Privacy Policy
Last updated: 31 August 2026
We process personal data in accordance with the revised Swiss Federal Act on Data Protection (revFADP). This policy explains what data we process, why, who receives it and what rights you have.
1. Controller
Thai Style GmbH
Sumatrastrasse 25 (side entrance Sumatrasteig)
8006 Zurich, Switzerland
Phone: +41 44 500 50 88
E-mail: bureau@tida-thai-massage.ch
Data protection matters are handled by Thomas Schildknecht.
2. Scope
- the website tida-thai-massage.ch
- the booking system booking.tida-thai-massage.ch
- the gift voucher shop shop.tida-thai-massage.ch
- treatments at our practices Zurich HB and Zurich Schaffhauserplatz
- our communication with you by e-mail, SMS and telephone
3. What data we process
3.1 When you visit our website
Each time a page is called up, our hosting provider records technical details in server logs: IP address, date and time, page requested, volume of data transferred, browser type and operating system. We need this for secure operation and to fend off attacks. We do not combine it with other data.
We also record which pages are opened and which buttons are clicked, so that we can see where our pages are unclear. See section 4 for details.
3.2 When you book an appointment
For a booking we process:
- first name and surname
- e-mail address and mobile number
- the massage, duration, practice, time and any add-ons you select
- whatever you write in the notes field
- for couple bookings, the details of the second person
- payment method and amount
- whether and when you received confirmations and reminders
We need this data to arrange, deliver and invoice the appointment. Without it we cannot accept a booking.
3.3 Around the treatment
We record which treatments you have received, together with notes that matter for the next treatment — preferred oils, pressure, areas to avoid, or health-related information you tell us.
Health-related information constitutes sensitive personal data under Art. 5 revFADP. We record it only if you provide it yourself, keep it as brief as possible and use it solely for your treatment. Access is limited to the people treating you and to management.
3.4 Checking eligibility for reduced rates
For our reduced rates (among others for people of AHV retirement age, children and young people, and other eligible groups) we have to verify once that the conditions are met.
- As a rule we verify the document by looking at it and do not make a copy.
- We record only the date of birth, or the fact that the condition is met, together with the date of the check.
- In some cases the document is photographed for the purpose of the check, for instance where a second opinion is needed. The image is used solely for that purpose, is not circulated further internally, and is deleted once the check is complete, at the latest after 30 days.
- We do not record the AHV social security number. Under Art. 153c of the Swiss Federal Act on Old-Age and Survivors' Insurance it may only be used systematically by designated bodies; a massage practice is not one of them.
- The check is carried out once. Once it is recorded, we will not ask you again.
3.5 When you contact us by e-mail, SMS or phone
We process your contact details and the content of your enquiry. Confirmations, reminders and replies are logged so that we can establish whether a message was delivered. Since August 2026 we also store the text of SMS messages we send, and the subject line of e-mails.
3.6 Gift vouchers
When you buy a voucher in our online shop we process your order, invoicing and payment details and, where the voucher is sent to someone else, that person's details. Payment is handled by Stripe (cards and TWINT); we do not receive full card details.
3.7 Social media, Google Business Profile and reviews
Our website merely links to our pages on Facebook and Instagram. No plugins from these networks are embedded, so simply opening our pages transfers no data to them. Only when you click such a link do you reach the provider's site, where your data is then processed under their own terms. The same applies to our Google Business Profile. There we see your public posts, the messages you send us, and aggregated, non-personal statistics.
On our website we display reviews that you have published publicly on Google yourself. We do not invite you by e-mail or SMS to leave a review.
We do not send a newsletter.
4. Cookies, analytics and session recording
Necessary cookies. These keep your session alive in the booking system and the shop. Booking and ordering do not work without them.
Google Analytics and Google Tag Manager (Google Ireland Limited). We measure how our pages are used in order to improve them. IP addresses are truncated. You can prevent collection using Google's browser add-on: https://tools.google.com/dlpage/gaoptout
Session recording. In the booking system and on the website we record movement and click sequences in order to identify drop-offs and usability problems. What is recorded is mouse movement, clicks, scrolling and the page structure. Entries in form fields are not recorded in clear text. Recordings are deleted automatically: after 90 days in the booking system, after 30 days on the website.
5. Who we share data with
We do not sell data. We pass it on only where this is necessary to run our business or where we are legally obliged to. Our service providers are contractually bound to process data only on our instructions.
| Service provider | Purpose | Registered office |
|---|---|---|
| Hohl IT e.U. ("Alwyzon") | Hosting of website and voucher shop | Vienna, Austria (EU) |
| Multimedia Networks AG ("Hoststar") | Domain administration | Fraubrunnen, Switzerland |
| Vercel Inc. | Operation of the booking system, servers in Frankfurt | USA |
| Supabase Inc. | Booking system database, servers in Frankfurt | USA |
| Google Ireland Ltd. | E-mail service, analytics, Business Profile | Ireland (EU) |
| Helpwise (SaaS Labs Inc.) | shared mailboxes for customer enquiries | USA |
| Resend | Sending the booking system's e-mails | USA |
| BulkGate s.r.o. | Sending SMS | Czech Republic (EU) |
| Twilio Inc. | Sending SMS (fallback) | USA |
| Stripe | Payment processing in the voucher shop | USA / Ireland (EU) |
Beyond this we disclose data only where we are legally obliged to do so, for instance to public authorities.
6. Transfers abroad
Some of the providers listed above are based outside Switzerland, mainly in the EU and the USA. For the EU, the Swiss Federal Council has recognised an adequate level of data protection. For the USA we rely on the Swiss-U.S. Data Privacy Framework where the provider is certified under it, and otherwise on the standard contractual clauses recognised by the FDPIC.
Where data is held by a US company, access by US authorities under US law cannot be entirely ruled out, even when the data is stored in Europe.
7. How long we keep data
| Data | Period |
|---|---|
| Bookings and payments with accounting relevance | 10 years (Art. 958f CO) |
| Customer account and contact details | for the duration of the customer relationship, at the latest 5 years after the last appointment |
| Treatment notes | for the duration of the customer relationship |
| Proof of eligibility (date of birth, date of check) | for the duration of the customer relationship |
| Content of SMS sent and e-mail subject lines | 24 months |
| Session recordings, booking system | 90 days |
| Session recordings, website | 30 days |
| Server logs | 30 days |
After that, data is deleted or anonymised so that it can no longer be linked to you.
8. Data security
All connections to our sites are encrypted (TLS). Access to the booking system is personal and role-based; staff see only what they need for their work. The database is backed up daily. Our staff are bound to confidentiality.
9. Your rights
You have the right
- to know whether and what data we process about you (right of access, Art. 25 revFADP),
- to have incorrect data corrected,
- to request deletion of your data, unless a statutory retention obligation applies,
- to object to processing,
- to receive your data in a common format (Art. 28 revFADP),
- to withdraw consent you have given at any time.
Please contact us at the address given in section 1. We will respond within 30 days. We may ask you to prove your identity.
You may also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
10. Automated individual decisions
We do not take decisions about you that are based solely on automated processing and that would have legal effect or seriously disadvantage you.
11. Changes
We update this policy when our processing changes. The version published on this page, bearing the date given above, is the applicable one.
