Effective date: 25 June 2026 · Last updated: 25 June 2026 · Version 2.0
This Policy is published in English. A Thai translation is provided for convenience; the English version prevails in case of conflict.
Travellife ("Travellife", "we", "us", "our") operates the Travellife platform, mobile app, and related services (the "Service"). This Policy explains what personal data we process, why, the legal bases we rely on, and the rights you have. It is designed to meet the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and the Personal Data Protection Act B.E. 2562 of Thailand ("PDPA").
The data controller is Travellife, operating the platform at travellifeapp.com.
We do not knowingly process special categories of data (health, religion, biometrics).
Personal data may be processed in countries outside your country of residence, including the United States, the European Economic Area, the United Kingdom, and Thailand. Where we transfer personal data outside the EEA/UK, we rely on European Commission adequacy decisions or the Standard Contractual Clauses (2021/914) plus supplementary safeguards. Transfers out of Thailand rely on PDPA Section 28 safeguards.
Under GDPR / UK GDPR / PDPA you have the right to:
If you are a California resident (CCPA/CPRA) you additionally have the right to:
To exercise any right, email privacy@travellifeapp.com. We respond within 30 days (GDPR) or 45 days (CCPA), extendable once where permitted by law. We verify your identity before fulfilling requests.
We apply administrative, technical, and organizational measures appropriate to the risk: TLS 1.2+ in transit, encryption at rest, row-level security on every user-owned table, least-privilege access for staff, audit logging, and a documented incident response plan. In the event of a personal data breach likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Art. 33–34 and PDPA Section 37.
The Service is not directed to children under 16 (or the equivalent minimum digital-consent age in your country). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@travellifeapp.com and we will delete it.
We may update this Policy to reflect changes in our practices or in law. Material changes will be communicated by email or in-app notice before they take effect.
Privacy questions: privacy@travellifeapp.com
You may also lodge a complaint with your local data-protection authority — e.g. your EU member state DPA, the UK ICO, or Thailand's PDPC (pdpc.or.th).
See also: Terms of Service
