In order to process your booking and issue tickets through LipeGo.com, we need to collect the following personal data:
Contact details: full name · email · phone number · nationality
Government ID: national ID card number or passport number — collected under the Thai Navigation Act B.E. 2456 for the Passenger Manifest
Travel details: origin · destination · travel date & time · boat operator · passenger count and type (adult/child/infant)
Payment information: payment method · amount paid · gateway transaction reference — we never store your credit/debit card number
Payment proof: bank transfer slip image (when paying via bank transfer) — stored on private cloud storage with strict access controls
Consent records: timestamp and proof of your consent under the Personal Data Protection Act (PDPA)
2. Why We Collect Your Data
We collect and use your data solely for the following purposes:
To process your booking and issue your e-ticket as requested
To verify passenger identity as required by Thai maritime law
To communicate with you regarding your booking — confirmations, schedule changes, or urgent alerts — via email and phone
To verify payments and prevent fraud (duplicate slip detection)
To comply with legal obligations — accounting and tax laws (7-year record retention) and maritime regulations
To improve our service quality — in anonymised, statistical form only
3. Legal Basis for Processing
We process your data under the following legal bases per Sections 24–26 of the Personal Data Protection Act B.E. 2562:
Contractual Necessity: booking and ticketing — if you do not provide this data, we cannot process your booking
Legal Obligation: national ID / passport and passenger details — required by the Thai Navigation Act
Consent: marketing communications or any processing beyond your transaction — you may withdraw consent at any time
4. Who We Share Your Data With
We never sell or rent your personal data to third parties for marketing. Your data may be shared only as follows:
Boat Operators: full name · nationality · passport/ID number — for the Passenger Manifest required by law
Payment Gateways: Stripe (PCI-DSS Level 1) and WeChat Pay — transaction amount and reference only
SlipOK: bank transfer slip image — for automated slip verification
Resend: name · email · booking details — to send booking confirmation emails (transactional)
Cloudflare R2: slip images — stored in a private bucket, accessible only via temporary signed URLs
Government authorities: only when required by a valid court order, warrant, or legal request
International data transfers: some of our service providers (e.g. Resend, Cloudflare R2, SlipOK) operate servers outside Thailand. We transfer data to these providers only where appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or an adequate level of data protection in the destination country
5. How Long We Keep Your Data
We retain your data only as long as necessary and as required by law:
Booking and passenger records: 7 years — per accounting, tax, and maritime law
Payment slips and proof: 7 years — financial records
Consent logs: 10 years — per PDPC recommended practice
System logs / audit trail: 1 year
Once the retention period expires, your data will be securely deleted or destroyed
6. Your Rights
Under the Personal Data Protection Act B.E. 2562, you have the right to:
Access: request a copy of the personal data we hold about you
Rectification: ask us to correct inaccurate or incomplete data
Erasure: request deletion of your data in certain circumstances
Object: object to processing in certain circumstances
Withdraw consent: revoke your consent at any time (does not affect the lawfulness of prior processing)
Complain: lodge a complaint with the Personal Data Protection Committee (PDPC) at pdpc.go.th
To exercise any of these rights, contact us at: privacy@lipego.com — we will respond within 30 days
7. Security Measures
We maintain the following security policies and measures to protect your data:
Encryption in transit (TLS/HTTPS) — all data between your browser and our servers is encrypted
Slip images: stored in private Cloud Storage — accessible only via temporary signed URLs by authorised personnel
Credit/debit card data: never stored on our servers — processed exclusively through Stripe (PCI-DSS Level 1) and WeChat Pay, both globally certified payment providers
Internal access control: restricted by authentication and audit logging — only authorised staff may access personal data, and every access is recorded
Fraud prevention: duplicate slip detection (sha256 hash) · API access hardening against unauthorised public requests
Data breach response: if a personal data breach occurs that poses a high risk to your rights and freedoms, we will notify the Personal Data Protection Committee (PDPC) within 72 hours of becoming aware of it, as required by law, and notify you directly if the breach poses a high risk to you
8. Cookies & Tracking
We use two types of cookies on this website:
Strictly Necessary: e.g. admin_session for the admin system — required for the website's basic functionality, no consent needed
Analytics / Advertising: Facebook Pixel — used to measure ad campaign performance and usage behaviour. Loaded only if you click "Accept All" on the cookie banner
You can change your cookie preferences at any time via the "Cookie Settings" link at the bottom of this page
9. Contact Us
Data Controller: Satun Tourist Guide Co., Ltd. (TAT tourism business licence no. 43/00601)
Address: Pak Bara Pier, Pak Nam Sub-district, La-Ngu District, Satun Province 91110, Thailand
Tel/Fax: (+66) 074 783 507 · Mobile: 095 079 4715
Website: https://lipego.com
Data Protection Officer (DPO): reachable at privacy@lipego.com
PDPA / privacy enquiries: privacy@lipego.com
Supervisory authority: Personal Data Protection Committee (PDPC) — pdpc.go.th
If you have questions or wish to exercise your rights, please contact us through the channels above
This policy may be updated from time to time — material changes will be notified on our website or via email