Privacy Policy
Last updated 19 September 2026
[ชื่อผู้ให้บริการ / Operator legal name] ("Openspot", "we") operates the booking and deposit service at openspot.live. This policy explains what personal data we collect, why, who we share it with, and what rights you have under the Thai Personal Data Protection Act B.E. 2562 (PDPA).
1. Who controls your data
[ชื่อผู้ให้บริการ / Operator legal name]
[ที่อยู่ / Address]
Data protection contact: [privacy@example.com]
Note that when you book with a provider through Openspot, that provider is also a controller of your data. We supply the tooling; the provider decides how to use their own client information.
2. Data we collect from providers
Account data from sign-in: your LINE user ID, display name and avatar, or if you sign in with Google, your email, name and avatar.
Shop data: business name, link slug, bio, cover image, avatar, services, prices, deposits and working hours.
Your PromptPay ID (phone number or national ID), used to generate the deposit QR code.
An email address for booking notifications when LINE is not connected.
If you connect Google Calendar, an encrypted refresh token and the selected calendar ID, used to read your busy times.
We never store a password for you. All sign-in happens through LINE or Google.
3. Data we collect from booking customers
The name, phone number and optional LINE ID you enter when booking.
The service, date and time you chose, and the deposit payment status.
For consultation requests, the note and any images you attach.
About payment slips: when you upload a slip, the image is read in memory to scan its QR code and sent to our slip verification provider (EasySlip). We do not save the slip image to our storage. What is retained is the bank transaction reference, the time verification succeeded, and the result.
4. Data collected automatically
Usage and page performance data via Vercel Analytics.
Google Analytics, only where enabled, for aggregate traffic measurement.
Error reports via Sentry, which may include technical details of the failing request.
Rate-limiting counters derived from IP address, to prevent abuse.
5. Purposes and lawful bases
Providing the booking service and confirming deposits — performance of a contract.
Authenticating providers and securing accounts — contract and legitimate interest.
Preventing fraud, double-booking and abuse — legitimate interest.
Improving and debugging the service — legitimate interest.
Meeting legal obligations — legal obligation.
6. Sharing with third parties
We use external processors only as far as the service requires:
Supabase — database and file storage.
Vercel — web hosting and usage analytics.
EasySlip — payment slip verification (a Thailand-based provider).
LINE and Google — sign-in, and Google Calendar where you choose to connect it.
Sentry — error monitoring.
Upstash — rate limiting.
Resend — notification email.
When you make a booking, your booking details are disclosed to the provider you booked with. We do not sell your personal data, and we do not share it for third-party advertising.
7. International transfers
Some processors handle data outside Thailand — our database is hosted in an East Asia region and our hosting provider operates a global network. We select providers that maintain recognised data protection safeguards.
8. Retention
Provider account and booking records: kept while the account is active, and deleted on account closure request.
Slip images: not retained at all (see section 3).
Idempotency keys: automatically deleted within 24 hours.
Error logs and analytics: retained per each processor’s own schedule.
9. Your rights
Under the PDPA you have the right to:
Access and obtain a copy of your data.
Have inaccurate data corrected.
Request erasure or destruction of your data.
Request restriction of processing.
Object to processing.
Request portability of your data to another controller.
Withdraw consent you previously gave.
To exercise any of these, contact [privacy@example.com]. We will respond within 30 days. If you believe we are not complying with the law, you may lodge a complaint with the Personal Data Protection Committee (PDPC) of Thailand.
10. Security
All connections are encrypted with HTTPS, Google Calendar tokens are encrypted before storage, provider session cookies are cryptographically signed, and database access is restricted to the minimum each role needs. No system is perfectly secure; in the event of a high-risk data breach we will notify affected individuals and the regulator as the law requires.
11. Changes to this policy
We may update this policy from time to time. Where a change is material we will say so in the service. The last updated date appears at the top of this page.