Protein Chef
Back to Home

Privacy Policy

Last updated: May 2025 · Compliant with Thailand PDPA

§01

Overview

Protein Chef BKK ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights as a customer — in compliance with Thailand's Personal Data Protection Act B.E. 2562 (PDPA) and other applicable data protection laws.

By using our website and services, you consent to the collection and use of your information as described in this policy. If you do not agree with any part of this policy, please do not use our services.

§02

Information We Collect

We collect information in the following ways:

Information you provide directly

  • Name and contact details (phone number, Instagram handle if you provide it)
  • Delivery address and delivery instructions
  • Payment information (processed securely by Shopify — we do not store full card details)
  • Account credentials for your customer account
  • Communications you send us (support messages, feedback, reviews)
  • Dietary preferences or allergen information you voluntarily provide

Information collected automatically

  • IP address and browser/device type
  • Pages visited, time spent, and navigation patterns on our website
  • Referring website or source
  • Cookies and similar tracking technologies (see Section 06)
  • Purchase history and order data

Information from third parties

  • Payment processors (transaction status, fraud indicators)
  • Social media platforms (if you interact with our pages or ads)
  • Analytics providers (aggregated usage data)
§03

How We Use Your Information

We use your personal information to:

  • Process and fulfil your orders, including delivery coordination
  • Manage your customer account and orders
  • Send order confirmations, delivery notifications, and support communications
  • Respond to your enquiries and support requests
  • Improve our website, menu, and customer experience based on usage data
  • Send marketing communications and promotions — only where you have opted in or where permitted by law
  • Comply with legal obligations, including tax records and fraud prevention
  • Enforce our Terms of Service and Refund Policy
  • Personalise your experience on our website

We will only use your information for the purposes described above. We will not sell your personal data to third parties.

§04

Sharing Your Information

We do not sell or rent your personal information. We may share your data with trusted third parties in the following limited circumstances:

  • Delivery partners and couriers — to fulfil your order (name, address, contact number, delivery instructions)
  • Payment processors — to securely process transactions (Shopify Payments and associated partners)
  • Communications and marketing platforms — to send transactional and, where opted in, promotional communications
  • Analytics providers — aggregated, anonymised data only
  • Legal authorities — where required by law, court order, or to protect the rights and safety of our customers

All third parties we work with are contractually required to handle your data securely and only for the purposes we specify.

§05

Shopify & Third-Party Processors

Our store is powered by Shopify Inc. By using our website, you acknowledge that your information will be transmitted to and processed by Shopify as part of providing the service. Shopify may store and process data in countries other than Thailand.

Shopify is certified compliant with PCI DSS for payment processing and maintains its own Privacy Policy, which governs their handling of data collected through our store. You can review Shopify's Privacy Policy at shopify.com/legal/privacy.

We are not responsible for Shopify's data practices. For questions about how Shopify handles your data, please contact Shopify directly.

§06

Cookies & Tracking

Our website uses cookies and similar technologies to enhance your browsing experience, analyse site traffic, and support marketing. Cookies are small text files stored on your device.

Essential Cookies

Required for the website to function — shopping cart, checkout session, login state. Cannot be disabled.

Analytics Cookies

Help us understand how visitors use our website (e.g. Google Analytics). Data is aggregated and anonymised.

Marketing Cookies

Used to deliver relevant advertising and track campaign performance (e.g. Meta Pixel). Only active where you consent.

You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of our website.

§07

Data Retention

We retain your personal information for as long as necessary to fulfil the purposes outlined in this policy, or as required by law. Specifically:

  • Customer account data — retained for the lifetime of your account, plus 2 years after account closure
  • Order history — retained for 7 years for tax and accounting compliance
  • Marketing opt-in data — retained until you unsubscribe or withdraw consent
  • Support communications — retained for 2 years
  • Payment records — subject to Shopify's and payment processor's retention policies

You may request deletion of your personal data at any time (subject to legal retention requirements) by messaging us on Instagram at @proteinchefnutrition.

§08

Data Security

We implement reasonable technical and organisational measures to protect your personal information from unauthorised access, disclosure, alteration, or destruction. These include:

  • SSL/TLS encryption for all data transmitted between your browser and our website
  • Secure payment processing via Shopify's PCI DSS-compliant infrastructure
  • Limited employee access to customer data on a need-to-know basis
  • Regular review of our data security practices

No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you believe your account has been compromised, please contact us immediately.

§09

Your Rights (PDPA)

Under Thailand's Personal Data Protection Act (PDPA) and other applicable laws, you have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data, subject to legal retention obligations.
  • Right to Restriction: Request that we limit how we process your data in certain circumstances.
  • Right to Data Portability: Request your data in a structured, machine-readable format.
  • Right to Object: Object to processing of your data for direct marketing purposes at any time.
  • Right to Withdraw Consent: Withdraw consent to marketing communications at any time by contacting us.

To exercise any of these rights, message us on Instagram at @proteinchefnutrition. We will respond within 30 days. Some requests may require verification of your identity.

§10

Minors

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us and we will take steps to delete it promptly.

§11

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by posting the updated policy on this page with a revised "Last updated" date.

We encourage you to review this policy periodically. Your continued use of our services after any changes constitutes your acceptance of the updated policy.

§12

Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:

Protein Chef BKK

Data Controller

@proteinchefnutrition

Bangkok, Thailand

You also have the right to lodge a complaint with Thailand's Personal Data Protection Committee (PDPC) if you believe your data rights have been violated.