AAppoint and AnySpa Privacy Notice
Version 1.0 · Last updated 25 September 2026
1. Who we are and how to contact us
Appointment Anywhere Co., Ltd. ("we", "us") is the data controller for the AAppoint and AnySpa booking platform.
This notice explains how we collect, use, disclose and protect your personal data under Thailand's Personal Data Protection Act B.E. 2562 (PDPA) and, where it applies, the EU General Data Protection Regulation (GDPR).
AnySpa is a brand of the same company, on the same platform. This notice applies to both brands.
Privacy contact
- Email: info@aappoint.me. Use it for every request: access, copy, correction, deletion, withdrawing consent, objecting, and complaints.
- Address: No. 25 Alma Link Building, 17th Floor, Room 222, Soi Chidlom, Ploenchit Road, Lumpini, Pathumwan, Bangkok 10330, Thailand
- Phone: +66 2 681 9700
1.1 Our role and the shop's role
- We are the controller for platform accounts and platform services: bookings and payments made through the platform, notifications, marketing messages, platform security, and our websites.
- The shop is the controller for customer records it keeps and manages in its own shop tools, such as its customer list, walk-in guests entered by staff, and its own notes. For these records we process data on the shop's behalf as its processor, under our data processing agreement with shops (Merchant DPA).
- When you book with a shop, we send your booking details to that shop so it can serve you. The shop also uses them under its own policies.
- To use your rights over records a shop keeps, contact the shop directly, or email info@aappoint.me and we will forward your request and help the shop respond.
2. Scope of this notice
This notice covers:
- The AAppoint (marketplace.aappoint.me) and AnySpa (marketplace.anyspa.me) booking websites, including the booking and payment pages opened from Reserve with Google and the waitlist pages opened from a shop's QR code
- Our mobile apps
- The merchant portal for shop owners and staff (shop.aappoint.me and the AnySpa merchant portal)
- Our LINE Official Account, which shop staff link to receive booking information
- Bookings that arrive through Reserve with Google (Google Search and Google Maps) and through Mozrest (booking channels on Meta services such as Instagram and Facebook)
- Bookings made through Gita, our own AI concierge service, and through partners' AI assistants connected to our partner API (see 7.6)
- Our company website www.aappoint.me, including its contact form and restaurant registration form
- The emails, SMS messages and notifications we send you
This notice does not cover other parties' services, such as shops, payment providers, Google, Meta, LINE or partners' AI assistants. Each has its own privacy notice.
3. Personal data we collect
3.1 Data you give us directly
- Account: first name, last name, phone number, email, password (stored as a one-way hash), profile picture (optional; it is stored at a public web address, so anyone who has the link can view it), language, SMS and email notification settings, and your marketing opt-in choice. Other signed-in users can find your name and profile picture through account search.
- Verification: one-time codes (OTP) sent to verify your phone or email, and password reset links. These expire automatically.
- Bookings: shop, service, date and time, service location (usually the shop's address), party size (adults, youths and children), occasion (for example a birthday), chosen zone or table, add-on products or services, special requests or notes to the shop, and ratings you give a shop or its staff
- Companions: the email or phone number of friends you add to a booking. Please tell them about this notice.
- Deposits and payments: amount, payment method, order and reference numbers, status, and the payment result returned by the provider (see 3.6)
- Waitlist: name, phone number, email (if given), party size, and your browser push subscription if you tap "Notify me"
- Contacting us: messages and emails you send us, including rights requests
3.2 Data we receive from other people and services
This section is our notice under PDPA section 25 and GDPR Article 14 for data we do not collect from you directly.
- People who book for you or add you as a companion: your name, email or phone number
- Shops: when staff record a phone booking, enter you as a walk-in or waitlist guest, or invite you as a customer, the shop sends us your name, phone number, email, party size, notes and contact logs. The shop is the controller of these records (see 1.1).
- Google (Reserve with Google): when you book through Google Search or Google Maps, we receive your name, email, phone number, Google booking user ID, booking details, notes and a booking conversion token
- Mozrest: when you book through Meta services such as Instagram or Facebook, we receive your name, contact details, booking details, notes and, where a deposit applies, a payment token
- Partners' AI assistants you use to book: your name, email, phone number, notes, booking details and the partner's reference for you. If you let an assistant pay from your e-wallet on your behalf (where offered), we keep that payment authorisation in encrypted form and a partly masked wallet ID.
- Payment providers: payment status and payer details the provider returns, such as name, email, phone number, address, card brand, last 4 card digits, card expiry or wallet user ID
- Meta (Facebook Login): your name, email and Facebook user ID when you choose to sign in with Facebook
- LINE: your LINE user ID and the messages you send to our LINE Official Account, when shop staff link their LINE account
Guest accounts: when a booking arrives through one of these channels, we look for an existing account with the same email, phone number or name and link the booking to it. If there is none, we create a guest account from the details received. You can activate it later or ask us to delete it (see section 11).
3.3 Data collected automatically
- Usage and log data: IP address, device and browser type, the URLs requested (including link parameters), times and errors, recorded in our server logs on Google Cloud. Logs can also contain phone numbers, email addresses and the content of notifications we send.
- Device data for notifications: the mobile app's push token and your browser's web push subscription
- Data stored in your browser and app: see section 12
- Data the system derives from bookings: how many times you have visited a shop, how many times you did not show up (no-shows), and a regular-customer (VIP) status. A shop sees this only for visits to that shop. It may use it to prioritise service or to give regular customers a longer grace period for arriving late. We do not use it to make automated decisions with legal or similarly significant effects on you.
- Shop customer lists: when you book with a shop through our booking website, you are added to that shop's customer list
3.4 Shop owners and staff
- Account and role: first name, last name, email, phone number, profile picture, role in the shop (owner, admin or staff), and your LINE user ID if you link our LINE Official Account
- Work data: schedules, working days, leave days with notes, services assigned to you, and ratings customers give you
- Shop details (personal data when the shop is run by an individual): email, phone number, address and map location, bank account number and account name for payouts, and referral code
- Business or identity documents (KYC) uploaded for shop approval, such as a company certificate or a copy of an ID card
- Purchases of our plans or services: tax ID (for an individual, the national ID number), name and address for tax invoices, and card details returned by Omise (cardholder name, last 4 digits and expiry)
- Use of the merchant portal: a sign-in cookie, plus the IP address and browser details received by our hosting, font and map providers (see 12.3)
3.5 Company website visitors and business contacts (www.aappoint.me)
- Contact form: email, phone number and message
- Restaurant registration form: name, position, email, mobile number, preferred time to be contacted, the restaurant's name, address, phone number and location (from Google Places), and how you reached the site (UTM parameters)
- Submissions from both forms are stored in Google Sheets. Our sales team uses them to contact you, and we send a welcome email to people who register a restaurant.
- Cookies and browsing data: analytics and advertising cookies are used only if you accept them. Our hosting provider (Vercel) receives your IP address and browser details on every visit, and Google receives them when a page shows the office map or you use the address search on the restaurant form. Google may set its own cookies (see 7.4, 7.5 and 12.1).
3.6 Payment card data
- Card numbers you enter are sent from your browser directly to the payment provider (for example Omise), or entered on the provider's own payment page (for example Stripe, ShopeePay and Alipay).
- Our servers receive only a token and limited details the provider returns, such as card brand, last 4 digits, expiry and cardholder name.
- We do not store full card numbers or CVV codes.
- If you choose to save a card, the card is stored by Omise and we keep only Omise's customer reference.
4. Sensitive data
- We do not intentionally collect sensitive data such as health, religious or belief information (PDPA section 26 / GDPR Article 9).
- Please do not put health information (such as symptoms, conditions or medicines) or religious information in booking notes. Notes are sent to the shop and can appear in booking emails, SMS messages and notifications.
- A booking at a clinic, dental, spa or beauty shop can imply health information. We use it only to deliver that booking, and share it only with that shop and the providers that send your booking messages.
- For shops: please cover the religion and blood type fields on ID card copies before uploading, and do not record health information in customer notes or staff leave notes.
5. Purposes and legal bases
| Purpose | Data used | Legal basis (PDPA / GDPR) |
|---|---|---|
| Create and manage your account, sign you in (including through Facebook and LINE), and verify your phone or email by OTP | Account, OTP | Contract (s.24(3) / Art 6(1)(b)) |
| Make, reschedule and cancel bookings and waitlist entries, send booking details to the shop, create guest accounts, and link bookings to an existing account | Booking, contact details, notes | Contract (s.24(3) / Art 6(1)(b)) |
| Send service messages such as confirmations, reminders, changes, cancellations, waitlist calls and OTPs by SMS, email, push and LINE | Contact details, booking, push token | Contract (s.24(3) / Art 6(1)(b)) |
| Take deposits and payments, make refunds, and reconcile payments | Payment | Contract (s.24(3) / Art 6(1)(b)) |
| Keep accounting and tax records | Booking, payment, tax invoice details | Legal obligation (s.24(6) / Art 6(1)(c)) |
| Accept bookings from Google, Mozrest and partners' AI assistants, and send booking status back to them | Data received from those channels | Contract (s.24(3) / Art 6(1)(b)) |
| Provide shop tools such as customer lists, notes, visit history, no-shows and VIP status | Records the shop keeps | The shop is the controller and sets its own legal basis; we process on its behalf under the Merchant DPA |
| Onboard shops, check shop documents (KYC), pay shops, bill for our services and issue tax invoices | Shop and staff data | Contract (s.24(3) / Art 6(1)(b)); legal obligation (s.24(6) / Art 6(1)(c)); legitimate interests in preventing fraud (s.24(5) / Art 6(1)(f)) |
| Keep the platform secure, prevent fraud and misuse, keep logs, fix problems and improve the service | Logs, device and usage data | Legitimate interests (s.24(5) / Art 6(1)(f)) |
| Follow up business enquiries from the company website forms and send a welcome email | Form data | Legitimate interests (s.24(5) / Art 6(1)(f)) |
| Send news and promotions from shops and from us | Contact details, push token, language | Consent (s.19 / Art 6(1)(a)) |
| Analytics and advertising cookies on the company website | Cookies, IP address, browsing data | Consent (s.19 / Art 6(1)(a)) |
| Comply with the law and with orders from authorities | Relevant data | Legal obligation (s.24(6) / Art 6(1)(c)) |
| Establish, exercise or defend legal claims | Relevant data | Legitimate interests (s.24(5) / Art 6(1)(f)) |
- If you do not give the data a booking or payment needs, such as your name and phone number, we cannot make the booking or send you messages about it.
- Where we rely on legitimate interests, you can object (see section 11).
6. Marketing messages
- We send news and promotions only to people who opt in. The option is never pre-ticked, and people who have not opted in do not receive these messages.
- They cover promotions that shops on the platform send through our system (both shops you have booked with and other shops on the platform) and news from us.
- They are sent by SMS, app push notification and the in-app inbox. We approve every message before it is sent.
- You can withdraw at any time by emailing info@aappoint.me from your account email or with your account phone number, or by turning the option off in the app's settings where the app offers it. Every promotional message includes a line explaining how to unsubscribe.
- Withdrawing does not stop messages about your bookings and account, such as booking confirmations and OTPs, which are needed to provide the service.
7. Who we share data with
We do not sell your personal data. We share only what is needed with the following recipients.
7.1 Shops you book or queue with
The shop and its staff receive your name, phone number, email, booking details, notes, deposit status and your visit history at that shop.
7.2 Payment providers
They take payment by the method you choose. They also process data under their own legal obligations and their own privacy notices.
- Stripe: card payments on Stripe's payment page, including payments an AI assistant makes on your behalf. Receives user and booking references, the service name and the amount; you enter your card and email on Stripe's page. (United States)
- Omise (Opn Payments): card payments, saved cards and billing shops for our services. Receives your email and a customer reference. (Thailand/Japan)
- GB Prime Pay: PromptPay QR payments. Receives your name, email, the service name and the amount. (Thailand)
- ShopeePay: wallet payments. Receives user and booking references and the amount. (Thailand)
- Ksher: WeChat Pay payments. Receives a customer reference, the service name and the amount, and passes the payment on to WeChat Pay (China).
- Antom (Alipay+): Alipay and AlipayHK payments. Receives the order number, the service name and the amount. (Singapore, passing payments on to wallet operators in China and Hong Kong)
7.3 Messaging providers
- BytePlus: sends all SMS messages (OTPs, bookings and waitlist). Receives your phone number and the message text. Cancellation messages sent to the shop can include your name and booking note. (Singapore-based company in the ByteDance group)
- Microsoft 365: sends email. Receives your name, email and the email content, such as booking details, notes and calendar invitations.
- Firebase Cloud Messaging (Google): sends notifications to the mobile app. Receives the push token and the notification content (shop, service and time).
- Browser push services (Google, Mozilla or Apple, depending on your browser): deliver waitlist notifications. The content is encrypted and contains only the shop name and your queue position.
- LINE (LY Corporation): sends replies to shop staff who link their LINE account to our LINE Official Account. (Japan/Thailand)
7.4 Google, Mozrest and Meta
- Google Cloud: runs our servers, database, file storage and logs, so all platform data is held on Google Cloud (Singapore, see section 8). The merchant portal is served by Google's Firebase Hosting.
- Reserve with Google: when you book through Google, we send Google the booking number, shop and service IDs, start time, status and the booking conversion token. Google is an independent controller.
- Google Maps: shows maps on shop pages, in the merchant portal and on the company website. Google receives your IP address and browser details.
- Google Sheets: stores submissions from the company website forms.
- Google Fonts: serves fonts in the merchant portal and in our emails. Google receives your IP address.
- Mozrest: receives the status of bookings made through Meta channels (booking number, party size, date and status). (United Kingdom/European Union)
- Meta: verifies Facebook sign-in, and runs the Meta Pixel on the company website only if you accept cookies. (United States/Ireland)
7.5 Company website
- Vercel: hosts the company website and receives your IP address and browsing data. Vercel Analytics and Speed Insights run only if you accept cookies. (United States)
- Google Tag Manager, and the Google tags it loads such as Google Analytics: run only if you accept cookies.
7.6 AI assistants you use to book
We send the assistant your booking result and status, the booking details you gave, deposit details and payment links.
- Gita (AgentGita.com) is our own AI concierge service. It uses Google Gemini to understand your messages and files. The Gita privacy notice explains what Gita collects and how it uses it.
- Partners' AI assistants, such as hellomind.ai, are run by other companies. Each is an independent controller, and its own privacy notice covers its conversations and processing.
7.7 Authorities and advisers
We disclose data to government authorities, courts or officials when the law requires it, and to professional advisers such as auditors and lawyers when needed for a legal obligation or a legal claim.
8. International transfers
- The platform's main data (database, servers and files) is hosted on Google Cloud in Singapore (asia-southeast1).
- Other providers in section 7 may process data outside Thailand, for example in Singapore, the United States, the European Union, the United Kingdom, Japan, China and Hong Kong.
- We transfer data under PDPA sections 28-29 and GDPR Chapter V, relying on the providers' data processing terms or standard contractual clauses, or where the transfer is needed to perform our contract with you, such as paying through the provider you choose.
- You can ask for more information about these safeguards at info@aappoint.me.
9. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data | While the account is active; erased or anonymised within 30 days of a verified deletion request |
| Booking, deposit and payment records | Up to 5 years after the transaction for accounting/tax and legal claims (Accounting Act B.E. 2543 / Revenue Code), then deleted or anonymised. Before that, identity can be removed on request while the transaction record is kept pseudonymised. |
| Waitlist entries | Kept with booking history; deleted on request |
| Notification and message history | Same as bookings |
| Marketing opt-in | Until withdrawn |
| Merchant and staff accounts and KYC documents | While the shop account is active and up to 5 years after closure for legal claims |
| Server and application logs | Google Cloud Logging default retention (about 30 days) |
| Website leads (contact and registration forms) | Up to 2 years from last contact, or until the person asks us to delete them |
| Website analytics and advertising cookies | Per the cookie lifetime of each provider, only with consent |
- Expired OTPs, password reset links and sessions are deleted automatically.
- Deleted data may remain in database backups until those backups expire.
10. Security
- Encrypted connections (HTTPS) between the apps, websites and our servers
- Role-based access: a shop's booking records are available only to that shop, according to each person's role, and our team's access is limited to what their work needs
- Passwords are stored as hashes, and we do not store full card numbers (see 3.6)
- Partner access keys and tokens are stored as hashes, and e-wallet payment authorisations are encrypted
- We use Google Cloud's infrastructure and security measures
- If a personal data breach occurs, we will notify the Office of the Personal Data Protection Committee within 72 hours of becoming aware of it where the breach poses a risk to your rights, and notify you without delay where the risk is high
- No system is 100% secure. If you find a security problem, please tell us at info@aappoint.me
11. Your rights
Subject to the conditions in the law, you have the right to:
- Access your data and get a copy (PDPA s.30 / GDPR Art 15)
- Receive your data, or have it sent to another organisation, in a machine-readable format (s.31 / Art 20)
- Have your data corrected and kept up to date (s.35 / Art 16)
- Have your data deleted or anonymised (s.33 / Art 17)
- Restrict the use of your data (s.34 / Art 18)
- Object to processing, including direct marketing (s.32 / Art 21)
- Withdraw consent at any time, without affecting processing carried out before you withdraw (s.19 / Art 7(3))
- Complain to a supervisory authority (s.73 / Art 77), see section 15
How to make a request
- Email info@aappoint.me with the subject "Personal data request". There is currently no delete-account or download-data button in the apps; please send requests by email.
- Send it from your account email, or include your name, the phone number or email used for booking, the shop name or booking number, and what you want us to do.
- Before we give you a copy of your data or correct, delete or restrict it, we send a one-time code to the phone number or email we hold for your account and ask you to send it back, to make sure the request comes from you.
- We reply within 30 days of receiving a verified request, free of charge.
Good to know
- Deleting your account: we delete or anonymise your account data (name, contact details, sign-in details, devices and notification subscriptions) and clear your name, phone number and email from waitlist entries you joined through AAppoint. Booking and payment records are kept, linked only to the deleted account, for the period in section 9. Until that period ends, payment records still hold the payer details the payment provider sent us (for example name, email or card holder name), and notes you wrote on a booking stay with that booking. After deletion you can no longer sign in to that account.
- Records a shop keeps in its shop tools: the shop decides on the request. We forward your request to the shop and help it respond.
- When we cannot fully agree: we may refuse or only partly carry out a request where the law allows, for example when we must keep accounting records. We will tell you why.
12. Cookies and similar technologies
12.1 Company website (www.aappoint.me)
- Necessary cookie:
cookie_consentremembers your choice in the cookie banner for 365 days. - Analytics and advertising: Google Tag Manager (and the Google tags it loads, such as Google Analytics), the Meta Pixel, and Vercel Web Analytics and Speed Insights load only after you click "Accept". If you click "Decline", they do not load.
- To change your choice, delete the website's cookies in your browser and choose again when the cookie banner reappears.
- The office map in the contact section is an embedded Google Map, and the address search on the restaurant form uses Google Maps. Google may set its own cookies when they load.
12.2 Booking websites (marketplace.aappoint.me and marketplace.anyspa.me)
- No analytics or advertising cookies are used.
- Your browser's local storage keeps:
- your sign-in token, removed when you sign out
- booking and payment progress for bookings from Reserve with Google
- your waitlist entry
- A service worker delivers waitlist notifications when you turn them on.
- You can remove this data by clearing the site's data in your browser.
- Shop pages show Google Maps, and card payment pages load Omise's script, so both providers receive your IP address and browser details.
12.3 Merchant portal
- A sign-in cookie keeps you signed in. It is removed when you sign out or close the browser, and a sign-in lasts at most 24 hours.
- A language cookie remembers the language you chose.
- Pages are served through Firebase Hosting and use Google Fonts and Google Maps.
12.4 Mobile apps
The apps keep your sign-in session on your device and use a push token for notifications.
13. Children
- Our services are intended for people aged 20 or over, or people using them with the consent of a parent or guardian.
- A booking may record how many children are in the party. This is a number only; we do not collect data that identifies the children.
- If you believe a child has given us personal data without a parent's or guardian's consent, email info@aappoint.me and we will delete it.
14. Changes to this notice
- We may update this notice when our services or the law change. We will publish the new version on our websites and apps with the updated date.
- For significant changes we will tell you through the app, email or SMS, and ask for your consent again where the law requires it.
- Version 1.0 (25 September 2026) replaces all previous privacy policies.
15. Complaints
- If you have a concern, please contact us first at info@aappoint.me so we can put it right.
- You have the right to complain to Thailand's Office of the Personal Data Protection Committee (PDPC), www.pdpc.or.th.
- If you are in the EU or EEA, you can also complain to the data protection supervisory authority in your country.