- Home Privacy Policy
Privacy Policy
We collect only what we need, never sell your data, and explain everything clearly below.
We don't sell your data
Your personal information is never sold to third parties, marketing companies, or data brokers. We collect data to operate the site, not to monetise your identity.
Minimal data collection
We collect only what is necessary for the services you use — email for newsletters, usage data for site improvement. We do not build detailed personal profiles.
Analytics is anonymised
We use analytics to understand how content is used and improve it. This data is aggregated and anonymised — we cannot identify individual users from it.
Right to deletion
You have the right to request deletion of your data at any time. Email us and we will remove your information within 30 days.
Who we are
ThailandKnowledge is an independent travel and expat information website focused on Thailand. For the purposes of this privacy policy, "we", "us", and "our" refers to the ThailandKnowledge editorial team. If you have questions about this policy, contact us at our contact page.
Information we collect
1. Information you provide directly
Newsletter subscription: If you subscribe to our newsletter, we collect your email address. We use this only to send you the newsletter you requested. You can unsubscribe at any time via the unsubscribe link in every email.
Contact form submissions: When you use our contact form, we collect your name, email address, and the content of your message. This information is used only to respond to your enquiry.
Account creation (if applicable): If you create an account on this site, we collect your email address and any profile information you choose to provide. Passwords are stored in hashed form — we cannot read them.
2. Information collected automatically
Analytics data: We use privacy-focused web analytics to understand how pages are used. This includes: pages visited, time spent on pages, referrer source (where you came from), device type and browser, and approximate country location. This data is aggregated and does not identify you individually.
Server logs: Our web server automatically records standard log information including IP address, browser type, request timestamp, and pages requested. These logs are retained for a maximum of 90 days for security and debugging purposes and then deleted.
Cookies: We use essential cookies to remember your preferences (such as dark/light mode settings). We do not use advertising cookies or behavioural tracking cookies. See our cookie section below for more detail.
3. Information from third parties
When you interact with third-party services linked from our site (such as booking through Booking.com or clicking an affiliate link), those services have their own privacy policies that govern what data they collect. We do not receive personal data from these interactions beyond aggregate commission reports.
How we use your information
We use the information we collect for the following purposes:
- Delivering the newsletter — using your email address to send the newsletter you subscribed to
- Responding to enquiries — using your contact form details to answer your message
- Improving content — using anonymised analytics data to understand which guides are useful and where we can improve
- Site security — using server logs to detect and prevent malicious activity
- Legal compliance — retaining records as required by applicable law
We do not use your data for advertising targeting, profiling, or selling to third parties. Ever.
Data storage and security
Newsletter data is stored with our email service provider (Resend). This provider is GDPR-compliant and stores data in secure data centres. We retain your email address for as long as you remain subscribed, and delete it within 30 days of unsubscription on request.
Contact form data is temporarily processed through our email system and not permanently stored in a database beyond the email thread for correspondence purposes.
Account data (where applicable) is stored with Supabase, our database provider. Supabase is SOC 2 Type II certified and stores data in encrypted form.
We implement industry-standard security measures including HTTPS for all connections, encrypted data storage where personal data is involved, and access controls limiting who can view personal data on our team.
Cookies
A cookie is a small text file stored on your device by your browser. We use the following categories of cookies:
- Essential cookies: Required for the site to function correctly. These include session management and user preference storage (dark/light mode). These cannot be disabled without affecting site functionality.
- Analytics cookies: Used to collect anonymised usage data. These do not identify you personally. You can opt out of analytics tracking via our cookie banner or by using a browser with privacy protection enabled.
We do not use advertising cookies, behavioural tracking cookies, or third-party remarketing cookies.
Third-party services
Our site uses the following third-party services:
- Supabase — database and authentication provider. Their privacy policy is available at supabase.com/privacy.
- Resend — email delivery service for newsletters. Their privacy policy is available at resend.com/legal/privacy-policy.
- Netlify — website hosting and deployment. Their privacy policy is available at netlify.com/privacy.
Each of these providers processes data only as necessary to provide their services and is contractually bound to GDPR-compliant data handling.
Your rights
Under GDPR and applicable privacy laws, you have the following rights regarding your personal data:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can request correction of inaccurate personal data.
- Right to erasure: You can request deletion of your personal data. We will action this within 30 days.
- Right to restrict processing: You can request that we restrict how we process your data in certain circumstances.
- Right to data portability: You can request your data in a machine-readable format.
- Right to object: You can object to our processing of your data for specific purposes.
To exercise any of these rights, please contact us. We will respond within 30 days.
Children's privacy
ThailandKnowledge is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
Changes to this policy
We may update this privacy policy periodically. When we make material changes, we will update the "Last updated" date below and, where appropriate, notify newsletter subscribers. Continued use of the site after a policy change constitutes acceptance of the updated policy.