Privacy Policy
What personal data reaches us when you use Thailandka, why we have it, who else sees it, how long it lasts, and what you can ask us to do about it.
Effective 9 September 2026 · Last updated 9 September 2026
Thailandka compares places to stay in Thailand. There is no account, no login, no newsletter and no payment here, and we never ask you for anything about yourself.
The only personal data that reaches us is what your browser sends automatically to load a page: your IP address, a line of text called the user agent that names your browser and device, and the address of the page you asked for. The companies that host and deliver this site record those three things for every request, in a file called an access log. That is personal data, so this notice explains it properly.
What this site stores on your own device is a separate, short read — Cookies and browser storage.
Who we are
Thailandka is operated by to be supplied: registered company name, a company registered in Thailand under company registration number to be supplied: Thai company registration number, with its registered office at to be supplied: registered address in Thailand. We publish the site at www.thailandka.com. Under the Thai Personal Data Protection Act B.E. 2562 (the PDPA) and the EU General Data Protection Regulation (the GDPR), we are the controller of the data described here: we decide what is collected and why.
Privacy contact:to be supplied: privacy contact address(One address for everything in this notice, including any request about your personal data. There is no form to fill in — email is the whole process.)
We have not appointed a Data Protection Officer, and we are not required to — not under section 41 of the PDPA, nor under Article 37 of the GDPR. We are not a public authority, we compare places to stay rather than monitor people, we hold no sensitive data, and we handle data about far fewer people than the 100,000 the Thai regulator uses as its guide. We will run that test again before we start recording click-outs.
Our representative in the European Union (GDPR Article 27): to be supplied: EU representative (GDPR Art. 27). You can write to them instead of us, or as well as us, about anything to do with your personal data, and so can regulators. It moves no responsibility away from us: we stay accountable for everything in this notice.
Which law applies to this notice
We are a Thai company, so Thai data protection law — the PDPA — covers everything we do with personal data. It applies because we are based in Thailand, not because of where you are.
We have no office and no staff in the European Union. But we publish this site in Spanish and Italian at the same quality as English, and we want travellers who live in the EU to use it. So the GDPR applies to us for visitors in the EU and the EEA under its Article 3(2)(a), and this notice is written to meet it. This site is aimed at people in the EU, and we say so rather than pretend otherwise.
Because we have no office in the EU, no single EU regulator is ours. A complaint goes to the regulator in your own country, not to one we picked — see How to complain.
What we never ask you for
Nothing on this site asks you for personal data. There is:
- no account, no login and no password
- no contact form, no price alert and no newsletter
- no payment, no card details and no billing address
- no live chat, no support widget and no upload of any kind
No law and no contract requires you to give us anything, so there is nothing to withhold and nothing happens if you do.
One honest qualification. The one thing you can fill in is the search — where you want to go, your dates, how many of you there are, the filters you choose, any area you draw on the map. That is not information about you and we save none of it, but it travels in the web address of the results page, so it lands in the same access logs as every other page you open.
What we process, and why
Two things, and the second happens only if you write to us.
| What we receive | Why | Legal basis in Thailand | Legal basis in the EU and EEA | How long |
|---|---|---|---|---|
| Your IP address, your browser's user agent, and the address of every page you open here — search results and click-outs included | To send you the page you asked for, and keep the site up and safe from attack | Section 24(5) — our legitimate interests. We never ask for consent | Article 6(1)(f) — our legitimate interests, named below | to be supplied: hosting access-log retention, in days |
| What you send us if you email our privacy contact: your address, and whatever you write | Answering you, and keeping a record that we answered | Section 24(6) — a duty the PDPA itself puts on us | Article 6(1)(c), and Article 6(1)(f) for the record we keep | Two years from our reply |
Our legitimate interests, named, because European law wants the interests and not the label. Three: keeping this site available and working; protecting it and its visitors from attack and abuse; and meeting the record-keeping and disclosure duties that Thai law, the law of our place of establishment, puts on us. That third one is why a Thai retention duty appears below. A Thai statute cannot be an Article 6(1)(c) legal obligation in Europe, so we rely on Article 6(1)(f) for it and have recorded the balancing internally.
We ask you for nothing, and we store nothing about you in our own database — it holds properties and destinations, not people. Section 22 of the PDPA limits collection to what is necessary, and this is the least a website can receive and still answer a request. We collect no sensitive personal data as defined in section 26: health, disability, religion, race, political opinion, sexual behaviour. There is no accessibility filter here today; if we add one, such as step-free access, we will say what happens to it first.
And here is what we do not do with it. We do not measure you to improve our service, build a profile, personalise what you see, market to you or score you for fraud. We sell personal data to nobody, and share it with nobody beyond the providers below.
The language cookie is deliberately not in that table: it carries a two-letter code, identifies nobody, and we do not treat it as personal data — which is why this site shows no cookie banner. See Cookies and browser storage.
We do not ask for your consent
Under Thai law consent is the default, and section 24(5) is the exception we rely on: we may collect the data above without consent where it is necessary for our legitimate interests, and running and protecting a site you asked to see is one. Section 27 then lets us use and disclose what we collected that way — to the companies that run the site for us, and to a competent official where the law requires it — without asking separately for a consent we never had.
Because that is our basis and not your consent, you can object to it — see Your right to object.
What happens when you click through to a booking site
We send the partner nothing beyond what any ordinary outbound link conveys: the link itself, which names the property you tapped, and the fact that you came from Thailandka. With the settings this site and current browsers use, your browser sends them our address but not the page you were on. Once you land there, their privacy notice governs, not ours.
Why the click-out exists is in How we make money; what the link carries is in What happens when you click through.
Who else sees your data
Three companies are involved in running this site. We name them.
| Who | What they do for us | What they receive | Where |
|---|---|---|---|
| Cloudflare, Inc. | The network in front of our site: DNS, the edge that answers your connection, and protection against attack | Every request: your IP address, user agent and the page address, click-outs included | A United States company, with edge locations worldwide. Your connection is answered at the nearest |
| Vercel Inc. | Hosting: the servers that build each page and send it to you | The same: your IP address, user agent and the page address | A United States company. Pages are rendered in to be supplied: hosting regions where pages are rendered |
| MongoDB, Inc. (MongoDB Atlas) | The database behind our catalogue of properties and destinations | Nothing about you: it holds properties, not people, and no visitor data is written to it | A United States company, on one cloud region: to be supplied: database cluster region |
One more company sees personal data, and only if you write to us: the mailbox behind our privacy address is run by to be supplied: provider hosting our email, which receives your message and the address you sent it from.
Your browser talks to us and to the network that delivers our site, and to nobody else. Fonts are compiled in when we build the site, and photographs are fetched by our servers and served from our own domain, so your browser never contacts Google, Unsplash or Pexels. Nothing loads from a third party, nothing sets a third-party cookie, and no analytics provider, advertising network or chat tool could learn anything about your visit. The one call your browser may make elsewhere goes to an error-reporting address at our network provider: it fires only when a connection to us fails, and carries no page content.
One category we cannot rule out is public authorities: we may have to disclose access logs to a competent official under Thailand's Computer-Related Crime Act B.E. 2550, or to a court. Where the law lets us tell you, we will.
Where your data is processed
The short answer: nothing about this site runs in Thailand. We are a Thai company, but your browser connects to the network that delivers our site, which passes the request to our hosting provider's servers — Who else sees your data says where those are. European guidance does not treat what your own browser sends as a transfer made by us, because you are the one sending it, though the GDPR still governs what we do with it afterwards. What we pass on to those companies is a transfer, and a transfer needs a legal safeguard.
The safeguard we are putting in place is the standard contract the European Commission wrote for exactly this — the Standard Contractual Clauses, Implementing Decision (EU) 2021/914 — written into a data-processing agreement with each provider. Section 40 of the PDPA requires that written agreement anyway, and the Thai regulator accepts the same clauses as a section 29 safeguard, so one contract does both jobs. MongoDB receives no personal data at all, but section 40 applies whatever the data, so it is on the same list. We will not open this site to search engines before all three are signed, and this section will then name the clause version and date of each.
You are entitled to see a safeguard, not just be told it exists. All three publish their standard agreements — Cloudflare's, Vercel's and MongoDB's — and once ours are signed you can ask our privacy contact for a copy. We claim no adequacy decision for any country — the formal ruling that a country's protection is equivalent to Europe's. There is none covering Thailand, and none is needed for what you send us directly.
How long we keep your data
| What | How long | Who controls that |
|---|---|---|
| Access logs: your IP address, user agent and the page address | to be supplied: hosting access-log retention, in days, then deleted automatically | The companies that host and deliver this site, under their own retention policies. We do not extend them and hold no separate copy |
| An email you send our privacy contact, and our reply | Two years from our reply, then deleted | Us |
Section 37(3) of the PDPA wants a real erasure mechanism, not a promise. Ours is deliberately plain: we keep no second copy of the access logs and have built nothing that reads, exports or analyses them, so deletion is our providers' automatic expiry, not a task anyone must remember. When a plan changes we re-check the figure above first.
There is a Thai counterweight to that minimalism. The Computer-Related Crime Act may require a service provider to keep computer traffic data for at least ninety days, and to hand it to a competent official on a lawful request. Where it applies it sets a floor under the retention above — never more kinds of data, only the same data for longer. For an EU reader it rests on Article 6(1)(f), for the reason given in What we process, and why.
What this site stores on your own device — the language cookie and your light or dark choice — has its own lifetimes, in Cookies and browser storage. Neither is personal data to us, which is why neither is above.
Automated decisions and profiling
We make no automated decision that produces legal effects concerning you or similarly significantly affects you, and we do not profile you. There is no model of you here, because there is nothing to build one from.
The order in which properties appear is the same for every visitor: not personalised, dependent on nothing about you, and overridable with the sorts we offer. How it is computed is published in full in How we rank results.
Children
We ask no one for personal data, whatever their age, and nothing here is aimed at children. The only data that reaches us about any visitor, adult or child, is the access-log entry described above.
We would rather be straight about the limits. With no account and no sign-up we cannot know how old a visitor is, and an access log records a network address, not a person. The parental-consent rules — section 20 of the PDPA, Article 8 of the GDPR — apply where a site relies on consent, and we ask for none.
If you believe a child's data has reached us, write to our privacy contact with an approximate time and an IP address. We will tell you honestly what we can see and what we can do — which today means asking our providers, because we hold no copy of those logs and they expire on the providers' own schedule.
Your rights
Under the Thai PDPA, wherever you are:
- Withdraw consent — section 19
- Nothing to withdraw: we never ask for your consent.
- Access, and receive a copy — section 30
- Ask what we hold about you, get a copy, or ask where we got it.
- Data portability — section 31
- Covers only data collected with consent or under section 24(3). Our logs sit under 24(5), so there is nothing to port.
- Object — section 32
- Everything we do rests on legitimate interests, so this right matters most here.
- Erasure — section 33
- Ask us to erase your data or make it anonymous, including after an objection succeeds.
- Restriction — section 34
- Ask us to pause our use of the data while an objection is resolved.
- Rectification — section 36
- Ask us to correct data that is wrong, out of date, incomplete or misleading.
- Complain — section 73
- Complain to the Office of the Personal Data Protection Committee, without coming to us first.
Under the GDPR, in the EU or the EEA, you have the same rights under different numbers:
- Access — Article 15
- As above, plus a copy of the information in this notice.
- Rectification, erasure and restriction — Articles 16, 17 and 18
- As above. Erasure applies where an Article 17 ground is met.
- Portability — Article 20
- Reaches consent- and contract-based processing only, so it does not reach our logs either.
- Object — Article 21
- At any time, on grounds relating to your particular situation. See the next section.
- Withdraw consent — Article 7(3)
- We never use consent as a basis, so there is nothing to withdraw.
- Complain, and go to court — Articles 77 to 79
- A complaint to a regulator and a case in court, neither depending on the other.
One limitation applies to all of them. We hold no account and no profile, so usually we hold nothing linkable to you as a person, and we may have to say so — Article 11(2) of the GDPR allows for exactly that. Give us an approximate date, time and IP address and we will search whatever logs still exist.
Your right to object
If you object we stop, unless we can show compelling legitimate grounds that override your interests — and we will tell you which.
How to make a request, and how fast we answer
Email our privacy contact and say what you want. There is no form, no account and no template. The routes are also on How to send us a request.
Thai law gives us 30 days, and only the regulator can extend that — we cannot. European law gives one month, which in some months is shorter. We work to whichever is shorter for you, so 30 days is the longest you will ever wait.
We will ask you to identify yourself only if we genuinely cannot find your data otherwise, and then for the least that will do: a site with no accounts demanding a passport scan would be creating a privacy problem, not solving one. One warning, though. The only data we are likely to hold sits in access logs our providers keep and we do not query, so without a time window and the IP address you used, the honest answer will be that we cannot identify any of it as yours.
How we protect your data
Short, and limited to what we can evidence. The site is served over HTTPS everywhere, and connections are redirected to HTTPS before anything is sent. No personal data is written to our application database. The consoles for our network, hosting and database providers are reached only through individual named accounts protected by two-factor authentication.
Those are the measures the Thai regulator's 2022 security rules ask for: access control, identity checking, authentication. Section 37(1) of the PDPA requires us to review them when necessary or when the technology changes, and we do that before each release and whenever a provider or a plan changes.
If there is a data breach
If personal data here is breached, we tell the Office of the Personal Data Protection Committee — without delay, and within 72 hours of finding out where that is possible. The one exception is a breach posing no real risk to you. If a breach is likely to put you at high risk, we tell the people affected too, and say what we are doing about it. Articles 33 and 34 of the GDPR require the same of us in the EU and the EEA.
Two honest limits. We hold no email address for you, so we could not write to you personally; we would publish a notice prominently on this site, in every language we serve. And realistically a breach here means a compromise at a provider rather than in our own code, so we pass on any notification we get from them.
How to complain
In Thailand you may complain to the Office of the Personal Data Protection Committee (สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล) at pdpc.or.th, without coming to us first. We would like the chance to fix a problem, but that is a preference of ours, not a condition on a right the law gives you.
In the EU or the EEA, complain to the supervisory authority where you live, where you work, or where you think the problem happened. None of them is our lead regulator, so it is your own national authority you write to; the European Data Protection Board keeps the list of national data protection authorities. That does not require complaining to us first, and does not affect your right to go to court.
What we do not do today
None of the following runs on this site:
- live connections to the booking partners' systems — the catalogue you see is sample content used while we build
- affiliate tracking parameters on our outbound links
- any click log written by our own application
- website analytics, tag managers, advertising pixels, session recording and A/B testing tools
- any third-party cookie, and therefore any need for a cookie banner
In advance: a click record tied to an identifier would be personal data in a way today's logs are not, and affiliate parameters letting a partner recognise you across sites would be a disclosure to them and, for EU visitors, a consent question. See What changes when we add affiliate tracking.
Changes to this notice
We update this notice when the facts change — a new provider, a new kind of data, a change in the law. We post the new version with a new effective date, summarise what changed below, and keep previous versions so you can see what it said when you read it. The notice changes before the practice does, never after.
The language of this notice
The English text is the operative version. Translations are provided for convenience; if a translation and the English differ, the English governs.
This notice is only useful if you understood it. If any part is unclear in your language, write to our privacy contact and we will explain it, in your language. Spanish and Italian versions are under consideration — the two languages the European side of this analysis rests on. Until they exist, asking is the route.
Version history
| Version | Effective | What changed |
|---|---|---|
| 1.0 | 9 September 2026 | First published version, from the deployed pre-launch build: access logs as the only personal data collected automatically, three providers in the request path, no consent, no analytics, no click logging, no live partner connections. |