ARKHIPELAG
ToursTicketsTransportCateringDestinationsAbout
Explore Thailand Sign in
ToursTicketsTransportCateringDestinationsAboutSign in

Legal

Tour Operator LicenseTerms of ServiceRefund PolicyPrivacy Policy

Privacy Policy

Last updated: 1 September 2026

Arkhipelag (“we”, “us”, or “our”) operates the website travel.arkhipelag.com (the “Site”). This Privacy Policy explains how we collect, use, share and protect personal data when you visit the Site or book services through our marketplace, and what rights you have in relation to that data.

1. Who Is Responsible for Your Data

1.1 The controller of your personal data is ARKHIPELAG Co., Ltd., registration number 0835566018842, registered address 63/202 Moo 2, Ko Kaeo Subdistrict, Mueang Phuket District, Phuket Province, 83000, Thailand.

1.2 For any question about this Policy or about your data, contact us at support@arkhipelag.shop.

1.3 This Policy applies to data collected through the Site and the booking platform. It does not apply to the independent processing carried out by the providers who supply the services you book, by payment providers, or by other third parties for their own purposes.

2. What Information We Collect

2.1 When you make a booking, we collect:

  • your name;
  • your email address;
  • your phone number;
  • your billing country, for payment processing;
  • booking details, including the selected service, date, time, number of participants and pickup or delivery location;
  • information specific to the category you book, namely: any special requirements for a tour or activity, such as dietary requirements or a medical condition where the listing requires it; driving licence details, licence category and, where applicable, International Driving Permit details for a vehicle rental; the name to appear on a ticket and any age or eligibility confirmation an organizer requires; and the menu, headcount, venue, timings and allergen and dietary information for a catering order;
  • any messages you send us about the booking.

2.2 Because identity verification is required for every purchase, we also collect the information described in section 4, including a photograph or scan of an identity document, the data contained in that document, and confirmation that your email address and telephone number have been verified.

2.3 Where a booking is paid for by someone other than the person receiving the service, we also process the payer’s name, contact details and the confirmation of payment received from the payment provider, together with any additional verification information provided in connection with the checks described in section 4.

2.4 When you simply browse our website, we automatically collect:

  • your IP address;
  • basic browser and device information;
  • which pages you visit;
  • approximate location derived from your IP address, and referral information showing how you reached the Site.

2.5 We also use cookies to remember your preferences, such as language and currency, and to understand how visitors use our Site. Further detail is set out in section 11.

2.6 We do not deliberately collect special categories of personal data. Where a service requires health, fitness, pregnancy, allergy or dietary information for safety reasons, which is most common for activities and for catering orders, we collect only what is necessary and share it only with the provider supplying that service.

2.7 The Site is not directed to children under 16, and we do not knowingly collect data directly from them. Bookings must be made by an adult, who provides any minor’s details on their behalf.

2.8 Where we receive data from others. We also receive data from our identity verification provider (the outcome of the check and the data extracted from your document), from payment providers (confirmation of payment, billing country, fraud-screening results), from analytics providers, and from providers in connection with the supply of your service.

3. How We Use Your Information and Our Legal Basis

We use your information for the following purposes:

Purpose Legal basis
Verify your identity before a purchase can be completed, including document, email and phone checks Steps taken at your request before entering into a contract, verification being a precondition of every purchase; our legitimate interests in preventing fraud and unauthorised use of payment instruments; the identity verification requirements imposed on us by our payment service providers
Process and confirm your bookings; transmit booking details to the provider supplying the service Performance of a contract
Send booking confirmations, reminders, tickets and vouchers, and information about changes to your booking, such as weather, schedule, delivery window or cancellation Performance of a contract
Provide customer support and handle refund requests Performance of a contract; our legitimate interests
Verify payments, prevent fraud, and handle chargebacks and payment disputes Our legitimate interests in protecting customers, providers and our business
Improve our website and our listings; analytics Our legitimate interests; your consent where analytics cookies require it
Keep accounting and tax records Compliance with legal obligations
Send marketing messages about tours and offers Your consent, which you may withdraw at any time
Establish, exercise or defend legal claims Our legitimate interests

We do not sell your personal information to anyone.

4. Identity Verification, Payment Verification and Fraud Prevention

Identity verification through Didit

4.1 Verification is required for every purchase. Before a booking can be completed and a payment accepted, the person making the booking must pass an identity verification check. It is not possible to complete a purchase on the platform without it.

4.2 Why we verify. We verify identity in order to secure payments, to protect customers and providers against fraud and unauthorised use of payment instruments, and to meet the identity verification and “know your customer” (KYC) requirements applicable to us and to our payment service providers.

4.3 Who carries out the check. The check is performed through Didit, an independent identity verification provider established in Spain. Didit acts as our service provider and processes the information you submit on our behalf, on our instructions and under a data processing agreement. Didit also processes certain data as a controller for its own compliance and security purposes; its own privacy notice is available on its website.

4.4 What we collect during verification:

  • a photograph or scan of a valid identity document, such as a passport, national identity card or driving licence;
  • the data contained in that document, such as your full name, date of birth, nationality, document number, issuing country and expiry date;
  • the result of technical authenticity checks on the document;
  • your email address and confirmation that it has been verified by a code sent to it;
  • your telephone number and confirmation that it has been verified by a code sent by SMS;
  • technical data relating to the verification session, such as IP address, device and browser information, and the time and outcome of the check.

4.5 What we do not collect. The verification check does not include facial recognition, biometric comparison of your face against your document, liveness detection, or the capture of a selfie or video for those purposes. We do not collect, generate or store biometric data or biometric templates, and we do not use your data for biometric identification.

4.6 Sensitive information on documents. Identity documents can contain information we do not need, such as religion, place of birth or a national identification number. You may mask or cover any field other than your name, date of birth, document number, issuing country, expiry date and the document photograph itself. Where such information nevertheless reaches us, we do not use it and delete it in accordance with section 10.

4.7 Who else sees your document. Identity documents are never shared with the providers who supply the services you book, including tour operators, rental companies, event organizers and caterers. Where a provider needs to see a document in order to supply the service, such as a driving licence at a rental desk or proof of age at a venue, you present it to them directly at that moment; that is separate from our verification and is not carried out through us. They may be disclosed to our payment providers, to a bank or card scheme in connection with a payment dispute, to our professional advisers, or to a public authority where we are legally required to do so.

4.8 Where the data is processed. Didit is established in Spain, in the European Union. Where you are located outside the European Union, or where data is subsequently accessed from Thailand, the transfer safeguards described in section 8 apply.

4.9 How long we keep verification data. Identity documents and the data extracted from them are kept for 180 days from the date of the check, which corresponds to the period during which a card payment may be disputed, and are then deleted. Where a payment dispute or legal claim is actually raised, the relevant records are kept until it is finally resolved. The fact that a verification was completed, together with its date and outcome, is kept as part of the booking record for the period stated in section 10.

4.10 Automated decisions and human review. Verification decisions may be reached wholly or partly by automated means, and a negative result will prevent a purchase from being completed. If you believe a decision is incorrect, contact us at support@arkhipelag.shop. You may ask for the decision to be reviewed with human involvement, express your point of view, and submit further information.

4.11 If you choose not to verify. You are never obliged to submit a document. However, because verification is a precondition of every purchase, we will be unable to accept a booking or a payment from you without it. Where an amount has nevertheless been taken, it is returned in full to the original payment method.

Payment screening

4.12 Payments made through the Site are subject to automated and, where necessary, manual checks intended to detect fraud and unauthorised use of payment instruments.

4.13 Where a booking is paid for by a person other than the named customer, these checks may include verification of the payer’s identity, confirmation that the payer authorised the payment, or information about the relationship between the payer and the customer.

4.14 Payments may be declined, held or cancelled as a result of these checks, as described in the Terms of Service and the Refund Policy.

4.15 We retain records of declined and disputed payments for the purpose of preventing further fraud, for the period stated in section 10.

5. Sharing Information with Providers

5.1 To complete your booking, we share with the provider supplying the service the information they need in order to supply it. What is shared depends on the category:

  • Tours and activities: your name, phone number, pickup details, number of participants, and any health, fitness or dietary information you have provided where the activity requires it for safety reasons;
  • Transport and vehicle rental: your name, phone number, pickup details, and the driving licence information required to prepare the rental agreement;
  • Tickets: your name and, where the organizer requires it, the details needed to issue a personalised ticket or to confirm eligibility;
  • Catering: your name, phone number, venue and delivery details, headcount, menu selection, and all allergen and dietary information you have provided.

5.2 We do not share your email address or billing country with providers unless necessary, and we never share your identity document or the data extracted from it.

5.3 Allergen and dietary information is shared because a caterer or activity operator cannot supply the service safely without it. Please provide it accurately and in advance.

5.4 Providers are independent businesses. Once they receive your data for the purpose of supplying your service, they are responsible for handling it in accordance with applicable law and their own practices.

6. Other Parties We Share Data With

We also share personal data with:

  • our identity verification provider Didit, to carry out the checks described in section 4;
  • payment providers such as Stripe, PayPal or similar, to process payments, refunds and fraud checks;
  • event organizers and ticket issuers, where a ticket must be issued in your name or your eligibility confirmed;
  • service providers acting on our behalf, such as hosting, email delivery, customer-support and analytics providers, who may process data only on our instructions;
  • professional advisers, such as lawyers and accountants, where necessary;
  • public authorities, where required by law or to establish, exercise or defend legal claims; and
  • a purchaser or successor, in connection with a sale, merger or reorganisation of our business.

7. Payment Information

We do not store your credit card details. All payments are processed securely by Stripe, PayPal or similar providers. We only receive confirmation that your payment was successful, your billing country, and limited technical information such as the card brand and the last digits of the card, where the provider makes it available.

8. International Transfers

Your data may be transferred to and processed in countries other than your country of residence, including Thailand, where our operations and our providers are located, Spain, where our identity verification provider is established, and other countries where our service providers operate. Where required by applicable law, we put appropriate safeguards in place for such transfers, such as standard contractual clauses or an equivalent mechanism.

9. Your Rights

Depending on where you live, you have the right to:

  • ask what personal information we hold about you and obtain a copy of it;
  • request corrections to incorrect or incomplete information;
  • request deletion of your information;
  • object to, or ask us to restrict, certain processing, including processing based on our legitimate interests;
  • receive certain data in a portable format, or ask us to transfer it to another provider;
  • withdraw consent at any time where processing is based on consent, including consent to marketing;
  • opt out of non-essential cookies through your browser settings or our cookie controls;
  • ask for human review of an automated verification decision, as described in section 4.10.

To exercise these rights, contact us at support@arkhipelag.shop. We may ask you for information to verify your identity before acting on a request, and we will respond within the period required by applicable law.

Some rights are not absolute. In particular, we may need to keep booking and payment records to comply with tax and accounting obligations or to defend legal claims, even after you have asked us to delete your data.

If you believe we have not handled your data properly, you may complain to us first and, if you remain dissatisfied, to the data protection authority in your country or to the Personal Data Protection Committee in Thailand.

10. How Long We Keep Your Information

10.1 We keep booking and payment records for 5 years, as required for tax and legal purposes.

10.2 Identity documents and the data extracted from them are kept for 180 days, as described in section 4.9. After that period we retain only the record that a verification was completed, together with its date and outcome, as part of the booking record.

10.3 Records relating to fraud prevention, declined payments and payment disputes are kept for 5 years from the date of the event.

10.4 Marketing contact details are kept until you withdraw consent or ask us to stop.

10.5 Website analytics data is kept for 14 months.

10.6 You may request deletion of your account and associated data at any time, subject to section 9.

11. Cookies

11.1 We use cookies and similar technologies that are strictly necessary for the Site to function, that remember your preferences such as language and currency, and that help us understand how the Site is used.

11.2 You can control or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent parts of the booking process from working.

12. Data Security

We use standard security measures, including SSL encryption, secure servers and access controls, to protect your information. Access to identity documents is restricted to the members of our team who need it to resolve a verification or payment issue. No system is 100% secure, but we take reasonable steps to protect your data.

13. Changes to This Policy

We may update this Policy from time to time. The latest version will always be posted on this page with the updated date. Where changes are significant, we will take reasonable steps to notify you.

14. Contact Us

If you have questions about this Policy or your personal information, please contact us:

Email: support@arkhipelag.shop

ARKHIPELAG

ARKHIPELAG is your go-to marketplace for budget-friendly tours. We link travelers with local hosts to deliver great value and amazing memories at the best possible price.

Book

ToursTicketsTransportCatering

Destinations

PhuketSurat ThaniKrabiPhang NgaChiang Mai
See all
Chiang RaiChon BuriBangkokRayongSamut PrakanThailandTrat

Company

About ArkhipelagContactWork with us

Legal

EmailTour operator licenseTerms & conditionsRefund policyPrivacy policy
© 2026 Arkhipelag Co., LtdTravel thoughtfully