Privacy Policy
Last updated: 7 September 2026
This Privacy Policy ("Policy") explains how Tabu Co., Ltd. ("Tabu", "we", "us" or "our"), a company registered in Thailand under company registration number 0105569086462, collects, uses, discloses, transfers, retains and protects personal data when you access or use the Tabu mobile applications, website, operator dashboard and related services (together, the "Platform").
This Policy is issued in accordance with Thailand’s Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and other applicable data-protection laws.
This Policy should be read together with our:
- Customer Terms of Service;
- Refund & Cancellation Policy;
- Community Guidelines & Acceptable Use Policy;
- Cookie & Similar Technologies Policy; and
- any additional privacy notice presented to you in connection with a particular feature.
By creating an account or using the Platform, you acknowledge that you have been provided with this Policy.
Your use of Tabu does not constitute consent to every processing activity described in this Policy. Where consent is required under the PDPA or another applicable law, Tabu will seek that consent separately.
Capitalised terms not defined in this Policy have the meanings given in the Customer Terms of Service.
1. Summary
This Section provides an overview of Tabu’s privacy practices. The remainder of this Policy provides further detail.
1.1 Who we are
Tabu Co., Ltd. is generally the data controller responsible for the personal data described in this Policy.
1.2 What we collect
Depending on how you use Tabu, we may process:
- account and profile information;
- Booking and Event information;
- payment and transaction information;
- Social Feature content and activity;
- messages and communications;
- device and location information;
- technical and usage information;
- support and complaint information;
- information concerning Venue and Host representatives; and
- information received from service providers and other parties involved in providing the Platform.
1.3 Why we use it
We process personal data to:
- create and secure accounts;
- operate the Platform;
- process Bookings, tickets and payments;
- operate The Scene and other Social Features;
- provide location and nearby-user functionality;
- personalise discovery;
- provide customer support;
- communicate with users;
- prevent fraud, abuse and security incidents;
- enforce applicable Platform rules;
- comply with legal and regulatory obligations; and
- send marketing where we have an appropriate lawful basis and any required consent.
1.4 Who receives it
Personal data may be disclosed to:
- Venues and Hosts;
- other Tabu users through Social Features;
- service providers;
- payment providers;
- professional advisers;
- authorities where required or permitted by law; and
- other parties described in this Policy.
1.5 We do not sell personal data
Tabu does not sell your personal data.
1.6 International processing
Tabu is based in Thailand. Certain service providers may process or store personal data outside Thailand, including in Singapore and other countries in which those providers operate.
1.7 Your rights
Subject to applicable law, you may have rights to:
- access personal data;
- correct it;
- request deletion;
- restrict certain processing;
- object to certain processing;
- withdraw consent;
- obtain or transfer certain personal data; and
- complain to Thailand’s Personal Data Protection Committee.
2. Who We Are
2.1 Data controller
The data controller responsible for this Policy is:
- Tabu Co., Ltd.
- Company registration number: 0105569086462
- Registered address: 27/2 Sukhumvit 33 (Daeng Udom), Khlong Tan Nuea, Watthana, Krung Thep Maha Nakhon 10110, Thailand
- Website: tabu.social
2.2 Privacy contact
For questions about this Policy, complaints about our processing of personal data or requests to exercise your privacy rights:
Email: support@tabubookings.com
2.3 Data Protection Officer
Tabu has not appointed a Data Protection Officer at the date of this Policy.
Tabu will keep its obligations under the PDPA under review and will appoint and publish the contact details of a Data Protection Officer if and when required by applicable law.
2.4 Regulator
You may have the right to submit a complaint to the Office of the Personal Data Protection Committee of Thailand ("PDPC") in accordance with applicable law.
3. Scope of This Policy
3.1 People covered
This Policy applies to personal data Tabu processes about:
- customers and other users of the Platform;
- users of The Scene and other Social Features;
- visitors to Tabu’s website;
- people who contact Tabu;
- Venue and Host representatives who use Tabu’s operator dashboard or otherwise interact with Tabu in a business capacity; and
- other individuals whose personal data is provided to Tabu in connection with the Platform.
3.2 Third-party services
Tabu integrates with third-party services for functions including:
- cloud infrastructure;
- authentication;
- payments;
- mapping;
- mobile application services;
- push notifications;
- diagnostics;
- email and SMS delivery; and
- other Platform functionality.
The legal role of a third party depends on the relevant processing.
Where a provider processes personal data on Tabu’s behalf and under Tabu’s instructions, the provider may act as a data processor.
Where a provider determines its own purposes or means of processing, including for its own payment, regulatory, fraud-prevention, security or compliance obligations, it may act as a separate data controller and its own privacy notice may also apply.
3.3 International users
Tabu is established in Thailand and initially focuses on Venues and Events in Thailand.
If you use Tabu from another country, mandatory laws of that jurisdiction may also apply in certain circumstances.
Tabu does not treat ordinary use of the Platform as blanket consent to international transfers or processing.
4. Personal Data We Collect
The personal data we collect depends on how you use the Platform.
4.1 Account and profile information
When you create and use a Tabu account, we may collect:
- name;
- username;
- email address;
- mobile number;
- date of birth;
- authentication information and identifiers;
- profile photograph;
- cover photograph;
- profile biography;
- gender or pronoun information;
- city, neighbourhood or other location information you provide;
- account settings;
- privacy and Social Feature settings; and
- other profile preferences.
Gender or pronoun information may be used for profile presentation and to enable Tabu to use appropriate pronouns or other user-facing language in connection with your account.
Certain information is required to create or operate a Tabu account, while other information may depend on the features you choose to use.
Where you use Google Sign-In or Sign in with Apple, Tabu receives information made available through the relevant provider according to the applicable authentication flow and your settings.
Tabu does not currently use Facebook Login or LINE Login.
4.2 Booking and Event information
When you browse, request, make, purchase, transfer or manage a Booking or Event ticket, we may process information including:
- the Venue or Event;
- Booking or Event date;
- time;
- party size;
- table, space, seating or ticket type;
- Booking Request or confirmation status;
- Deposit or other prepayment;
- payment status;
- cancellation status;
- Late Cancellation status;
- No-Show status;
- attendance or check-in information;
- special requests;
- Booking or ticket transfer information;
- applicable Booking conditions; and
- other information reasonably necessary to process and administer the Booking or Event.
5. Payment and Transaction Information
5.1 Omise / Opn Payments
Tabu uses Omise / Opn Payments for payment processing.
Tabu may process information concerning:
- Booking payments;
- Deposits;
- Event ticket purchases;
- Event table packages;
- Tabu Service Fees;
- Late Cancellation Charges;
- No-Show Charges;
- refunds;
- payment corrections;
- disputes; and
- chargebacks.
5.2 Card information
When you enter payment-card information through the Tabu payment flow, your card details are transmitted directly from your browser or device to Omise / Opn Payments for tokenisation and payment processing.
Tabu does not receive or store your complete payment-card number or card security code in Tabu-controlled systems.
Omise returns a token or payment source that allows the payment to be processed.
For some payment methods, including certain 3-D Secure or wallet flows, you may be redirected to an Omise-controlled or other payment-provider page. Technologies operating on that external page are subject to the relevant provider’s privacy and technology practices.
5.3 Payment metadata
Tabu stores transaction and payment information returned by Omise where reasonably necessary to administer and evidence transactions.
Depending on the transaction and the information returned by Omise, this may include:
- payment, charge or transaction identifiers;
- payment amount;
- payment status;
- payment-method type;
- card brand;
- masked card information, such as the last digits of the card number;
- card expiry information;
- cardholder name where returned;
- card or payment fingerprints or other identifiers;
- issuing country or bank information where returned;
- authentication or 3-D Secure information;
- payment-risk or fraud information where returned; and
- webhook and other payment-processing information.
We retain relevant payment records where reasonably necessary to:
- process and reconcile transactions;
- administer refunds;
- manage disputes and chargebacks;
- prevent fraud;
- maintain accounting and tax records; and
- comply with legal and regulatory obligations.
6. Social Features and The Scene
6.1 Social Feature information
When you use The Scene or other Social Features, Tabu may process:
- profile photographs;
- cover images;
- biographies and profile information;
- posts;
- stories;
- photographs and other uploaded content;
- captions;
- comments;
- emoji Reactions;
- tags and mentions;
- followers;
- following relationships;
- friend and connection relationships;
- Venue follows;
- content sharing;
- shared Booking or Event activity;
- blocks;
- user and content reports;
- moderation and enforcement information;
- location and co-presence settings; and
- other Social Feature interactions.
Tabu does not currently operate a public Venue-review system.
Emoji Reactions to posts or stories are social interactions and are not Venue ratings or verified Venue reviews.
6.2 Messages and private communications
Where you use messaging or other private communication features within The Scene, Tabu may process:
- the participants;
- message content;
- captions;
- attachment or media references where supported;
- timestamps;
- related conversation information;
- blocking information; and
- safety, reporting or moderation information.
Messages are stored within Tabu’s Supabase-hosted infrastructure.
Messages are protected using encrypted network connections during transmission and provider-managed protections for stored data.
Messages are not end-to-end encrypted. Authorised Platform systems may therefore technically process message content where necessary to provide, secure or administer the service.
Messages do not currently have an automatic time-based expiry.
Blocking another user does not itself delete messages that were already stored.
7. Location Information
7.1 Foreground device location
The Scene includes location-based functionality.
When you use the relevant Scene map functionality and grant Tabu location permission, Tabu may collect your device’s foreground location.
Depending on your device settings, the location may be precise or approximate.
Tabu does not currently request or use background location permission for this functionality.
Location collection stops when the relevant map screen is no longer active in the foreground.
While the Scene map is active, the application may:
- obtain an initial location;
- obtain updated locations when significant movement occurs; and
- refresh the location periodically while the map remains active.
7.2 Ghost Mode and location publication
Tabu provides privacy and visibility controls for location functionality, including Ghost Mode.
When Ghost Mode prevents location publication, the Platform does not publish your location through the applicable Scene location feature.
Other Scene privacy, blocking and visibility rules may also affect whether location-related information is available to another user.
7.3 Scene map and nearby users
Where the applicable sharing conditions are satisfied, Tabu may use your permitted foreground location to:
- display your position through the Scene map;
- determine nearby users or friends;
- provide local Social Feature functionality; and
- support other location-based Scene experiences.
Tabu may use geographic coordinates internally to provide this functionality.
The nearby-user functionality applies sharing, Ghost Mode, friendship and blocking rules before returning information to other users and does not provide another user with your raw latitude and longitude coordinates.
However, another user may still be able to infer your approximate physical location from your displayed position on the Scene map.
Where your displayed position appears at or close to a Venue, another user may also be able to infer that you are at or near that Venue.
A Booking is not automatically shared merely because you made it. Booking-sharing functionality is separate.
7.4 Location retention
Tabu stores only the current or last-known Scene location record used for this functionality rather than maintaining a historical trail of your precise movements.
Each newer location replaces the previous stored location for the user.
Each published Scene location record is assigned a 15-minute expiry period.
An automated cleanup process runs periodically to remove expired location records. Because cleanup occurs on a periodic schedule, an expired record may remain briefly after the 15-minute expiry until the next cleanup cycle.
Tabu does not use this system to maintain a historical route or playback of your movements.
Location records associated directly with your account are removed as part of deletion of the associated user record, subject to applicable backup and legal-retention processes.
8. Co-Presence
The Scene may include functionality that identifies limited co-presence, meaning that two users were within a defined proximity during a particular time period.
Co-presence is subject to protective conditions.
A co-presence record is created only where:
- the users are already friends;
- both users have Ghost Mode disabled;
- both users have enabled co-presence broadcasting; and
- both users have enabled co-presence reception.
The relevant co-presence settings are disabled by default unless the user enables them.
A co-presence record stores limited information such as:
- the two relevant profile identifiers;
- the applicable event type; and
- a limited time bucket.
The co-presence record does not store the users’ geographic coordinates.
Co-presence records expire on the same short-lived basis used for the underlying Scene location functionality and are automatically removed by the location cleanup process.
9. Communications With Tabu
We may process information contained in:
- customer-support requests;
- complaints;
- payment or refund enquiries;
- enforcement appeals;
- reports submitted under the Community Guidelines;
- privacy requests;
- feedback;
- surveys; and
- other communications with Tabu.
Customer support is currently provided primarily through email at:
support@tabubookings.com
Tabu does not currently use a separate third-party live-chat or helpdesk platform for ordinary customer support.
Support correspondence is hosted through Tabu’s email-service infrastructure.
10. Device, Technical and Usage Information
10.1 Website information
The Tabu website is hosted through Vercel and uses Supabase for backend services.
When users access the website, hosting and backend infrastructure may necessarily process technical connection information such as:
- IP address;
- browser or user-agent information;
- network information;
- request information; and
- security or access logs.
Tabu does not currently use device fingerprinting or an advertising identifier on the website.
10.2 Mobile device information
The mobile application may process information including:
- Expo push token;
- device model;
- operating-system version;
- Tabu app version;
- app installation or session identifiers used for diagnostics;
- runtime and platform metadata;
- IP address where received by infrastructure providers; and
- technical and diagnostic information.
Certain backend security logs may store privacy-preserving or hashed representations of IP information rather than the raw address.
10.3 Advertising identifiers
Tabu does not currently access:
- Apple’s Identifier for Advertisers ("IDFA"); or
- Android Advertising ID.
Tabu does not currently use these identifiers for behavioural advertising or cross-app tracking.
The iOS application does not currently implement an Apple App Tracking Transparency prompt because Tabu does not currently engage in tracking requiring that permission.
10.4 Usage information
Tabu may process information about how you use the Platform, including:
- pages or screens viewed;
- Venues or Events viewed;
- searches;
- Bookings;
- Social Feature interactions;
- clicks and actions;
- session activity;
- Platform performance;
- technical events; and
- errors or crashes.
11. Analytics, Crash Reporting and Diagnostics
11.1 Product analytics
At the date of this Policy, Tabu does not use a dedicated third-party product analytics platform to track user behaviour across the Platform.
Tabu does not currently use:
- PostHog;
- behavioural session replay;
- heatmaps; or
- advertising or retargeting analytics SDKs.
Tabu may process operational information generated through its own systems where reasonably necessary to operate, secure, troubleshoot and improve the Platform.
If Tabu introduces a new analytics or tracking technology in the future, it will update the relevant privacy and cookie disclosures and implement any required consent or controls before using the technology.
11.2 Sentry
Tabu uses Sentry for crash, error and performance diagnostics.
Depending on the Platform and diagnostic event, Sentry may process information including:
- application or website version;
- device model;
- operating system;
- application installation or session identifiers;
- technical error information;
- crash information;
- performance traces;
- technical events associated with an error; and
- related diagnostic information.
Tabu configures Sentry to reduce the personal information included in diagnostic events.
In particular:
- default personally identifying information is disabled;
- Session Replay is disabled;
- performance tracing is sampled rather than applied to every event; and
- diagnostic information is filtered and scrubbed before transmission to reduce the risk that sensitive information, payment details, authentication tokens, email addresses, telephone numbers or similar information is included.
Sentry is used for service reliability, troubleshooting, security and performance purposes and is not configured by Tabu as an advertising or behavioural-marketing service.
Diagnostic data is retained in accordance with Tabu’s applicable provider configuration and only for as long as reasonably necessary for these purposes and applicable legal requirements.
12. Personalisation and Recommendations
Tabu may use information including:
- location;
- neighbourhood;
- Venues or Events viewed;
- searches;
- previous Bookings;
- followed Venues;
- activity of friends or connections where relevant;
- popularity or engagement;
- availability; and
- other relevant Platform activity
to personalise Venue, Event or content discovery.
Tabu may derive preferences or behavioural groupings from this information to improve recommendations.
Such information is not used for unrelated purposes merely because it may be commercially useful to Tabu.
13. Sensitive Personal Data and Special Requests
13.1 Sensitive information
Certain Booking requests may involve information that constitutes sensitive personal data under the PDPA.
For example, you may voluntarily disclose:
- allergy or health information;
- accessibility requirements;
- disability-related requirements;
- religious requirements;
- dietary information that reveals sensitive information; or
- other sensitive circumstances relevant to your Booking.
13.2 Booking special requests
Where you voluntarily provide such information in a special request, Tabu will process it only as reasonably necessary to:
- administer the Booking;
- communicate the request to the relevant Venue or Host;
- facilitate the service you requested;
- provide customer support; and
- address associated safety matters or disputes.
Where the PDPA requires explicit consent for processing sensitive personal data, Tabu will obtain the required consent separately.
Acceptance of the general Terms of Service or this Privacy Policy is not intended to substitute for explicit consent where the law requires explicit consent.
13.3 Sensitive information in Social Features
You should not post sensitive personal data about another person through Social Features unless you are legally entitled to do so.
The fact that a person voluntarily posts sensitive information does not give Tabu unrestricted permission to use that information for unrelated purposes.
14. How and Why We Use Personal Data
Tabu processes personal data only where there is an appropriate purpose and lawful basis.
| Purpose | Main lawful basis |
|---|---|
| Create and administer your account | Performance of contract |
| Authenticate users and maintain account security | Performance of contract; legitimate interests |
| Provide the Platform and core functionality | Performance of contract |
| Process Bookings, Event tickets, Deposits, payments and refunds | Performance of contract; legal obligations where applicable |
| Administer Late Cancellations and No-Shows | Performance of contract; legitimate interests in operating and protecting the Booking system |
| Send Booking confirmations, reminders and essential service communications | Performance of contract; legitimate interests |
| Operate The Scene and other Social Features | Performance of the service requested; legitimate interests |
| Operate messages and private communications | Performance of the requested service; legitimate interests |
| Use foreground device location | Consent/device permission and another lawful basis where applicable |
| Display location or nearby-user functionality through The Scene | Consent and/or performance of the Social Feature requested, as applicable |
| Operate opt-in co-presence features | Consent or user choice and performance of the requested feature |
| Provide local discovery and recommendations | Contract and/or legitimate interests; consent where required for underlying data |
| Personalise Venue, Event and content recommendations | Legitimate interests, subject to appropriate balancing; consent where required |
| Crash, error and performance diagnostics | Legitimate interests in maintaining reliability, security and performance |
| Provide customer support | Performance of contract; legitimate interests |
| Community moderation, safety and abuse prevention | Legitimate interests; legal obligations where applicable |
| Fraud detection and payment-risk management | Legitimate interests; legal obligations and payment requirements where applicable |
| Send promotional email, SMS, push or in-app marketing | Consent or another lawful basis where permitted |
| Comply with tax, accounting, regulatory and legal requirements | Legal obligation |
| Respond to complaints and legal claims | Legitimate interests; legal obligations where applicable |
| Corporate transactions and due diligence | Legitimate interests subject to confidentiality and applicable law |
Where Tabu relies on legitimate interests, we consider:
- the relevant business, safety or operational interest;
- whether processing is necessary; and
- the effect on the individuals concerned.
15. Marketing and Communications
15.1 Service communications
Tabu may send communications reasonably necessary to operate the Platform, including:
- account notices;
- Booking confirmations;
- Booking reminders;
- cancellation notices;
- Event updates;
- ticket information;
- payment and refund notices;
- security alerts;
- Community Guidelines or enforcement notices;
- privacy communications; and
- important changes to Platform terms or services.
These are service communications rather than marketing.
15.2 Marketing
Tabu may send promotional communications concerning:
- Tabu;
- Venues;
- Events;
- offers;
- promotions; and
- recommendations
where Tabu has an appropriate lawful basis and any consent required by law.
Marketing may be sent through:
- email;
- SMS;
- push notifications; and
- in-app communications.
Where Tabu asks for marketing consent, the marketing choice is presented separately from mandatory acceptance of contractual terms and is optional.
15.3 Withdrawal
Where marketing relies on your consent, you may withdraw that consent through the applicable settings, unsubscribe mechanism or by contacting Tabu.
Withdrawal does not affect processing that lawfully occurred before withdrawal.
Device permission to receive push notifications and consent to receive promotional marketing are separate concepts.
16. Who We Disclose Personal Data To
16.1 Venues and third-party Hosts
Where you make a Booking with a Venue or third-party Host, Tabu shares information reasonably necessary to administer and provide the booked service.
This may include:
- your name;
- telephone number;
- email address;
- Booking date and time;
- party size;
- table, space or ticket details;
- special requests;
- payment or Deposit status where relevant;
- cancellation or No-Show information where relevant; and
- other information reasonably necessary to administer the Booking.
A Venue or Host may act as a separate data controller for personal data it lawfully receives and uses for:
- supplying the booked service;
- Venue or Event operations;
- legal obligations; and
- other lawful purposes.
Tabu’s arrangements with Venues restrict the use of Tabu guest information for unrelated purposes.
A Booking through Tabu does not automatically authorise a Venue to add you to its independent marketing list.
16.2 Tabu-Hosted Events
Where an Event is organised by Tabu itself as a Tabu-Hosted Event, Tabu processes personal data in its capacity as both Platform operator and Event organiser.
This may include:
- Booking and ticket information;
- attendee information;
- payment information;
- attendance or check-in information;
- Event communications;
- support information;
- safety and operational information; and
- other information reasonably necessary to organise and administer the Event.
Where a separate Venue supplies premises, food, drink, security or other onsite services for a Tabu-Hosted Event, relevant attendee information may also be disclosed to that Venue where reasonably necessary for those services.
16.3 Other Tabu users
Depending on the Social Feature, settings and choices involved, other Tabu users may see information such as:
- profile information;
- posts and stories;
- follows and connections;
- comments and Reactions;
- tags and mentions;
- Bookings or Venues you choose to share;
- messages sent to them;
- Scene location information; and
- co-presence information where the applicable mutual settings are enabled.
Users may be able to save, screenshot or further share information they are legitimately able to view.
Tabu cannot technically control all activity occurring outside the Platform after another user has viewed information.
16.4 Service providers
Tabu uses service providers and technology partners to operate the Platform.
These include:
Supabase
Used for functions including:
- database infrastructure;
- authentication;
- application backend functionality; and
- storage of Scene media and user content.
Vercel
Used to host and deliver the Tabu website and related web infrastructure.
Omise / Opn Payments
Used to process payments and payment-related transactions.
Used for:
- Google Sign-In;
- Google Maps functionality;
- interactive mapping;
- directions and estimated travel information; and
- static map imagery used within the mobile application.
Depending on the feature, Google may receive information such as device or connection information and map origin or destination coordinates.
Apple
Used for:
- Sign in with Apple;
- Apple device and application services; and
- Apple Push Notification Service.
Expo / EAS
Used for mobile application infrastructure including:
- application builds;
- Expo push-token services; and
- over-the-air application update services.
When the application checks for an update, Expo may receive information such as:
- device IP address;
- runtime metadata;
- platform information; and
- application-version information.
Expo push services also process device push tokens used to route notifications.
Firebase Cloud Messaging
Used to route push notifications to supported Android devices.
Sentry
Used for crash, error and performance diagnostics as described in Section 11.
Hostinger
Used in connection with Tabu’s support email infrastructure.
Resend
Used to send transactional communications such as Booking confirmations and reminders and may process information such as:
- recipient name;
- email address; and
- relevant Booking details.
Authentication message delivery providers
Supabase Auth may use email or SMS delivery providers to send authentication or verification codes.
Tabu may also use other infrastructure providers reasonably necessary to operate, secure and support the Platform.
16.5 Professional advisers and corporate transactions
Tabu may disclose personal data where reasonably necessary to:
- lawyers;
- accountants;
- auditors;
- insurers;
- investors;
- prospective purchasers; and
- other professional advisers,
subject to appropriate confidentiality arrangements and applicable law.
16.6 Authorities and legal disclosures
We may disclose personal data where required or permitted by law, including to:
- courts;
- regulators;
- law-enforcement authorities; and
- other competent authorities.
We may also make proportionate disclosures where reasonably necessary to:
- protect users;
- investigate serious fraud;
- address security incidents;
- investigate serious safety matters; or
- establish, exercise or defend legal claims.
16.7 No sale of personal data
Tabu does not sell personal data.
Tabu does not currently provide identifiable customer information to advertising partners in exchange for payment or other consideration.
If Tabu’s business model materially changes, we will update relevant disclosures and implement any choices or consent required before the new processing begins.
17. Cookies, SDKs and Similar Technologies
Tabu uses cookies and similar technologies as described in the separate Cookie & Similar Technologies Policy.
17.1 Website cookies and storage
The Tabu website currently uses limited technologies for authentication, language preferences and Booking functionality.
These include:
- Supabase authentication/session cookies;
- a transient authentication code-verifier cookie;
- a language-preference cookie; and
- temporary session storage used to carry a guest Booking reference across sign-in.
A first-time anonymous visitor does not receive the authentication cookies unless the relevant authentication functionality is used.
The website does not currently use:
- third-party advertising cookies;
- retargeting cookies;
- behavioural-advertising cookies; or
- dedicated third-party product-analytics cookies.
17.2 Mobile technologies
The native mobile application does not rely on browser cookies for ordinary application sessions.
Instead, it may use technologies such as:
- app-private local storage;
- Supabase authentication sessions;
- Expo push tokens;
- push-notification technologies;
- Google Maps services;
- Sentry diagnostics; and
- Expo application-update functionality.
17.3 Future technologies
If Tabu introduces additional analytics, advertising or tracking technologies, relevant privacy disclosures, Cookie Policy information, consent mechanisms and app-store declarations will be updated where required before that processing begins.
18. International Transfers
18.1 Processing outside Thailand
Tabu is based in Thailand.
Certain providers may process or store personal data outside Thailand, including in Singapore and other countries in which the relevant providers maintain infrastructure, systems or personnel.
The precise processing location may vary according to the relevant provider and service configuration.
18.2 Transfer safeguards
Where personal data is transferred outside Thailand, Tabu will use a transfer mechanism permitted by applicable law.
Depending on the circumstances, this may include:
- transfer to a jurisdiction recognised as providing appropriate protection;
- appropriate contractual or organisational safeguards;
- transfer necessary for an applicable contractual purpose;
- another statutory exception; or
- consent where consent is genuinely the applicable lawful mechanism.
Tabu does not treat ordinary use of the Platform as blanket consent to every international transfer.
19. How Long We Keep Personal Data
Tabu retains personal data only for as long as reasonably necessary for the purposes for which it was collected and for applicable:
- legal;
- tax;
- accounting;
- security;
- fraud-prevention;
- safety;
- dispute; and
- regulatory purposes.
Retention periods differ according to the category of information.
19.1 Account and profile information
Account and profile information is generally retained while your account is active.
Following an account-deletion request, information may remain during the applicable deletion process and for longer where retention is reasonably necessary for:
- legal obligations;
- fraud prevention;
- security;
- disputes;
- safety; or
- legal claims.
19.2 Booking and payment records
Booking and payment records relevant to accounting, tax or regulatory requirements are generally retained for at least the applicable statutory recordkeeping period.
Certain relevant financial records may need to be retained for at least five years and potentially longer where applicable law requires or permits.
19.3 Refunds, disputes and chargebacks
Records relating to refunds, payment disputes and chargebacks may be retained for the duration of the matter and thereafter for a reasonable period necessary for:
- accounting;
- evidence;
- fraud prevention; and
- legal claims.
19.4 No-Show and Booking-enforcement records
These records may be retained while reasonably relevant to:
- Booking administration;
- enforcement;
- disputes;
- fraud prevention;
- safety; or
- legal claims.
19.5 Social content
Posts, stories, comments, profile content and other User Content may be retained until:
- deleted where deletion functionality is available;
- expired according to the relevant feature;
- the account is erased; or
- longer retention is reasonably necessary for moderation, safety, disputes or legal obligations.
19.6 Messages
Messages currently do not have an automatic time-based expiry and may remain stored while necessary to provide the messaging service and until the applicable deletion or erasure process occurs.
Some limited records may also need to be retained where necessary to:
- preserve legitimate conversation functionality for another user;
- investigate safety or abuse;
- resolve a dispute; or
- comply with law.
19.7 Scene location
Scene location records are short-lived.
Each published location has a 15-minute expiry period and expired records are removed by a periodic automated cleanup process.
Tabu does not use these records to build a continuous location history.
19.8 Co-presence
Co-presence records are also short-lived and expire through the same location-cleanup mechanism.
They do not store geographic coordinates.
19.9 Security, access and audit information
Security, access, error and audit records are retained for as long as reasonably necessary for:
- Platform security;
- service integrity;
- fraud prevention;
- debugging;
- audits;
- investigations; and
- legal requirements.
19.10 Sentry diagnostics
Diagnostic information sent to Sentry is retained in accordance with Tabu’s configured service settings and for only as long as reasonably necessary for:
- troubleshooting;
- performance monitoring;
- service reliability;
- security; and
- related technical purposes.
19.11 Marketing preferences
Marketing preferences and opt-out information may be retained for as long as reasonably necessary to manage the marketing relationship and respect your choices.
19.12 Support records
Support correspondence may be retained for as long as reasonably necessary to:
- respond to the request;
- manage complaints or disputes;
- maintain appropriate records; and
- comply with applicable law.
19.13 Venue and operator records
Venue and operator account records may be retained during the relevant business relationship and for appropriate legal, accounting, audit, security and dispute periods afterwards.
19.14 Anonymised information
Information that has been irreversibly anonymised so that it no longer identifies or can reasonably be linked to an individual may be retained without a fixed personal-data retention period.
20. Account Deletion
20.1 Requesting deletion
Tabu provides an in-app Delete Account function through which you may request deletion of your Tabu account.
You may also contact:
support@tabubookings.com
for assistance with account deletion or privacy rights.
20.2 Grace period
When an account-deletion request is submitted through the applicable process, a 14-day grace period applies.
During that period, the deletion request may be cancelled through the functionality made available by Tabu.
The 14-day period is a grace period before irreversible account-erasure steps and should not be understood as a guarantee that every technical deletion step will be completed at the exact moment that the grace period ends.
20.3 Information that may be retained
Account deletion does not require Tabu to erase information that it lawfully needs to retain.
Tabu may retain limited information where reasonably necessary to:
- comply with tax or accounting obligations;
- complete or evidence a Booking, payment, refund or dispute;
- prevent fraud or abuse;
- maintain security;
- preserve necessary safety or moderation evidence;
- establish, exercise or defend legal claims; or
- comply with another legal obligation.
20.4 Backups
Information deleted from active Platform systems may remain temporarily within infrastructure backups until those backups are overwritten or deleted according to the relevant backup cycle.
Information retained only in backups is not ordinarily used for normal Platform operations.
Where a backup is restored, Tabu will take reasonable steps to ensure that previously processed deletion or erasure requirements continue to be respected.
21. Your Rights
Subject to the PDPA and applicable conditions and exceptions, you may have rights to:
- access certain personal data and obtain a copy;
- correct inaccurate or incomplete information;
- request deletion in applicable circumstances;
- request restriction of processing in applicable circumstances;
- object to certain processing;
- withdraw consent where processing relies on consent;
- receive or transfer certain personal data where the portability right applies; and
- lodge a complaint with the PDPC.
21.1 How to make a request
Certain information may be managed directly through Platform settings.
Account deletion may be requested through the in-app Delete Account function.
For other privacy requests, contact:
support@tabubookings.com
This includes requests concerning:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability; and
- withdrawal of consent.
Tabu may take reasonable steps to verify your identity before responding.
21.2 Requests and exceptions
Tabu will respond within the period required by applicable law.
A request may be limited or refused where permitted by law, including where information must be retained to:
- comply with a legal obligation;
- protect another person’s rights;
- investigate or prevent fraud;
- maintain security; or
- establish, exercise or defend legal claims.
Where Tabu cannot fulfil a request, it will explain the basis where required and permitted.
21.3 Fees
Tabu does not intend to charge users simply for exercising rights under the PDPA unless a charge is specifically permitted by applicable law.
22. Automated Processing, Moderation and Fraud Detection
22.1 Automated moderation and safety tools
Tabu may use automated filtering or detection tools to identify or flag:
- potentially prohibited content;
- spam;
- suspicious activity;
- possible fraud;
- security concerns; or
- potential Community Guidelines violations.
Flagged matters may be referred to the Tabu Support Team or other authorised personnel for human review.
Tabu does not intend to rely solely on automated processing to make decisions producing legal or similarly significant effects on a user without an appropriate lawful basis and safeguards.
22.2 Automated Platform mechanics
Certain Platform functions operate automatically according to technical or contractual rules.
For example:
- Booking Requests may expire;
- checkout or ticket holds may expire;
- payment authorisations may fail or be released;
- authentication attempts may be rate-limited; and
- technical safeguards may prevent obviously invalid or abusive activity.
These processes do not necessarily constitute profiling.
22.3 Payment-provider systems
Payment processors, banks, card networks and other financial-service providers may independently use automated systems to:
- authenticate transactions;
- approve or decline payments;
- identify fraud;
- assess payment risk; or
- satisfy regulatory requirements.
Where Omise / Opn Payments or another provider performs such processing for its own purposes, that provider’s own privacy information may also apply.
22.4 Content moderation
To help protect users, enforce our Terms and Community Guidelines, and comply with applicable law, Tabu may use automated classification tools together with human moderation to review content submitted to The Scene. Depending on the type of content, these systems may analyse to identify content that may be unsafe, unlawful or otherwise prohibited. The result may cause content to be allowed, withheld for human review, or blocked from publication.
Automated classification is used as a moderation and safety signal. Where appropriate, content may be reviewed by authorised Tabu personnel. Tabu may use service providers acting on our behalf to provide content-safety and moderation technology. We limit the information shared with those providers to what is reasonably necessary for the moderation purpose and apply contractual and security safeguards appropriate to the service.
23. Security
Tabu maintains technical and organisational measures designed to protect personal data against:
- unauthorised access;
- loss;
- alteration;
- misuse; and
- unauthorised disclosure.
Depending on the relevant system, these measures include:
- encrypted network connections;
- provider-managed protections for stored cloud data;
- authentication and authorisation controls;
- role-based and row-level access controls where applicable;
- private or restricted storage controls for user media;
- restricted access to production systems and service credentials;
- security and audit logging;
- payment-webhook verification;
- server-side determination of payment amounts;
- credential, API-key and secret-management practices;
- diagnostic-data filtering and redaction; and
- development and review practices intended to reduce security risks.
Access to personal data is restricted to personnel and service providers requiring access for authorised purposes.
Security measures may vary according to the relevant system, service and architecture.
No information system can guarantee absolute security.
24. Personal Data Breaches
Tabu maintains procedures designed to identify, assess, contain, document and respond to personal-data breaches.
Where a breach triggers notification obligations under the PDPA, Tabu will notify the PDPC and affected individuals as required by applicable law.
25. Children and Age Requirements
25.1 Minimum age
You must be at least 13 years old to create or maintain a Tabu account or use Tabu’s general Platform and Social Features.
25.2 Users under legal adulthood
If you are under the age at which you may independently:
- enter into a relevant agreement;
- provide a particular consent; or
- exercise a particular right,
Tabu may require the consent or involvement of your parent, legal representative or person exercising parental responsibility where required by applicable law.
25.3 Venue and Event age restrictions
Being eligible to use Tabu does not mean you are eligible to make every Booking or attend every Venue or Event.
Venues and Events may impose separate:
- minimum-age requirements;
- identification requirements; and
- admission conditions.
Where a Venue, Event or activity is legally restricted to persons aged 20 or older, a user under 20 may not use Tabu to circumvent that restriction.
25.4 Age verification
Tabu may request your:
- date of birth;
- identification; or
- other reasonable evidence
where necessary to verify eligibility, protect users, enforce applicable terms or comply with law.
25.5 Personal data of minors
Tabu does not knowingly process minors’ personal data in a manner that violates applicable law.
If Tabu learns that personal data has been processed without a required lawful basis or consent, Tabu may take appropriate steps, including:
- restricting the relevant feature;
- seeking required consent; or
- deleting the affected information.
25.6 Privacy choices
Optional activities involving matters such as:
- precise location;
- location sharing;
- co-presence;
- marketing;
- sensitive personal data; or
- other consent-based processing
may require additional consent or parental/legal-representative involvement where required by applicable law.
26. Venue and Host Representatives
Where you use Tabu on behalf of a Venue or Host, Tabu may process:
- name;
- work email address;
- work telephone number;
- employer or organisation;
- role;
- authentication information;
- dashboard activity;
- Booking-administration actions;
- support communications;
- settlement-related information; and
- security and audit information.
Tabu uses this information to:
- administer the Venue or Host relationship;
- operate and secure the operator dashboard;
- provide support;
- process Bookings and settlements;
- maintain appropriate business records;
- prevent fraud; and
- comply with law.
The relevant lawful basis may include:
- legitimate interests;
- administration or performance of the relevant business relationship; and
- legal obligations.
27. Omise Venue and Sub-Merchant Verification
Where Omise / Opn Payments requires a Venue or Sub-Merchant to complete Know Your Customer or similar compliance verification, the intended process is for the relevant Venue or Sub-Merchant to provide required verification information through the applicable Omise / Opn Payments process.
Tabu may receive limited information required to administer the payment relationship, such as:
- Venue or Sub-Merchant identifiers;
- linked payment-account information;
- onboarding status;
- verification status;
- notification that additional verification or action is required; and
- other limited integration information.
Tabu does not currently operate a general repository within the Platform for formal Omise KYC files such as:
- directors’ identity documents;
- shareholder identity documents;
- beneficial-owner identity documents;
- bank verification documents; or
- comparable payment-provider KYC documents.
28. Third-Party Links and Independent Services
The Platform may contain links to third-party websites, applications or services.
Where you leave Tabu and independently interact with another service, that service’s own privacy practices apply.
This differs from a provider processing personal data as part of a service supplied to Tabu, which remains subject to Tabu’s applicable legal and contractual responsibilities.
29. Changes to This Policy
Tabu may update this Policy where its:
- Platform features;
- technology;
- service providers;
- business practices; or
- legal obligations
change.
The revised Policy will display an updated "Last updated" date.
Where a change materially affects how personal data is processed, Tabu will provide appropriate additional notice where required.
Publication of an updated Privacy Policy does not, by itself, constitute consent to a new processing activity where consent or another legal step is required.
Where a new activity requires consent, Tabu will obtain that consent before relying on it.
30. Contact Us
For questions, requests or complaints about this Policy or Tabu’s processing of personal data:
- Tabu Co., Ltd.
- Company registration number: 0105569086462
- 27/2 Sukhumvit 33 (Daeng Udom), Khlong Tan Nuea, Watthana, Krung Thep Maha Nakhon 10110, Thailand
- Privacy email: support@tabubookings.com
- Website: tabu.social
You may also have the right to submit a complaint to the Office of the Personal Data Protection Committee of Thailand.