Chiang Mai Tours

Privacy Policy

Effective Date: October 2025

At ChiangMai-Tours.com (operated by Malloo Holiday), we are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, and protect your data when you use our website and services.

1. Information We Collect

1.1 Personal Information: When you book a tour or create an account, we collect:

  • Full name
  • Email address
  • Phone number
  • Payment information (processed securely through Stripe)
  • Passport details (if required for certain tours)
  • Emergency contact information
  • Special requirements (dietary, medical, accessibility needs)

1.2 Booking Information: Details about your bookings, including:

  • Tour selections and dates
  • Number of participants
  • Special requests and preferences
  • Communication history with us

1.3 Technical Information: When you visit our website, we automatically collect:

  • IP address
  • Browser type and version
  • Device information
  • Pages visited and time spent on site
  • Referring website

2. How We Use Your Information

We use your personal information for the following purposes:

  • Booking Management: To process and confirm your tour bookings
  • Communication: To send booking confirmations, updates, and important information about your tours
  • Payment Processing: To process payments securely through our payment provider (Stripe)
  • Customer Support: To respond to your inquiries and provide assistance
  • Service Improvement: To analyze usage patterns and improve our website and services
  • Marketing: To send promotional offers and newsletters (only with your consent)
  • Legal Compliance: To comply with legal obligations and protect our rights

3. Data Sharing and Disclosure

3.1 Service Providers: We share your information with trusted third-party service providers who assist us in operating our business:

  • Supabase: Database and authentication services
  • Stripe: Secure payment processing
  • Email Service Providers: For sending booking confirmations and communications
  • Tour Partners: Local guides and activity providers for tour fulfillment

3.2 Legal Requirements: We may disclose your information if required by law or to protect our legal rights.

3.3 Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new owner.

3.4 No Selling: We do not sell, rent, or trade your personal information to third parties for marketing purposes.

4. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Encryption: All data transmitted between your browser and our servers is encrypted using SSL/TLS
  • Secure Storage: Personal information is stored in secure databases with restricted access
  • Payment Security: We use Stripe for payment processing and do not store credit card details on our servers
  • Access Controls: Only authorized personnel have access to personal information
  • Regular Audits: We regularly review and update our security measures

However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

5. Cookies and Tracking

5.1 What are Cookies: Cookies are small text files stored on your device that help us improve your browsing experience.

5.2 How We Use Cookies:

  • Essential Cookies: Required for website functionality (login, shopping cart)
  • Analytics Cookies: To understand how visitors use our website
  • Preference Cookies: To remember your settings and preferences

5.3 Managing Cookies: You can control cookies through your browser settings. Note that disabling cookies may affect website functionality.

6. Your Rights

Under applicable data protection laws, you have the following rights:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information (subject to legal obligations)
  • Objection: Object to processing of your personal information for certain purposes
  • Portability: Request transfer of your data to another service provider
  • Withdraw Consent: Withdraw consent for marketing communications at any time

To exercise these rights, please contact us using the details in the Contact section below.

7. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy:

  • Booking Information: Retained for 7 years for accounting and legal purposes
  • Account Information: Retained until you request deletion or close your account
  • Marketing Data: Retained until you unsubscribe or object to processing
  • Technical Logs: Typically deleted after 90 days

8. International Data Transfers

Your information may be transferred to and processed in countries other than Thailand. We ensure that appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.

9. Children's Privacy

Our services are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe we have collected information about a child, please contact us.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Effective Date" at the top. We encourage you to review this policy periodically.

11. Contact Us

If you have questions about this Privacy Policy or how we handle your personal information, please contact us:

Malloo Holiday (ChiangMai-Tours.com)
Office: The Astra Condo & Astra Sky River, Chiang Mai, Thailand
Email: Available on our contact page
Phone: Available on our contact page

Last updated: October 2025
By using our services, you acknowledge that you have read and understood this Privacy Policy.