Privacy Policy
Effective Date: June 29, 2026
Sri U-Thong Grand Hotel (“we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data in accordance with Thailand’s Personal Data Protection Act B.E. 2562 (2019) and applicable regulations.
This policy applies when you visit our website, use our Internet Booking Engine (IBE), stay at our hotel, or communicate with our staff.
1. Personal Data We Collect
We collect personal data necessary to process bookings, provide hotel services, communicate with guests, maintain security, and fulfill our legal obligations. This includes:
- Identity Data: First name, last name, date of birth, nationality, and passport or national ID card details (collected upon check-in as required by Thai law).
- Contact Data: Email address, phone number, and physical address.
- Transaction & Financial Data: Booking references, stay dates, room preferences, and payment gateway tokens. Payment card details are entered directly into our payment provider’s secure payment flow. We receive transaction status, limited payment metadata, and a payment token/reference, but not your full card number or CVV.
- Technical Data: IP address, browser type, timezone setting (e.g., Asia/Bangkok), and booking session data generated while navigating our website.
- Sensitive Data: Where you choose to provide health, allergy, disability, accessibility, religious dietary, or other sensitive information, we will request your explicit consent where required by law and process such data only to prepare, protect, or personalize your stay, or where otherwise permitted by law.
- CCTV & Security Data: Our hotel premises may be monitored by CCTV for safety, security, incident investigation, and protection of guests, staff, and property. CCTV cameras are not placed inside guest rooms, bathrooms, or areas where guests have a reasonable expectation of privacy. CCTV recordings are retained only as long as necessary for security or legal purposes, unless required for an investigation, claim, or legal obligation.
2. How We Collect Your Data
We collect your data through the following channels:
- Directly from You: When making a reservation, checking in at our front desk, or contacting us.
- Data About Other Guests: If you provide personal data about another guest, companion, family member, employee, or representative, you confirm that you have authority to provide that data and that you have informed them about this Privacy Policy.
- Automated Technologies (Cookies): We use necessary cookies to operate the website and booking engine. We may use analytics or marketing cookies only where permitted by law or with your consent where required. You can manage cookie preferences through our cookie banner/settings.
- Third Parties: From Online Travel Agencies (OTAs), our Channel Manager, or our Payment Gateway providers confirming the status of your booking.
3. Lawful Basis and Purpose of Processing
We only process your personal data under the lawful bases defined by the PDPA:
- Contractual Necessity: To process your reservation, manage your booking holds, confirm your payment, and provide the accommodation services you requested.
- Legal Obligation: To comply with Thai regulations, including reporting guest arrivals to the Thailand Immigration Bureau (TM.30) and maintaining financial records for the Revenue Department.
- Legitimate Interest: To maintain the security of our digital infrastructure, manage reservations, prevent fraud, verify staff actions, and maintain secure hotel operations.
- Consent: To send promotional offers or process specific sensitive data. You may withdraw this consent at any time.
4. Disclosure of Personal Data
We do not sell your personal data. We only share your information on a strict, need-to-know basis with:
- Service Providers: Trusted third-party processors necessary for our operations, including our Property Management System (PMS), Payment Gateways, and secure cloud infrastructure providers.
- Government Authorities: Regulatory or law enforcement agencies when explicitly required by Thai law.
5. Cross-Border Data Transfers
Where personal data is transferred outside Thailand, we will rely on lawful transfer mechanisms under the PDPA, such as adequate protection standards, appropriate safeguards, contractual protections, or other lawful exceptions where applicable.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, generally following these periods:
- Booking records: Retained during the guest relationship and for as long as necessary for accounting, tax, legal claims, dispute resolution, and hotel operation records.
- Tax/accounting records: As required by Thai tax/accounting law, generally 5–7 years unless longer required.
- Passport/ID / immigration records: Only as long as required by hotel/immigration law and internal compliance needs.
- Payment tokens: As long as needed for payment, refund, chargeback, or accounting purposes.
- Marketing consent: Until withdrawn or inactive for a defined period.
- Server/security logs: Short operational period (e.g., 90–180 days) unless needed for security investigation.
- Sensitive stay preferences: Deleted after your stay unless you explicitly ask us to remember them for future visits.
7. Data Security
We use appropriate administrative, technical, and organizational safeguards designed to protect your personal data. However, no online system or transmission method can be guaranteed to be completely secure. This includes HTTPS/TLS encryption across our platforms, atomic database transaction locks to prevent data bleeding, role-based access control (RBAC) on our Staff Dashboard, and cryptographic webhook validations to secure your financial transactions.
8. Minors
Our website and booking engine are intended for adults who can make hotel reservations. If a parent, guardian, or accompanying adult provides personal data of a minor guest, they confirm they have authority to do so. We do not knowingly collect personal data from minors for marketing purposes without appropriate consent.
9. Third-Party Links
Our website or booking flow may contain links to third-party websites or services, such as payment gateways, online travel agencies, maps, or social media platforms. Their privacy practices are governed by their own privacy policies.
10. Your Rights as a Data Subject
Under the Thai PDPA, you are entitled to the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request corrections to any incomplete or inaccurate data.
- Right to Erasure: Request the deletion of your personal data when we no longer have a lawful basis to retain it.
- Right to Restriction & Objection: Object to or limit the processing of your data (e.g., opting out of marketing emails).
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Withdraw Consent: Revoke any consent you have previously provided to us.
- Right to Lodge a Complaint: File a grievance with the Personal Data Protection Committee (PDPC) of Thailand if you believe your rights have been compromised.
We may need to verify your identity before fulfilling a request. We will respond to your request within the period required by applicable law.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The latest version will be published on our website with the effective date. Where required by law, we will notify you of material changes.
12. Contact Us
To exercise your rights, update your information, or ask questions about this Privacy Policy, please contact our privacy team at:
Sri U-Thong Grand Hotel
- Address: 19 Nang Phim Road, Tha Phi Liang, Mueang Suphan Buri District, Suphan Buri 72000, Thailand
- Email: privacy@sriuthonggrand.com
- Phone: +66 35 501 290