nightbnb
HostSign in

Privacy Policy

Last updated: 8 October 2026

1. Who handles your data

Data controller: Liang Cui. For privacy questions and to exercise your rights, contact [email protected].

This policy explains what personal data NightBnB collects, why, who receives it, how long we keep it and your rights. We link to it before you submit data, for example when you sign in, pay or apply to host.

2. What we collect

Account: your email, plus your Google name and profile photo if you sign in with Google.

Bookings: name, phone, email (optional), number of guests, bookings, offers and payment status.

Payments: processed by Stripe. We keep only the result, amount and payment reference, not card numbers.

Hosts: name, phone, LINE ID, property address and photos, door code, licence or exemption certificate photos, payout details.

Technical: IP address, browser information and the essential cookies listed below.

3. Purposes and legal bases

Contract (PDPA s. 24(3)): creating and managing bookings, payments and refunds, giving your host what's needed for your stay, booking notifications and support.

Legal obligation (s. 24(6)): accounting and tax records; lawful requests from authorities.

Legitimate interests (s. 24(5)): preventing fraud, offer abuse and off-platform deals, and keeping the site secure.

We don't use your data for marketing and don't sell personal data. If we ever send marketing, we'll ask for your consent first.

4. Who receives it

The host you book: your name and number of guests, and your phone during the stay (hosts stop seeing the full number 2 hours after checkout).

Service providers: Stripe (payments), Resend (email), Google (if you sign in with Google), Cloudflare (network delivery), LINE (only for host notifications). They process data only on our instructions.

Authorities: when the law requires.

5. International transfers

Some of these providers process data outside Thailand (for example in the US, Japan or Europe). We use only providers with data protection commitments such as standard contractual clauses, and send only the data needed for the service.

6. How long we keep it

Booking, payment and refund records: as long as Thai accounting and tax law requires (generally 5 years).

Account data: deleted or anonymised within 90 days after you close your account, except where the law requires us to keep it.

Licence photos: deleted within 1 year after the partnership ends.

Sign-in codes expire after 10 minutes; sign-in sessions last up to 60 days.

7. Your rights

You can access and get a copy of your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent (without affecting processing before withdrawal).

Email [email protected]. We'll verify your identity and respond within 30 days (longer for complex or large requests, in which case we'll tell you why).

You can also complain to Thailand's Personal Data Protection Committee (PDPC).

8. If you don't provide data

Your name and phone are needed to complete a booking and check-in; without them you can't book. Email is optional; without it you won't get email notifications.

9. Cookies

We only use cookies the site needs to work: sign-in, language, an anonymous booking ID, and short-lived cookies that protect sign-in. We don't use advertising or tracking cookies, so there's no cookie consent banner.

10. Security and breaches

Data is stored on protected servers. Sign-in tokens and codes are stored only in hashed form, and certificate photos are visible only to our review team.

If a breach may affect your rights, we report it to the PDPC within 72 hours of becoming aware of it, and if the risk is high we tell you promptly what happened and what we're doing about it.

11. Minors

The service isn't intended for people under 20.

12. Changes

We publish changes on this page and notify registered users of significant changes.