Privacy Policy

Effective date: 3 September 2026 Version: 2026-09-03

1. Who we are and who controls the data

This Privacy Policy explains how personal data is collected and used when you use the SamuiToday website or make a booking through it.

SamuiToday is the customer-facing brand, website, and sales channel operated by Samui Transport & Tours, a licensed Thai travel business holding Tourism Business Licence No. 44/00292. In this Policy, ‘we,’ ‘us,’ and ‘our’ mean Samui Transport & Tours operating through the SamuiToday brand and website. Samui Transport & Tours is the data controller for personal data collected through this website and through our customer-support channels for bookings made via SamuiToday.

SamuiToday is the customer-facing brand, website, and sales channel. Bookings and online payments are arranged by Samui Transport & Tours. Independent tour operators may receive the information needed to perform a booked service. Each operator is responsible for its own operations and, where it handles personal data, for its own privacy practices.

Depending on the service and applicable law, some recipients act as service providers or data processors on our instructions, and some recipients may act as independent data controllers for their own activities. Samui Transport & Tours remains responsible for selecting and managing its processors where required by applicable law. Independent operators remain responsible for their own separate processing.

2. Scope of this Privacy Policy

This Policy applies to browsing the SamuiToday website, requesting a price quote, saving a booking draft, creating a booking, paying through Stripe Checkout, receiving an E-ticket or other booking messages, pickup coordination, verified review invitations, and contacting us about a booking.

It also covers personal data you send us by WhatsApp, LINE, telephone, or email when that information relates to a SamuiToday booking or enquiry.

This Policy does not cover websites, apps, or payment pages that we do not operate, including Stripe Checkout, WhatsApp, and LINE after you leave our website.

This website does not currently run advertising, retargeting, newsletter signup, Google Analytics, Meta Pixel, TikTok Pixel, or similar marketing trackers. If that changes, we will update this Policy before those tools are switched on.

3. Personal data we collect

We collect only what is needed for the activity you are doing. The website booking form collects lead-traveller details, not a full identity record for every guest.

  • Lead-traveller name, email address, WhatsApp or phone number, and optional country or calling code.
  • Optional hotel name, room number, and special-request notes, including when hotel pickup is part of the booking.
  • The tour you selected, service date, departure, guest quantities, and related booking details generated by our system, such as a booking number and booking status.
  • Payment status and Stripe identifiers for the checkout session or payment, but not your full card number. We do not store card numbers, CVV codes, or card expiry dates on our systems.
  • Information needed to issue and display your E-ticket after payment is confirmed.
  • If you submit a verified review: a star rating, optional title and comments, optional photos, and a shortened display name derived from the booking. We do not publish your email address on the review.
  • Technical data used to run and protect the website: a session identifier, CSRF security token, IP address, browser user agent, and security or error logs. Rate limiting may use your IP address to reduce abuse.
  • If you contact us outside the website: the messages, images, or documents you send, such as questions, pickup notes, passport details requested for a specific tour, or health information you choose to provide.

We do not currently collect passport numbers or passport images through the SamuiToday booking form. We do not create a customer login account for public bookings. We do not collect a separate name list for every guest unless a specific tour later requires it through our support channels.

4. How data is collected

We collect data in these ways:

  • Directly from you on the website when you request a quote, save a draft, create a booking, pay, or submit a review.
  • Automatically when you use the website, through necessary cookies, sessions, and security logs.
  • From Stripe, when Stripe confirms whether an online payment succeeded or failed. Stripe sends us payment-status information and Stripe reference numbers, not your full card number.
  • From you through WhatsApp, LINE, telephone, or email when you contact us or when we contact you about a booking.
  • From our own systems, when we generate a booking number, quote, E-ticket link, pickup record, or review invitation.

Browsing published tour pages does not require you to enter your name or contact details. A booking draft is stored in your website session so you can continue the booking on the same device for a limited time.

5. Purposes for using data

We use personal data to:

  • Provide quotes, hold a short-lived booking draft, create the booking, and take online payment.
  • Confirm payment, issue the E-ticket, and send transactional messages about the booking.
  • Coordinate hotel pickup or meeting instructions with you and, where needed, with the operator or driver.
  • Share information reasonably necessary for the selected operator, transport provider, guide, or insurer to provide the booked service, register participants, or arrange cover.
  • Respond to WhatsApp, LINE, telephone, and email support, including changes, cancellations, and complaints.
  • Send a verified review invitation after the travel date, and publish a review if you choose to submit one.
  • Keep records needed for refunds, disputes, accounting, tax, and legal claims.
  • Protect the website and bookings against fraud, abuse, and technical failures.

We do not currently use your booking data to send promotional newsletters or advertising messages.

6. Lawful bases under Thai personal-data law

The principal privacy law for this Policy is the Thai Personal Data Protection Act B.E. 2562 (2019) (PDPA). We do not treat every activity as consent-based. Where Thai law allows another lawful basis, we rely on that basis.

For most booking, payment, E-ticket, pickup, and support activity, we rely on processing that is necessary to take steps at your request before a booking is made, or to perform the booking contract.

We may also process data where it is necessary to comply with a legal obligation, such as tax, accounting, or a lawful request from a competent authority.

We may rely on legitimate interests for fraud prevention, website and payment security, keeping operational records, improving service reliability, and sending a verified review invitation after a completed booking, except where those interests are overridden by your rights. You can choose not to submit a review.

If you send health, pregnancy, mobility, or similar information because it is relevant to safe participation, we use it only for that booking, safety, or support purpose. Under Thai law, health-related data is sensitive personal data. We ask you to provide it only when needed. Where the law requires a specific consent for sensitive data and no other lawful basis applies, we will ask for that consent separately and specifically. Acknowledgement of this Privacy Policy at checkout is not that consent. In an emergency, we may also use information to help prevent or respond to a danger to life, body, or health.

7. Payment data and Stripe

Online card payment is processed by Stripe on Stripe’s own checkout page. We redirect you to Stripe to pay. We do not collect or store your full card number, CVV, or card expiry date on the SamuiToday website.

When we create a Stripe Checkout session, we send Stripe the amount, currency, a description that includes your booking number, and internal booking identifiers. We do not currently pre-fill your name, email, or phone number into Stripe from our booking form.

Stripe may collect payer details on its own page, including card data and any email Stripe asks for. Stripe handles that information under Stripe’s terms and privacy policy. We receive back payment status and Stripe reference numbers so we can confirm the booking.

A booking stays unpaid until Stripe confirms payment through Stripe’s verified webhook. Opening or returning from a payment page does not, by itself, mark the booking as paid.

We do not control Stripe’s systems, cookies, or international processing. Please read Stripe’s privacy information if you want details of how Stripe uses payment data.

8. Booking fulfilment and sharing with independent operators and suppliers

Tours and activities listed on SamuiToday may be performed by independent operators. To fulfil a booking we may share information reasonably necessary with the selected tour operator, transport provider, guide, meeting-point staff, insurer, or other supplier responsible for that service.

This typically includes the lead-traveller name and phone number, hotel name and room number when pickup is arranged, travel date, departure, guest numbers, booking number, and any special request needed to provide the service safely.

We share only what is reasonably necessary for that booking, pickup, safety, registration, insurance, or customer support. We do not sell personal data.

Independent operators remain responsible for their own separate processing. Where a recipient acts as our processor, Samui Transport & Tours remains responsible for selecting and managing that processor where required by applicable law.

9. Passport, insurance, and sensitive information

Passport details, passport images, health information, pregnancy, mobility restrictions, allergies, or similar sensitive information are requested only when necessary for a specific service, such as operator check-in, accident-insurance registration, or safe participation. When that is required, we or the operator may ask you to provide the information through WhatsApp, LINE, or another support channel. The SamuiToday website booking form does not currently collect passport images or passport numbers.

Identification data is used only for the booking, check-in, insurance, or legal purpose for which it was requested. We ask you not to send passport images through public web forms or to people who do not need them.

You may also voluntarily provide health, pregnancy, mobility, dietary, or similar notes if they are relevant to safe participation. You can use the special-request field or a support channel. Please include only what the operator needs. Do not send medical records unless we or the operator specifically ask for them.

Health-related information is sensitive under Thai law. We do not use it for marketing. We share it only with people who need it for that booking or for safety. If you prefer not to provide it, tell us before travel so we can explain whether the activity can still go ahead. Where explicit consent is legally required for sensitive personal data, that consent is obtained separately and specifically for the relevant purpose. A general checkout acknowledgement of this Privacy Policy is not treated as that consent.

We aim to delete or redact passport images and sensitive participation notes within 30 days after the service date, unless they are needed for insurance, an incident, a dispute, a fraud investigation, or law. If that information is held in WhatsApp, LINE, email, or the booking special-request field, our staff handle deletion or redaction through those channels and records. It is not currently an automatic website purge.

10. Communications through WhatsApp, LINE, email, and telephone

WhatsApp is our main customer-support channel. You may also contact us by LINE, telephone, or email. Our published contact details are WhatsApp and telephone +66 97 925 44 55, email info@samuitoday.com, LINE, and the Contact page. Hours are 09:00–22:00, Thailand time.

If you message us, the messaging app, telephone network, or email provider will also process the communication. We do not control WhatsApp, LINE, or those networks. Their own terms and privacy policies apply to use of their services.

We use these channels to answer questions, complete a booking, collect information that a tour requires, coordinate pickup, and handle changes or problems. Messages may include personal data you choose to send.

The Contact page on this website contains links only. It does not currently provide a message form that stores submissions on our server.

11. E-tickets and transactional messages

After Stripe confirms payment, we issue an E-ticket and send a confirmation to the email address you provided. The E-ticket and confirmation may include your name, contact details, hotel information, special request, booking number, and tour details.

The E-ticket is accessed through a unique link. Anyone with that link can view the ticket details, so you should keep it confidential and share it only with people who need it for travel or support.

We may also send transactional email about pickup times, cancellations, refunds, or a review invitation. These messages are part of operating the booking, not marketing newsletters.

Email is sent through our configured email delivery service. That provider processes the recipient address and message content in order to deliver the email.

12. Verified review invitations and reviews

After the service date, we may email a verified review invitation to the address on the booking. The invitation uses a unique link. Submitting a review is optional.

If you submit a review, we store the rating, optional title and comments, optional photos, and a shortened display name. Approved reviews and approved photos may be shown on the website. Your email address is not shown on the public review.

Review photos are stored on our systems and may include people or places you photographed. Do not upload images you are not entitled to share.

We use review data to show customer feedback and to understand service quality. We do not currently pay for or run advertising campaigns from review content.

If you ask us to remove a published review or review photos under your privacy rights, we will remove them from public display when that request is accepted. We may keep a limited internal record of the request and related moderation history where needed for dispute handling. Asking us to remove a review does not delete your booking record.

13. Cookies, sessions, logs, and website security

This website uses first-party cookies that are necessary to run the booking process and protect the site. These include a session cookie so your booking draft and security state can continue, and a CSRF token used to prevent cross-site request forgery on draft requests.

Session data may include the booking step you reached, the selected tour options, and any lead-traveller details you entered before payment. Sessions are stored by our application and associated with an IP address and browser user agent. Unused sessions expire after a period of inactivity, currently about two hours.

We keep application and security logs that may include IP address, user agent, error details, and technical events. Rate limiting uses IP addresses to reduce automated abuse.

We do not currently set advertising, analytics, or social-media tracking cookies on the SamuiToday website, and we do not currently display a cookie-consent banner because we have not implemented non-essential tracking cookies. If we later add analytics or marketing cookies, we will review this Policy and cookie practices before those tools are activated.

Stripe, WhatsApp, and LINE may set their own cookies or similar technologies on their websites or apps. Those are outside this Policy.

14. Service providers and data recipients

Depending on the booking, personal data may be received by:

  • Samui Transport & Tours staff who handle bookings, pickup, support, refunds, and administration.
  • The independent operator, driver, guide, or other supplier performing the booked service.
  • An insurer or insurance intermediary, when identification or participant data is required for cover or a claim.
  • Stripe, for online payment processing.
  • Our email delivery provider, for transactional messages.
  • Our website hosting, database, backup, and security providers, who process data as instructed to operate the service.
  • A competent public authority, where Thai law requires or permits disclosure.

Depending on the service and applicable law, some of these recipients act as service providers or data processors on our instructions, and some may act as independent data controllers for their own activities. Samui Transport & Tours remains responsible for selecting and managing its processors where required by applicable law. Independent operators remain responsible for their own separate processing.

Admin users of this system can see booking records needed to operate the business. Admin access is authenticated and activity may be logged for security.

15. International data transfers

Some recipients process data outside Thailand. In particular, Stripe is an international payment provider, and WhatsApp, LINE, and some email or hosting providers may process data in other countries.

When data is transferred abroad, we rely on the transfer being necessary for the booking or payment you requested, on the provider’s safeguards, and on Thai PDPA rules for cross-border transfers where they apply.

We do not claim that all personal data is stored only in Thailand.

16. Data retention

We keep personal data only as long as needed for the purposes in this Policy. Where a retention period is stated below, we may keep data longer if Thai law, tax or accounting rules, insurance, an incident, fraud or security investigation, a legal claim, or an active dispute requires it. Backups may still hold a copy after information is removed from live systems. We do not promise instantaneous or complete deletion from every backup.

  • Incomplete website booking drafts and quote tokens: short-lived according to current system behaviour. Drafts follow the website session and currently expire after about 120 minutes of inactivity. Quote tokens currently expire after about 30 minutes.
  • Booking, payment, E-ticket, and transactional-email records: kept for 5 years after the service date shown in the booking, or longer where legally required or necessary for an active claim or dispute. The website does not currently run an automatic deletion job for these records; retention is applied through our operational records process.
  • Passport or other identification images received through WhatsApp, LINE, email, or similar support channels: we aim to delete them from our devices and chat records within 30 days after the service date, unless they are needed for insurance, an incident, a dispute, a fraud investigation, or law. This is a staff handling process. Messaging apps may keep their own copies under their own policies, and the SamuiToday website booking form does not currently store passport images.
  • Health, pregnancy, mobility, dietary, or similar sensitive participation information: used only for safety and fulfilment of that booking. We aim to delete or redact it within 30 days after the service date, unless it is connected to an incident, insurance claim, dispute, or legal requirement. If that information was typed into the booking special-request field or sent through WhatsApp, LINE, or email, deletion or redaction is carried out by our staff through those records and channels; it is not currently an automatic system purge.
  • Review invitations: unique invitation links currently expire after 30 days.
  • Published reviews and customer-submitted review photos: kept while the review remains published, or until we remove them under our review moderation or privacy-request process. If you ask us to remove a published review or review photos, we will remove them from public display when that request is accepted. We may keep a limited internal record of the request and related moderation history where needed for dispute handling. Asking us to remove a review does not delete your booking record.
  • System, security, and backup records are retained only for as long as reasonably necessary for security, system recovery, operational continuity, legal obligations, and the establishment, exercise, or defence of legal claims. Backup copies are removed or overwritten according to the applicable backup cycle.
  • Records of privacy requests and our responses are generally retained for three years after the request is closed, or longer where reasonably necessary for an unresolved dispute, legal obligation, or legal claim.

17. Data security

We take reasonable technical and organisational measures to protect personal data, including HTTPS on the public website, access controls for administration, hashed or tokenised public ticket and review links, and not storing full card numbers on our systems.

No website or messaging channel is completely secure. WhatsApp, LINE, email, and telephone have their own risks. You should not send unnecessary sensitive documents through a public form or to an unverified contact.

If we become aware of a personal-data incident that Thai law requires us to notify, we will follow the applicable notification rules.

18. Customer and data-subject rights

Subject to the PDPA and other applicable law, you may ask to access your personal data, obtain a copy, correct inaccurate data, delete data, restrict or object to certain processing, withdraw consent where processing is based on consent, and in some cases receive data in a portable form.

These rights are not unlimited. We may refuse or limit a request where the law allows, including where we must keep records for the booking contract, a legal obligation, a claim, or another overriding ground.

We will respond to an access request without undue delay and, where the PDPA requires, within 30 days after receiving a valid and sufficiently verified request. Other requests will be handled within the period required by applicable law.

To make a request, contact us using the details in section 22. Please include enough information for us to verify that we are speaking with the right person and to find the relevant booking, such as your name, email or phone number, booking number, and travel date. Do not send a passport image or other sensitive document unless we ask for it through a channel we have confirmed.

We do not currently provide an automated self-service privacy portal. Requests are handled by our support team during published hours.

19. Children’s data

This website is intended for adults who are booking tours. We do not knowingly collect a child’s identity as the lead traveller.

If you book an activity that includes children, you should be a parent or guardian, or have authority to book for them. The website collects the adult booker’s contact details. A child’s name or ID is collected only if a specific tour later requires it through our support channels.

If you believe we have collected a child’s data inappropriately, contact us and we will review it.

21. Changes to this Privacy Policy

We may update this Policy when our services, suppliers, or the law change. The version identifier and effective date are shown at the top of this page. The version identifier is 2026-09-03.

If checkout acknowledgement is enabled, we may record the version of this Policy that was presented and acknowledged when the booking was made. This record does not turn acknowledgement of this Policy into consent for processing that requires separate consent under applicable law.

A later update does not automatically rewrite the Privacy text stored as evidence on a booking you already made.

22. Contact details and complaint rights

For privacy questions or data-subject requests, contact Samui Transport & Tours through the SamuiToday channels: email info@samuitoday.com, WhatsApp or telephone +66 97 925 44 55, LINE, or the Contact page. Hours: 09:00–22:00, Thailand time.

Please contact us first so we can try to help. You also have the right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC), the Thai authority that oversees the PDPA. Information is published at https://www.pdpc.or.th/.

This Policy does not waive rights that Thai law does not allow to be waived, and it is not a limitation of liability.

Terms & Conditions Contact