Last updated: January 15, 2025
Data Protection Officer (DPO)
Email: dpo@sabaifit.com
Phone: [DPO Contact - To be updated]
1. Information We Collect
1.1 Personal Information
- Account Information: Name, email address, phone number, date of birth
- Profile Information: Fitness goals, health information, location preferences
- Payment Information: Credit card details (processed securely through Stripe)
- Communication Data: Messages exchanged with trainers, support communications
- Usage Data: Session bookings, preferences, app interactions
1.2 Trainer-Specific Information
- Professional Credentials: Certifications, qualifications, work experience
- Identity Verification: Government ID, background check information
- Financial Information: Bank account details for payouts
- Availability Data: Schedule, location preferences, service areas
2. How We Use Your Information
2.1 Service Provision
- Facilitate trainer-customer matching and booking
- Process payments and manage credit transactions
- Enable communication between users
- Provide customer support
2.2 Legal Basis (PDPA Compliance)
- Contract Performance: To fulfill our service obligations
- Legitimate Interest: To improve our services and prevent fraud
- Consent: For marketing communications and optional features
- Legal Obligation: To comply with applicable laws and regulations
3. Information Sharing and Disclosure
3.1 With Trainers
We share necessary information with trainers to facilitate sessions, including:
- Customer contact information and fitness goals
- Session details and location information
- Health information relevant to training safety
3.2 With Service Providers
- Stripe: Payment processing and fraud prevention
- Supabase: Database hosting and authentication
- Vercel: Website hosting and CDN services
- Resend: Email delivery services
3.3 Legal Requirements
We may disclose information when required by law or to protect our rights and safety.
4. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption: Data encrypted in transit and at rest
- Access Controls: Role-based access with authentication
- Regular Audits: Security assessments and monitoring
- Data Minimization: We only collect data necessary for our services
5. Your Rights Under PDPA
You have the following rights regarding your personal data:
- Right to Access: Request copies of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for consent-based processing
To exercise your rights: Contact our DPO at dpo@sabaifit.com. We will respond within 30 days.
6. Data Retention
We retain personal data for the following periods:
- Account Data: Until account deletion or 3 years of inactivity
- Transaction Records: 7 years for financial compliance
- Communication Data: 2 years after last interaction
- Marketing Data: Until consent is withdrawn
7. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your login session
- Remember your preferences
- Analyze website usage and performance
- Provide personalized content
You can control cookie settings through your browser preferences.
8. International Data Transfers
Some of our service providers are located outside Thailand. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses and adequacy decisions.
9. Children's Privacy
Our service is not intended for children under 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through our service. Your continued use of the service constitutes acceptance of the updated policy.
11. Contact Information
Data Protection Officer: dpo@sabaifit.com
General Privacy Inquiries: privacy@sabaifit.com
Company Address: [Company Address - To be updated]
Phone: [Contact Number - To be updated]
This Privacy Policy complies with Thailand's Personal Data Protection Act (PDPA) and other applicable privacy laws.