1.General Provisions and Scope of Application
[Company Name] (the "Company") operates a massage/spa booking and shop-management SaaS platform (the "Service") and values the personal data of its users. This Policy applies to all three of the following categories of Service users.
- Subscribing Business: a business that signs up for the Service to operate its own shop, together with its admin account
- Staff (Therapists): in-house, outcall, or PR (freelance) massage therapists that a Subscribing Business registers with the Service
- End User (Customer): a general consumer who books the Service through a Subscribing Business's booking screen
The Service is divided by an independent subdomain for each business (e.g., business-name.xau1.com), and each Subscribing Business also bears its own responsibility as a data controller for the personal data of Customers and Staff that it collects. The Company provides the technical infrastructure (servers, databases, software) for that processing, and the Company itself is also a data controller within the scope of its own purposes, such as preventing fraudulent use and operating the Service.
2.Personal Data We Collect
| Category | Items Collected |
|---|---|
| Subscribing Business Admin | Business name, admin email, password (stored encrypted), subdomain, contact information (optional), currency/timezone settings |
| Staff (Therapists) | Name, age (optional), photo (optional), phone number/contact channel (optional), working hours, service type (in-shop/outcall/PR), personal access code, settlement method and commission rate |
| Booking Customers | Name, contact information (phone number or messenger ID such as WhatsApp/Line), booking date/time and service type, outcall address (optional), payment method, receipt photo for payment confirmation (optional), referrer information (optional) |
| Referrers/Affiliates | Name, contact information, referral code, commission rate, message-receiving channel |
| Automatically Collected Information | Access IP address (hashed and retained only briefly, solely to prevent brute-force attacks), browser information, session cookies |
3.How Personal Data Is Collected
Personal data is collected when users directly enter it during sign-up and while using the Service; we do not separately request sensitive data such as biometric or location information. A Customer's information is collected either directly through the booking screen or entered on the Customer's behalf by a Subscribing Business admin for offline (phone/in-person) bookings.
4.Purpose of Use
- Receiving, confirming, and changing bookings, and assigning therapists
- Confirming and settling payment of service fees (subscription fees, deposits, etc.)
- Handling customer inquiries/complaints and delivering notices
- Detecting and blocking fraudulent use (brute-force login attempts, spam sign-ups/bookings, etc.)
- Statistical analysis to improve the Service (processed in a form that does not identify individuals)
The Company does not use personal data for any purpose other than those listed above, and does not provide users' contact information to third parties for separate marketing or promotional purposes.
5.Retention and Use Period
In principle, personal data is destroyed without delay once the purpose of use is achieved or the Subscribing Business's service agreement ends. However, where applicable law requires retention for accounting, tax, or similar purposes, the data is retained separately for the period required by that law before being destroyed. Access IP records (hashed) collected to prevent brute-force attacks are automatically deleted within a maximum of 7 days. If a Subscribing Business terminates its service agreement, that business's data, including Customer and Staff personal data, is deleted within a reasonable period.
6.Provision to Third Parties
In principle, the Company does not provide users' personal data to third parties. The following are exceptions.
- Where the user has separately consented in advance
- Where required by law, or requested by an investigative authority in accordance with the procedures and methods prescribed by law
The feature within the Service that allows a Subscribing Business admin to contact a Customer or therapist directly via a messenger such as WhatsApp only creates a deep link that connects the Customer and the business to talk to each other directly, using contact information the Customer has provided themselves; the Company's servers do not store, transmit, or view the content of those messages.
7.Outsourcing of Processing
The Company outsources server hosting operations, to the extent necessary to provide the Service, to an external hosting provider ([Enter the hosting provider's name]). The outsourced provider is managed and supervised, under its contract with the Company, to comply with applicable personal data protection laws.
8.Overseas Transfer
The Service is a multi-national service that can be used not only by users in Laos but also by users in neighboring countries (Thailand, China, Korea, etc.). Servers are located in [Enter server location], and where cross-border transfer of personal data occurs, the Company complies with the procedures required by applicable law, including the Lao Law on Electronic Data Protection (obtaining prior approval from the relevant authority where required).
9.Rights of Data Subjects
Users (Subscribing Business admins, Staff, and Customers) may at any time request access to, correction of, deletion of, or suspension of processing of their personal data. Customers and Staff may make such a request directly to the admin of the Subscribing Business with which they have a booking or affiliation, or may request it from the Company using the contact information in Section 14 below. The Company (or the relevant Subscribing Business) will take the necessary action and notify the user of the result within a reasonable period after receiving the request.
10.Measures to Ensure Security
The Company implements the following technical and administrative measures to protect personal data.
- HTTPS encryption applied to all communication
- Passwords are encrypted using an irreversible method (hashing) and are never stored in plain text
- Admin login session cookies carry the HttpOnly (blocks JavaScript access), SameSite (prevents cross-site request forgery), and Secure (transmitted only over HTTPS) attributes
- Rate-limiting is applied to key authentication steps, such as admin login, staff lookup PINs, and platform operator secret keys, to block repeated attempts within a short period
- Uploaded photos (therapist photos, payment receipts, etc.) are verified on the server to confirm they are genuine image files, and script execution is blocked in the folders where uploaded files are stored
- Each business's data is logically fully separated, and the server verifies on every request that a business cannot access another Subscribing Business's data
11.Use of Cookies
The Company uses only the minimum session cookies necessary to provide the Service, such as maintaining admin login state, and does not use cookies for advertising or tracking purposes. These cookies are required for an essential function (staying logged in); if you decline them through your browser settings, features that require admin login will not be available.
12.Children's Personal Data
The Service is intended for users aged 18 and over, and we do not knowingly collect personal data from children under 18. If we become aware that a child's personal data has been collected, we will delete it without delay.
13.Personal Data Protection Officer
For inquiries regarding personal data, or to request access, correction, or deletion, please contact us as follows.
| Contact Person | [Name or title of contact person] |
|---|---|
| [Contact email address] | |
| Address | [Company address] |
14.Duty to Notify
Any addition, deletion, or amendment to this Policy will be announced through the Service at least [e.g., 7 days] before it takes effect. Where a change is materially disadvantageous to users, a longer notice period will be given.