Legal

Privacy Policy

Effective Date: May 10, 2026  ·  Last Updated: May 10, 2026

1.

Overview

Booky.spa (“Booky.spa,” “we,” “us,” or “our”) provides a platform for discovering, booking, and paying for wellness, spa, and related services offered by independent partner shops. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our websites, applications, booking tools, dashboards, communications, and related services (the “Platform”).

By using the Platform, you acknowledge this Privacy Policy and our Terms of Service. If you use Booky.spa on behalf of a partner shop, this policy also applies to the information you provide or process through your shop dashboard.

2.

Information We Collect

We collect information you provide directly, information generated when you use the Platform, and information from partner shops or service providers. This may include:

  • Account information, such as name, email address, phone number, password credentials, and account preferences.
  • Booking information, such as selected shop, service, staff member, appointment time, cancellation details, notes, tips, reviews, and customer support requests.
  • Payment and transaction information, such as amounts, payment status, gift card or membership purchases, processor transaction identifiers, and limited billing details. We do not store complete payment card numbers.
  • Health and intake information you choose to provide for a booking, such as allergies, injuries, pregnancy status, preferences, contraindications, or other wellness-related notes.
  • Shop information, such as business details, services, staff, room availability, payroll-related records, customer lists imported by a shop, calendar settings, and publication settings.
  • Communications, such as email campaign preferences, unsubscribe choices, chatbot messages, support messages, and service-related notifications.
  • Device and usage information, such as IP address, browser type, pages viewed, timestamps, referring pages, approximate location derived from device or network signals, and diagnostic logs.
3.

How We Use Information

We use personal information to operate, improve, secure, and support the Platform. These uses include:

  • Creating and managing customer and shop accounts.
  • Processing bookings, cancellations, payments, deposits, balances, tips, gift cards, memberships, and refunds.
  • Sharing booking details with the partner shop responsible for providing the selected service.
  • Sending transactional emails, confirmations, reminders, review requests, account messages, security notices, and support replies.
  • Providing optional marketing communications where permitted by law and honoring opt-out or unsubscribe choices.
  • Connecting shop tools, such as calendars, payment processors, terminal devices, imports, exports, and email campaign features.
  • Monitoring, debugging, protecting, and improving Platform performance, reliability, fraud prevention, and security.
  • Complying with legal obligations and enforcing our agreements and policies.
4.

Health and Intake Information

The Platform may collect health-related or wellness intake information only when you provide it or when a partner shop records it in connection with your booking. We use this information to help the partner shop prepare for and provide the requested service. Booky.spa is not a healthcare provider and does not use this information to provide medical advice, diagnosis, or treatment.

Where supported by the Platform, sensitive intake information is protected with additional safeguards such as encryption and limited access controls. You should provide only information that is accurate and relevant to the service you are booking.

5.

How We Share Information

We share personal information only as reasonably needed for the Platform and as described in this policy, including with:

  • Partner shops, staff, or service providers involved in your booking or shop account.
  • Payment processors, terminal providers, banking providers, and fraud prevention services that process transactions for us or partner shops.
  • Email, hosting, database, storage, analytics, mapping, calendar, import/export, and support providers that help us operate the Platform.
  • Professional advisers, authorities, courts, regulators, or other parties when we believe disclosure is required by law or necessary to protect rights, safety, security, or prevent fraud.
  • Successors or counterparties in a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, subject to appropriate protections.

We do not sell personal information for money. We also do not share complete payment card details with partner shops.

6.

Third-Party Services

The Platform integrates with third-party services such as payment processors, calendar providers, email providers, mapping services, analytics tools, and authentication providers. Those services may process information according to their own privacy policies when you interact with them or connect them to your account.

7.

Cookies and Similar Technologies

We may use cookies, local storage, pixels, and similar technologies to keep you signed in, remember preferences, protect accounts, understand Platform usage, and improve performance. You can control cookies through your browser settings, but disabling them may prevent parts of the Platform from working correctly.

8.

Marketing Choices

If you opt in to marketing, we or a partner shop may send wellness tips, offers, campaign messages, or promotional updates. You can unsubscribe using the link in marketing emails or by contacting us. We may still send transactional or service-related messages even if you opt out of marketing.

9.

Data Retention

We retain personal information for as long as reasonably necessary to provide the Platform, maintain accurate business and transaction records, comply with legal obligations, resolve disputes, enforce agreements, and protect the Platform. Retention periods vary based on the type of information, account status, legal requirements, and operational needs.

10.

Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls and encryption for certain sensitive records. No system is perfectly secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed without authorization.

11.

International Transfers

Booky.spa is operated from Thailand and may use service providers in other countries, including the United States and other jurisdictions. Your information may be processed in countries with data protection laws different from those where you live. Where required, we use appropriate safeguards for cross-border transfers.

12.

Your Privacy Rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or portability of your personal information. You may also have the right to object to certain processing, withdraw consent where processing is based on consent, or lodge a complaint with a data protection authority.

Residents of certain U.S. states may have additional rights, including the right to know what categories of personal information we collect, use, disclose, or share; the right to request deletion or correction; and the right to opt out of certain targeted advertising or sale/share practices where applicable.

To make a privacy request, contact us using the details below. We may need to verify your identity before fulfilling a request.

13.

Children

The Platform is not intended for children under the age of 18 or the age of legal majority in their jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us so we can take appropriate action.

14.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Platform, by email, or by another reasonable method. The updated policy will be effective as of the date posted unless otherwise stated.

15.

Contact Us

For privacy questions, requests, or concerns, please contact us at:

Booky.spa
Hua Hin, Prachuap Khiri Khan, Thailand
Email: legal@booky.spa
General Inquiries: wellness@booky.spa

This Privacy Policy is publicly available at /privacy.

© 2026 Booky.spa - All rights reserved.