Privacy Policy
Last updated: 06/18/2025
1. Introduction
B&H Pampering (« we, » « our, » or « us ») is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our booking platform for beauty and wellness services, in compliance with Thailand’s Personal Data Protection Act (PDPA) B.E. 2562 (2019).
2. Information We Collect
2.1 Booking and Account Information
When you make a reservation or create an account, we collect:
- Personal details: First name, last name, email address, phone number
- Service location: Full address, apartment/room number, access instructions
- Booking preferences: Service type, location choice, preferred time slots
- Account information: Username, password (encrypted), booking history
2.2 Service-Related Information
For service delivery purposes, we collect:
- Location data: Address verification through Google Maps API
- Access information: Building access codes, parking instructions, special directions
- Service notes: Any special requests or preferences you provide
- Appointment history: Record of services booked and completed (accessible to business owner only)
2.3 Payment Information
- Online payments: Credit/debit card information processed securely through Stripe
- Cash payments: Transaction records maintained in our Late Point booking system
- Billing information: Address and contact details for payment processing
2.4 Communication Data
- Service communications: SMS confirmations, appointment reminders, follow-up messages
- Support interactions: Information provided when contacting customer service
- Automated notifications: System-generated emails based on booking status
2.5 Automatically Collected Data
- Technical information: IP address, browser type, device information, operating system
- Usage data: Pages visited, booking patterns, service preferences
- Location data: Approximate location for service area verification (via Google Maps API)
- Analytics data: Website performance metrics through Google Analytics
3. How We Use Your Information
3.1 Essential Service Operations
- Booking management: Processing and confirming your service reservations
- Service delivery: Coordinating with therapists for appointment fulfillment
- Location services: Using Google Maps API to verify and optimize service delivery routes
- Payment processing: Handling transactions through Stripe or recording cash payments
- Communication: Sending booking confirmations, reminders, and service updates
3.2 Service Improvement
- Quality assurance: Maintaining service standards across all locations
- Booking optimization: Improving appointment scheduling and therapist coordination
- Customer experience: Personalizing services based on previous bookings and preferences
- Operational efficiency: Optimizing routes and scheduling for better service delivery
3.3 Business Operations
- Record keeping: Maintaining booking history and transaction records via Late Point system
- Customer support: Providing assistance with bookings, cancellations, and service inquiries
- Legal compliance: Meeting Thai business and tax requirements
4. Legal Basis for Processing
Under the PDPA, we process your personal data based on:
- Contract performance: To provide the beauty and wellness services you’ve booked
- Consent: For service preferences, marketing communications, and location services
- Legal obligation: To comply with Thai business and tax regulations
- Legitimate interest: For service improvement, fraud prevention, and business operations
5. Data Sharing and Disclosure
5.1 Service Providers and Partners
Therapists and Service Staff
- Shared information: Name, phone number, service address, appointment details
- Purpose: Enable service delivery and client contact for appointment coordination
- Access limitations: No access to payment information or full booking history
- Data security: All staff trained on confidentiality and data protection
Technology Partners
- Stripe: Secure payment processing for online transactions
- Google Maps API: Address verification and route optimization for service delivery
- Late Point: Booking system management and appointment scheduling
- Google Analytics: Website usage analysis and performance optimization
- SMS service providers: Appointment reminders and confirmations
5.2 Related B&H Websites
Information may be shared with our related platforms:
- B&H Relax: For massage service specialization
- B&H Beauty: For nail care and eyelash extension services
- B&H Shop: For product recommendations related to services booked
5.3 Legal Requirements
We may disclose information when required by Thai law or to:
- Comply with legal proceedings or government requests
- Protect our rights, property, or safety
- Prevent fraud or ensure service provider and client safety
6. International Data Transfers
Some of our service providers are located outside Thailand:
- Google services: Maps API and Analytics data processed globally with appropriate safeguards
- Stripe: Payment data processed within European data protection frameworks
- Cloud storage: Booking data may be stored on international servers with adequate protection
We ensure all international transfers comply with PDPA requirements and maintain appropriate data protection standards.
7. Data Retention
7.1 Booking and Service Data
- Active accounts: Data retained while account remains active
- Booking history: 3 years for service improvement and customer preferences
- Payment records: 7 years for tax and business compliance requirements
- Communication logs: 2 years for customer service quality assurance
7.2 Location and Technical Data
- Address information: Retained for future booking convenience until account deletion
- Location data: Google Maps API data processed according to Google’s retention policies
- Analytics data: 14 months (Google Analytics default)
- System logs: 1 year for technical support and security purposes
8. Location Services and Google Maps
8.1 Google Maps Integration
We use Google Maps API to:
- Verify addresses: Ensure accurate service delivery locations
- Optimize routes: Help therapists find efficient paths to appointments
- Service area validation: Confirm appointments are within our coverage areas
8.2 Location Data Processing
- Address geocoding: Converting addresses to coordinates for mapping
- Route calculation: Determining travel times and distances
- Area verification: Ensuring service availability in requested locations
- Privacy protection: Location data used only for service delivery purposes
9. Communication and Notifications
9.1 Service Communications
We may send you:
- Booking confirmations: Immediate confirmation of successful reservations
- Appointment reminders: SMS and email reminders before scheduled services
- Service updates: Notifications about therapist arrival times or schedule changes
- Follow-up messages: Post-service satisfaction surveys or feedback requests
9.2 Communication Preferences
You can manage communication preferences by:
- Account settings: Updating notification preferences in your account
- Opt-out links: Using unsubscribe options in emails
- Contact us: Requesting specific communication modifications
10. Your Rights Under PDPA
10.1 Access and Information Rights
- Data access: Request information about personal data we hold
- Booking history: Access your complete service and payment history
- Data portability: Receive your data in a portable format
10.2 Correction and Update Rights
- Profile updates: Modify personal information and preferences
- Address changes: Update service locations and contact details
- Preference modifications: Change service preferences and communication settings
10.3 Deletion and Objection Rights
- Account deletion: Request complete removal of your account and data
- Selective deletion: Remove specific data (subject to legal retention requirements)
- Processing objection: Object to certain types of data processing
- Consent withdrawal: Withdraw consent for non-essential processing
11. How to Exercise Your Rights
To exercise your privacy rights or for data-related inquiries:
Email: contact@bhpampering.com
Phone: +66 81 068 2096
Available: Monday – Sunday, 9:00 AM – 8:00 PM (Thailand time)
We will respond to your request within 30 days as required by the PDPA.
12. Data Security
12.1 Technical Safeguards
- Encryption: SSL encryption for all data transmission
- Secure payment processing: PCI DSS compliant payment systems
- Access controls: Role-based access to customer information
- System monitoring: Regular security updates and vulnerability assessments
12.2 Organizational Measures
- Staff training: Regular data protection training for all personnel
- Confidentiality agreements: All therapists and staff bound by confidentiality terms
- Limited access: Service providers only receive information necessary for service delivery
- Data minimization: Collection and retention limited to business needs
13. Service-Specific Privacy Considerations
13.1 In-Home Services
- Address privacy: Client addresses shared only with assigned therapists
- Access security: Building codes and access information handled confidentially
- Service discretion: Professional standards maintained for client privacy
13.2 Multi-Location Services
Our services across Bangkok, Phuket, Pattaya, Chiang Mai, and Koh Samui maintain consistent privacy standards regardless of location.
14. Third-Party Integrations
14.1 Late Point Booking System
Our booking platform processes:
- Appointment scheduling and management
- Customer profile and preference data
- Payment tracking for cash transactions
- Service history and booking analytics
14.2 Google Services Privacy
For information about how Google processes data through Maps API and Analytics, please refer to Google’s Privacy Policy: https://policies.google.com/privacy
15. Children’s Privacy
Our services are intended for adults (18+). We do not knowingly collect personal data from minors. If a minor requires services, parental consent and supervision are required.
16. Data Protection Officer
For privacy matters and PDPA compliance: Contact: Le Beschu Maixent
Email: contact@bhpampering.com
Role: Business owner and designated privacy contact
17. Complaints and Regulatory Contact
If you believe we have not handled your personal data appropriately, you may file a complaint with:
Thailand Personal Data Protection Committee
Office of the Personal Data Protection Committee
Ministry of Digital Economy and Society
18. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our services or legal requirements. Material changes will be communicated via:
- Email notification to account holders
- Prominent notice on our booking platform
- SMS notification for significant changes affecting service delivery
19. Multi-Platform Privacy
This Privacy Policy covers data processing across our integrated platform including related services accessed through B&H Relax, B&H Beauty, and referrals to B&H Shop.
20. Contact Information
B&H Pampering
Owner: Le Beschu Maixent
Email: contact@bhpampering.com
Phone: +66 81 068 2096
Service Areas: Bangkok, Phuket, Pattaya, Chiang Mai, Koh Samui
This Privacy Policy is governed by Thai law and complies with the Personal Data Protection Act (PDPA) B.E. 2562 (2019).