Back

Privacy Policy

Effective date: 25 June 2026 · Last updated: 25 June 2026 · Version 2.0

This Policy is published in English. A Thai translation is provided for convenience; the English version prevails in case of conflict.

Travellife ("Travellife", "we", "us", "our") operates the Travellife platform, mobile app, and related services (the "Service"). This Policy explains what personal data we process, why, the legal bases we rely on, and the rights you have. It is designed to meet the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and the Personal Data Protection Act B.E. 2562 of Thailand ("PDPA").

1. Data controller and contact

The data controller is Travellife, operating the platform at travellifeapp.com.

2. Personal data we process

  • Account data: name, email, phone number, profile photo, password hash, language preference.
  • Booking data: items booked, dates, guest count, special requests, cancellation history.
  • Payment data: card brand, last four digits, billing country, and Stripe identifiers. Full card numbers are processed directly by Stripe — we never see, store, or log them.
  • KYC / identity documents (partners only): government-issued ID and business registration, processed for verification.
  • Communications: messages you send to support, reviews you post.
  • Device and usage data: IP address, device type, OS, app version, crash logs, anonymized analytics events.
  • Location: only when you explicitly grant permission for nearby search.

We do not knowingly process special categories of data (health, religion, biometrics).

3. Purposes and legal bases (GDPR Art. 6)

  • Provide the Service (contract, Art. 6(1)(b)): create your account, process bookings, deliver receipts.
  • Payments & fraud prevention (contract + legitimate interest, Art. 6(1)(b)/(f)).
  • Partner KYC (legal obligation, Art. 6(1)(c)): comply with anti-money-laundering and tax law.
  • Service emails (contract): booking confirmations, payment receipts, password resets.
  • Marketing emails (consent, Art. 6(1)(a)): only when you opt in; you can withdraw consent at any time.
  • Security & abuse prevention (legitimate interest, Art. 6(1)(f)).
  • Legal claims and audits (legal obligation / legitimate interest).

4. Sharing and subprocessors

We share personal data only with:

  • Partner providers (hotels, villas, car rentals, restaurants) — limited to what is needed to fulfill your booking.
  • Stripe Payments Europe Ltd. / Stripe, Inc. — payment processing (PCI DSS Level 1).
  • Hosting & database — Lovable Cloud (built on Supabase / AWS infrastructure).
  • Email delivery — Resend / SendGrid for transactional and authentication emails.
  • Government authorities — only where required by valid legal process.

We do not sell or "share" personal information as those terms are defined under CCPA/CPRA, and we do not engage in cross-context behavioral advertising.

5. International data transfers

Personal data may be processed in countries outside your country of residence, including the United States, the European Economic Area, the United Kingdom, and Thailand. Where we transfer personal data outside the EEA/UK, we rely on European Commission adequacy decisions or the Standard Contractual Clauses (2021/914) plus supplementary safeguards. Transfers out of Thailand rely on PDPA Section 28 safeguards.

6. Retention

  • Account data: while your account is active, plus 12 months after deletion.
  • Booking and tax records: 7 years (statutory tax retention period).
  • Payment records: 7 years.
  • Support tickets: 3 years.
  • Marketing consent logs: until you withdraw consent, plus 2 years for evidence.
  • Anonymized analytics: indefinitely (no longer personal data).

7. Your rights

Under GDPR / UK GDPR / PDPA you have the right to:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure ("right to be forgotten").
  • Restriction of processing.
  • Data portability (in a structured, machine-readable format).
  • Object to processing based on legitimate interest or direct marketing.
  • Withdraw consent at any time, without affecting prior processing.
  • Lodge a complaint with your supervisory authority.

If you are a California resident (CCPA/CPRA) you additionally have the right to:

  • Know what personal information we collect and how we use it.
  • Delete your personal information.
  • Correct inaccurate personal information.
  • Opt out of "sale" or "sharing" (we do not engage in either).
  • Non-discrimination for exercising your rights.

To exercise any right, email privacy@travellifeapp.com. We respond within 30 days (GDPR) or 45 days (CCPA), extendable once where permitted by law. We verify your identity before fulfilling requests.

8. Security

We apply administrative, technical, and organizational measures appropriate to the risk: TLS 1.2+ in transit, encryption at rest, row-level security on every user-owned table, least-privilege access for staff, audit logging, and a documented incident response plan. In the event of a personal data breach likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Art. 33–34 and PDPA Section 37.

9. Children

The Service is not directed to children under 16 (or the equivalent minimum digital-consent age in your country). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@travellifeapp.com and we will delete it.

10. Cookies and similar technologies

We use first-party storage strictly necessary to keep you signed in and to remember your preferences. We do not use third-party advertising cookies or cross-site tracking.

11. Changes to this Policy

We may update this Policy to reflect changes in our practices or in law. Material changes will be communicated by email or in-app notice before they take effect.

12. Contact and complaints

Privacy questions: privacy@travellifeapp.com

You may also lodge a complaint with your local data-protection authority — e.g. your EU member state DPA, the UK ICO, or Thailand's PDPC (pdpc.or.th).

See also: Terms of Service

Travellife