v2026-08-13.1 · 13 August 2026
Privacy notice
These are Thai4.me’s operational policies, not legal advice. A production launch still needs a solicitor to sign them off.
Who we are
Thai4.me is the data controller for this dating service. Contact privacy@thai4.me. Our data protection officer: dpo@thai4.me.
We operate a Thailand-focused dating service used by people in Thailand, the UK, the EEA and elsewhere. This notice covers UK GDPR, EU GDPR, the UK Data Protection Act 2018, PECR, and Thailand’s PDPA B.E. 2562.
This product currently stores most personal data on your device (local demo). The same rules apply when we host data on servers.
What we collect
Account: name, age, gender, email, nationality, province in Thailand, photos, bio, prompts, job, lifestyle answers, dating intention.
Special category data (Art. 9 / PDPA s.26): dating and sexual life, orientation implied by who you seek, optional religion. We only process this with your explicit consent.
Usage: likes, passes, matches, messages (and translations), wishlist links, treat records.
Safety: reports you send, blocks, age-assurance outcome. Thai ID images are sealed with AES-256-GCM; the key is discarded. Staff see a one-way fingerprint and pass/fail only.
Device: language, 18+ gate, cookie choices. We do not sell personal data.
Why we process it (lawful bases)
Contract (Art. 6(1)(b)): running the dating service you asked for.
Explicit consent (Art. 6(1)(a) + 9(2)(a)): special category dating data, optional marketing, non-essential cookies.
Legal obligation (Art. 6(1)(c)): UK Online Safety Act age-assurance and illegal-content duties; responding to DSAR and lawful requests.
Legitimate interests (Art. 6(1)(f)): keeping the service safe, preventing romance fraud, measuring product quality. You can object.
Who sees what
Other members see the public profile you publish (photos, first name, age if enabled, bio, wishlist titles — not your email).
Trust & Safety see reports, public profile fields, and sealed ID metadata — never the raw Thai ID number or card image.
We do not give data to advertisers unless you opt in to marketing cookies. We may disclose data if the law requires it (e.g. a valid police request about a romance scam).
International transfers: if we host outside Thailand or the UK we use UK IDTA / EU SCCs and PDPA s.28 safeguards.
How long we keep it
Account and chat: until you delete the account, then we aim to erase within 30 days except where we must keep a record.
Consent logs and illegal-content reports: up to 6 years (proof of consent; OSA).
Age-assurance metadata (pass/fail + fingerprint): as long as needed to show we ran the check — not the card.
Your rights
You can access, correct, erase, restrict, object, withdraw consent, and port your data. Use Settings → Privacy centre, or /legal/dsar, or email dsar@thai4.me. We have one month (extendable by two) under UK/EU GDPR; PDPA allows up to 30 days.
You can complain to the ICO (ico.org.uk) if you are in the UK, a supervisory authority in the EEA, or the PDPC in Thailand.
Automated decisions: matching and discovery ranking are not solely automated decisions that produce legal effects. Age-gate under-18 is an automated refusal of service as required by law.