Privacy Policy
Last updated: 16 July 2026
Who we are
Endless Summer Samui is operated by Samathi Co., Ltd., a company registered in Thailand (registration no. 0845567016509), with its registered office at 19/29 Moo. 1 T. Maenam, Koh Samui District, Koh Samui 84330. For anything in this policy, we are the “data controller” under Thailand's Personal Data Protection Act B.E. 2562 (2019) (“PDPA”). You can reach us at Samuisamathi@gmail.com or on WhatsApp at +66 62 417 0628.
What we collect
We only collect what we need to run your trip:
Booking details — your name, WhatsApp number, party size, chosen trip and date, hotel or pickup point, and any notes you add (for example dietary needs or occasions).
Messages — because bookings are confirmed on WhatsApp, we keep the messages you exchange with us there, including messages handled by our automated assistant.
How you found us— if you tell us (or arrive via a partner's QR code), we record which business or channel referred you, so we can apply your discount and thank the right partner. This is not linked to any advertising profile.
Technical basics — standard web server logs (IP address, browser type, pages visited) and the minimum needed to protect the booking form from spam. We do not run third-party advertising trackers.
Why we collect it (legal bases)
We process your data to perform the contractyou're asking us for — taking, confirming and operating your booking; to meet legal obligations — passenger manifests and safety requirements that apply to licensed passenger vessels in Thailand, plus tax and accounting rules; and for our legitimate interests — answering your questions, preventing fraud and spam, applying referral discounts, and understanding which channels bring guests so we can run the business sensibly. Where the PDPA requires consent for anything beyond this, we will ask you first, and you can withdraw consent at any time.
How long we keep it
Booking records are kept for as long as Thai tax and accounting law requires. WhatsApp conversation transcripts are retained for 12 months and then anonymised. Referral and analytics records are kept in aggregate; personal identifiers are removed on the same 12-month cycle. We delete or anonymise sooner where a record is no longer needed.
Who we share it with
We never sell your data and never share it for third-party advertising. We use a small number of processors to operate the service: website and database hosting, WhatsApp (Meta) for messaging, and — if you booked through a travel platform — that platform, to the extent needed to honour your booking. Each processor only receives what it needs and is bound by data-processing terms. Some processors store data outside Thailand; where they do, we rely on their standard safeguards as permitted by the PDPA.
We may disclose data where Thai law requires it — for example passenger manifests to the Marine Department or other authorities.
Your rights
Under the PDPA you can ask us to: access a copy of your data, correct it, delete or anonymise it, restrict or object to processing, port it to another provider, and withdraw any consent you gave. Message us on WhatsApp or email Samuisamathi@gmail.com — we respond within 30 days. If you believe we have mishandled your data, you also have the right to lodge a complaint with Thailand's Personal Data Protection Committee (PDPC).
How we protect it
Data is stored in access-controlled systems with encryption in transit, role-based access for staff, and row-level security on our booking database. Payment happens in person or by bank transfer — we do not store card numbers.
Children
Bookings must be made by an adult. We only hold children's details as part of a party size and any safety notes their guardian gives us.
Changes to this policy
If we change this policy materially, we will update this page and the date above. See also our Booking Terms.