TOHSAKAN

Privacy Policy

Effective Date: September 21, 2026

The operator of the TOHSAKAN application ("the Platform", "we", "us") within the BENJARONG Ecosystem respects your privacy. This policy explains what personal data the TOHSAKAN app collects, why, who it is shared with, how long it is kept, and the rights you have under Thailand's Personal Data Protection Act B.E. 2562 (PDPA). It describes the app as it exists today; features that are not yet enabled are listed at the end and collect nothing.

1. Who is responsible for your data

The data controller is the operator of the TOHSAKAN application. For anything about this policy or your data, use the contact channels in section 12. We reply within 30 days as the PDPA requires.

2. What we collect and when

We collect only what each feature needs. Nothing below is collected until you use the feature it belongs to.

  • Account — Name, email address, and a password you choose (stored only in protected, hashed form). Optionally a username, phone number, profile picture, and short bio that you add to your profile. Your language preference and the Private account setting.
  • Sign in with Google or Apple — If you sign in with Google or Apple, that provider sends us your name, email address, and a signed token that proves who you are. Apple may give us a private relay address instead of your real email. We never receive your Google or Apple password. Apple sign-in also gives us a one-time authorization code that lets us revoke the Apple link when you delete your account.
  • Content you share — Posts, photos, videos, captions, comments, likes, saves, shares, follows, follow requests, and the places or services you tag. Media is uploaded to our storage. Photos and videos you choose may contain metadata such as the time they were taken; we do not extract embedded location into your post unless you tag a place yourself.
  • Camera, microphone, photos — Used only when you create a post or record a video, and only after you grant permission. The app writes to your photo library only when you tap Save on a payment QR code.
  • Location — Requested only while the app is open and only when you tag a place on a post, so nearby places can be sorted first. There is no background location tracking. You can decline; tagging then works by search.
  • Bookings — Details needed to book a stay, transport, restaurant, or activity: dates, number of guests, traveler names, contact details, special requests, and your booking history and references.
  • Payments — Card numbers are entered into a Stripe form and go directly to Stripe; they never reach our servers, and we store only the last four digits, card brand, and payment status. PromptPay QR payments are also processed by Stripe.
  • AI travel assistant — The messages you type, a conversation identifier, and, when you are signed in, your account token so the assistant can personalise replies. The assistant service keeps your conversation history so context carries across turns. Do not share sensitive personal data in chat.
  • Notifications — A device push token so notifications can reach your phone, and your notification preferences. You can turn push off in your device settings at any time.
  • Safety tools — The accounts you block, the posts or comments you report, and the reason you give.
  • Device and technical data — Device model, operating system, app version, IP address, language, and server logs of requests. The app contains no third-party analytics or advertising SDK.

3. Why we use it and the legal basis

  • Providing the service — Running your account, feed, bookings, payments, and notifications. Basis: performance of a contract with you (PDPA section 24(3)).
  • Safety and integrity — Detecting fraud and abuse, enforcing the Terms of Use, acting on reports, and keeping systems secure. Basis: our legitimate interests (section 24(5)).
  • Legal duties — Keeping accounting, tax, and payment records for as long as Thai law requires, and answering lawful requests from authorities. Basis: legal obligation (section 24(6)).
  • Features that need your permission — Camera, microphone, photos, location, and push notifications run only after you allow them in the device permission prompt. Basis: consent, which you can withdraw in your device settings at any time.
  • Improving TOHSAKAN — Understanding which features are used and where the app fails, using our own server logs. We do not profile you for advertising.

4. Who we share it with

We do not sell personal data. We share it only with the parties below, and only what each needs.

  • Service providers you book — Hotels, transport operators, restaurants, and activity operators receive the booking details needed to deliver what you booked.
  • Payment processor — Stripe processes card and PromptPay payments for bookings. Stripe is a PCI DSS certified processor with its own privacy policy.
  • Sign-in providers — Google and Apple, when you choose to sign in with them.
  • Agoda — The Agoda section shows live hotel prices. When you open a hotel there, you leave TOHSAKAN and the link carries your search: destination, dates, number of guests, and sort order. Any booking you then make is with Agoda under Agoda's terms and privacy policy; Agoda does not send us your payment details. TOHSAKAN is an Agoda affiliate partner and may receive a commission on bookings made through those links.
  • Google Maps and Places — Some place, restaurant, and photo information in search results and the assistant comes from Google and is shown with its attribution. We do not send Google your personal data to display it.
  • AI model provider — The assistant service runs on the operator's systems and generates replies using a third-party large-language-model provider, such as Anthropic (Claude). Your chat messages are sent to that provider to produce a reply.
  • Infrastructure — Cloud hosting and object storage for our servers and your media, Cloudflare for content delivery and security, and an email delivery service for account and booking messages.
  • Authorities — Courts, regulators, or law enforcement when the law requires it or to protect the safety of users.

5. Transfers outside Thailand

Some of the providers above, including Stripe, Google, Apple, Cloudflare, and the AI model provider, process data outside Thailand. We transfer personal data abroad only where the PDPA allows it: to a country with adequate protection, under contractual safeguards with the recipient, with your consent, or where necessary to perform your contract, for example to complete a payment or sign-in.

6. How long we keep it

  • Account and content — For as long as your account exists. When you delete your account it is anonymised: your profile, name, email, and sign-in are removed and your published content is detached from you.
  • Bookings and payments — Kept for as long as Thai accounting and tax law requires after the transaction, then deleted or anonymised.
  • AI assistant conversations — Kept by the assistant service to carry context between turns. Starting a new chat begins a new conversation; to erase past conversations, send a request to support.
  • Logs and push tokens — Server logs are kept for a short period for security and debugging. Push tokens are removed when you sign out or uninstall.

7. Your rights under the PDPA

You can exercise most rights yourself in the app; for the rest, contact support through the channels in section 12. We may ask you to verify your identity first.

  • Access and portability — Settings > Privacy > Download your data gives you everything we hold about you as one JSON file.
  • Rectification — Edit your name, username, picture, and bio in your profile; change your password under Account.
  • Erasure — Settings > Account > Delete account anonymises your account as described in section 6. Records the law obliges us to keep are retained for that period only.
  • Withdraw consent — Turn camera, photos, microphone, location, or notifications off in your device settings. Set your account to Private to limit who sees your posts.
  • Object and restrict — You may object to, or ask us to restrict, processing based on legitimate interests by writing to us.
  • Complain — You have the right to lodge a complaint with the Personal Data Protection Committee (PDPC) of Thailand.

8. Security

Traffic between the app and our servers is encrypted with TLS. Sign-in tokens are kept in the device's secure storage. Card data is handled entirely by Stripe. Access to production data is restricted to staff who need it. No system is perfectly secure; if a breach affects you we will notify you and the PDPC as the law requires.

9. Children

TOHSAKAN is intended for users aged 18 and over. If you are under 20, Thai law may require a parent or guardian to consent on your behalf before you use features that rely on consent. We do not knowingly collect data from children; if we learn we have, we delete it.

10. Features not yet enabled

The app contains screens for features that are not active in this release. They collect, transmit, and store nothing today, and this policy will be updated before any of them is switched on:

  • Smart Safety — Geofencing alerts, SOS dispatch, and background location.
  • Health Care — Blood type, allergies, vital signs, fall detection, or anything from a smart watch.
  • KYC verification — Identity documents are not collected.
  • Points, Tohsakan Passport stamps, and TOHSAKAN+ membership — Rewards, stamps, and paid membership tiers are preview screens only.
  • Live streaming and Marketplace — Preview screens only.
  • Form-Fill Assistant (TDAC) — No passport or immigration data is collected.

11. Changes to this policy

When this policy changes we update the effective date above and show the new version in the app. Material changes are announced in the app before they take effect.

12. Contact

  • Data controller — The TOHSAKAN application team
  • Contact email — support@scgs.co