination of payment amounts rather than reliance on user-supplied payment values;
- credential, API-key and secrets-management practices;
- diagnostic-data filtering and redaction intended to reduce the transmission of sensitive or identifying information to diagnostic providers; and
- development and review practices designed to reduce security risks, particularly for changes affecting authentication, payments and personal data.
Access to personal data is restricted to personnel and providers requiring such access for authorised purposes and subject to appropriate confidentiality and security obligations.
Tabu does not claim that every Platform database table uses the same technical access-control mechanism, and security measures may differ according to the relevant service and system architecture.
No information system can guarantee absolute security.
17. Personal Data Breaches
Tabu will maintain procedures to identify, assess, contain, document and respond to personal-data breaches.
Where a breach triggers notification obligations under the PDPA, Tabu will notify the PDPC and affected individuals as required by applicable law.
18. Children and Age Requirements
18.1 Minimum age.
You must be at least 13 years old to create or maintain a Tabu account or use Tabu’s general Platform and Social Features.
18.2 Users under legal adulthood.
If you are under the age at which you may independently enter into the relevant agreement, provide a particular consent, or exercise a particular right under applicable law, Tabu may require the consent or involvement of your parent, legal representative or person exercising parental responsibility before allowing the relevant activity.
Under Thailand’s Personal Data Protection Act B.E. 2562 (2019), additional requirements apply to the processing of personal data and consent involving minors. Tabu will obtain consent from a parent, legal representative or person exercising parental responsibility where required by applicable law.
18.3 Age-restricted Venues and Events.
Being eligible to hold a Tabu account does not mean that you are eligible to make every Booking or attend every Venue or Event. Venues and Events may impose separate minimum-age, identification and admission requirements. Users must satisfy the requirements disclosed for the relevant Booking.
In particular, where a Venue, Event or activity is legally restricted to persons aged 20 or older, a user under 20 may not use Tabu to circumvent that restriction or make a Booking that they are not legally eligible to use.
18.4 Age verification.
Tabu may request your date of birth, identification or other reasonable evidence where necessary to verify eligibility for an age-restricted Booking, comply with law, protect users or enforce the Terms.
18.5 Personal data of minors.
Tabu does not knowingly process the personal data of minors in a manner that violates applicable law. If Tabu learns that personal data has been collected or processed without consent or another lawful basis required for that minor, Tabu will take appropriate steps, which may include restricting the relevant feature, obtaining the necessary consent, or deleting the affected personal data.
18.6 Privacy choices.
Certain optional activities, including precise location sharing, marketing, sensitive personal-data processing and other consent-based features, may require additional consent or parental/legal-representative involvement where required by applicable law.
19. Venue and Host Representatives
Where you use Tabu on behalf of a Venue or Host, Tabu may process:
- your name;
- work email;
- work telephone number;
- employer or organisation;
- role;
- account/authentication information;
- dashboard activity;
- support communications;
- Booking administration actions;
- settlement-related activity; and
- security and audit information.
Tabu uses this information to administer and secure its relationship with the Venue or Host, operate the dashboard, provide support, maintain appropriate records, prevent fraud and comply with law.
The applicable legal basis may include legitimate interests, performance or administration of the relevant business relationship and legal obligations.
19.1 Omise KYC
Where Omise / Opn Payments requires a Venue or Sub-Merchant to complete payment-provider Know Your Customer or other compliance verification, Tabu's current Platform does not provide a function for uploading or storing those formal KYC documents within Tabu's own systems.
The intended onboarding process is for the relevant Venue or Sub-Merchant to provide required KYC information and documents through the applicable Omise / Opn Payments onboarding or verification process.
Tabu may receive information necessary to administer the payment relationship, such as:
- Venue or Sub-Merchant identifiers;
- linked payment-account information;
- onboarding or verification status;
- information indicating that additional verification or action is required; and
- other limited information reasonably necessary to administer the payment integration.
Tabu does not currently maintain a repository for directors' identity documents, shareholder or beneficial-owner identity documents, bank documents or comparable formal Omise KYC files.
If Tabu later receives or retains additional KYC information for a Venue, Sub-Merchant or other compliance purpose, this Policy will be updated where necessary to describe the relevant categories of information, purposes, recipients and retention.
20. Third-Party Links and Independent Services
The Platform may contain links to third-party websites, apps or services.
Where you leave Tabu and interact independently with another service, that service’s own privacy practices apply.
This is different from a provider processing personal data on Tabu’s behalf, which remains subject to Tabu’s applicable processor and vendor-management obligations.
21. Changes to This Policy
Tabu may update this Policy where its practices, technology, features, providers or legal obligations change.
The revised Policy will display an updated "Last updated" date.
Where a change materially affects how personal data is processed, Tabu will provide appropriate additional notice where required.
A new Privacy Policy does not, by itself, constitute consent to a new processing activity where consent or another additional legal step is required.
Where a new purpose requires consent, Tabu will obtain that consent before relying upon it.
22. Contact Us
For questions, requests or complaints about this Policy or Tabu’s processing of personal data:
- Tabu Co., Ltd.
- Company registration number: 0105569086462
- Address: 27/2 Sukhumvit 33 (Daeng Udom), Khlong Tan Nuea, Watthana, Krung Thep Maha Nakhon 10110, Thailand
- Privacy email: support@tabubookings.com
- Website: tabu.social
Note: You may also have the right to submit a complaint to the Office of the Personal Data Protection Committee of Thailand.