Privacy Policy

Last updated: 7 September 2026

This Privacy Policy ("Policy") explains how Tabu Co., Ltd. ("Tabu", "we", "us" or "our"), a company registered in Thailand under company registration number 0105569086462, collects, uses, discloses, transfers, retains and protects personal data when you access or use the Tabu mobile applications, website, operator dashboard and related services (together, the "Platform").

This Policy is issued in accordance with Thailand’s Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and other applicable data-protection laws.

This Policy should be read together with our:

  1. Customer Terms of Service;
  2. Refund & Cancellation Policy;
  3. Community Guidelines & Acceptable Use Policy;
  4. Cookie & Similar Technologies Policy; and
  5. any additional privacy notice presented to you in connection with a particular feature.

By creating an account or using the Platform, you acknowledge that you have been provided with this Policy.

Your use of Tabu does not constitute consent to every processing activity described in this Policy. Where consent is required under the PDPA or another applicable law, Tabu will seek that consent separately.

Capitalised terms not defined in this Policy have the meanings given in the Customer Terms of Service.

1. Summary

This Section provides an overview of Tabu’s privacy practices. The remainder of this Policy provides further detail.

1.1 Who we are

Tabu Co., Ltd. is generally the data controller responsible for the personal data described in this Policy.

1.2 What we collect

Depending on how you use Tabu, we may process:

  1. account and profile information;
  2. Booking and Event information;
  3. payment and transaction information;
  4. Social Feature content and activity;
  5. messages and communications;
  6. device and location information;
  7. technical and usage information;
  8. support and complaint information;
  9. information concerning Venue and Host representatives; and
  10. information received from service providers and other parties involved in providing the Platform.

1.3 Why we use it

We process personal data to:

  1. create and secure accounts;
  2. operate the Platform;
  3. process Bookings, tickets and payments;
  4. operate The Scene and other Social Features;
  5. provide location and nearby-user functionality;
  6. personalise discovery;
  7. provide customer support;
  8. communicate with users;
  9. prevent fraud, abuse and security incidents;
  10. enforce applicable Platform rules;
  11. comply with legal and regulatory obligations; and
  12. send marketing where we have an appropriate lawful basis and any required consent.

1.4 Who receives it

Personal data may be disclosed to:

  1. Venues and Hosts;
  2. other Tabu users through Social Features;
  3. service providers;
  4. payment providers;
  5. professional advisers;
  6. authorities where required or permitted by law; and
  7. other parties described in this Policy.

1.5 We do not sell personal data

Tabu does not sell your personal data.

1.6 International processing

Tabu is based in Thailand. Certain service providers may process or store personal data outside Thailand, including in Singapore and other countries in which those providers operate.

1.7 Your rights

Subject to applicable law, you may have rights to:

  1. access personal data;
  2. correct it;
  3. request deletion;
  4. restrict certain processing;
  5. object to certain processing;
  6. withdraw consent;
  7. obtain or transfer certain personal data; and
  8. complain to Thailand’s Personal Data Protection Committee.

2. Who We Are

2.1 Data controller

The data controller responsible for this Policy is:

  • Tabu Co., Ltd.
  • Company registration number: 0105569086462
  • Registered address: 27/2 Sukhumvit 33 (Daeng Udom), Khlong Tan Nuea, Watthana, Krung Thep Maha Nakhon 10110, Thailand
  • Website: tabu.social

2.2 Privacy contact

For questions about this Policy, complaints about our processing of personal data or requests to exercise your privacy rights:

Email: support@tabubookings.com

2.3 Data Protection Officer

Tabu has not appointed a Data Protection Officer at the date of this Policy.

Tabu will keep its obligations under the PDPA under review and will appoint and publish the contact details of a Data Protection Officer if and when required by applicable law.

2.4 Regulator

You may have the right to submit a complaint to the Office of the Personal Data Protection Committee of Thailand ("PDPC") in accordance with applicable law.

3. Scope of This Policy

3.1 People covered

This Policy applies to personal data Tabu processes about:

  1. customers and other users of the Platform;
  2. users of The Scene and other Social Features;
  3. visitors to Tabu’s website;
  4. people who contact Tabu;
  5. Venue and Host representatives who use Tabu’s operator dashboard or otherwise interact with Tabu in a business capacity; and
  6. other individuals whose personal data is provided to Tabu in connection with the Platform.

3.2 Third-party services

Tabu integrates with third-party services for functions including:

  1. cloud infrastructure;
  2. authentication;
  3. payments;
  4. mapping;
  5. mobile application services;
  6. push notifications;
  7. diagnostics;
  8. email and SMS delivery; and
  9. other Platform functionality.

The legal role of a third party depends on the relevant processing.

Where a provider processes personal data on Tabu’s behalf and under Tabu’s instructions, the provider may act as a data processor.

Where a provider determines its own purposes or means of processing, including for its own payment, regulatory, fraud-prevention, security or compliance obligations, it may act as a separate data controller and its own privacy notice may also apply.

3.3 International users

Tabu is established in Thailand and initially focuses on Venues and Events in Thailand.

If you use Tabu from another country, mandatory laws of that jurisdiction may also apply in certain circumstances.

Tabu does not treat ordinary use of the Platform as blanket consent to international transfers or processing.

4. Personal Data We Collect

The personal data we collect depends on how you use the Platform.

4.1 Account and profile information

When you create and use a Tabu account, we may collect:

  1. name;
  2. username;
  3. email address;
  4. mobile number;
  5. date of birth;
  6. authentication information and identifiers;
  7. profile photograph;
  8. cover photograph;
  9. profile biography;
  10. gender or pronoun information;
  11. city, neighbourhood or other location information you provide;
  12. account settings;
  13. privacy and Social Feature settings; and
  14. other profile preferences.

Gender or pronoun information may be used for profile presentation and to enable Tabu to use appropriate pronouns or other user-facing language in connection with your account.

Certain information is required to create or operate a Tabu account, while other information may depend on the features you choose to use.

Where you use Google Sign-In or Sign in with Apple, Tabu receives information made available through the relevant provider according to the applicable authentication flow and your settings.

Tabu does not currently use Facebook Login or LINE Login.

4.2 Booking and Event information

When you browse, request, make, purchase, transfer or manage a Booking or Event ticket, we may process information including:

  1. the Venue or Event;
  2. Booking or Event date;
  3. time;
  4. party size;
  5. table, space, seating or ticket type;
  6. Booking Request or confirmation status;
  7. Deposit or other prepayment;
  8. payment status;
  9. cancellation status;
  10. Late Cancellation status;
  11. No-Show status;
  12. attendance or check-in information;
  13. special requests;
  14. Booking or ticket transfer information;
  15. applicable Booking conditions; and
  16. other information reasonably necessary to process and administer the Booking or Event.

5. Payment and Transaction Information

5.1 Omise / Opn Payments

Tabu uses Omise / Opn Payments for payment processing.

Tabu may process information concerning:

  1. Booking payments;
  2. Deposits;
  3. Event ticket purchases;
  4. Event table packages;
  5. Tabu Service Fees;
  6. Late Cancellation Charges;
  7. No-Show Charges;
  8. refunds;
  9. payment corrections;
  10. disputes; and
  11. chargebacks.

5.2 Card information

When you enter payment-card information through the Tabu payment flow, your card details are transmitted directly from your browser or device to Omise / Opn Payments for tokenisation and payment processing.

Tabu does not receive or store your complete payment-card number or card security code in Tabu-controlled systems.

Omise returns a token or payment source that allows the payment to be processed.

For some payment methods, including certain 3-D Secure or wallet flows, you may be redirected to an Omise-controlled or other payment-provider page. Technologies operating on that external page are subject to the relevant provider’s privacy and technology practices.

5.3 Payment metadata

Tabu stores transaction and payment information returned by Omise where reasonably necessary to administer and evidence transactions.

Depending on the transaction and the information returned by Omise, this may include:

  1. payment, charge or transaction identifiers;
  2. payment amount;
  3. payment status;
  4. payment-method type;
  5. card brand;
  6. masked card information, such as the last digits of the card number;
  7. card expiry information;
  8. cardholder name where returned;
  9. card or payment fingerprints or other identifiers;
  10. issuing country or bank information where returned;
  11. authentication or 3-D Secure information;
  12. payment-risk or fraud information where returned; and
  13. webhook and other payment-processing information.

We retain relevant payment records where reasonably necessary to:

  1. process and reconcile transactions;
  2. administer refunds;
  3. manage disputes and chargebacks;
  4. prevent fraud;
  5. maintain accounting and tax records; and
  6. comply with legal and regulatory obligations.

6. Social Features and The Scene

6.1 Social Feature information

When you use The Scene or other Social Features, Tabu may process:

  1. profile photographs;
  2. cover images;
  3. biographies and profile information;
  4. posts;
  5. stories;
  6. photographs and other uploaded content;
  7. captions;
  8. comments;
  9. emoji Reactions;
  10. tags and mentions;
  11. followers;
  12. following relationships;
  13. friend and connection relationships;
  14. Venue follows;
  15. content sharing;
  16. shared Booking or Event activity;
  17. blocks;
  18. user and content reports;
  19. moderation and enforcement information;
  20. location and co-presence settings; and
  21. other Social Feature interactions.

Tabu does not currently operate a public Venue-review system.

Emoji Reactions to posts or stories are social interactions and are not Venue ratings or verified Venue reviews.

6.2 Messages and private communications

Where you use messaging or other private communication features within The Scene, Tabu may process:

  1. the participants;
  2. message content;
  3. captions;
  4. attachment or media references where supported;
  5. timestamps;
  6. related conversation information;
  7. blocking information; and
  8. safety, reporting or moderation information.

Messages are stored within Tabu’s Supabase-hosted infrastructure.

Messages are protected using encrypted network connections during transmission and provider-managed protections for stored data.

Messages are not end-to-end encrypted. Authorised Platform systems may therefore technically process message content where necessary to provide, secure or administer the service.

Messages do not currently have an automatic time-based expiry.

Blocking another user does not itself delete messages that were already stored.

7. Location Information

7.1 Foreground device location

The Scene includes location-based functionality.

When you use the relevant Scene map functionality and grant Tabu location permission, Tabu may collect your device’s foreground location.

Depending on your device settings, the location may be precise or approximate.

Tabu does not currently request or use background location permission for this functionality.

Location collection stops when the relevant map screen is no longer active in the foreground.

While the Scene map is active, the application may:

  1. obtain an initial location;
  2. obtain updated locations when significant movement occurs; and
  3. refresh the location periodically while the map remains active.

7.2 Ghost Mode and location publication

Tabu provides privacy and visibility controls for location functionality, including Ghost Mode.

When Ghost Mode prevents location publication, the Platform does not publish your location through the applicable Scene location feature.

Other Scene privacy, blocking and visibility rules may also affect whether location-related information is available to another user.

7.3 Scene map and nearby users

Where the applicable sharing conditions are satisfied, Tabu may use your permitted foreground location to:

  1. display your position through the Scene map;
  2. determine nearby users or friends;
  3. provide local Social Feature functionality; and
  4. support other location-based Scene experiences.

Tabu may use geographic coordinates internally to provide this functionality.

The nearby-user functionality applies sharing, Ghost Mode, friendship and blocking rules before returning information to other users and does not provide another user with your raw latitude and longitude coordinates.

However, another user may still be able to infer your approximate physical location from your displayed position on the Scene map.

Where your displayed position appears at or close to a Venue, another user may also be able to infer that you are at or near that Venue.

A Booking is not automatically shared merely because you made it. Booking-sharing functionality is separate.

7.4 Location retention

Tabu stores only the current or last-known Scene location record used for this functionality rather than maintaining a historical trail of your precise movements.

Each newer location replaces the previous stored location for the user.

Each published Scene location record is assigned a 15-minute expiry period.

An automated cleanup process runs periodically to remove expired location records. Because cleanup occurs on a periodic schedule, an expired record may remain briefly after the 15-minute expiry until the next cleanup cycle.

Tabu does not use this system to maintain a historical route or playback of your movements.

Location records associated directly with your account are removed as part of deletion of the associated user record, subject to applicable backup and legal-retention processes.

8. Co-Presence

The Scene may include functionality that identifies limited co-presence, meaning that two users were within a defined proximity during a particular time period.

Co-presence is subject to protective conditions.

A co-presence record is created only where:

  1. the users are already friends;
  2. both users have Ghost Mode disabled;
  3. both users have enabled co-presence broadcasting; and
  4. both users have enabled co-presence reception.

The relevant co-presence settings are disabled by default unless the user enables them.

A co-presence record stores limited information such as:

  1. the two relevant profile identifiers;
  2. the applicable event type; and
  3. a limited time bucket.

The co-presence record does not store the users’ geographic coordinates.

Co-presence records expire on the same short-lived basis used for the underlying Scene location functionality and are automatically removed by the location cleanup process.

9. Communications With Tabu

We may process information contained in:

  1. customer-support requests;
  2. complaints;
  3. payment or refund enquiries;
  4. enforcement appeals;
  5. reports submitted under the Community Guidelines;
  6. privacy requests;
  7. feedback;
  8. surveys; and
  9. other communications with Tabu.

Customer support is currently provided primarily through email at:

support@tabubookings.com

Tabu does not currently use a separate third-party live-chat or helpdesk platform for ordinary customer support.

Support correspondence is hosted through Tabu’s email-service infrastructure.

10. Device, Technical and Usage Information

10.1 Website information

The Tabu website is hosted through Vercel and uses Supabase for backend services.

When users access the website, hosting and backend infrastructure may necessarily process technical connection information such as:

  1. IP address;
  2. browser or user-agent information;
  3. network information;
  4. request information; and
  5. security or access logs.

Tabu does not currently use device fingerprinting or an advertising identifier on the website.

10.2 Mobile device information

The mobile application may process information including:

  1. Expo push token;
  2. device model;
  3. operating-system version;
  4. Tabu app version;
  5. app installation or session identifiers used for diagnostics;
  6. runtime and platform metadata;
  7. IP address where received by infrastructure providers; and
  8. technical and diagnostic information.

Certain backend security logs may store privacy-preserving or hashed representations of IP information rather than the raw address.

10.3 Advertising identifiers

Tabu does not currently access:

  1. Apple’s Identifier for Advertisers ("IDFA"); or
  2. Android Advertising ID.

Tabu does not currently use these identifiers for behavioural advertising or cross-app tracking.

The iOS application does not currently implement an Apple App Tracking Transparency prompt because Tabu does not currently engage in tracking requiring that permission.

10.4 Usage information

Tabu may process information about how you use the Platform, including:

  1. pages or screens viewed;
  2. Venues or Events viewed;
  3. searches;
  4. Bookings;
  5. Social Feature interactions;
  6. clicks and actions;
  7. session activity;
  8. Platform performance;
  9. technical events; and
  10. errors or crashes.

11. Analytics, Crash Reporting and Diagnostics

11.1 Product analytics

At the date of this Policy, Tabu does not use a dedicated third-party product analytics platform to track user behaviour across the Platform.

Tabu does not currently use:

  1. PostHog;
  2. behavioural session replay;
  3. heatmaps; or
  4. advertising or retargeting analytics SDKs.

Tabu may process operational information generated through its own systems where reasonably necessary to operate, secure, troubleshoot and improve the Platform.

If Tabu introduces a new analytics or tracking technology in the future, it will update the relevant privacy and cookie disclosures and implement any required consent or controls before using the technology.

11.2 Sentry

Tabu uses Sentry for crash, error and performance diagnostics.

Depending on the Platform and diagnostic event, Sentry may process information including:

  1. application or website version;
  2. device model;
  3. operating system;
  4. application installation or session identifiers;
  5. technical error information;
  6. crash information;
  7. performance traces;
  8. technical events associated with an error; and
  9. related diagnostic information.

Tabu configures Sentry to reduce the personal information included in diagnostic events.

In particular:

  1. default personally identifying information is disabled;
  2. Session Replay is disabled;
  3. performance tracing is sampled rather than applied to every event; and
  4. diagnostic information is filtered and scrubbed before transmission to reduce the risk that sensitive information, payment details, authentication tokens, email addresses, telephone numbers or similar information is included.

Sentry is used for service reliability, troubleshooting, security and performance purposes and is not configured by Tabu as an advertising or behavioural-marketing service.

Diagnostic data is retained in accordance with Tabu’s applicable provider configuration and only for as long as reasonably necessary for these purposes and applicable legal requirements.

12. Personalisation and Recommendations

Tabu may use information including:

  1. location;
  2. neighbourhood;
  3. Venues or Events viewed;
  4. searches;
  5. previous Bookings;
  6. followed Venues;
  7. activity of friends or connections where relevant;
  8. popularity or engagement;
  9. availability; and
  10. other relevant Platform activity

to personalise Venue, Event or content discovery.

Tabu may derive preferences or behavioural groupings from this information to improve recommendations.

Such information is not used for unrelated purposes merely because it may be commercially useful to Tabu.

13. Sensitive Personal Data and Special Requests

13.1 Sensitive information

Certain Booking requests may involve information that constitutes sensitive personal data under the PDPA.

For example, you may voluntarily disclose:

  1. allergy or health information;
  2. accessibility requirements;
  3. disability-related requirements;
  4. religious requirements;
  5. dietary information that reveals sensitive information; or
  6. other sensitive circumstances relevant to your Booking.

13.2 Booking special requests

Where you voluntarily provide such information in a special request, Tabu will process it only as reasonably necessary to:

  1. administer the Booking;
  2. communicate the request to the relevant Venue or Host;
  3. facilitate the service you requested;
  4. provide customer support; and
  5. address associated safety matters or disputes.

Where the PDPA requires explicit consent for processing sensitive personal data, Tabu will obtain the required consent separately.

Acceptance of the general Terms of Service or this Privacy Policy is not intended to substitute for explicit consent where the law requires explicit consent.

13.3 Sensitive information in Social Features

You should not post sensitive personal data about another person through Social Features unless you are legally entitled to do so.

The fact that a person voluntarily posts sensitive information does not give Tabu unrestricted permission to use that information for unrelated purposes.

14. How and Why We Use Personal Data

Tabu processes personal data only where there is an appropriate purpose and lawful basis.

PurposeMain lawful basis
Create and administer your accountPerformance of contract
Authenticate users and maintain account securityPerformance of contract; legitimate interests
Provide the Platform and core functionalityPerformance of contract
Process Bookings, Event tickets, Deposits, payments and refundsPerformance of contract; legal obligations where applicable
Administer Late Cancellations and No-ShowsPerformance of contract; legitimate interests in operating and protecting the Booking system
Send Booking confirmations, reminders and essential service communicationsPerformance of contract; legitimate interests
Operate The Scene and other Social FeaturesPerformance of the service requested; legitimate interests
Operate messages and private communicationsPerformance of the requested service; legitimate interests
Use foreground device locationConsent/device permission and another lawful basis where applicable
Display location or nearby-user functionality through The SceneConsent and/or performance of the Social Feature requested, as applicable
Operate opt-in co-presence featuresConsent or user choice and performance of the requested feature
Provide local discovery and recommendationsContract and/or legitimate interests; consent where required for underlying data
Personalise Venue, Event and content recommendationsLegitimate interests, subject to appropriate balancing; consent where required
Crash, error and performance diagnosticsLegitimate interests in maintaining reliability, security and performance
Provide customer supportPerformance of contract; legitimate interests
Community moderation, safety and abuse preventionLegitimate interests; legal obligations where applicable
Fraud detection and payment-risk managementLegitimate interests; legal obligations and payment requirements where applicable
Send promotional email, SMS, push or in-app marketingConsent or another lawful basis where permitted
Comply with tax, accounting, regulatory and legal requirementsLegal obligation
Respond to complaints and legal claimsLegitimate interests; legal obligations where applicable
Corporate transactions and due diligenceLegitimate interests subject to confidentiality and applicable law

Where Tabu relies on legitimate interests, we consider:

  1. the relevant business, safety or operational interest;
  2. whether processing is necessary; and
  3. the effect on the individuals concerned.

15. Marketing and Communications

15.1 Service communications

Tabu may send communications reasonably necessary to operate the Platform, including:

  1. account notices;
  2. Booking confirmations;
  3. Booking reminders;
  4. cancellation notices;
  5. Event updates;
  6. ticket information;
  7. payment and refund notices;
  8. security alerts;
  9. Community Guidelines or enforcement notices;
  10. privacy communications; and
  11. important changes to Platform terms or services.

These are service communications rather than marketing.

15.2 Marketing

Tabu may send promotional communications concerning:

  1. Tabu;
  2. Venues;
  3. Events;
  4. offers;
  5. promotions; and
  6. recommendations

where Tabu has an appropriate lawful basis and any consent required by law.

Marketing may be sent through:

  1. email;
  2. SMS;
  3. push notifications; and
  4. in-app communications.

Where Tabu asks for marketing consent, the marketing choice is presented separately from mandatory acceptance of contractual terms and is optional.

15.3 Withdrawal

Where marketing relies on your consent, you may withdraw that consent through the applicable settings, unsubscribe mechanism or by contacting Tabu.

Withdrawal does not affect processing that lawfully occurred before withdrawal.

Device permission to receive push notifications and consent to receive promotional marketing are separate concepts.

16. Who We Disclose Personal Data To

16.1 Venues and third-party Hosts

Where you make a Booking with a Venue or third-party Host, Tabu shares information reasonably necessary to administer and provide the booked service.

This may include:

  1. your name;
  2. telephone number;
  3. email address;
  4. Booking date and time;
  5. party size;
  6. table, space or ticket details;
  7. special requests;
  8. payment or Deposit status where relevant;
  9. cancellation or No-Show information where relevant; and
  10. other information reasonably necessary to administer the Booking.

A Venue or Host may act as a separate data controller for personal data it lawfully receives and uses for:

  1. supplying the booked service;
  2. Venue or Event operations;
  3. legal obligations; and
  4. other lawful purposes.

Tabu’s arrangements with Venues restrict the use of Tabu guest information for unrelated purposes.

A Booking through Tabu does not automatically authorise a Venue to add you to its independent marketing list.

16.2 Tabu-Hosted Events

Where an Event is organised by Tabu itself as a Tabu-Hosted Event, Tabu processes personal data in its capacity as both Platform operator and Event organiser.

This may include:

  1. Booking and ticket information;
  2. attendee information;
  3. payment information;
  4. attendance or check-in information;
  5. Event communications;
  6. support information;
  7. safety and operational information; and
  8. other information reasonably necessary to organise and administer the Event.

Where a separate Venue supplies premises, food, drink, security or other onsite services for a Tabu-Hosted Event, relevant attendee information may also be disclosed to that Venue where reasonably necessary for those services.

16.3 Other Tabu users

Depending on the Social Feature, settings and choices involved, other Tabu users may see information such as:

  1. profile information;
  2. posts and stories;
  3. follows and connections;
  4. comments and Reactions;
  5. tags and mentions;
  6. Bookings or Venues you choose to share;
  7. messages sent to them;
  8. Scene location information; and
  9. co-presence information where the applicable mutual settings are enabled.

Users may be able to save, screenshot or further share information they are legitimately able to view.

Tabu cannot technically control all activity occurring outside the Platform after another user has viewed information.

16.4 Service providers

Tabu uses service providers and technology partners to operate the Platform.

These include:

Supabase

Used for functions including:

  1. database infrastructure;
  2. authentication;
  3. application backend functionality; and
  4. storage of Scene media and user content.

Vercel

Used to host and deliver the Tabu website and related web infrastructure.

Omise / Opn Payments

Used to process payments and payment-related transactions.

Google

Used for:

  1. Google Sign-In;
  2. Google Maps functionality;
  3. interactive mapping;
  4. directions and estimated travel information; and
  5. static map imagery used within the mobile application.

Depending on the feature, Google may receive information such as device or connection information and map origin or destination coordinates.

Apple

Used for:

  1. Sign in with Apple;
  2. Apple device and application services; and
  3. Apple Push Notification Service.

Expo / EAS

Used for mobile application infrastructure including:

  1. application builds;
  2. Expo push-token services; and
  3. over-the-air application update services.

When the application checks for an update, Expo may receive information such as:

  1. device IP address;
  2. runtime metadata;
  3. platform information; and
  4. application-version information.

Expo push services also process device push tokens used to route notifications.

Firebase Cloud Messaging

Used to route push notifications to supported Android devices.

Sentry

Used for crash, error and performance diagnostics as described in Section 11.

Hostinger

Used in connection with Tabu’s support email infrastructure.

Resend

Used to send transactional communications such as Booking confirmations and reminders and may process information such as:

  1. recipient name;
  2. email address; and
  3. relevant Booking details.

Authentication message delivery providers

Supabase Auth may use email or SMS delivery providers to send authentication or verification codes.

Tabu may also use other infrastructure providers reasonably necessary to operate, secure and support the Platform.

16.5 Professional advisers and corporate transactions

Tabu may disclose personal data where reasonably necessary to:

  1. lawyers;
  2. accountants;
  3. auditors;
  4. insurers;
  5. investors;
  6. prospective purchasers; and
  7. other professional advisers,

subject to appropriate confidentiality arrangements and applicable law.

16.6 Authorities and legal disclosures

We may disclose personal data where required or permitted by law, including to:

  1. courts;
  2. regulators;
  3. law-enforcement authorities; and
  4. other competent authorities.

We may also make proportionate disclosures where reasonably necessary to:

  1. protect users;
  2. investigate serious fraud;
  3. address security incidents;
  4. investigate serious safety matters; or
  5. establish, exercise or defend legal claims.

16.7 No sale of personal data

Tabu does not sell personal data.

Tabu does not currently provide identifiable customer information to advertising partners in exchange for payment or other consideration.

If Tabu’s business model materially changes, we will update relevant disclosures and implement any choices or consent required before the new processing begins.

17. Cookies, SDKs and Similar Technologies

Tabu uses cookies and similar technologies as described in the separate Cookie & Similar Technologies Policy.

17.1 Website cookies and storage

The Tabu website currently uses limited technologies for authentication, language preferences and Booking functionality.

These include:

  1. Supabase authentication/session cookies;
  2. a transient authentication code-verifier cookie;
  3. a language-preference cookie; and
  4. temporary session storage used to carry a guest Booking reference across sign-in.

A first-time anonymous visitor does not receive the authentication cookies unless the relevant authentication functionality is used.

The website does not currently use:

  1. third-party advertising cookies;
  2. retargeting cookies;
  3. behavioural-advertising cookies; or
  4. dedicated third-party product-analytics cookies.

17.2 Mobile technologies

The native mobile application does not rely on browser cookies for ordinary application sessions.

Instead, it may use technologies such as:

  1. app-private local storage;
  2. Supabase authentication sessions;
  3. Expo push tokens;
  4. push-notification technologies;
  5. Google Maps services;
  6. Sentry diagnostics; and
  7. Expo application-update functionality.

17.3 Future technologies

If Tabu introduces additional analytics, advertising or tracking technologies, relevant privacy disclosures, Cookie Policy information, consent mechanisms and app-store declarations will be updated where required before that processing begins.

18. International Transfers

18.1 Processing outside Thailand

Tabu is based in Thailand.

Certain providers may process or store personal data outside Thailand, including in Singapore and other countries in which the relevant providers maintain infrastructure, systems or personnel.

The precise processing location may vary according to the relevant provider and service configuration.

18.2 Transfer safeguards

Where personal data is transferred outside Thailand, Tabu will use a transfer mechanism permitted by applicable law.

Depending on the circumstances, this may include:

  1. transfer to a jurisdiction recognised as providing appropriate protection;
  2. appropriate contractual or organisational safeguards;
  3. transfer necessary for an applicable contractual purpose;
  4. another statutory exception; or
  5. consent where consent is genuinely the applicable lawful mechanism.

Tabu does not treat ordinary use of the Platform as blanket consent to every international transfer.

19. How Long We Keep Personal Data

Tabu retains personal data only for as long as reasonably necessary for the purposes for which it was collected and for applicable:

  1. legal;
  2. tax;
  3. accounting;
  4. security;
  5. fraud-prevention;
  6. safety;
  7. dispute; and
  8. regulatory purposes.

Retention periods differ according to the category of information.

19.1 Account and profile information

Account and profile information is generally retained while your account is active.

Following an account-deletion request, information may remain during the applicable deletion process and for longer where retention is reasonably necessary for:

  1. legal obligations;
  2. fraud prevention;
  3. security;
  4. disputes;
  5. safety; or
  6. legal claims.

19.2 Booking and payment records

Booking and payment records relevant to accounting, tax or regulatory requirements are generally retained for at least the applicable statutory recordkeeping period.

Certain relevant financial records may need to be retained for at least five years and potentially longer where applicable law requires or permits.

19.3 Refunds, disputes and chargebacks

Records relating to refunds, payment disputes and chargebacks may be retained for the duration of the matter and thereafter for a reasonable period necessary for:

  1. accounting;
  2. evidence;
  3. fraud prevention; and
  4. legal claims.

19.4 No-Show and Booking-enforcement records

These records may be retained while reasonably relevant to:

  1. Booking administration;
  2. enforcement;
  3. disputes;
  4. fraud prevention;
  5. safety; or
  6. legal claims.

19.5 Social content

Posts, stories, comments, profile content and other User Content may be retained until:

  1. deleted where deletion functionality is available;
  2. expired according to the relevant feature;
  3. the account is erased; or
  4. longer retention is reasonably necessary for moderation, safety, disputes or legal obligations.

19.6 Messages

Messages currently do not have an automatic time-based expiry and may remain stored while necessary to provide the messaging service and until the applicable deletion or erasure process occurs.

Some limited records may also need to be retained where necessary to:

  1. preserve legitimate conversation functionality for another user;
  2. investigate safety or abuse;
  3. resolve a dispute; or
  4. comply with law.

19.7 Scene location

Scene location records are short-lived.

Each published location has a 15-minute expiry period and expired records are removed by a periodic automated cleanup process.

Tabu does not use these records to build a continuous location history.

19.8 Co-presence

Co-presence records are also short-lived and expire through the same location-cleanup mechanism.

They do not store geographic coordinates.

19.9 Security, access and audit information

Security, access, error and audit records are retained for as long as reasonably necessary for:

  1. Platform security;
  2. service integrity;
  3. fraud prevention;
  4. debugging;
  5. audits;
  6. investigations; and
  7. legal requirements.

19.10 Sentry diagnostics

Diagnostic information sent to Sentry is retained in accordance with Tabu’s configured service settings and for only as long as reasonably necessary for:

  1. troubleshooting;
  2. performance monitoring;
  3. service reliability;
  4. security; and
  5. related technical purposes.

19.11 Marketing preferences

Marketing preferences and opt-out information may be retained for as long as reasonably necessary to manage the marketing relationship and respect your choices.

19.12 Support records

Support correspondence may be retained for as long as reasonably necessary to:

  1. respond to the request;
  2. manage complaints or disputes;
  3. maintain appropriate records; and
  4. comply with applicable law.

19.13 Venue and operator records

Venue and operator account records may be retained during the relevant business relationship and for appropriate legal, accounting, audit, security and dispute periods afterwards.

19.14 Anonymised information

Information that has been irreversibly anonymised so that it no longer identifies or can reasonably be linked to an individual may be retained without a fixed personal-data retention period.

20. Account Deletion

20.1 Requesting deletion

Tabu provides an in-app Delete Account function through which you may request deletion of your Tabu account.

You may also contact:

support@tabubookings.com

for assistance with account deletion or privacy rights.

20.2 Grace period

When an account-deletion request is submitted through the applicable process, a 14-day grace period applies.

During that period, the deletion request may be cancelled through the functionality made available by Tabu.

The 14-day period is a grace period before irreversible account-erasure steps and should not be understood as a guarantee that every technical deletion step will be completed at the exact moment that the grace period ends.

20.3 Information that may be retained

Account deletion does not require Tabu to erase information that it lawfully needs to retain.

Tabu may retain limited information where reasonably necessary to:

  1. comply with tax or accounting obligations;
  2. complete or evidence a Booking, payment, refund or dispute;
  3. prevent fraud or abuse;
  4. maintain security;
  5. preserve necessary safety or moderation evidence;
  6. establish, exercise or defend legal claims; or
  7. comply with another legal obligation.

20.4 Backups

Information deleted from active Platform systems may remain temporarily within infrastructure backups until those backups are overwritten or deleted according to the relevant backup cycle.

Information retained only in backups is not ordinarily used for normal Platform operations.

Where a backup is restored, Tabu will take reasonable steps to ensure that previously processed deletion or erasure requirements continue to be respected.

21. Your Rights

Subject to the PDPA and applicable conditions and exceptions, you may have rights to:

  1. access certain personal data and obtain a copy;
  2. correct inaccurate or incomplete information;
  3. request deletion in applicable circumstances;
  4. request restriction of processing in applicable circumstances;
  5. object to certain processing;
  6. withdraw consent where processing relies on consent;
  7. receive or transfer certain personal data where the portability right applies; and
  8. lodge a complaint with the PDPC.

21.1 How to make a request

Certain information may be managed directly through Platform settings.

Account deletion may be requested through the in-app Delete Account function.

For other privacy requests, contact:

support@tabubookings.com

This includes requests concerning:

  1. access;
  2. correction;
  3. deletion;
  4. restriction;
  5. objection;
  6. portability; and
  7. withdrawal of consent.

Tabu may take reasonable steps to verify your identity before responding.

21.2 Requests and exceptions

Tabu will respond within the period required by applicable law.

A request may be limited or refused where permitted by law, including where information must be retained to:

  1. comply with a legal obligation;
  2. protect another person’s rights;
  3. investigate or prevent fraud;
  4. maintain security; or
  5. establish, exercise or defend legal claims.

Where Tabu cannot fulfil a request, it will explain the basis where required and permitted.

21.3 Fees

Tabu does not intend to charge users simply for exercising rights under the PDPA unless a charge is specifically permitted by applicable law.

22. Automated Processing, Moderation and Fraud Detection

22.1 Automated moderation and safety tools

Tabu may use automated filtering or detection tools to identify or flag:

  1. potentially prohibited content;
  2. spam;
  3. suspicious activity;
  4. possible fraud;
  5. security concerns; or
  6. potential Community Guidelines violations.

Flagged matters may be referred to the Tabu Support Team or other authorised personnel for human review.

Tabu does not intend to rely solely on automated processing to make decisions producing legal or similarly significant effects on a user without an appropriate lawful basis and safeguards.

22.2 Automated Platform mechanics

Certain Platform functions operate automatically according to technical or contractual rules.

For example:

  1. Booking Requests may expire;
  2. checkout or ticket holds may expire;
  3. payment authorisations may fail or be released;
  4. authentication attempts may be rate-limited; and
  5. technical safeguards may prevent obviously invalid or abusive activity.

These processes do not necessarily constitute profiling.

22.3 Payment-provider systems

Payment processors, banks, card networks and other financial-service providers may independently use automated systems to:

  1. authenticate transactions;
  2. approve or decline payments;
  3. identify fraud;
  4. assess payment risk; or
  5. satisfy regulatory requirements.

Where Omise / Opn Payments or another provider performs such processing for its own purposes, that provider’s own privacy information may also apply.

22.4 Content moderation

To help protect users, enforce our Terms and Community Guidelines, and comply with applicable law, Tabu may use automated classification tools together with human moderation to review content submitted to The Scene. Depending on the type of content, these systems may analyse to identify content that may be unsafe, unlawful or otherwise prohibited. The result may cause content to be allowed, withheld for human review, or blocked from publication.

Automated classification is used as a moderation and safety signal. Where appropriate, content may be reviewed by authorised Tabu personnel. Tabu may use service providers acting on our behalf to provide content-safety and moderation technology. We limit the information shared with those providers to what is reasonably necessary for the moderation purpose and apply contractual and security safeguards appropriate to the service.

23. Security

Tabu maintains technical and organisational measures designed to protect personal data against:

  1. unauthorised access;
  2. loss;
  3. alteration;
  4. misuse; and
  5. unauthorised disclosure.

Depending on the relevant system, these measures include:

  1. encrypted network connections;
  2. provider-managed protections for stored cloud data;
  3. authentication and authorisation controls;
  4. role-based and row-level access controls where applicable;
  5. private or restricted storage controls for user media;
  6. restricted access to production systems and service credentials;
  7. security and audit logging;
  8. payment-webhook verification;
  9. server-side determination of payment amounts;
  10. credential, API-key and secret-management practices;
  11. diagnostic-data filtering and redaction; and
  12. development and review practices intended to reduce security risks.

Access to personal data is restricted to personnel and service providers requiring access for authorised purposes.

Security measures may vary according to the relevant system, service and architecture.

No information system can guarantee absolute security.

24. Personal Data Breaches

Tabu maintains procedures designed to identify, assess, contain, document and respond to personal-data breaches.

Where a breach triggers notification obligations under the PDPA, Tabu will notify the PDPC and affected individuals as required by applicable law.

25. Children and Age Requirements

25.1 Minimum age

You must be at least 13 years old to create or maintain a Tabu account or use Tabu’s general Platform and Social Features.

25.2 Users under legal adulthood

If you are under the age at which you may independently:

  1. enter into a relevant agreement;
  2. provide a particular consent; or
  3. exercise a particular right,

Tabu may require the consent or involvement of your parent, legal representative or person exercising parental responsibility where required by applicable law.

25.3 Venue and Event age restrictions

Being eligible to use Tabu does not mean you are eligible to make every Booking or attend every Venue or Event.

Venues and Events may impose separate:

  1. minimum-age requirements;
  2. identification requirements; and
  3. admission conditions.

Where a Venue, Event or activity is legally restricted to persons aged 20 or older, a user under 20 may not use Tabu to circumvent that restriction.

25.4 Age verification

Tabu may request your:

  1. date of birth;
  2. identification; or
  3. other reasonable evidence

where necessary to verify eligibility, protect users, enforce applicable terms or comply with law.

25.5 Personal data of minors

Tabu does not knowingly process minors’ personal data in a manner that violates applicable law.

If Tabu learns that personal data has been processed without a required lawful basis or consent, Tabu may take appropriate steps, including:

  1. restricting the relevant feature;
  2. seeking required consent; or
  3. deleting the affected information.

25.6 Privacy choices

Optional activities involving matters such as:

  1. precise location;
  2. location sharing;
  3. co-presence;
  4. marketing;
  5. sensitive personal data; or
  6. other consent-based processing

may require additional consent or parental/legal-representative involvement where required by applicable law.

26. Venue and Host Representatives

Where you use Tabu on behalf of a Venue or Host, Tabu may process:

  1. name;
  2. work email address;
  3. work telephone number;
  4. employer or organisation;
  5. role;
  6. authentication information;
  7. dashboard activity;
  8. Booking-administration actions;
  9. support communications;
  10. settlement-related information; and
  11. security and audit information.

Tabu uses this information to:

  1. administer the Venue or Host relationship;
  2. operate and secure the operator dashboard;
  3. provide support;
  4. process Bookings and settlements;
  5. maintain appropriate business records;
  6. prevent fraud; and
  7. comply with law.

The relevant lawful basis may include:

  1. legitimate interests;
  2. administration or performance of the relevant business relationship; and
  3. legal obligations.

27. Omise Venue and Sub-Merchant Verification

Where Omise / Opn Payments requires a Venue or Sub-Merchant to complete Know Your Customer or similar compliance verification, the intended process is for the relevant Venue or Sub-Merchant to provide required verification information through the applicable Omise / Opn Payments process.

Tabu may receive limited information required to administer the payment relationship, such as:

  1. Venue or Sub-Merchant identifiers;
  2. linked payment-account information;
  3. onboarding status;
  4. verification status;
  5. notification that additional verification or action is required; and
  6. other limited integration information.

Tabu does not currently operate a general repository within the Platform for formal Omise KYC files such as:

  1. directors’ identity documents;
  2. shareholder identity documents;
  3. beneficial-owner identity documents;
  4. bank verification documents; or
  5. comparable payment-provider KYC documents.

28. Third-Party Links and Independent Services

The Platform may contain links to third-party websites, applications or services.

Where you leave Tabu and independently interact with another service, that service’s own privacy practices apply.

This differs from a provider processing personal data as part of a service supplied to Tabu, which remains subject to Tabu’s applicable legal and contractual responsibilities.

29. Changes to This Policy

Tabu may update this Policy where its:

  1. Platform features;
  2. technology;
  3. service providers;
  4. business practices; or
  5. legal obligations

change.

The revised Policy will display an updated "Last updated" date.

Where a change materially affects how personal data is processed, Tabu will provide appropriate additional notice where required.

Publication of an updated Privacy Policy does not, by itself, constitute consent to a new processing activity where consent or another legal step is required.

Where a new activity requires consent, Tabu will obtain that consent before relying on it.

30. Contact Us

For questions, requests or complaints about this Policy or Tabu’s processing of personal data:

  • Tabu Co., Ltd.
  • Company registration number: 0105569086462
  • 27/2 Sukhumvit 33 (Daeng Udom), Khlong Tan Nuea, Watthana, Krung Thep Maha Nakhon 10110, Thailand
  • Privacy email: support@tabubookings.com
  • Website: tabu.social

You may also have the right to submit a complaint to the Office of the Personal Data Protection Committee of Thailand.