Capoeira Zoador Thailand
Privacy Policy
Last updated: 31 July 2026
Capoeira Zoador Thailand (“we”, “us”, or “our”) operates the public website at capoeira.in.th, the student portal at student.capoeira.in.th, the admin console at admin.capoeira.in.th, and related APIs at api.capoeira.in.th. This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our sites, book classes or events, use our portals, or message us on Facebook Messenger, Instagram, or LINE. We process personal data in accordance with Thailand’s Personal Data Protection Act (PDPA) and other applicable law.
1. Who we are
Capoeira Zoador Thailand is a Capoeira school based in Bangkok, Thailand, with studios at Punnawithi and Lat Phrao 64. We provide class and event information, online booking requests, student learning tools, and staff tools to manage communications and school operations.
2. Information we collect
Depending on how you interact with us, we may collect:
- Identity and contact details — such as full name, email address, phone number, LINE ID, and optional notes or social contacts — when you request a class or event booking.
- Guest information — if you book seats for guests, we record how many guests you bring (we do not separately collect each guest’s personal details on the public form).
- Account credentials — username/email and password for student or admin portals created by our staff (passwords are stored in hashed form). Students may update profile fields such as name, nickname (apelido), email, username, and phone.
- Booking, package, and attendance records — session choices, dates, course packs (for example 5 or 10 sessions), remaining credits, visit type (trial or drop-in), and related class records.
- Messages you send to our official channels — including Facebook Messenger, Instagram Direct, and LINE Official Account. For staff alerts we may store channel identifiers, sender display name, message IDs, and a short preview of the message.
- Technical and analytics data — with your consent, anonymous page-visit information (page path, external referrer, and a randomly generated visitor ID) to help us improve schedules and services. See our Cookie Policy for details.
- Device push subscription data — only for signed-in admin staff who enable browser notifications for inbox alerts.
3. Information we do not collect online
We do not process payment card numbers, e-wallet credentials, or other online payment instruments through our websites or apps. Fees for trials, drop-ins, meetups, and course packs are typically arranged and paid in person after confirmation or at the session, as communicated when you book or purchase.
We do not offer public self-registration for student accounts. Portal accounts for package students are created by authorized staff.
4. How we use Meta (Facebook Messenger & Instagram)
We use a Meta app connected to our Facebook Page and Instagram professional account so that when someone messages our school, our systems can receive a webhook notification and alert authorized staff in the admin inbox (and optionally via web push).
We use this integration to operate our school’s customer communication workflow: detect new messages, notify staff, and help staff open the conversation in Meta Inbox to reply. We do not sell message content. Message replies are handled through Meta’s own inbox tools.
Meta (Facebook/Instagram) also processes messaging data under Meta’s own terms and policies when you use those platforms.
5. How we use your information
We use personal data to:
- Receive, confirm, manage, or cancel class and event booking requests and send related emails.
- Operate student and admin accounts, attendance, course packs, and school operations.
- Notify staff about new bookings and inbound messages (LINE, Messenger, Instagram).
- Improve and secure our websites, APIs, and services (including optional visit analytics after consent).
- Comply with legal obligations where applicable.
6. Legal basis and sharing
We process personal data where needed to provide requested services (for example bookings and messaging replies), to run our school operations, with your consent (for example analytics), and where we have a legitimate interest in securing and improving our systems, consistent with the PDPA.
We do not sell your personal data. We may share data with service providers that help us host infrastructure and databases, send transactional email, store media files, or deliver push notifications, and with Meta or LINE only as needed to operate those messaging channels. We may also disclose information if required by law.
Our primary technical providers include cloud hosting and object storage (DigitalOcean), managed PostgreSQL database hosting (Supabase), and transactional email delivery (Resend). These providers process data on our behalf under their respective terms.
7. Retention
We keep personal data only as long as needed for the purposes above — for example while an account remains active, while booking/attendance/package records are required for school administration, or while inbox alert records are useful for staff follow-up — and then delete or anonymize them when no longer needed, unless a longer period is required by law.
8. Security
We use reasonable technical and organizational measures to protect personal data, including encrypted transport (HTTPS), access controls for admin tools, role-separated database access, and hashed passwords. No method of transmission or storage is completely secure; please use strong unique passwords for portal accounts.
9. Your choices and rights
Under the PDPA and other applicable law, you may request access to, correction of, or deletion of personal data we hold about you, withdraw consent where processing is based on consent, or ask questions about how we process it. Contact us using the email below.
You can change or withdraw analytics consent anytime via “Cookie settings” in the website footer. You can also stop messaging our Page/account on Meta or LINE at any time, and admin staff can disable push notifications in the admin console.
10. Children’s privacy
Our classes may include children (including CAPO-KIDS programs). Portal accounts and messaging integrations are intended to be used by parents/guardians or adult students and by authorized staff. Bookings for children should be made by a parent or guardian. If you believe we have collected a child’s data inappropriately, contact us and we will take appropriate steps.
11. Related policies
Please also read our Cookie Policy, Terms & Conditions, and Refund & Cancellation Policy published on this website. Together they describe how our services work and how we handle personal data and payments.
12. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of our services after an update means you acknowledge the revised policy.
Contact
If you have questions about this policy or wish to exercise your privacy rights, contact us at:
[email protected]