Overview
Protein Chef BKK ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights as a customer — in compliance with Thailand's Personal Data Protection Act B.E. 2562 (PDPA) and other applicable data protection laws.
By using our website and services, you consent to the collection and use of your information as described in this policy. If you do not agree with any part of this policy, please do not use our services.
Information We Collect
We collect information in the following ways:
Information you provide directly
- Name and contact details (phone number, Instagram handle if you provide it)
- Delivery address and delivery instructions
- Payment information (processed securely by Shopify — we do not store full card details)
- Account credentials for your customer account
- Communications you send us (support messages, feedback, reviews)
- Dietary preferences or allergen information you voluntarily provide
Information collected automatically
- IP address and browser/device type
- Pages visited, time spent, and navigation patterns on our website
- Referring website or source
- Cookies and similar tracking technologies (see Section 06)
- Purchase history and order data
Information from third parties
- Payment processors (transaction status, fraud indicators)
- Social media platforms (if you interact with our pages or ads)
- Analytics providers (aggregated usage data)
How We Use Your Information
We use your personal information to:
- Process and fulfil your orders, including delivery coordination
- Manage your customer account and orders
- Send order confirmations, delivery notifications, and support communications
- Respond to your enquiries and support requests
- Improve our website, menu, and customer experience based on usage data
- Send marketing communications and promotions — only where you have opted in or where permitted by law
- Comply with legal obligations, including tax records and fraud prevention
- Enforce our Terms of Service and Refund Policy
- Personalise your experience on our website
We will only use your information for the purposes described above. We will not sell your personal data to third parties.
Shopify & Third-Party Processors
Our store is powered by Shopify Inc. By using our website, you acknowledge that your information will be transmitted to and processed by Shopify as part of providing the service. Shopify may store and process data in countries other than Thailand.
Shopify is certified compliant with PCI DSS for payment processing and maintains its own Privacy Policy, which governs their handling of data collected through our store. You can review Shopify's Privacy Policy at shopify.com/legal/privacy.
We are not responsible for Shopify's data practices. For questions about how Shopify handles your data, please contact Shopify directly.
Data Retention
We retain your personal information for as long as necessary to fulfil the purposes outlined in this policy, or as required by law. Specifically:
- Customer account data — retained for the lifetime of your account, plus 2 years after account closure
- Order history — retained for 7 years for tax and accounting compliance
- Marketing opt-in data — retained until you unsubscribe or withdraw consent
- Support communications — retained for 2 years
- Payment records — subject to Shopify's and payment processor's retention policies
You may request deletion of your personal data at any time (subject to legal retention requirements) by messaging us on Instagram at @proteinchefnutrition.
Data Security
We implement reasonable technical and organisational measures to protect your personal information from unauthorised access, disclosure, alteration, or destruction. These include:
- SSL/TLS encryption for all data transmitted between your browser and our website
- Secure payment processing via Shopify's PCI DSS-compliant infrastructure
- Limited employee access to customer data on a need-to-know basis
- Regular review of our data security practices
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you believe your account has been compromised, please contact us immediately.
Your Rights (PDPA)
Under Thailand's Personal Data Protection Act (PDPA) and other applicable laws, you have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data, subject to legal retention obligations.
- Right to Restriction: Request that we limit how we process your data in certain circumstances.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Object: Object to processing of your data for direct marketing purposes at any time.
- Right to Withdraw Consent: Withdraw consent to marketing communications at any time by contacting us.
To exercise any of these rights, message us on Instagram at @proteinchefnutrition. We will respond within 30 days. Some requests may require verification of your identity.
Minors
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us and we will take steps to delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by posting the updated policy on this page with a revised "Last updated" date.
We encourage you to review this policy periodically. Your continued use of our services after any changes constitutes your acceptance of the updated policy.
Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:
You also have the right to lodge a complaint with Thailand's Personal Data Protection Committee (PDPC) if you believe your data rights have been violated.
