🔒 Privacy Policy
Personal Data Protection Policy
Thaibad Tournaments — In accordance with the Personal Data Protection Act B.E. 2562 (PDPA)
Thaibad Tournaments ("we" or "the service provider") respects and values the privacy rights of our users ("you") and strictly complies with the Personal Data Protection Act B.E. 2562 (PDPA). This policy explains how we collect, use, disclose, and protect your personal data.
1. Respect for users' privacy rights
We respect your right to personal data and will use the collected data only for the operation of the badminton tournament management system in accordance with the stated purposes. We maintain appropriate security measures to prevent unauthorized access.
2. Limited collection of personal data
We collect only data necessary to provide the service, including:
- Account data: username, password (one-way hashed with bcrypt)
- Identity data: first and last name, profile picture
- Contact data: email, phone number, LINE ID (if you provide them)
- Usage data: tournament registration history, player statistics, match results
- Technical data: IP address, User Agent, page access logs (automatically collected for analytics and troubleshooting)
We do not collect sensitive data such as race, religion, political opinions, health information, or biometric data, unless we obtain written consent.
3. Quality of personal data
We have processes to keep your data accurate, current, complete, and not misleading. You may edit your information yourself through the "Edit Profile" page or notify the administrator.
4. Purposes of collecting personal data
- To authenticate users and manage user accounts
- To register and manage badminton tournaments
- To publicly display match results, player statistics, and standings for tournament transparency
- To send notifications via LINE Messaging API or email (e.g. opponent notices, schedules, password resets)
- To collect usage statistics, analyze, and improve the quality of the system
- To maintain security, prevent fraud, and comply with applicable law
5. Limited use of personal data
We will use your personal data only within the scope of the purposes in section 4 and will not disclose it to third parties, except:
- Name, profile picture, match results, and statistics will be publicly displayed in the system for tournament purposes
- Email, phone number, LINE ID, and password will not be disclosed to any third party under any circumstances
- Where required by law, to prevent threats to safety, or for investigations under official orders
6. Data subject participation (your rights)
Under the PDPA you have the following rights:
- Right to access and request a copy of your personal data
- Right to request correction so the data is accurate and up to date
- Right to erasure or destruction of data (Right to be Forgotten)
- Right to request restriction of processing
- Right to object to data processing
- Right to data portability
- Right to withdraw consent at any time
- Right to lodge a complaint with the Personal Data Protection Committee
We may decline a request where the law provides an exception, or where the data has already been anonymized.
7. Linking data with third parties or other organizations
We use third-party services only as necessary, namely LINE Messaging API (for sending notifications) and Google OAuth (for sign-in with Google), sharing only data necessary to provide the service. We will not link your data with any other organization without prior consent.
8. Security measures and retention period
- Passwords are stored as one-way hashes using bcrypt
- Prepared statements are used for database queries to prevent SQL injection
- Data is stored on servers with access controls
- Account data is retained for the duration of your use and will be deleted within 90 days after you request account closure
- Visitor logs / IP data are retained for no more than 12 months and then automatically deleted
9. Cookies
We use cookies only to remember your login session and your light/dark theme preference. We do not use cookies for advertising tracking or third-party analytics.
10. Changes to this policy
We may update this policy from time to time and will notify you via the website before changes take effect. Continued use of the website after such changes constitutes acceptance of the new policy.
11. Consent and contact
By registering and using this system, you acknowledge that you have read and accept this policy. To exercise the above rights, or for any inquiries, please contact: [email protected]
Last updated: 19 April 2026