top of page

PRIVACY POLICY

Last updated: July 15, 2026

The Oracle ("we", "us", "our") operates [website URL] and our wellness space in Bangkok, Thailand. This policy explains what personal data we collect, why we collect it, and how we protect it, in accordance with Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA").

1. What we collect

  • Account and booking details: name, email address, phone number, and appointment history when you create an account or book a session

  • Payment information: processed securely by our payment providers; we do not store your full card details

  • Membership and credits: package purchases, credit balance, redemption history, and birthday (if you choose to share it for birthday rewards)

  • Communications: messages you send us by email, contact forms, or social media

  • Website usage: cookies and analytics data such as pages visited, device type, and general location (see section 6)
     

2. Why we collect it

We use your personal data to:

  • Process bookings, payments, and package purchases

  • Manage your credit balance and member benefits

  • Send booking confirmations and reminders

  • Send newsletters and offers, only where you have opted in

  • Improve our website and services

  • Comply with legal and accounting obligations

3. Legal basis

We process your data on the basis of: performance of a contract (bookings, packages, credits), your consent (marketing, birthday perks), and our legitimate interests in operating and improving our services. You may withdraw consent at any time.

4. Who we share it with

We never sell your personal data. We share it only with service providers who help us operate:

  • Wix.com, which hosts our website, booking system, and member accounts

  • Payment processors [name them: e.g. Stripe, Omise, PromptPay provider]

  • Email and marketing tools [if applicable]

These providers may store data outside Thailand. Where data is transferred internationally, we rely on the safeguards those providers maintain in line with PDPA requirements.

5. How long we keep it

We keep your data for as long as your account is active and as required for legal, tax, and accounting purposes. Booking and payment records are retained for [X years, typically 5–10 for Thai tax purposes]. You may request deletion at any time (see section 7).

6. Cookies

Our website uses cookies for essential site functions, analytics, and (with your consent) marketing. You can manage cookie preferences through the banner on our site or your browser settings.

7. Your rights

Under the PDPA, you have the right to:

  • Access a copy of your personal data

  • Correct inaccurate data

  • Request deletion of your data

  • Withdraw consent to processing

  • Object to or restrict certain processing

  • Receive your data in a portable format

  • Lodge a complaint with Thailand's Personal Data Protection Committee (PDPC)
     

To exercise any of these rights, contact us using the details below. We will respond within 30 days.

8. Children

Our services are intended for adults. We do not knowingly collect personal data from anyone under 20 years of age (the age of majority in Thailand) without parental consent.

9. Security

We use appropriate technical and organizational measures to protect your data, including encrypted connections (HTTPS), secure payment processing, and access controls on member information.

10. Changes to this policy

We may update this policy from time to time. The latest version will always be available on this page with the date of the most recent revision.

11. Contact us

Data controller: [legal business name] Address: [Bangkok address] Email: [email address] Phone: [phone number]

Before publishing, three things to sort:

  1. Fill the placeholders accurately, especially the payment processors and the legal entity name. If Pyn's business is a registered Thai company, the controller must be the company name, not the brand.

  2. Wix's cookie banner: turn on the consent banner in Wix (Settings → Privacy & Cookies) so section 6 is actually true. Wix handles most of the mechanics.

  3. The standard caveat: this is a solid working draft, but I'm not a lawyer and PDPA enforcement has been tightening in Thailand. If The Oracle grows or starts collecting anything sensitive (health information for healing sessions arguably qualifies as sensitive data under PDPA, which has stricter consent rules), it's worth a one-off review by a Thai lawyer. That health-data point is the one I'd flag most: if intake forms ever ask about medical conditions, mental health, or medications before sessions, that needs explicit consent language added.

bottom of page