HomePrivacy

Privacy policy

Last updated · May 2026

Your privacy matters to us. This policy explains how we collect, use, and protect your personal information when you visit our cafe or use our website.

1. Introduction

Baboon Phuket ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at baboonphuket.com or dine at our establishment.

We comply with the Thailand Personal Data Protection Act (PDPA) B.E. 2562 (2019) and relevant international data protection standards.

2. Information We Collect

Personal Information You Provide

When you make a reservation or contact us, we may collect:

  • Full name
  • Email address
  • Phone number (including country code)
  • Reservation details (date, time, party size, seating preference)
  • Special requests or dietary requirements
  • Payment information (processed securely via Stripe)

Automatically Collected Information

When you visit our website, we automatically collect:

  • IP address and approximate location
  • Browser type and version
  • Device information
  • Pages visited and time spent
  • Referring website

3. How We Use Your Information

We use your personal information for the following purposes:

  • Reservation Management: To confirm, modify, or cancel your table reservation
  • Communication: To send booking confirmations, reminders, and respond to enquiries
  • Payment Processing: To process deposits and manage refunds
  • Service Improvement: To understand guest preferences and enhance our offerings
  • Legal Compliance: To comply with applicable laws and regulations
  • Marketing: With your explicit consent, to send promotional communications

4. Legal Basis for Processing

We process your personal data based on:

  • Contract: Necessary for fulfilling your reservation
  • Consent: Where you have given explicit permission
  • Legitimate Interest: For improving our services and security
  • Legal Obligation: To comply with Thai law

5. Information Sharing

We do not sell your personal information. We may share data with:

  • Service Providers: Stripe (payments), Supabase (database), Resend (emails), Vercel (hosting)
  • Legal Authorities: When required by law or to protect our rights
  • Business Transfers: In the event of a merger or acquisition

All third-party service providers are contractually obligated to protect your data and may only use it for the specific services they provide to us.

6. Data Retention

  • Reservation Records: Retained for 24 months for service and accounting purposes
  • Contact Submissions: Retained for 12 months
  • Payment Records: Retained for 7 years as required by Thai tax law
  • Analytics Data: Retained for 26 months

You may request earlier deletion of your data at any time.

7. Your Rights

Under the PDPA, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data
  • Restriction: Limit how we process your data
  • Data Portability: Receive your data in a structured format
  • Objection: Object to certain processing activities
  • Withdraw Consent: Withdraw previously given consent

To exercise these rights, contact us at info@baboonphuket.com. We will respond within 30 days.

8. Data Security

We implement appropriate security measures including:

  • SSL/TLS encryption for all data transmissions
  • Encrypted data storage at rest
  • Access controls and authentication
  • Regular security audits and updates
  • Staff training on data protection

While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

9. International Data Transfers

Some of our service providers operate outside Thailand. When we transfer data internationally, we ensure appropriate safeguards are in place to protect your information in accordance with the PDPA.

10. Cookies

Our website uses cookies to enhance your experience. For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.

11. Children's Privacy

Our services are not directed to individuals under 20 years of age. We do not knowingly collect personal information from minors. If we discover that we have collected data from a minor without parental consent, we will delete it promptly.

12. Updates to This Policy

We may update this Privacy Policy periodically. The "Last Updated" date will reflect any changes. We encourage you to review this policy regularly. Continued use of our services after changes constitutes acceptance of the updated policy.

13. Contact Us

For any privacy-related questions or to exercise your rights: