Legal

Privacy Policy

Last updated: 14 September 2026

The short version

We collect what we need to match you with a Buddy, run your booking and keep both sides safe. We do not sell your data, we do not run advertising trackers, and we share your details with a Buddy only once a booking is confirmed, and only as much as they need. Because you pay your Buddy directly, we never handle your card or bank details at all.

1. Who is responsible for your data

BuddyEase is the data controller for the personal data described here. That means we decide what is collected and why. If you want to exercise any of the rights in section 8 or ask a question, the contact details are in section 12.

2. What we collect

Information you give us

  • Account details: your name, email address, phone number, password (stored hashed, never in readable form) and profile photo if you add one.
  • Booking details: dates, group size, destination, interests, language preferences, and anything you tell us in a trip request, including accessibility or dietary notes you choose to share.
  • Messages: what you send through our in-platform messaging, including messages to support.
  • Identity verification data: before you can book, or be matched as a Buddy, you verify your identity with Didit, our verification provider. Didit captures your ID document and a selfie. We receive the result, the name, document type, document number and issuing country Didit read from the document, a reference to the verification session, and a record of the consent you gave, including when you gave it and which version of this policy was in force. We do not receive the images.
  • Buddy application data: if you apply to become a Buddy, we additionally collect a profile photo, your interview notes, and the details needed to pay you or settle commission.

Information we collect automatically

  • Session data: the essential cookies that keep you signed in. See our Cookie Policy for the full list.
  • Technical data: IP address, browser type, device type and the pages you visit, used to keep the service secure and to understand what is working. Our usage analytics is anonymous and stored in your browser.

We do not collect special-category data such as health, religion or political views, and we ask you not to send it. If you volunteer something of that kind in a trip note, for example an allergy, we use it only to make the trip work.

3. Why we use it, and our legal basis

  • To run your booking (matching, confirmation, reminders, changes, cancellations). Basis: performance of a contract with you.
  • To keep people safe (verifying Buddies, masking contact details before confirmation, investigating complaints, providing an emergency contact). Basis: legitimate interest in a safe marketplace, and legal obligation where applicable.
  • To verify your identity through Didit before you book or guide a trip. Basis: your consent, given before the check opens, and legitimate interest in a safe marketplace.
  • To provide support and answer your questions. Basis: performance of a contract and legitimate interest.
  • To improve the service using anonymous usage data. Basis: legitimate interest.
  • To send service email such as booking confirmations and receipts. Basis: performance of a contract. Marketing email, if we ever send it, is consent-based and carries an unsubscribe link in every message.
  • To meet legal and accounting obligations, including tax records. Basis: legal obligation.

4. What your Buddy sees

Contact details are masked in messaging until a booking is confirmed. That is deliberate: it protects both sides while a match is being arranged. Once a booking is confirmed, your matched Buddy sees your first name, the trip details they need to run the day, and the contact route needed to meet you. They do not see your full account history, your other bookings or your payment records.

5. Who else we share with

We do not sell personal data and we do not share it with advertisers. We share it only with service providers who process it on our behalf, under contract, and only for these purposes:

  • Hosting and infrastructure: the cloud providers that run our site, database and file storage.
  • Email delivery: the provider that sends booking confirmations, receipts and account email.
  • Identity verification: Didit, which runs the ID document and selfie check and holds the images it captures. We pass it a reference to your account so the result can be matched back to you.
  • Legal and safety: law enforcement, regulators or professional advisers where we are legally required to disclose, or where disclosure is necessary to protect someone from harm.

Payment for your booking is made directly to your Buddy, so no card or bank details of yours pass through BuddyEase or any payment processor. We hold no payment method for you and there is nothing of that kind for us to share.

6. Where your data is stored

Our infrastructure providers operate globally, so your data may be processed on servers outside Thailand. Where that happens we rely on providers that offer an appropriate level of protection and contractual safeguards for international transfers.

7. How long we keep it

  • Account data: for as long as your account is open, then deleted or anonymised within a reasonable period after closure.
  • Booking and financial records: kept for the period required by Thai tax and accounting law, currently five years, even after an account closes.
  • Messages: kept while the booking is live and for a limited period afterwards so disputes can be resolved fairly.
  • Identity verification records: the result, document details, session references and consent records are kept while your account is open, so a verification can be traced if it is ever questioned. The document and selfie images are held by Didit, not by us.

8. Your rights

Under Thailand’s Personal Data Protection Act (PDPA), and equivalent laws where they apply to you, you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything that is wrong or out of date.
  • Delete your data, where we are not required to keep it.
  • Restrict or object to a particular use.
  • Provide your data in a portable format.
  • Withdraw consent, where our use was based on consent.

Email us and we will respond within 30 days. Most requests are free. If you are not happy with our answer you can complain to the Personal Data Protection Committee in Thailand.

9. Security

Passwords are stored hashed, traffic to the site is encrypted in transit, session cookies are set so that scripts in your browser cannot read them, and access to production data is limited to the people who need it. No system is perfectly secure, so please use a strong, unique password and tell us straight away if you think your account has been accessed by someone else.

10. Cookies

We use only essential first-party cookies plus anonymous browser-stored analytics. There are no advertising cookies or cross-site trackers. The detail, including how to remove them, is on the Cookie Policy page.

11. Minors

Accounts are for people aged 20 and over, the age of majority in Thailand, and we do not knowingly collect data directly from anyone younger. Travelers under 20 may join a trip booked by an accompanying adult, and we hold only what that booking needs. If you believe a minor has given us data directly, contact us and we will remove it.

12. Changes and contact

If we change how we handle your data we will update this page and move the date at the top. Where a change is significant we will tell you by email or through the site.

For any privacy question or request, email contact@buddyease.com, or use the details on our contact page. Our Terms of Service explain the agreement this policy sits under.