TrainMate Privacy Policy

Effective date: 2026-08-01

This policy explains how the TrainMate system (the "System", "we") collects, uses, and discloses users' personal data, with regard to Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA).

1. Information We Collect

  • Google account information — your email, name, and profile picture when you sign in with Google OAuth. We do not store your password, and your profile picture is displayed directly from Google, not uploaded or stored by us.
  • Training service data — appointments, bookings, session statuses, Session Passes, and session counts used and remaining.
  • Payment information (if provided) — the amount and transfer evidence (slip) that a user chooses to enter or attach. Both are optional.
  • Trainer income data — calculated from Session Pass and session records.
  • System usage data — sign-in and system event logs, kept for security and troubleshooting.

2. How We Use Information

We do not use your data for advertising, and we do not sell your data.

  • To provide the System's core services — managing training schedules, booking/confirming sessions, and tracking remaining sessions.
  • To record and track payment and income data for trainers.
  • To generate summary reports for trainers.
  • To authenticate users and enforce role-based access control.
  • To keep the System secure and resolve usage issues.

3. Who Can See What

  • Members — see only their own data: appointments, remaining/over-used session counts, and payment information they recorded. Members cannot see trainer income data and cannot see other members' data.
  • Trainers — see only the data of members linked to them (appointments, remaining sessions, related payment information) and their own income data.
  • Administrators — access data only as necessary to operate the System, such as account management and email linking.

4. Data Retention

  • Data is retained for as long as the account and the trainer-member relationship remain active.
  • When a trainer deactivates a member, the data between that trainer-member pair remains viewable for 90 days from the deactivation date, and the System shows the number of days remaining. After that period, the System no longer displays that data to users.
  • Account data is retained until a deletion request is made under Section 7.

5. Disclosure to Third Parties

  • We do not sell or share your personal data with third parties for marketing purposes.
  • Data may be processed on the infrastructure (servers / hosting providers) used to operate the System, only as necessary to provide the service.
  • We may disclose data where required by law or by order of a competent authority.

6. Data Security

We use appropriate measures to protect data, such as authentication via Google OAuth, role-based access control, and the visibility restrictions described in Section 3. However, no system is completely secure; users should also keep their Google account safe.

7. Your Rights

  • Request access to or a copy of your personal data.
  • Request correction of your data (members with a linked email can edit their own name in the System).
  • Request deletion of your personal data — contact us via Section 9; we will act within a reasonable period unless retention is required by law.
  • Withdraw consent or object to processing, subject to the conditions of the PDPA.

8. Cookies and Sessions

The System uses cookies only as necessary to maintain your signed-in session. We do not use cookies for tracking or advertising.

9. Contact

For questions about this policy or to exercise your rights under Section 7, contact the system administrator at [email protected]

10. Changes to This Policy

This policy may be updated from time to time. The latest version with its effective date will be shown on this page. Continued use after changes constitutes acknowledgement of the updated policy.