1. Who is responsible for your data
The Vela platform operator (“Vela”, “we”, “us”) is responsible for account administration, platform security, subscriptions, referrals and operation of the Vela service. The shop you book with is generally responsible for appointment delivery, staff allocation, customer communications, deposits and shop records. Vela processes booking data to provide the service to that shop. Depending on the activity, Vela and the shop may each have separate obligations under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”).
2. Personal data we handle
Do not include health, biometric, religious, political or other sensitive personal data in booking notes or receipt images unless it is genuinely necessary and the receiving shop has explained a lawful reason for collecting it.
- Account data: authenticated account identifier, email address, display name, language and legal-agreement records.
- Customer profile and booking data: name, mobile number, selected shop, services, preferred staff, appointment time, notes, status and booking history.
- Payment evidence: deposit amount, PromptPay or bank instructions supplied by the shop, and receipt images uploaded for shop review. Vela does not need your online-banking password or PIN.
- Merchant data: shop identity and contact information, services, prices, schedules, closures, staff profiles and photos, permissions, subscription and referral details.
- Technical and security data: request metadata, timestamps and diagnostic information reasonably required to keep the service reliable and prevent misuse.
3. Where data comes from
We receive data directly from you, from the authenticated sign-in service, from a shop owner or authorised manager, and from activity generated when appointments and shop settings are managed.
4. Why we use personal data
- To create and secure accounts; provide appointment, shop-management, history, deposit-review, subscription and referral features; and communicate service-related information.
- To perform a contract with you or take steps you request before entering one, including arranging an appointment or operating a shop workspace.
- To comply with legal, accounting, tax, fraud-prevention and dispute-handling obligations where applicable.
- For legitimate interests such as platform security, service reliability, abuse prevention and product improvement, balanced against your rights.
- Where an activity truly requires consent, we will request it separately and allow withdrawal. This first-login acknowledgement is not marketing consent.
5. Required and optional information
Account identity and the core details needed for a booking or shop workspace are required to provide those services. Without them, Vela cannot create an account-linked appointment or merchant workspace. Booking notes are optional. A receipt image is required only when the shop requires a deposit and asks for proof of transfer.
6. Who may receive data
Some service providers may process data outside Thailand. Where cross-border transfer rules apply, Vela will use an available lawful transfer mechanism and appropriate safeguards.
- The shop you choose and its authorised staff, according to their booking, store and finance permissions.
- Vela personnel who need access for platform operations, security, support or subscription administration.
- Hosting, storage, authentication and infrastructure providers acting under appropriate contractual and security controls.
- Professional advisers, regulators, courts or authorities when disclosure is required or legally justified.
- A successor organisation in a genuine merger, financing or transfer, subject to applicable safeguards.
7. Retention
We retain personal data only while reasonably necessary for the purposes above, including active bookings and accounts, customer and shop history, security, disputes, accounting and legal obligations. Receipt evidence and inactive records may be retained where the shop or law requires it. When data is no longer needed, it will be deleted, destroyed or anonymised. Deleting a shop removes its operational records from Vela, subject to residual backups or records that must be retained by law.
8. Security
Vela uses access controls, role-based permissions, authentication, restricted receipt access and other reasonable organisational and technical safeguards. No internet service can guarantee absolute security. Notify us promptly if you suspect unauthorised account or data access.
9. Your PDPA rights
Some rights are subject to legal exceptions and identity verification. To exercise a right, contact us using the details below. For booking records controlled by a shop, Vela may refer the request to that shop or assist it in responding.
- Request access to and a copy of personal data about you.
- Request correction of inaccurate or incomplete data.
- Request deletion, destruction, anonymisation or restriction where the legal conditions apply.
- Object to certain processing and request portability where applicable.
- Withdraw optional consent at any time without affecting earlier lawful processing.
- Complain to Thailand’s Personal Data Protection Committee if you believe your rights have been infringed.
10. Changes and contact
We may update this notice when our service or legal obligations change. A material change will be shown before continued signed-in use and may require a new acknowledgement. Questions or rights requests can be sent to phoomipat.u@gmail.com. Please include enough information to identify your account and request; do not email banking passwords, PINs or unnecessary sensitive data.